• Found a backdoor in [Harry Potter] Magic Wand...
    59 replies, posted
-snip-
There's literally no difference between uncommenting it or just repasting it
I'm willing to bet this guy just happened to miss the uncommented code.
-snip-
As many have said before it is a breach of trust. Malicious backdooring to steal everything you own? No, I doubt this guy knows how to do that. Being able to go on servers that trusted your coding and completely fuck their serverbase up so they rage, or just giving yourself special "perks"? You coded so others can use, you shouldn't be giving yourself any special privileges.
[QUOTE=Willox;45545775]So I can add commands to spawn me every weapon a server has and give me god mode to my addons?[/QUOTE] Yes still allowed as it's your script. Still a "harmless" script that won't give you access to the server files or ranks or block the owner from accessing it. Wont make you a lesser dick tho and people will give you a bad reputation for it.
[QUOTE=Nak;45551091]Yes still allowed as it's your script. Still a "harmless" script that won't give you access to the server files or ranks or block the owner from accessing it. Wont make you a lesser dick tho and people will give you a bad reputation for it.[/QUOTE] What about making it so it gives you admin when you join the server? Or force sv_allowdownload/upload to 1?
If you really have to add bullshit power for yourself in your own scripts at least have the decency to make it so it enables only on your own servers , and explain it properly with a comment in your code. The whole "it's my script I do what I want" is fair and all but you're still giving it to thousands of people ( if the addon is liked enough ), and the last thing an owner wants is to go look through each addon on his server, extract them and look for this kind of unexpected behavior in the code.
I like how the only one who thought this post was "Dumb" was the creator of the addon. :rock:
[QUOTE=Damnedone;45557802]I like how the only one who thought this post was "Dumb" was the creator of the addon. :rock:[/QUOTE] this post is dumb because this piece of code isnt backdoor
[QUOTE=Robotboy655;45534696]This isn't a "backdoor", it's a hidden/blocked "feature".[/QUOTE] [QUOTE=HK47;45561874]this post is dumb because this piece of code isnt backdoor[/QUOTE] Are you serious? Of course it is a backdoor, what else would it be? [QUOTE=]A backdoor in a login system might take the form of a hard coded user and password combination which gives access to the system[/QUOTE] Source: [url]http://en.wikipedia.org/wiki/Backdoor_(computing)[/url] It's essentially the same thing but intead of granting access to the system it grants access to a weapon or whatever. Stuff like this should not be on the workshop and people who release code like that should be banned from the workshop.
There's no such thing as "banned from workshop", and a backdoor is usually a way to get control over a server through a backdoored addon, but you are kind of correct.
[QUOTE=syl0r;45562398]Are you serious? Of course it is a backdoor, what else would it be? Source: [url]http://en.wikipedia.org/wiki/Backdoor_(computing)[/url] It's essentially the same thing but intead of granting access to the system it grants access to a weapon or whatever. Stuff like this should not be on the workshop and people who release code like that should be banned from the workshop.[/QUOTE] as said Robotboy its not backdoor anyway i commented this stuff and removed secret spells and never add this functions to my addons
Just stating it's not a backdoor does not change the truth. I would also like to point out that whether something is a backdoor or not does not have anything to do with the severity of the things you can do with it.
[QUOTE=HK47;45562871]as said Robotboy its not backdoor anyway i commented this stuff and removed secret spells and never add this functions to my addons[/QUOTE] It doesn't matter whether it is or not, such code is considered malicious and is bannable.
[QUOTE=Robotboy655;45562935]It doesn't matter whether it is or not, such code is considered malicious and is bannable.[/QUOTE] then you will ban my addon even after i commented and removed this "backdoor"?
[QUOTE=HK47;45562945]then you will ban my addon even after i commented and removed this "backdoor"?[/QUOTE] No as long as it stays commented out or removed.
[QUOTE=HK47;45562945]then you will ban my addon even after i commented and removed this "backdoor"?[/QUOTE] It's not a "Backdoor". it's a backdoor. It could print gibberish in the console. Still a backdoor. If you want to feel better about it, you can call it a "Special ability granted to only the creator of the addon, designed to kill everything instantly and unfairly". Oh wait that sounds worse. Anyway, just because you removed it when someone noticed it, doesn't mean it's excused. If you throw a rock at someone and miss, it doesn't make you any less prone to getting beat up.
[QUOTE=LauScript;45563827]It's not a "Backdoor". it's a backdoor. It could print gibberish in the console. Still a backdoor.[/QUOTE] I guess the uploader of the Sammy Server's Textscreen on the workshop that advertises a minecraft host should be crucified then.
pretty big discussion on something that doesnt fucking matter
[QUOTE=Walrus Viking;45564808]pretty big discussion on something that doesnt fucking matter[/QUOTE] To you it may not matter, But to them it seems too.
[QUOTE=Walrus Viking;45564808]pretty big discussion on something that doesnt fucking matter[/QUOTE] Maybe not to you.
Yeah it doesn't really matter that someone could join someones server and kill everyone with no way to figure out who. Not a problem at all! [QUOTE=Shinycow;45564117]I guess the uploader of the Sammy Server's Textscreen on the workshop that advertises a minecraft host should be crucified then.[/QUOTE] No but why even have it there. Everyone is going to remove it. This isn't quite the same though - it has malicious intent.
[QUOTE=LauScript;45565021]Yeah it doesn't really matter that someone could join someones server and kill everyone with no way to figure out who. Not a problem at all! [/QUOTE] If you don't actually look at what you put on your server then you shouldn't even run a server in the first place.
[QUOTE=StonedPenguin;45565388]If you don't actually look at what you put on your server then you shouldn't even run a server in the first place.[/QUOTE] That is 100% true. And if you're going to put malicious content in your workshop releases you should be banned from the workshop.
[QUOTE=StonedPenguin;45565388]If you don't actually look at what you put on your server then you shouldn't even run a server in the first place.[/QUOTE] No one reads through every line of code, you assume the poster isn't a twat.
[QUOTE=Baron von Hax;45565441]No one reads through every line of code, you assume the poster isn't a twat.[/QUOTE] Actually it's pretty common for server owners to read through code because they usually are scripters themselves. But that isn't so simple in a workshop addon anyway and no experienced user is [b]ever[/b] going to be putting workshop addons on their server.
[QUOTE=LauScript;45565455]Actually it's pretty common for server owners to read through code because they usually are scripters themselves. But that isn't so simple in a workshop addon anyway and no experienced user is [b]ever[/b] going to be putting workshop addons on their server.[/QUOTE] Even though that USED to be the case, this is far from true in the current Garry's Mod scene. Most servers are owned by people who know jackshit of what they are doing.
I know a lot of people will disagree with me, but imo it should be the responsibility of whoever is using the free addon that someone else spent their time making to check it. Obviously malicious code is a dick move, but I don't think in the case of this wand item it was.
[QUOTE=nazer1290;45566045]I know a lot of people will disagree with me, but imo it should be the responsibility of whoever is using the free addon that someone else spent their time making to check it. Obviously malicious code is a dick move, but I don't think in the case of this wand item it was.[/QUOTE] What the fuck makes you think that? The coder placed the backdoor and he should be punished for doing so. If the coder wants his time to be rewarded then he should release his god damn plugin on coderhire not on the workshop.
Sorry, you need to Log In to post a reply to this thread.