1. Trouble with the game?
    Try the troubleshooter!

    Dismiss Notice
  2. Issues with the game?
    Check the Known Issues list before reporting!

    Dismiss Notice

I'm so confused.

Discussion in 'General Discussion' started by MarcDoesRacing, Jul 25, 2024.

  1. MarcDoesRacing

    MarcDoesRacing
    Expand Collapse

    Joined:
    Dec 21, 2022
    Messages:
    570
    0.32.5 is the most urgent an update has been released and I didn't notice it until two days after it released. Why are the patch notes so vague? And why are mod approvals suspended until further notice? What is going on?
    Screenshot2024-07-25085649.png
     
  2. catchow1977

    catchow1977
    Expand Collapse

    Joined:
    Jun 2, 2022
    Messages:
    1,657
    wait I think I remember some sort of hack going around that exploited a beam vulnerability through mods
    --- Post updated ---
    its probably related to that
     
    • Like Like x 1
  3. RealVector

    RealVector
    Expand Collapse

    Joined:
    May 19, 2023
    Messages:
    625
    you mean the whole Disney thing? yeah that might be it...
     
  4. MarcDoesRacing

    MarcDoesRacing
    Expand Collapse

    Joined:
    Dec 21, 2022
    Messages:
    570
    deleted
     
    #4 MarcDoesRacing, Jul 25, 2024
    Last edited: Jul 25, 2024
  5. RealVector

    RealVector
    Expand Collapse

    Joined:
    May 19, 2023
    Messages:
    625
    it was all over some subreddits for a day, I mean hacking Disney is a pretty big thing...
     
  6. MarcDoesRacing

    MarcDoesRacing
    Expand Collapse

    Joined:
    Dec 21, 2022
    Messages:
    570
    Off-topic but didn't you used to be VinsWie?
     
  7. RealVector

    RealVector
    Expand Collapse

    Joined:
    May 19, 2023
    Messages:
    625
    yeah... the name change was done a few days ago. The main reason was that there was a Steam scammer going around using my name and obviously I didn't want to be associated with that guy. And btw: if any of you got a Steam message with a guy using my previous name asking you for gift cards or anything, that was not me!
     
  8. MarcDoesRacing

    MarcDoesRacing
    Expand Collapse

    Joined:
    Dec 21, 2022
    Messages:
    570
    Man Steam scammers are smart in the most annoying ways.
     
    • Agree Agree x 3
  9. Blood-PawWerewolf

    Blood-PawWerewolf
    Expand Collapse

    Joined:
    Jan 18, 2016
    Messages:
    702
    yeah BeamNG has gotten front-and-center attention by everyone, including law enforcement (possibly due to it being theft of confidential information).

    i wouldn't be surprised if they halted everything due to an investigation, that might include current development.
     
    • Agree Agree x 1
  10. RealVector

    RealVector
    Expand Collapse

    Joined:
    May 19, 2023
    Messages:
    625
    I really just hope they don't get in a legal fight with Disney because we know how those end...
     
  11. catchow1977

    catchow1977
    Expand Collapse

    Joined:
    Jun 2, 2022
    Messages:
    1,657
    it was the same group that hacked Disney but the beam exploit was not used in the hack to my knowledge and even if it was used why would beam be at fault that the hackers hacked them
     
    • Agree Agree x 1
  12. RealVector

    RealVector
    Expand Collapse

    Joined:
    May 19, 2023
    Messages:
    625
    yeah, I mean the Beam even warns not to download from these shmitty Russian sites and if the employee is just too incompetent to not download everything without checking, he shouldn't even be working for such a company in the first place
     
    • Agree Agree x 2
  13. Lordlichi2006

    Lordlichi2006
    Expand Collapse

    Joined:
    Apr 4, 2021
    Messages:
    1,272
    suposedly a modland mod (suposedly a mk4 golf leaked mod) on some disney guys work computer and thats how he got hacked
    i think they are trying to patch the hack but workarounds may have been found so thats why the .32.5 update. most likely someone has tried to upload viruses to the repository and since they may be hard to check for the virus they have just halted any mod uploads until they can fi xit
     
    • Like Like x 2
  14. r3eckon

    r3eckon
    Expand Collapse

    Joined:
    Jun 15, 2013
    Messages:
    592
    I doubt they allow obfuscated code in repository mods which means it'll be pretty much impossible for malicious code to go unnoticed on the repo, though they might double down on their verification process especially if there are lua scripts, even more so if said scripts contain calls to the LuaJIT FFI library (which I'd be willing to bet is the case only for a very tiny minority of mods on the repo).

    Patching the actual vulnerability might be tricky, because running C code is a part of LuaJIT and from what I've seen looking at vanilla code it's used quite a bit. We might see something along the lines of an in-game "antivirus" that detects mod scripts that contain the FFI library and blocks loading of that script during game start unless it's a verified repo mod or has been manually added to a whitelist by the player, with some UI message after launch about potentially dangerous mod files being detected.

    At this point if you're seeing that message after installing some modland meshslap on your 80+ billion dollar yearly revenue company work computer and you allow it to load, there's nothing anyone can do to help you.
     
    • Like Like x 5
  15. Lordlichi2006

    Lordlichi2006
    Expand Collapse

    Joined:
    Apr 4, 2021
    Messages:
    1,272
    i mean that multiple ppl might have tried to upload it and incase it gets past them they have stopped repo uploads temporarly
     
  16. Blood-PawWerewolf

    Blood-PawWerewolf
    Expand Collapse

    Joined:
    Jan 18, 2016
    Messages:
    702
    and knowing that the code for the malware is now public, i wouldn't be surprised if that's the case.
     
  17. brunifdez

    brunifdez
    Expand Collapse

    Joined:
    Nov 8, 2023
    Messages:
    172
    I really hope this serves as a clear example to why you should never download mods from any other website that isn't the Official Beamng Forums or Repository, and hopefully we can get each one of them banned out of the internet
     
  18. TalksWithNoise

    TalksWithNoise
    Expand Collapse

    Joined:
    Jul 10, 2023
    Messages:
    260
    Does anyone know if there’s proof showing the supposed hacker/hackers claimed it was a Disney manager downloading a game mod? They’ve been plastering malware all over the internet, and a few sources use them as their reference. But after looking at their site and Twitter all I see is a fabricated publicity stunt identity and motives alongside a few flaunty blog posts. Nothing reputable outside of news sources (which are known for snowballing off of each other and get things wrong) indicate the Disney situation was even tied to a game mod.
     
    #18 TalksWithNoise, Jul 26, 2024
    Last edited: Jul 26, 2024
    • Agree Agree x 2
  19. brunifdez

    brunifdez
    Expand Collapse

    Joined:
    Nov 8, 2023
    Messages:
    172
    The only "source" I could find which talked about a beamng mod was from a Gaming Newspage called "PCGamer" which does not have any actual proven source: https://www.pcgamer.com/software/se...-and-says-its-because-club-penguin-shut-down/

    More trustable sources like BBC News DO NOT mention anything related to beamng nor any game mod: https://www.bbc.com/news/articles/cprq1d280ggo

    Same with CNN, who claims the hacker had access to "cookies" and was Russian: https://edition.cnn.com/2024/07/15/business/internal-disney-slack-leak-hacker-group/index.html

    Then there's this other website called "Cybersecuritynews" where they talk about the user NullBulge and his "hacking methods" which he used to leak Disney's data. Here it is also mentioned that he targeted beamng players so that kind of implies he used mods to do so: https://cybersecuritynews.com/tools-used-nullbulge-disney-slack-leak/
    Again, this might not be a trusted source :confused:

    Edit: there's another post by "TheDrive.com" where it is indeed claimed the hack was done through a beamng mod: https://www.thedrive.com/news/cultu...ng-sim-to-pull-off-massive-disney-data-breach
    I do not know how trustable this news source is though
     
    #19 brunifdez, Jul 26, 2024
    Last edited: Jul 26, 2024
    • Like Like x 2
    • Agree Agree x 1
  20. TroLLeX_

    TroLLeX_
    Expand Collapse

    Joined:
    Sep 18, 2016
    Messages:
    226
    The mentioned privilege escalation exploit has already been fixed since version 0.32.3 on the 09.07.2024 aka a month after its report which happend on the 03.06.2024. The reason why users or companies may have a case is not just because it took that long to fix it, but also because the company didnt warn their users about it as soon as they got to know about it (maybe commercial users got warned? idk). Even after the fix, there was no statement about it. Thats where i see potential liability.

    But be aware that not just luajit can be the cause to escape the environment, the cef of the game is also super old and likely attackable if you just give it a dive. Good that there are some people looking into each and every part of this game right at this moment to find everything that could maybe be misused. The fix in 0.32.5 is pretty much just another outcome of that. Which is good, but id wish the company to be more open to its users when someone discovers something not just insiders
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice