gfxgfxDen of the WORM.gfxgfx
gfx gfx
gfx
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 19, 2012, 08:54:57 PM

Login with username, password and session length

Go to http://acmectf.com for more info and file downloads!
gfx
gfx
* *   HIDE/SHOW
gfxgfx
gfxgfx gfxgfx
Search:     Advanced search
gfxgfx Home Forum Help Search Calendar Login Register   gfxgfx
gfx gfx
gfx
News

Go to http://acmectf.com for more info and file downloads!
Pages: [1]   Go Down
Print
Author Topic: Careful..Mods can be backdoored  (Read 831 times)
0 Members and 1 Guest are viewing this topic.
virus.357
Grenade Spammer
**

Karma: +6/-2
Offline Offline

Posts: 143


View Profile
« on: December 15, 2005, 08:22:12 AM »

Does the Acme q4 server require any mods other than instagib? If so, I probably don't need the security risk.

I wouldn't recommend installing a Quake 4 mod unless it was very well known, or open-source. The reason is that a4 mod authors have the ability to backdoor your system.

An unethical Quake 4 mod author can write a mod as bad as any Trojan horse or virus. Quake 4 Mods can attach to running processes on your system, scan the contents of ALL files on your hard drive (not just in the quake folder), take screen captures of your PC, read open window contents (potentially passowrds, credit card numbers, etc.).

There is no way to block the mod from sending info from your system back to the author. The reason is that such mods act like rootkits by communicating using the same TCP/IP channel that quake is using. So if you are allowing Q4 to run, then the mod data is also piped through the Q4 port that you have opened.

To give one example, here the following shows what an ETHICAL anti-cheat tool can do with your system:
http://www.rootkit.com/newsread_print.php?newsid=371

Keep in mind that Blizzard is an ethcial company, and their software is very careful to protect your privacy. I am highly in favor of professional anti-cheat products like this one. But you can see how much info a game plug-in can gather.

Unfortunately, some mods collect a lot more data than this. Now, imagine an unethical mod writer who is just out to collect Paypal addresses. He won't be bound by the ethics by which Blizzard and other companies have to abide.

I'm sure the mods WORM use are fine. But it's really about trusting the mod author. Unless it's open source, you are putting the trust (and potentially complete control) of your entire system up to the author of the mod.

If you are playing from a gaming console and you don't really care if your system is compromised, fine. Go ahead and play. You are not at great risk (other than potential sniffing attacks on your LAN). But for those of us who play from work or from an important home system, beware.

I for one won't be playing on ACME's q4 server until there is a way to verify the security of the mods used. I hope server admins will be careful, and that they will insist on as much trasparency for the end-user as possible.
Logged

357 CLAN OWNS YOU!
WORM
Site Admin & Server God
Administrator
Powerhouse, TBH
*****

Karma: +715/-304
Offline Offline

Posts: 4654



View Profile WWW
« Reply #1 on: December 15, 2005, 09:14:55 AM »

This is true of any mod and/or any game, not just Q4.

We are currently running three Quake4 servers, I didn't announce the last one started. They are:

Instagib on port 28004

Q4Max on port 28005

Arena CTF on port 28006 (the Arena CTF that came with the game and standard maps)

I trust the mods we are running now and haven't seen any unusual traffic or processes running.

This is all a moot point anyway because we will probably take the whole  box down after the first of the year. In case anyone hasn't noticed, Q4 multiplayer is on life support already....CTF anyway.
Logged

hell is other people
greider
Asshole Extraordinaire
Global Moderator
Powerhouse, TBH
*****

Karma: +108/-75
Offline Offline

Posts: 521



View Profile WWW
« Reply #2 on: December 15, 2005, 09:17:53 AM »

The instagib mod it's running now is only modified script def files and such. Anyone who knows how to get to the def files can open them and view them.
Logged

Wow isn't this childish.. well so long. Good luck continuing a community with such blatent assholes for admins
virus.357
Grenade Spammer
**

Karma: +6/-2
Offline Offline

Posts: 143


View Profile
« Reply #3 on: December 15, 2005, 09:24:42 AM »

yeah it's going to take a while for the hardware in people's PCs to catch up to Quake4.

also I didn't even know the game was out until this month...there was not much fanfare. It takes time for the word to spread.

I think once some good maps come out things will pick up. It took years for some of the good q2 maps to come out.

Without Punkbuster support for q2 there is no way to keep ahead of the cheaters anymore. So evolution will force us all in to q4ctf eventually. It's probably the best CTF game around, after q2ctf.
Logged

357 CLAN OWNS YOU!
RidetheLag
ACME Admin
Grapple Monkey
*****

Karma: +46/-6
Offline Offline

Posts: 260



View Profile
« Reply #4 on: December 15, 2005, 10:46:05 AM »

does q4ctf have grapple?
Logged
WORM
Site Admin & Server God
Administrator
Powerhouse, TBH
*****

Karma: +715/-304
Offline Offline

Posts: 4654



View Profile WWW
« Reply #5 on: December 15, 2005, 12:39:39 PM »

Quote from: RidetheLag
does q4ctf have grapple?


No..and that was just stupid to release it without one.
Logged

hell is other people
EternalJinX
Guest
« Reply #6 on: December 16, 2005, 12:02:19 AM »

i agree.  doesnt seem like many people playin but then again how many people can actually run it.  I run it but not pretty.  I need a new vid card on a brand new screemin fast machine.  I was not really impressed with the multiplay.  With as kool as the singlplay is they couldnt come up with a little bit more for the new mellinium.  I have been a long time very loyal quake fan since q1 and have just been totally adicted to q3 since the day it came out.  I was getting lil bored with q3 and was waiting for this game for a long time.  Connected to a server and was like wtf this runs like shit.  So what did I do?  Tweeked the config.  Now it looks like q3. So what the hell was the point.  It is as if i am playing q3 with shitty maps.  I am starting to get used to some of the maps but god wtf.  I wanted to be in awe when this game came out like i was when q3 came out going from q2 to q3.  They sold us the game now they want us to make it better errr dont make no sense.

I do like the arena ctf though reminds me of team arena for q3 w00t.
well maybe i just wont be happy till insta freeze comes out for q4.  Thats my fav mod for q3
Logged
ekauq
Powerhouse, TBH
*****

Karma: +152/-389
Offline Offline

Posts: 888


now, mes petits...


View Profile
« Reply #7 on: February 28, 2006, 10:07:34 PM »

wait....i thought you LIKED being backdoored...
Logged

:. :: :.
Pages: [1]   Go Up
Print
Jump to:  

IRC
Last 10 Shouts:
May 04, 2012, 02:22:47 PM
back up now...no cause for alarm. please proceed to your favorite map
May 04, 2012, 02:17:57 PM
i knew it was hardware!! =x
May 04, 2012, 01:45:54 PM
We have a hardware issue with acmectf.com server. NOC is working on it.
April 27, 2012, 05:29:36 PM
FFS, why do problems always come in pairs or more?  BIOS memory chksum errors now on another PC......grrrrr
April 27, 2012, 05:08:11 PM
You're doing a great job Targe+!
Links



Recent
[Today at 11:52:09 AM]

[May 18, 2012, 12:53:23 PM]

[May 17, 2012, 04:09:50 PM]

by ex
[May 16, 2012, 12:43:40 PM]

[May 14, 2012, 02:44:22 PM]

[May 14, 2012, 01:46:24 PM]

[May 14, 2012, 12:38:09 PM]

by WORM
[May 12, 2012, 03:07:44 PM]

by S!
[May 12, 2012, 06:38:11 AM]

by S!
[May 12, 2012, 06:22:10 AM]
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Cerberus / TinyPortal v0.9.7 © Bloc
Valid XHTML 1.0! Valid CSS!
gfx
gfxgfx gfxgfx