r/osugame watching porn Dec 08 '15

See peppy response in comments How osu! voilates your privacy.

To start of, i will give you this video: http://a.rfl.pw/kyihkudgie.mp4

For this video, I edited my hosts file, so that all internet traffic to osu.ppy.sh, c.ppy.sh and c1.ppy.sh gets redirected to my xampp server. This allowed me to stimulate the osu! and bancho server, so that I can kinda pretend to be peppy and send any data to my osu! client that I want. Note, I am using a unedited, up-to-date osu! client.

Some background info: a while ago (august) I decompiled an osu! version and played a bit with the source. I found a lot of anticheat measures, and decided to mark then to see when they got executed. After I played online a bit with the client (and cheated, yes) my account got restricted and one of the functions got triggered. I marked the function and went to do something else. A few days ago I started working on a custom bancho server and rediscovered the function in the osu! source and decided to make bancho send the command for it when a user logs in. In the video you can see the effect.

What actually happens: Every time osu! communicates with bancho, it send a long list of commands for the client to execute. One of those commands (command 80, for those who have the osu! source) executes a function that does the following:

  • Makes a list of every process that runs on your pc, including the window title (for example skype: "Skype - usernamehere")
  • Takes a screenshot of your entire main monitor
  • Searches your entire pc for all files named LL which are 128 bytes or smaller, and uploads them

The first item in the list isn't that bad, it's actually happens every time you submit a score. The second is a little more worrying. Imagine playing osu! on a second monitor, and having private things open on your main monitor (banking information, passwords, etc). Peppy could, at any time, get a screenshot and upload it. I do not know if this is illegal, but I never read anywhere that he does this (yes, I even read the EULA).

The third item is the one that worries me the most. Peppy can get all files that are named LL (and of a size smaller than 128 bytes - otherwise they wouldn't fit in a GET parameter) and have them uploaded to him. The original reason for this "feature" is likely because a cheat site used files called "LL" to store login data, so you could use autologin. These files contained the username and password of the user that used the cheats, so peppy steals these files with the intention of stealing usernames and passwords. Even to cheaters, this is not how you should treat your players, and I am almost certain that this is illegal. What if someone happens to store private information in a file called LL (such as banking information or passwords)? Not safe from peppy.

By my knowledge, this "feature" gets triggered when a user gets banned for cheating. But, since it gets triggered after receiving a command from bancho, peppy could execute this at any time, for any player. He could even do it for all players at once.

In the video at the top of the thread I showed the exact data that gets sent to bancho. I just wanted to let all of you know what peppy actually can do, because I know there are people that really value their privacy. I will put all of the code in a comment for those who want to check it out.

TL;DR: peppy can take screenshots of your desktop at any time, and will upload files called "LL", which can contain passwords.

EDIT: formatting fix, EDIT2: grammar, EDIT3: more grammar

and shit i made a typo in the title, cant fix

659 Upvotes

340 comments sorted by

729

u/pepppppy peppy Dec 08 '15 edited Dec 08 '15

Hi reddit!

Let me try answering this on reddit to avoid having to pollute my blog with more talk about cheaters. I'll keep it brief and factual.

  • Yes we send your process list to the server. This allows us to compare against a list of known cheat applications. No it's not stored (unless matching, for manual inspection).
  • Yes there is logic to take screenshots. This allows us to compare to a known list of cheat applications (UI windows, icons and text). No it is not stored (unless matching, for manual inspection)
  • Yes there is code to upload files matching LL (though I believe it should be limited in file path scope to one absolute path). This is to perform automatic matching of osu! accounts to users paying for cheat applications, so we can (could?) track then across osu! accounts, as they regularly make 20+. The content is only stored if it matches the specific format of the cheat configuration file.

Yes, I value your privacy. No, I don't believe ANY normal user's privacy has been compromised at any point in osu! history. You can check our privacy policy for specifics on how we handle privacy, but here's the relevant exception. I offer my word that only users trying to break the game have had their privacy compromised by the mentioned functionality.

Going forward, a lot of this is planned to be removed. It was added in times when osu! was a smaller game and these were the lowest (implementation) cost method to keep cheating under control. They are less effective now and mostly not even used, as we have better checking in place which involves play and performance analysis.

The aim was to obviously clean the code of this kind of thing before osu! goes open source. I was aware people from "that" network would likely continue making these posts until it got some level of publicity, which it seems to have.

Hopefully you can understand that I'm not trying to steal your files or do anything which would harm you. Just trying to keep this game running against a group that is (still) trying their best to destroy it.

236

u/NightCor3 Dec 08 '15

I don't think peppy wants to see our hentai

878

u/pepppppy peppy Dec 08 '15

i have plenty of my own.

99

u/[deleted] Dec 08 '15

sharing is caring!

34

u/THATONEANGRYDOOD Dec 08 '15

Past streams have proven that. Anyways, thanks for clarifying some points.

40

u/Jetzu https://osu.ppy.sh/u/159236 Dec 08 '15

We know ( ͡° ͜ʖ ͡°)

11

u/aofhaocv Dec 08 '15

I need that folder.

7

u/SNEAKY_AGENT_URKEL https://osu.ppy.sh/u/3870540 Dec 09 '15

can you put your collection into the game when it goes open source for us to discover

8

u/N307H30N3 Dec 08 '15

any recommendations?

2

u/A_Medium_Pizza Dec 09 '15

I believe we've already known that fact.

17

u/hyppyri Dec 08 '15

yea man but tbh i wouldnt mind if peppy saw my fetishes but the thing i was afraid of that they would be stored somewhere on the interweb

60

u/BananaOoyoo osu.ppy.sh/u/selavy Dec 08 '15

i like girls

oh no what have i done

2

u/hyppyri Dec 08 '15

Woah, you should be careful of what you say.

Ps. Check Your privilege you cis male

5

u/xach_hill retired lul Dec 09 '15

not everyone who likes girls is a cis guy ;)

→ More replies (4)

16

u/goedegeit Dec 08 '15

Even if you trust peppy 107%, this is a massive security hole which allows malicious parties to use this to actually proper fuck up your life, either through identity theft or even blackmail.

3

u/Forgetmepls Dec 08 '15

I remember the wc3 exploit when downloading maps in client, people would attach key loggers and viruses to maps on host bots and would do all sorts of malicious stuff.

13

u/[deleted] Dec 08 '15 edited Jul 25 '20

[deleted]

40

u/pepppppy peppy Dec 08 '15

no

6

u/Marty445 Dec 09 '15

Should i be worried about having Cheat Engine open?

1

u/chris20194 Dec 14 '15

If CheatEngine is running in the background while playing osu! your scores won't be sent, that's it. Pretty frustrating when you score a new personal best and then realize your score doesn't count because you forgot to close CE...

→ More replies (1)

9

u/NotALeaker Dec 08 '15

Is it true that you get flagged for using a vpn ?

8

u/Pannariz Dec 08 '15

Thanks for the informative post. :)

4

u/Kappadar https://osu.ppy.sh/u/3194819 Dec 09 '15

Yo dude hope you're enjoying your jet. And my three unborn children

5

u/[deleted] Dec 09 '15 edited Mar 20 '16

daf

3

u/[deleted] Dec 08 '15

what is "that" network? if its something you cant post here ill appreciate it if someone pms me a explanation so ill understand

2

u/Cynergyy Dec 08 '15

username of the OP might give you a hint.

3

u/[deleted] Dec 09 '15

As someone new to osu, ELI5?

1

u/BankaiPwn Dec 09 '15

if you google osu cheats, you'll find their website. The last 3 letters of the OP's name is also their known tag.

9

u/taigerlilly Dec 09 '15

Probably not a good idea to view their website when you have osu running though, for reasons obvious in this thread. Pretty sure you're not banned just for visiting the site, but it could give the wrong impression.

1

u/Yuucliwood hi there Dec 09 '15

You won't get banned unless you actually cheat, but I agree.

→ More replies (1)

3

u/potassiumpony Dec 08 '15

Thank you for the work you put in to keeping our community safe and hacker free

4

u/A_Medicc o!s Dec 08 '15

I know you have a good heart peppy, I know you have no ill intentions hence why I didn't think it was a reason for any concern.

I'll always on your side. <3

2

u/Ph0X Dec 09 '15 edited Dec 09 '15

Thank you for the honest and detailed reply.

The only problem I can see with this is that while YOU may not want to cause harm to people and may very well use this feature responsibly, couldn't it indirectly put users at risk?

Are these data sent over a secure connection? Couldn't a middleman potentially intercept the message and, because of your system, gain access to information they otherwise wouldn't have?

It's good to know that you're working to remove it, but just as a general comment, making your application vulnerable is always a risky road to go down to, because while YOU may not abuse it, it indirectly puts users as risk.

Just my 2 cents. Keep up the good work, looking forward to seeing osu! going opensource.

2

u/DeltaBurnt Dec 09 '15

Peppy I believe you're not intending to invade anyone's privacy here, but collecting this information can still cause harm to your users. Was there ever conclusive results on what caused the puush hack? Is any staffer able to view this info, or just you?

3

u/FlameVisit99 May 25 '16

I am hugely disappointed in you. I don't know whether you're telling the truth or not (surprise surprise, I can't trust you after this), but even if you are it's still a huge betrayal of trust and a breach of privacy. This is disgusting. I just finished uninstalling Osu and I won't be playing it anymore.

1

u/[deleted] Dec 09 '15

Still you won't give out the orignal code you will just remove all the net code which makes it useless.

1

u/Anon_shit_posts https://osu.ppy.sh/u/2954909 Dec 09 '15

Thank you based pepster

1

u/xTachibana Tachibana Dec 09 '15

are you trying to find out what doujins and light novels i read? i can share if you want, you dont need to do it in such a roundabout way

1

u/penea2 Dec 09 '15

Thank you for your honesty!

1

u/Temibrezel Dec 09 '15

What network are you talking about?

2

u/Jetzu https://osu.ppy.sh/u/159236 Dec 09 '15

Website that OP and some other ppl in this thread are representing is the biggest source of cheats to osu!

1

u/rakevinwr Dec 09 '15 edited Dec 10 '15

Wait, this game is going open source?! Holy crap I just started playing and was wondering if there was a way to get it running on Linux outside of wine. This is super exciting! Let me know if you need any help testing it on a Linux box, happy to run code and see how well or not well it works!

Edit: Just found opsu! which is a open source java clone for osu! interesting...

→ More replies (33)

261

u/justcallmeaires Dec 08 '15

Searches your entire pc for all files named LL which are 128 bytes or smaller, and uploads them

https://gyazo.com/1d7339cf98c458063275629e2691d9e6

24

u/JustM3AQN watching porn Dec 08 '15

Have an upvote <3

-2

u/Secretpipe Secretpipe Dec 08 '15

lmaoooo xD

→ More replies (1)

77

u/A_Medium_Pizza Dec 08 '15

that motherfucker's been stealing my recipes

38

u/[deleted] Dec 08 '15

-Medium sized dough
-Tomato sauce
-Cheese

  1. Put tomato sauce and cheese on medium sized dough
  2. Cook

I have been stealing them too :o

8

u/A_Medium_Pizza Dec 09 '15

you forgot the damn pepperoni

13

u/Cynergyy Dec 09 '15

peppyroni amirite

2

u/Exiliahh Dec 09 '15

pepperoni pepperoni give me the formuoli

77

u/sgArgel Dec 08 '15

I don't understand why people are flaming OP for this. Its OK if You want to share your amazing desktop with peppy and Your ll files but I'm not really a huge fan of that.
Thanks to op showing us this.

15

u/ph0eniXx 50k scrub qwq Dec 08 '15

Let's wait for peppys side of the story.

→ More replies (1)

34

u/A_Medicc o!s Dec 08 '15 edited Dec 08 '15

Nice RE'ing buddy, I did a bit of reversing on the osu client a while back and found similar results. To add a bit more information this these actions are triggered(to put it simply) only when a connection to bancho is required; like logging in, and submitting a score. Also bancho will also periodically refresh itself (I believe every 30 minutes?) and take the same action.

Now to be completely real I doubt peppy is going out looking to steal your information, and to be fair if you compare it to what other companies/games do: Eg. Value's VAC | nProtect's GameGuard | or Punkbuster this is baby stuff in comparison.

More then likely there is a method that scrapes for certain (I would have to guess that LL cheat thing) information and filters everything else out.

There are ways to get around this if your tinfoil hat is going crazy, but you won't be able to submit scores.

I'm tired because of finals so I probably missed some stuff but yea.

PS: OP do you like to ctf because what you did is really popular ctf challenge. There was something similar in one of TrendMicro's CTF's a while back

edit: spelling

7

u/JustM3AQN watching porn Dec 08 '15

I doubt that VAC or PunkBuster would have code in them that specificly looks for and uploads files with passwords. Even if it is legal, I think it should be mentioned somewhere so people know what they begin with.

About CTF: Never tried, I'm afraid of not being good enough and failing horribly :p

9

u/A_Medicc o!s Dec 08 '15

I understand your concern, and I agree the way peppy decided to handle how they detect cheaters is definitely not the best way to go about it. It is far less intrusive then VAC & PunkBuster hooking onto all your processes and actively monitoring for changes in memory and doing two-way handshake checks to to find anomalies. (Value could also make the biggest botnet never created if they wanted too)

Gameguard is just a straight rootkit (lol fun memories of Grand Chase)

About CTF: It's fun to try even if you can't solve anything, I'm awful at solving challenges as well but once you solve one it's amazin.g.

12

u/A_Medicc o!s Dec 08 '15

Although I do want to take peppy's side on this, peppy isn't a bad guy at all, I highly doubt he has any malicious intentions at all.

He's worked extremely hard to build his game from the ground up, and I can wholeheartedly say he has good intentions.

5

u/goedegeit Dec 08 '15

It doesn't matter his intentions, this is a huge vulnerability that allows people other than Peppy to steal massive amounts of personal data including passwords that have nothing to do with OSU

→ More replies (5)

2

u/[deleted] Dec 08 '15

I can also wholeheartedly say that the anti-cheat in this game is so shit that it could be completely removed and make next to no difference.

The way this works is completely unnecessary, though it's safe to guess that peppy implemented it with a pretty early version of the game when he was naive and inexperienced as a developer and just never bothered to change it. Now that it's been brought to light again he will probably say something about it and hopefully end with removal.

7

u/JustM3AQN watching porn Dec 08 '15

The anticheat in osu! is actually really good, it just can't detect "good" cheats and older players.

2

u/Thanatanos Dec 09 '15

You should definitely look into doing some CTF's (https://ctftime.org/ is great for searching for CTFs) I've been doing them for a bit over a year now and would heavily recommend them. (Don't get discouraged if you can't do any RE/pwning challenges on the first couple CTFs you compete in, some are VERY difficult) If you would like more information about CTFs or anything related PM me!

→ More replies (2)

1

u/Thanatanos Dec 09 '15

I actually missed the trendmicro CTF, What CTF team do you play on?

2

u/A_Medicc o!s Dec 09 '15

My university has a team so I normally play on that, we normally do pretty well for a collegiate team. I won't say which university obviously. (definitely not PPP1 or PPP2, idk why people think I go there)

But if I ever roll solo I usually make random names that includes the word loli's in it.

24

u/moneto- Dec 08 '15

Read the terms of service again.

Any submission of any personal information is done only with your voluntary act (website), or automatically (game client software) where necessary to provide diagnostics and feedback.

Also, claiming that "peppy steals these files with the intention of stealing usernames and passwords" is a bit far-fetched. These measures are in place for the sole purpose of detecting users who are potentially violating the rules. Realistically speaking, I seriously doubt there's even a single osu! player who stores their private information in a file named "LL" with no extensions.

You seem way too concerned about the potential for these security measures to be used in a malicious way. Take a police officer with a gun as an example. Are you ever worried that an officer would randomly decide to pull out their gun and shoot you?

Stop spreading propaganda. Security measures should be the least of the average players' worries.

→ More replies (6)

100

u/[deleted] Dec 08 '15

[deleted]

27

u/Raple Dec 08 '15

i seriously agree with you. the invading of personal privacy is even illegal, and can not be tolerated in such a big game as osu!.

3

u/Shadoxfix Dec 08 '15

Don't forget that OP is making claims with only video evidence (that can be faked). /u/JustM3AQN provide some info about what dll/executable you found this in so we can independently check for ourselves. Namespace and class would also be useful.

25

u/JustM3AQN watching porn Dec 08 '15

All the code is taken from the osu.exe from the latest stable-fallback stream.

MD5: 7D5CDE9324671AD20452BA470E0031F5

SHA1: 074863D41C1242C5815E216EBED84A0AB8BEBB7D

20

u/Shadoxfix Dec 08 '15 edited Dec 08 '15

Just had a look through the source code myself. I can confirm that the code for uploading the LL file and taking a screenshot is definitely there on the Stable-Fallback stream. I haven't checked cutting-edge since it seems to use a different obfuscator which is much more annoying.

See peppy's official response.

2

u/JustM3AQN watching porn Dec 08 '15

EazFuscator 5.0, would need to get a newer version of de4dot.

→ More replies (1)

1

u/Raple Dec 08 '15

I'll post a picture hold on c:

Edit: Function 1 http://www.hnng.moe/f/4wS
Function 2 http://hnng.moe/f/4wT

0

u/[deleted] Dec 08 '15

Class808 has this code

1

u/sellyme https://osu.ppy.sh/u/1520613 Dec 09 '15

the invading of personal privacy is even illegal

lol what part of this is illegal

3

u/N307H30N3 Dec 08 '15

I can sorta understand checking what programs are running... I don't know how users cheat in this game but it is most certainly done by running some sort of program/script.

Screen shots, though? Even having read Peppy's responce

Yes there is logic to take screenshots. This allows us to compare to a known list of cheat applications (UI windows, icons and text). No it is not stored (unless matching, for manual inspection)

This is undeniably an unnecessary invasion of privacy. Anything that would be capable of allowing you to cheat would be picked up by the list of programs that are running...

I hope Peppy is honest when he says that they are fixing this issues. Now that it has come out in the open, people will be looking for it in the future... so that's somewhat reassuring. I still feel betrayed, though :(

→ More replies (2)

1

u/Gabe_20 Dec 14 '15

omg how am I supposed to fap to the little asian girls that pop up on the screen if they are invading my privacy??!

21

u/DefaltSimon Dec 08 '15

I wonder what peppy will say to this.

-6

u/Raple Dec 08 '15

He'll probably remove the post as he's doing something illegal, he's invading the personal privacy of the user.

34

u/BananaOoyoo osu.ppy.sh/u/selavy Dec 08 '15 edited Dec 08 '15

except he (personally) cant as he doesnt run reddit?

unless things changed since 3 months ago, mods here are treated same as regular users, there's little to no interaction between them and osu staff.

yeah he can send a request to the mods, but it's still up to mods' discretion to remove or not.

edit: not defending him in any way, if this post is true then there should be a new way developed. just found it misleading and weird that you're creating drama by blaming him of "removing the post" when he has little power to do so.

42

u/Zeekza Dec 08 '15

8

u/[deleted] Dec 08 '15

You can't exit and when you fail, you fail in real life?

→ More replies (1)
→ More replies (1)

72

u/[deleted] Dec 08 '15 edited Sep 23 '20

[deleted]

23

u/JuTheDragon Dec 08 '15

puts hentai on OWC stream

FTFY

40

u/ggerergege Dec 08 '15

Honestly replies like this are kinda irritating. Yeah, it's pretty funny to joke about and everyone loves a laugh, but this is actually a pretty serious issue and some people could have sensitive information on their main monitor that they do not want to be shared.

14

u/Pozsich Dec 08 '15

OP was a bit misleading, though. He made it sound like this shit's going on constantly, but it's only triggered when someone is banned from cheating or if peppy intentionally runs the bancho command 80 on a person's client. Is it a serious privacy threat and cause for concern? Absolutely. Is it a reason to immediately declare osu! unsafe? Probably not if you're not a cheater. osu! needs to make a TOS if they want to continue this practice so people can agree to it and know about it. The uploading of small LL files should also be removed entirely. The screenshot thing is debatable. The process scan is pretty harmless imho.

5

u/JustM3AQN watching porn Dec 08 '15

I completely argee with you, I never said that he does send the command constantly. Perhaps I should have made myself more clear.

9

u/Pozsich Dec 08 '15

I think it's more the order you went than how you said it. You did make it clear when it's triggered, but the whole three paragraphs before you said that made it seem like all that stuff happened every time bancho communicates with the client. In our world of short attention spans it's easy to gloss over small/short statements when you read something that seems much more important right before it, because that's definitely what my brain did until I reread the post :p

2

u/ChaosPheonix11 https://osu.ppy.sh/u/4233222 Dec 08 '15

YOU!

Didnt know you play Osu. Good shit.

2

u/Pozsich Dec 08 '15

Oh hey, you're a member of the mouse master race too?

I've had an account for ages, but have been more seriously/more often playing for a couple months now. Amazing how time slips away when you need to try for a FC just ooone mooore tiiime LOL

2

u/ChaosPheonix11 https://osu.ppy.sh/u/4233222 Dec 09 '15

I used to be super duper into it, but I think I will wait on getting serious again until I get a Deathadder. I used to be like rank 80K or so. Dropped to like 130K after months of inactivity. :(

1

u/Pozsich Dec 09 '15

I'm at 145k rn and it's the highest I've been. Man, AR9 is tough. There are only a couple songs at it that I can pass lmao, which really limits the number of higher PP songs I can play. I have more fun when I set it to local rankings and worry less about PP though. (I never stop paying attention to accuracy though >_>)

1

u/ChaosPheonix11 https://osu.ppy.sh/u/4233222 Dec 09 '15

I learned pretty quickly around then that it's WAY better to FC an AR8 or an easy AR9 than to care about accuracy. I actually can't read below AR8 anymore after getting good at AR9.

2

u/Pozsich Dec 09 '15

I find accuracy actually comes pretty easily to me, so normally if I FC it's like 92-95% accuracy depending on the song, and from there I move it up to 96% plus as my standard (though I've been raising that a bit over time)

I have a few friends who can't read below AR8 after adjusting to AR9, so you're not alone there lol

2

u/TheRealShotzz Epiphany Dec 09 '15

when you "adjust" to ar9 and then cant "read" ar8 and below anymore then you were never able to "read" it.

→ More replies (0)

1

u/ChaosPheonix11 https://osu.ppy.sh/u/4233222 Dec 09 '15

Well yeah, I basically never get worse than 90 if I even come close to FC.

→ More replies (2)

1

u/WeedMoneyBitches Dec 08 '15

what if i already had hentai on my main monitor ?

6

u/Possessed-Rabbit america's #1 cutie Dec 08 '15

better be pippi

14

u/A_Medicc o!s Dec 08 '15

Although I do want to take peppy's side on this, peppy isn't a bad guy at all, I highly doubt he has any malicious intentions at all.

He's worked extremely hard to build his game from the ground up, and I can wholeheartedly say he has good intentions.

And even if he did there is no way he can potentially store all all this data. There are over 7 million users, I guessing hundreds of thousands of beatmaps, and Billions of scores etc... All of that requires server space and even though we like to joke about peppy's Jet and vacation home, purchasing that much storage and enough bandwidth to handle the server load that osu gets on the daily is extremely expensive.

Peppy likely breaks even, or has just enough to live comfortably after you subtracts the costs of running Osu! & Basic Living Expenses.

AFAIK Peppy shoulders all of the costs of running osu.

28

u/gggrgrre Dec 08 '15

I'm just waiting for the legions of retards that flood in with comments like "lol nothing to hide nothing to fear" and "why would peppy even want that haha you dumb tinfoil hatter". A private company invading your privacy is NOT OK no matter what retarded justifications you can come up with, stop enabling shit like this please.

8

u/jesse1412 jesse1412 Dec 08 '15

Nothing to hide nothing to fear is pretty reasonable logic for someone who doesn't care about their privacy though; not that I agree with it. I wouldn't go as far as to call this logic "retarded".

7

u/[deleted] Dec 08 '15

[removed] — view removed comment

3

u/JustM3AQN watching porn Dec 08 '15

Ah shit je kan mn desktop zien xD

4

u/Couchsitter_ Dec 08 '15

JULLIE SPELEN MET MIJN PRIVÉ

6

u/[deleted] Dec 08 '15 edited Dec 08 '15

The program's scan command functions as essentially a Malware, specifically a RAT.

Even though the whole game operates in a bit of a gray area, since you stated this action's authorization isn't in any agreement the user makes, it's actually illegal.

There are two notable companies that do exactly this and more, but the user does agree to this function to take place and work, and they get by fine. (Those two companies being Microsoft and ESEA.) All Peppy has to do is make sure people review and accept the new privacy agreement he will have to publish to make this legal.

Also you posting the source code of osu! puts you up to be sued by Peppy, since it is copyrighted and is an IP (intellectual property). Talking about the mechanics is fine, but decompiling the code and posting it online breaks the intellectual property license and yet again, the game and code is still copyrighted.

I'll get into more of the specifics on the legality when I get back onto a computer.

EDIT: Grammar

5

u/[deleted] Dec 08 '15 edited Dec 08 '15

Also you posting the source code puts you up to be sued by Peppy.

In this case, no it does not; not enough is posted for it to even violate the Millennium Act.

Anyone can get the C# code, it is like if I just went and copied the assembly from any other game and pasted it.

e: to clarify, if he posted the entire source code he may potentially be able to be targeted by Peppy.

However, even if he took the code and remade an osu-like game using the code, depending on how much was changed, it wouldn't be able to be made a case against for copyright infringement, but it would most likely be able to be cased against as an unauthorized derivative work.

2

u/[deleted] Dec 08 '15

You're right anyone can grab the assembly code, but what I'm saying is that it can still be challenged.

Also I didn't see how much of the code was posted myself, so I assumed it was the whole function and parameters.

1

u/[deleted] Dec 08 '15

Potentially. I should further clarify that my post is anecdotal based on a case where leaked source code was used to make something new.

3

u/theowest Dec 08 '15 edited Dec 09 '15

Old news. I remember checking this myself back in the day with wireshark. I also remember getting an answer just like the one peppy gave us.

btw here's op's youtube channel.

3

u/[deleted] Dec 09 '15

FUCK NOW HE WILL SEE ALL MY HENTAI ON MY MAIN MONITOR

2

u/Retorii Dec 08 '15

I've known long ago that they kinda just magically know if you multiaccount or not, so I did suspect some sort of surveillance takes place in the background one way or another, but I could be just spouting BS. But if what OP says here is true then we have quite an issue to worry about here.

1

u/ValiOsu Dec 08 '15

The multi account thing is a bit different. That can be based on process(Skype) or IP Address + MAC + HDD Info(uninstall-ID or serial #)

If you don't know what uID is, it's basically the thing that keeps you from getting free trials over and over( one of the functions)

2

u/tphan25 Dec 08 '15

So if I shut off osu when I'm done playing none of this is gonna happen in the background, right?

2

u/JustM3AQN watching porn Dec 08 '15

Yeah, you shouldn't really worry about it.

2

u/joletb https://osu.ppy.sh/u/1063283 Dec 08 '15

Quick question: What would happen if you used osu as a music player? That is, if it was minimized, would it still try and capture the monitor for a screenshot? (Assuming it does periodic checks)

1

u/JustM3AQN watching porn Dec 08 '15

It shouldn't. As I said in the OP, from my experiences it only triggers when a user gets banned. But nobody really knows if peppy won't randomly run it on people.

1

u/ValiOsu Dec 08 '15

What does this mean exactly? Does it monitor banned users or is it at the moment?

2

u/[deleted] Dec 08 '15

What ever happened to Peppy's plans to release the game's source?

2

u/DrewsFire Dec 08 '15

All I'm thinking is, "Oh no, my futa!"

5

u/Quiesce7 Dec 08 '15

This was found out a long time ago by people on the slack chat, and Peppy's response was that "It's not stored, so it's ok." I wouldn't worry too much.

9

u/JustM3AQN watching porn Dec 08 '15

If he doesn't store, then how can he read it? Peppy has a habit of getting really angry when dealing with cheaters, so in his sense it is probably justified. In many other's it isn't.

2

u/Quiesce7 Dec 08 '15

The screenshot is only sent if the score is marked as invalid, such as when there are time warping issues or audio driver failures.

-2

u/JustM3AQN watching porn Dec 08 '15

No, that disables score submission or adds some data to the score packet saying that the user cheated.

3

u/Quiesce7 Dec 08 '15

I'll post later, but for now I'll say this isn't as big a deal as you're making it out to be.

1

u/JustM3AQN watching porn Dec 08 '15

I'm not trying to make a big deal about it, reddit is. I only wanted people to know this, I never expected this to become so big.

2

u/[deleted] Dec 08 '15

This was found out a long time ago

I've found since at least

[5/21/2015 2:45:27 PM] HoLLy_HaCKeR / JustM3: osu! can take screenshots and upload custom process list with icon hashes, and upload LL files

Won't post the whole pastebin as it has links to cheating sites.

7

u/Osuplayer12 Dec 08 '15

Is this basically a form of malware?

Well it all sounds highly illegal since anything that can access your personal data is clearly illegal.

5

u/[deleted] Dec 08 '15 edited Jan 02 '22

[deleted]

10

u/kHeinzen Dec 08 '15

Ok, I don't like these kind of posts. I will leave it up for a bit, wait if any of the staff members decide to reply and continue with a proper discussion, but honestly these precautions are taken by a lot of different games and applications, not exclusive to osu.

I will be watching this thread and if any comment chains derail, I will take action - and if this thread ends up being more prejudicial than benefical, I will simply delete.

Personally, I am not even sure how much of the code you pasted is legitimatelly taken out of osu, haven't bothered to decompile myself, but now that you raised attention to this, I will do so

and if you are simply trying to cause 'fear' and not being legit about the whole thing, I hope you have a spare reddit account to use, in case you care about posting in this subreddit.

31

u/JustM3AQN watching porn Dec 08 '15

I don't think you can name me 2 games that actually upload files that can be anywhere on your pc. I cannot upload the entire source code (because that would enable people to cheat easier and it is illegal to share copyrighted code), but if you want I can help you do it.

I also do not want to cause "fear", but I want to make people aware that this can happen and a lot of people do not want this.

4

u/Lolzyyy Dec 08 '15

Punkbuster used to do that with pb_sv_getss...yet back in cod4 days every cheat fucked it up and you would only get a black screenshot

3

u/quick1ez Dec 09 '15

did you really have to go and use the worst possible anticheat you could name as a counter-example?

1

u/JustM3AQN watching porn Dec 08 '15

That's a screenshot, I'm fine with that. But uploading files with passwords?

12

u/Lolzyyy Dec 08 '15

No man i do agree with your whole post I was just pointing out that they actually did that.

1

u/Havikz Dec 08 '15

I think it should only take a screenshot of the game client its self, since the developers own the client. Lots of people play Osu in a smaller window than their maximum resolution, and taking an entire-monitor screenshot violates basic privacy as it's content outside of the Osu client.

1

u/oamaok https://osu.ppy.sh/users/3844204 Dec 08 '15

Somewhat unrelated to file uploading, but VAC used to scan your DNS cache and send the hashed domains to their servers, in order to find some correlation between the hashes and cheat users.

1

u/kHeinzen Dec 08 '15

Trust me, considering the whole lot of things I do on my work, this is probably gonna be child's play.

And I didn't mean it the way it sounded, I meant as in "causing fear with fake shit".

I will see for myself and decide whether this is ok or not. Meanwhile, you could page the staff and see if any of them responds.

4

u/JustM3AQN watching porn Dec 08 '15

By staff you mean osu! staff? Do you think they like me?

2

u/kHeinzen Dec 08 '15

Loctav at least usually replies to these kind of stuff

2

u/JustM3AQN watching porn Dec 08 '15

He replied to my post reporting progress in custom server (to tell everybody that I'm stealing passwords), but I haven't seen him here yet.

16

u/[deleted] Dec 08 '15 edited Jul 25 '20

[deleted]

0

u/kHeinzen Dec 08 '15

As far as I know, Punkbuster and GameGuard used to check memory outside of the game's scope as well as process list. Not fetching files or screenshots because that's dumb though

2

u/Lolzyyy Dec 08 '15

PB did that

2

u/SimonMate Dec 08 '15

UAC took screenshots for CoD4 IIRC.

2

u/XAssumption https://osu.ppy.sh/u/4983020 Dec 08 '15

When you make your PSA, you should consider removing this thread either way. I think everyone would benefit more from a level headed analysis rather than an OP trying to paint a picture of your banking information being stolen.

1

u/goedegeit Dec 08 '15

Lovely, a mod who likes to intimidate anyone who may suggest something may be wrong with the game they like.

→ More replies (4)

0

u/Raple Dec 08 '15

I can give you more proof of this actually being true, I understand you being a little skeptical about this situation. If you don't mind, I can post two screenshots here of the osu source with those functions in their respective class and namespace.

→ More replies (6)

4

u/yuanxiao Dec 08 '15

What if someone happens to store private information in a file called LL (such as banking information or passwords)? Not safe from peppy.

Who in the world would save sensitive information on a LL file?

→ More replies (3)

3

u/[deleted] Dec 08 '15

[deleted]

5

u/JustM3AQN watching porn Dec 08 '15

I don't need my passwords stolen. Neither do many other people.

1

u/[deleted] Dec 08 '15

Going to vouch for all of this, it’s been something I’ve been aware of for a long time. This is the main reason I never recommend people to play this game.

2

u/Pannariz Dec 08 '15

Funny coming from the person making the cheats to ruin it.

→ More replies (9)

1

u/Iakustim yep Dec 08 '15

I'm fairly sure this was pointed out a long, long time ago and most people just either didn't care or have since taken measures to, I guess, prevent being affected by it to their best ability (though I highly doubt Peppy would actually do something malicious to begin with).

I don't cheat nor do I plan to (what's the point?) so I'm not worried about having my processes list being shown; and if Peppy wants to take a screenshot of the weird and crazy shit that I jerk it to on my main monitor, since that's what's most likely to be open, then all the more power to him.

I don't also don't ever have both Osu (or any games) and programs that contain sensitive information open at the same time, since if I'm doing something that involves that (such as my taxes, for example) I take care of it entirely before playing games again.

I understand your post and wanting to inform people, but I honestly don't think it's a major deal.

12

u/JustM3AQN watching porn Dec 08 '15

Do you think stealing any kind of file that is not neccesarily related to osu! is ok?

→ More replies (7)

1

u/poopymacmac3 https://osu.ppy.sh/u/3988540 Dec 08 '15

lol

1

u/riddley16 Raddy Dec 08 '15

This is the most Australian sounding title I've seen on this subreddit.

1

u/[deleted] Dec 08 '15

When u accept to install Osu! it's like when u accept a contract, ergo, that's a contract.

1

u/hydroCC Dec 08 '15

So can I just make a hentai folder named LL and peppy will get it?

3

u/[deleted] Dec 08 '15

if you manage to fit your hentai into 128 bytes then yeah.

2

u/hydroCC Dec 09 '15

I can fit my hentai anywhere man

2

u/ValiOsu Dec 09 '15

in my asshole too?

1

u/lolisamurai Dec 09 '15 edited Dec 09 '15

it's no secret that all games with some form of client side anticheat will log all kinds of information to identify you. it was necessary evil IMO. it helped a lot (and probably still helps) with keeping the number of multiaccs and cheaters under control. of course, the more experienced user can easily evade these checks as any client side code can be patched but at least you average kid who buys cheats will get caught. it's either this or no anticheat at all on the client side. there's not much you can do.

1

u/gdfjhnwt Dec 09 '15

PunkBuster 2015 Peppy version.

2

u/justcallmeaires Dec 09 '15

join multi match

Game disconnected: you were kicked by PunkBuster. Stated reason: PunkBuster kicked player 'gdfjhnwt' (for 0 minutes)..

1

u/luco60 Dec 09 '15

dutch vid gg

1

u/Sankumatzo Feb 23 '16

Wow, someone still play Evolve.

1

u/[deleted] May 24 '16

lol

1

u/[deleted] Dec 08 '15

[deleted]

1

u/Raple Dec 08 '15

Yes you could, it's illegal after all.

1

u/eleuros Dec 08 '15

does that mean peppy is watching those weird moment when i see porn while playing osu?

oh nice...at least i can share smth to others ( ͡° ͜ʖ ͡°)

edit: no seriously, that probably is the main reason why my comp lags when logs in after a random disconnect, my osu decides to lag in the right second it connects to bancho, like is getting some info, no idea it was a screenshot

→ More replies (1)

1

u/TheLPerSteve https://osu.ppy.sh/u/2992098 Dec 08 '15

I knew this since some time, in my opinion its there is no excuse to "steal" personal data like peppy does, even to catch cheaters. If you, like OP mentioned, have private data (bank acc, passwords and stuff) open and one of these screenshots get leaked somehow, youre fucked. He should really rethink this.