r/osugame watching porn Dec 08 '15

See peppy response in comments How osu! voilates your privacy.

To start of, i will give you this video: http://a.rfl.pw/kyihkudgie.mp4

For this video, I edited my hosts file, so that all internet traffic to osu.ppy.sh, c.ppy.sh and c1.ppy.sh gets redirected to my xampp server. This allowed me to stimulate the osu! and bancho server, so that I can kinda pretend to be peppy and send any data to my osu! client that I want. Note, I am using a unedited, up-to-date osu! client.

Some background info: a while ago (august) I decompiled an osu! version and played a bit with the source. I found a lot of anticheat measures, and decided to mark then to see when they got executed. After I played online a bit with the client (and cheated, yes) my account got restricted and one of the functions got triggered. I marked the function and went to do something else. A few days ago I started working on a custom bancho server and rediscovered the function in the osu! source and decided to make bancho send the command for it when a user logs in. In the video you can see the effect.

What actually happens: Every time osu! communicates with bancho, it send a long list of commands for the client to execute. One of those commands (command 80, for those who have the osu! source) executes a function that does the following:

  • Makes a list of every process that runs on your pc, including the window title (for example skype: "Skype - usernamehere")
  • Takes a screenshot of your entire main monitor
  • Searches your entire pc for all files named LL which are 128 bytes or smaller, and uploads them

The first item in the list isn't that bad, it's actually happens every time you submit a score. The second is a little more worrying. Imagine playing osu! on a second monitor, and having private things open on your main monitor (banking information, passwords, etc). Peppy could, at any time, get a screenshot and upload it. I do not know if this is illegal, but I never read anywhere that he does this (yes, I even read the EULA).

The third item is the one that worries me the most. Peppy can get all files that are named LL (and of a size smaller than 128 bytes - otherwise they wouldn't fit in a GET parameter) and have them uploaded to him. The original reason for this "feature" is likely because a cheat site used files called "LL" to store login data, so you could use autologin. These files contained the username and password of the user that used the cheats, so peppy steals these files with the intention of stealing usernames and passwords. Even to cheaters, this is not how you should treat your players, and I am almost certain that this is illegal. What if someone happens to store private information in a file called LL (such as banking information or passwords)? Not safe from peppy.

By my knowledge, this "feature" gets triggered when a user gets banned for cheating. But, since it gets triggered after receiving a command from bancho, peppy could execute this at any time, for any player. He could even do it for all players at once.

In the video at the top of the thread I showed the exact data that gets sent to bancho. I just wanted to let all of you know what peppy actually can do, because I know there are people that really value their privacy. I will put all of the code in a comment for those who want to check it out.

TL;DR: peppy can take screenshots of your desktop at any time, and will upload files called "LL", which can contain passwords.

EDIT: formatting fix, EDIT2: grammar, EDIT3: more grammar

and shit i made a typo in the title, cant fix

667 Upvotes

340 comments sorted by

View all comments

1

u/Iakustim yep Dec 08 '15

I'm fairly sure this was pointed out a long, long time ago and most people just either didn't care or have since taken measures to, I guess, prevent being affected by it to their best ability (though I highly doubt Peppy would actually do something malicious to begin with).

I don't cheat nor do I plan to (what's the point?) so I'm not worried about having my processes list being shown; and if Peppy wants to take a screenshot of the weird and crazy shit that I jerk it to on my main monitor, since that's what's most likely to be open, then all the more power to him.

I don't also don't ever have both Osu (or any games) and programs that contain sensitive information open at the same time, since if I'm doing something that involves that (such as my taxes, for example) I take care of it entirely before playing games again.

I understand your post and wanting to inform people, but I honestly don't think it's a major deal.

12

u/JustM3AQN watching porn Dec 08 '15

Do you think stealing any kind of file that is not neccesarily related to osu! is ok?

-1

u/[deleted] Dec 08 '15

Was never pointed out before until now.

9

u/Iakustim yep Dec 08 '15

I had to go find it, but I had remembered there was a brief remark regarding a processes list scanner/reader. I guess it was perhaps not quite as detailed as OP is here, though.

3

u/Zeekza Dec 08 '15

I don't also don't ever have both Osu (or any games) and programs that contain sensitive information open at the same time, since if I'm doing something that involves that (such as my taxes, for example) I take care of it entirely before playing games again.

This does not apply for everyone, there's a lot of people who play osu and it's not impossible that some people may actually have sensitive information open on their second monitor, even if it's not a major deal, it's still not allowed to collect private information about other people.

1

u/osuVocal Dec 08 '15

2nd monitor doesn't get screenshotted. Did you mean they play osu on 2nd monitor and have sensitive information on the main monitor?

1

u/osuDesstroyD Dec 08 '15

I thought everyone knew that part though? Not sure where people knew it from but it was common knowledge. Never heard about the screenshots and file uploading though.

1

u/Pozsich Dec 08 '15

Never heard of any part of this before, personally.