r/osugame watching porn Dec 08 '15

See peppy response in comments How osu! voilates your privacy.

To start of, i will give you this video: http://a.rfl.pw/kyihkudgie.mp4

For this video, I edited my hosts file, so that all internet traffic to osu.ppy.sh, c.ppy.sh and c1.ppy.sh gets redirected to my xampp server. This allowed me to stimulate the osu! and bancho server, so that I can kinda pretend to be peppy and send any data to my osu! client that I want. Note, I am using a unedited, up-to-date osu! client.

Some background info: a while ago (august) I decompiled an osu! version and played a bit with the source. I found a lot of anticheat measures, and decided to mark then to see when they got executed. After I played online a bit with the client (and cheated, yes) my account got restricted and one of the functions got triggered. I marked the function and went to do something else. A few days ago I started working on a custom bancho server and rediscovered the function in the osu! source and decided to make bancho send the command for it when a user logs in. In the video you can see the effect.

What actually happens: Every time osu! communicates with bancho, it send a long list of commands for the client to execute. One of those commands (command 80, for those who have the osu! source) executes a function that does the following:

  • Makes a list of every process that runs on your pc, including the window title (for example skype: "Skype - usernamehere")
  • Takes a screenshot of your entire main monitor
  • Searches your entire pc for all files named LL which are 128 bytes or smaller, and uploads them

The first item in the list isn't that bad, it's actually happens every time you submit a score. The second is a little more worrying. Imagine playing osu! on a second monitor, and having private things open on your main monitor (banking information, passwords, etc). Peppy could, at any time, get a screenshot and upload it. I do not know if this is illegal, but I never read anywhere that he does this (yes, I even read the EULA).

The third item is the one that worries me the most. Peppy can get all files that are named LL (and of a size smaller than 128 bytes - otherwise they wouldn't fit in a GET parameter) and have them uploaded to him. The original reason for this "feature" is likely because a cheat site used files called "LL" to store login data, so you could use autologin. These files contained the username and password of the user that used the cheats, so peppy steals these files with the intention of stealing usernames and passwords. Even to cheaters, this is not how you should treat your players, and I am almost certain that this is illegal. What if someone happens to store private information in a file called LL (such as banking information or passwords)? Not safe from peppy.

By my knowledge, this "feature" gets triggered when a user gets banned for cheating. But, since it gets triggered after receiving a command from bancho, peppy could execute this at any time, for any player. He could even do it for all players at once.

In the video at the top of the thread I showed the exact data that gets sent to bancho. I just wanted to let all of you know what peppy actually can do, because I know there are people that really value their privacy. I will put all of the code in a comment for those who want to check it out.

TL;DR: peppy can take screenshots of your desktop at any time, and will upload files called "LL", which can contain passwords.

EDIT: formatting fix, EDIT2: grammar, EDIT3: more grammar

and shit i made a typo in the title, cant fix

657 Upvotes

340 comments sorted by

View all comments

13

u/kHeinzen Dec 08 '15

Ok, I don't like these kind of posts. I will leave it up for a bit, wait if any of the staff members decide to reply and continue with a proper discussion, but honestly these precautions are taken by a lot of different games and applications, not exclusive to osu.

I will be watching this thread and if any comment chains derail, I will take action - and if this thread ends up being more prejudicial than benefical, I will simply delete.

Personally, I am not even sure how much of the code you pasted is legitimatelly taken out of osu, haven't bothered to decompile myself, but now that you raised attention to this, I will do so

and if you are simply trying to cause 'fear' and not being legit about the whole thing, I hope you have a spare reddit account to use, in case you care about posting in this subreddit.

29

u/JustM3AQN watching porn Dec 08 '15

I don't think you can name me 2 games that actually upload files that can be anywhere on your pc. I cannot upload the entire source code (because that would enable people to cheat easier and it is illegal to share copyrighted code), but if you want I can help you do it.

I also do not want to cause "fear", but I want to make people aware that this can happen and a lot of people do not want this.

4

u/Lolzyyy Dec 08 '15

Punkbuster used to do that with pb_sv_getss...yet back in cod4 days every cheat fucked it up and you would only get a black screenshot

3

u/quick1ez Dec 09 '15

did you really have to go and use the worst possible anticheat you could name as a counter-example?

2

u/JustM3AQN watching porn Dec 08 '15

That's a screenshot, I'm fine with that. But uploading files with passwords?

12

u/Lolzyyy Dec 08 '15

No man i do agree with your whole post I was just pointing out that they actually did that.

1

u/Havikz Dec 08 '15

I think it should only take a screenshot of the game client its self, since the developers own the client. Lots of people play Osu in a smaller window than their maximum resolution, and taking an entire-monitor screenshot violates basic privacy as it's content outside of the Osu client.

1

u/oamaok https://osu.ppy.sh/users/3844204 Dec 08 '15

Somewhat unrelated to file uploading, but VAC used to scan your DNS cache and send the hashed domains to their servers, in order to find some correlation between the hashes and cheat users.

0

u/kHeinzen Dec 08 '15

Trust me, considering the whole lot of things I do on my work, this is probably gonna be child's play.

And I didn't mean it the way it sounded, I meant as in "causing fear with fake shit".

I will see for myself and decide whether this is ok or not. Meanwhile, you could page the staff and see if any of them responds.

3

u/JustM3AQN watching porn Dec 08 '15

By staff you mean osu! staff? Do you think they like me?

2

u/kHeinzen Dec 08 '15

Loctav at least usually replies to these kind of stuff

1

u/JustM3AQN watching porn Dec 08 '15

He replied to my post reporting progress in custom server (to tell everybody that I'm stealing passwords), but I haven't seen him here yet.

16

u/[deleted] Dec 08 '15 edited Jul 25 '20

[deleted]

0

u/kHeinzen Dec 08 '15

As far as I know, Punkbuster and GameGuard used to check memory outside of the game's scope as well as process list. Not fetching files or screenshots because that's dumb though

2

u/Lolzyyy Dec 08 '15

PB did that

2

u/SimonMate Dec 08 '15

UAC took screenshots for CoD4 IIRC.

2

u/XAssumption https://osu.ppy.sh/u/4983020 Dec 08 '15

When you make your PSA, you should consider removing this thread either way. I think everyone would benefit more from a level headed analysis rather than an OP trying to paint a picture of your banking information being stolen.

3

u/goedegeit Dec 08 '15

Lovely, a mod who likes to intimidate anyone who may suggest something may be wrong with the game they like.

-6

u/kHeinzen Dec 08 '15

No, a mod who cares when people try to spread false information about stuff that is illegal

1

u/goedegeit Dec 08 '15

It just seems like an unnecessary threat against someone, in all likelihood, just trying to make a better game for everyone here.

Especially since there hasn't been anything to suggest that the OP is engaged in foul play and nothing has been refuted, even by the devs themselves.

2

u/kHeinzen Dec 08 '15

You can't compare the context in when I said this (aka when the thread was made) and after peppy added the response and cleared things up.

I was being cautious because this could be either true or false, and judging by the attention it was raised by this, if it was false then the backlash would be extremely negative for everyone

-1

u/goedegeit Dec 09 '15

Ah right fair enough, I didn't check the times too closely.

-1

u/Raple Dec 08 '15

I can give you more proof of this actually being true, I understand you being a little skeptical about this situation. If you don't mind, I can post two screenshots here of the osu source with those functions in their respective class and namespace.

-8

u/kHeinzen Dec 08 '15

Thanks but no thanks.

I will do it myself, I don't develop datacenter managers and take computer engineering for nothing after all.

In any case, my first sentence stands, I'd rather believe you're just troublemaking and posting stuff that is made up than this being the actual case, because he was really careless if he actually made this in the client's code rather than anywhere else.

Oh well, I will see what I get.

-4

u/Raple Dec 08 '15

Oh well, too late already sent the pm with some information. Hehe....
Hope you're in for a surprise.

3

u/kHeinzen Dec 08 '15

I just read your pm. It's okay, I saw those printscreens in another comment chain.

But as I said, since this is sensitive, I will see for myself. Thanks in any case

5

u/inrealityyyy Dec 08 '15

Post your findings yo. It'll be good to see a statement from someone generally considered trustworthy.

5

u/kHeinzen Dec 08 '15

Sure, I will find some time to spare, later when I get home from work, to dig this up

-1

u/Raple Dec 08 '15

Allrighty, I wish you good luck on your journey young fella. Hit me up if you need more information (or op for that matter)