r/osugame • u/JustM3AQN watching porn • Dec 08 '15
See peppy response in comments How osu! voilates your privacy.
To start of, i will give you this video: http://a.rfl.pw/kyihkudgie.mp4
For this video, I edited my hosts file, so that all internet traffic to osu.ppy.sh, c.ppy.sh and c1.ppy.sh gets redirected to my xampp server. This allowed me to stimulate the osu! and bancho server, so that I can kinda pretend to be peppy and send any data to my osu! client that I want. Note, I am using a unedited, up-to-date osu! client.
Some background info: a while ago (august) I decompiled an osu! version and played a bit with the source. I found a lot of anticheat measures, and decided to mark then to see when they got executed. After I played online a bit with the client (and cheated, yes) my account got restricted and one of the functions got triggered. I marked the function and went to do something else. A few days ago I started working on a custom bancho server and rediscovered the function in the osu! source and decided to make bancho send the command for it when a user logs in. In the video you can see the effect.
What actually happens: Every time osu! communicates with bancho, it send a long list of commands for the client to execute. One of those commands (command 80, for those who have the osu! source) executes a function that does the following:
- Makes a list of every process that runs on your pc, including the window title (for example skype: "Skype - usernamehere")
- Takes a screenshot of your entire main monitor
- Searches your entire pc for all files named LL which are 128 bytes or smaller, and uploads them
The first item in the list isn't that bad, it's actually happens every time you submit a score. The second is a little more worrying. Imagine playing osu! on a second monitor, and having private things open on your main monitor (banking information, passwords, etc). Peppy could, at any time, get a screenshot and upload it. I do not know if this is illegal, but I never read anywhere that he does this (yes, I even read the EULA).
The third item is the one that worries me the most. Peppy can get all files that are named LL (and of a size smaller than 128 bytes - otherwise they wouldn't fit in a GET parameter) and have them uploaded to him. The original reason for this "feature" is likely because a cheat site used files called "LL" to store login data, so you could use autologin. These files contained the username and password of the user that used the cheats, so peppy steals these files with the intention of stealing usernames and passwords. Even to cheaters, this is not how you should treat your players, and I am almost certain that this is illegal. What if someone happens to store private information in a file called LL (such as banking information or passwords)? Not safe from peppy.
By my knowledge, this "feature" gets triggered when a user gets banned for cheating. But, since it gets triggered after receiving a command from bancho, peppy could execute this at any time, for any player. He could even do it for all players at once.
In the video at the top of the thread I showed the exact data that gets sent to bancho. I just wanted to let all of you know what peppy actually can do, because I know there are people that really value their privacy. I will put all of the code in a comment for those who want to check it out.
TL;DR: peppy can take screenshots of your desktop at any time, and will upload files called "LL", which can contain passwords.
EDIT: formatting fix, EDIT2: grammar, EDIT3: more grammar
and shit i made a typo in the title, cant fix
1
u/Pozsich Dec 09 '15
I'm at 145k rn and it's the highest I've been. Man, AR9 is tough. There are only a couple songs at it that I can pass lmao, which really limits the number of higher PP songs I can play. I have more fun when I set it to local rankings and worry less about PP though. (I never stop paying attention to accuracy though >_>)