Kard8p3

Member
Oct 25, 2017
7,288
What is the outcome we're looking at it here ?

For people that have been affected already, what can they do to check / fix it ?


its not yet actually out in the wild, the only people who currently know how to use it/have access only are doing it to raise awareness. I don't know if they've said what kind of recourse you could have if you get affected.
 

NeroPaige

Member
Jan 8, 2018
1,714
Apparently playing online can cause other players in insert scripts into your game.
Reminds me of Aliens Fireteam Elite where one person would be cheating or using mods (I think the bot mod) and it would also affect the engine of other online players as if they also installed the mod.

A fanpatch to fix a security exploit is the most From Software shit ever.
feels Koei-Tecmo tier too, same energy.
 

Yibby

Member
Nov 10, 2017
1,800
Wow I never thought that the network code was that bad for the Souls games. This needs more attention in the more mainstream media.

From the Mod:
Unfortunately, the item give cheat (aka Item Inject) was just the tip of the iceberg in this sense. Dark Souls III has some serious network vulnerabilities that can get your account banned or even cause lasting damage to your PC. I have reported all of these to the publisher and developers however it doesn't look like they will ever be addressed, it's only a matter of time before these security issues become popularised / public and Blue Sentinel offers a very high level of protection against these exploits.
 

FF Seraphim

Member
Oct 26, 2017
13,924
Tokyo
Man... wtf...
So we must not play any of the Dark Souls games until a patch comes out?
Now I am really glad I bought ER on PS5. Cannot imagine not playing that day one online.
 

Slaythe

The Wise Ones
Member
Oct 25, 2017
16,006
its not yet actually out in the wild, the only people who currently know how to use it/have access only are doing it to raise awareness. I don't know if they've said what kind of recourse you could have if you get affected.

I assume if someone wanted to use it to cryptomine and what not using other people, they wouldn't have made it public so we have no idea to know if this wasn't discovered before :/ .
 

Apathy

Member
Oct 25, 2017
11,992
Lucky it was found before elden ring and the hackers didn't wait to use it. They can fix it before launching.
 
OP
OP
Xyer

Xyer

Avenger
Aug 26, 2018
7,477
I've been debating just doing a clean install of Windows 10 just to be safe. Lol. I don't have anything on my computer anyways. I just built it. But damn.

I just finished replaying all 3 on PC to prepare for ER.
 

Alvis

Saw the truth behind the copied door
Member
Oct 25, 2017
11,294
Lucky it was found before elden ring and the hackers didn't wait to use it. They can fix it before launching.
Sure, I don't think anyone doubts that this will be fixed in Elden Ring, the problem is Dark Souls Prepare to Die Edition, Remastered, 2 and 3
 

Jawmuncher

Crisis Dino
Moderator
Oct 25, 2017
38,944
Ibis Island
This fucking sucks. DS3 is the only one I haven't beaten still and it's the PC version I have in h backlog with all the DLC already.

Really hope From/Namco will actually fix this.
 

NCR Ranger

Member
Oct 25, 2017
5,930
Jesus. How shittacular must the code base be to allow this and some of the other shenanigans mentioned in this tread. I normally play offline anyway, but this is giving pause at the idea of even buying Elden Ring at all.
 

Moebius

Member
Oct 28, 2017
5,432
Is it time for Valve to develop some type of Steam wide anti cheat solution? Would that solve anything?
 

Kard8p3

Member
Oct 25, 2017
7,288
I assume if someone wanted to use it to cryptomine and what not using other people, they wouldn't have made it public so we have no idea to know if this wasn't discovered before :/ .


this is very true, though everything i've read has just been a warning, no describing how to tell if youre affected/what to do if you are, though I might have missed it.
 

NoWayOut

Member
Oct 27, 2017
2,079
This is a good time to recommend people not to run games or any day to day applications (especially we browsers) as local administrator or user with local admin rights. Just create a regular user and use "run as administrator" when you need to install/update software or make system level changes.
 

Moebius

Member
Oct 28, 2017
5,432
This is a good time to recommend people not to run games or any day to day applications (especially we browsers) as local administrator or user with local admin rights. Just create a regular user and use "run as administrator" when you need to install/update software or make system level changes.

What permissions should the regular user have in these programs in order to function properly?
 

Jane

Member
Oct 17, 2018
1,277
Not sure if anyone's mentioned yet, but a friend just starting playing DS1: Remastered and noticed that apparently the servers are down for maintenance. Maybe they're working on it already?
 

Blade30

Member
Oct 26, 2017
4,666
Not sure if anyone's mentioned yet, but a friend just starting playing DS1: Remastered and noticed that apparently the servers are down for maintenance. Maybe they're working on it already?

Apparently it's down for DS2 and DS3 as well, looking at the recent forum posts. Here is hoping they are actually fixing it.
 

Roshin

Member
Oct 30, 2017
2,850
Sweden
I can't believe I'm saying this, but I'm going to wait on ER, until I'm sure that thing is safe. If the network code is so bad in DS1-3, then maybe it requires more than a simple fix, and who knows what snippets of code has been carried over to ER.

FFS, From.
 

Walnut

One Winged Slayer
Member
Nov 2, 2017
898
Austin, TX
It's a little bit presumptuous to assume this can't hit consoles considering how little information is public on it

This is a bigger deal than the old online ban problems PC Souls games had. I wouldn't be shocked if FromSoft is forced to fix this. They should try to take a stab at the other problems while they're at it, it would be much appreciated.
 

sweetmini

Member
Jun 12, 2019
3,921
Particularly when it s been announced there is a Jailbreak for PS5 sure for V4.03 but that s the first foray and there could be one for a live version at one time.
PS4 also should have sooner rather than later another route.

One shouldn t think they will be free of annoyances on playstation (but i would think the worst to happen there would be the botched save and game crashing), particularly if a doctored save is enough to do it.

With a little luck, it can be fixed with their network solution server side (which has some updates from time to time) , rather than the actual games (i wouldn t be surprised if they couldn t do a build of the old ones because of all the deprecated libraries and out of date development tools).

ER being opt in networking there is way to setup password only network play. Since it s in active development, if they can't fixed the server side, the client will be fixed for sure.
 

Sky87

Member
Oct 27, 2017
3,871
Not sure if anyone's mentioned yet, but a friend just starting playing DS1: Remastered and noticed that apparently the servers are down for maintenance. Maybe they're working on it already?
Taking the servers down to look into this is the first thing they should have done, pretty baffling they didn't do it earlier.
 

PMA

Alt account / Attempted to circumvent ban with alt
Banned
Sep 13, 2021
257
I like from but this is really bad. We rightfully criticise other companies for these sorts of security breaches, it is a corporations responsibility to ensure a user cannot be harmed through their product in this way. Really pathetic stuff imo.
 

dom

â–˛ Legend â–˛
Avenger
Oct 25, 2017
10,517
well, the exploit was in the ER open beta too. And that was console only.
It's assumed to be in there because the files responsible for their netcode is very similar if not the same as dark souls 3. The were able to compare the files only because firmware 9.0 was exploited. This allowed them to fully decrypt the game package to see the files inside. But this was well after the beta had ran. They dont actually have proof of this running during the beta.
 

Spacejaws

"This guy are sick" of the One Winged Slayer
Member
Oct 27, 2017
7,981
Scotland
Any idea if this affects Bloodborne and Demons Souls? I imagine it's all the same implementation?

Would be sad to see a Bloodborne patch finially and it's just to patch this vulnerability.
 

Henrar

Member
Nov 27, 2017
2,006
Any idea if this affects Bloodborne and Demons Souls? I imagine it's all the same implementation?

Would be sad to see a Bloodborne patch finially and it's just to patch this vulnerability.
It's possible that it affects those two games, but console games are running in a sandbox, so it's not going to cause such issues.
 

Tremorah

Member
Dec 3, 2018
4,975
Companies really should keep their shit together, some asshole owning your PC through a online game seems like a problem we shouldnt have these days
 

Spacejaws

"This guy are sick" of the One Winged Slayer
Member
Oct 27, 2017
7,981
Scotland
It's possible that it affects those two games, but console games are running in a sandbox, so it's not going to cause such issues.
Yea I know but if they have an official patch on PC I would expect them to roll it out to consoles anyway well maybe everything but the Switch that they don't give a shit about lol.
 

TronLight

Member
Jun 17, 2018
2,466
Any idea if this affects Bloodborne and Demons Souls? I imagine it's all the same implementation?

Would be sad to see a Bloodborne patch finially and it's just to patch this vulnerability.
The original Demons Souls server on PS3 haves been shut down years ago and the Remake likely has nothing in common with From Software's engine.
 

Deleted member 23046

Account closed at user request
Banned
Oct 28, 2017
6,876
If confirmed it's a very interesting way of intrusion, I wonder if there's a precedent or it will mark a new one.
 

Spacejaws

"This guy are sick" of the One Winged Slayer
Member
Oct 27, 2017
7,981
Scotland
The original Demons Souls server on PS3 haves been shut down years ago and the Remake likely has nothing in common with From Software's engine.
Was talking about the remake. I have 0 knowledge how different the netcode is. I know Bluepoint said most of the original code is there under the graphical changes which is obvious but I wasn't sure about the network side of it.
 
Oct 27, 2017
4,198
whats with all the fear mongering in this thread... if this has been a thing since it was released 6 years ago seems like a big nothing to me( we just now hearing about it just because a streamer that an hacker targeted... got hacked doesn't mean it can and will happen to someone else. why hasnt this been known about if its a really big deal.?... glad it was found but wtf lol i haven't played ds on pc since ds2 played everything else on ps4 but i 100% doubt this is gonna effect ERs launch...( THEY SHOULD HAVE NEVER PUT OUT THAT DAMN NT 3 fucking months before release... Ive had ER videos all over YouTube for months and months... :/ ) but at the same time maybe this wouldn't be fixed if it wasn't. seems like they working on a fix now... so with over 4 weeks left im sure its fine..
ER has had the most time for any from game... and they legit go another year because of covid... :/ i understand cyberpunk and 2042 and all the year after year releases that a bugged out trashed out messes.. yeah i get it.. but FROM hasn't really done that since OG DS1 on pc... bugs sure but a trashy unfinished mess... NOPE

their last game was literally GOTY... i put over 100 hours in and never got one bug.
 

Slaythe

The Wise Ones
Member
Oct 25, 2017
16,006
Yea I know but if they have an official patch on PC I would expect them to roll it out to consoles anyway well maybe everything but the Switch that they don't give a shit about lol.

Absolutely not.

It's a problem on Pc not on console, and having to pay for testing, QA, and two (three) consoles certification on all those games is absolutely not happening.
 

Deleted member 49611

Nov 14, 2018
5,052
hope they can patch it for Elden Ring without having to delay it lol