this post was submitted on 19 Mar 2024
468 points (92.4% liked)
Technology
59135 readers
2878 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There is currently no evidence of an RCE exploit in EAC, and EAC themselves as well as their owner, Epic, have both denied the existence of an RCE in their software.
There's a video from about a month ago in which ImperialHal and Genburten (on separate occasions) are in a match against the person named in the messages sent by the exploit on Genburten's machine.
It's possible that they were in contact with the hacker after that point and that he tricked them into downloading something they shouldn't have.
Otherwise, it's also possible that there is an exploit in Apex/Source that the hacker used. He may have been able to get their IP during the public match a month ago and then use it to target them during the competition.
Beyond what was seen during the competition, the hacker was also able to gift thousands of Apex packs to several players (seemingly without paying for them) and was able to get 40+ "bot" players into a single match and to all target an individual player. He also claimed to be able to open crates on another player's account. These other exploits seem to indicate that he has elevated access to both the server and to multiple APIs, but none of them indicate elevated access to user machines in general.
Cancel my comment about this being a possible 0day or whatever. They were playing this tournament on their personal systems, which makes it way easier for someone to accidentally download malicious software without players' consent.
Here is an alternative Piped link(s):
a video
Piped is a privacy-respecting open-source alternative frontend to YouTube.
I'm open-source; check me out at GitHub.
Because it’s super annoying, clogs comment feeds and is unnecessary to be a giant wall of text comment for something ~50% of people don’t care about.
And yes, I use the default YouTube app because it works.
We can always downvote piped bot posts.
Some people just dont like bots lmao, weird effect of reddit users migrating over.
Any bot that isn't explicitly summoned is spam.
I do love the abbreviation bots though, they should be automatically summoned the first time a new abbreviation is used in a comment tree
That one is actually nice.
I think it should be required to get manually added to a community by moderators still though. Or respond to a summon to a specific thread.