Was Vivox Chat p0wned by Emerald Developers?
by Pixeleen Mistral on 30/08/10 at 12:16 pm
LindenWorld staff meetings an open book to ban-proof Fractured Crystal, Lonely Bluebird?
Did two Emerald developers – Fractured Crystal and Lonely Bluebird – taunt Emerald critic Hazim Gazov after using the Vivox voice chat admin portal disable Gazov’s Second Life voice? Were the rogue developers able to track Lab staff on private Linden-only islands? It appears so, if a screen capture provided to the Herald this weekend can be believed.
Over the last several months, a YouTube video and chatlogs have circulated, both of which strongly suggest both Fractured Crystal and Lonely Bluebird took the faction wars between the Emeralds and the Soviet Woodbury group to new levels after the Emerald’s site security was compromised and the data mining operation was revealed. This weekend, a source we will refer to as DeepYiff has provided the Herald with evidence the exploit that left Hazim Gazov speechless could also have compromised the security of all Vivox voice chat in Second Life.
While it is impossible to be absolutely certain that the screen captures DeepYiff provided are real, they appear to be the Vivox administration portal which can be used to mute, kick, or ban players from the voice service. The Vivox documentation also states that administrative users can listen in to chat channels without appearing to other users – something that may give pause to the Linden staff using Vivox chat for in-world meetings. The screen capture below shows what is seems to be a Linden staff meeting in progress on the LindenWorld B private island.
click image for full size view
According to Emerald critic Hazim Gazov, both Joe Linden and Soft Linden were aware that some sort of Vivox exploit had taken place after Mr. Gazov reported that his Vivox chat had been disabled. However it is unclear what – if any – action was taken other than to re-enable Mr. Gazov’s voicechat.
While the Vivox admin screen capture appears to be a bit dated – 1/3 of the Linden staff shown are no longer with the lab, presumably due to the lab’s recent cost cutting measures – it appears to be common knowledge in certain circles that chat has been badly compromised.
I asked Plastic Duck for comment last night, and while he was unsure of the exact method Fractured Crystal (jcool) used, Plastic Duck thought it likely that Fractured Crystal had gained control over the Vivox admin interface.
Pixeleen Mistral: what do you know about the VIvox admin interface?
Plastic Duck: it’s insecure
Pixeleen Mistral: how insecure?
Plastic Duck: jcool was able to get full access
Pixeleen Mistral: yeah, I got a screen shot that implies that
Plastic Duck: and disable peoples accounts
Pixeleen Mistral: Hazim’s account for instance
Plastic Duck: yeah
Pixeleen Mistral: but Vivox has a game moderator can listen in feature
Pixeleen Mistral: and LL uses vivox for staff meetings
Plastic Duck: yeah he can likely listen in on whatever
Pixeleen Mistral: any idea how jcool got in?
Plastic Duck: from what I understand you could just force some admin bit
Plastic Duck: and the servers would happily comply
Plastic Duck: or it could have been related to the exploit that lets you run a rogue sim
Plastic Duck: jcool was abusing the shit out of that one
Plastic Duck: to download files from peoples computers heh
All of this raises further questions about why Fractured Crystal has not been banned from Second Life – and how much longer the Lab will tolerate the Emerald gang. Fractured Crystal claimed responsiblity for the DDoS attack that led to Philip Linden warning players against the Emerald viewer last week, but perhaps he overheard something in a staff meeting that made him ban-proof.
Friend of all
Sep 1st, 2010
http://www.bhr.vivox.com/api2/viv_get_acct.php?user_name=xcgtL_agHRsSOdHtTuYLqnw==
OKvx_sessionxN788byUiSE252PJ0E5ZgiQ==:1333374390:0aef63421bc9d695f1cf6c16049ac55c:216.40.74.200xN788byUiSE252PJ0E5ZgiQ==:1333374390:0aef63421bc9d695f1cf6c16049ac55c:216.40.74.2002554347xcgtL_agHRsSOdHtTuYLqnw==bhr.vivox.comengOskarLindenOskar%20Linden60522008-08-04 16:33:24.137257-042010-08-24 19:45:17.632174-042010-09-01 13:33:59.938735-042030-01-01 00:00:00-0501071212060000t
Friend of all
Sep 1st, 2010
How to replicate the newest exploit
http://pastebin.com/rKGyVLJ6
http://www.bhr.vivox.com/api2/viv_acct.php?mode=update&admin=300
Friend of all
Sep 1st, 2010
http://pastebin.com/cSFZMyW1
vivox lsl script leaked
http://pastebin.com/PUH4CjGN
Another haxor breaking into osgrid vivox
http://i51.tinypic.com/28aj79z.png
Friend of all
Sep 1st, 2010
Um score.
http://pastebin.com/WJbcX8qq
More info on breaking in vivox.
TOBSDA
Sep 1st, 2010
http://www.youtube.com/watch?v=6Ti3xc2K98s
Friend of all
Sep 1st, 2010
Before emerald, Jessica used Vlife.
Nelson Jenkins
Sep 1st, 2010
http://emeraldscandal.wordpress.com/2010/09/01/its-the-end-of-the-world-as-we-know-it-and-i-feel-fine/
The Emerald Saga « Ariane's Life in the Metaverse
Sep 4th, 2010
[...] developer’s website. In order to try and save Emerald, Fractured Crystal quit the team. Other exploits have been discovered in the Emerald code as [...]
candid
Sep 5th, 2010
They are a bunch of griefers, how dare they. Arabella or whatever her name is is a hidious creature and BTW her ugly voice is not typical of Austrailians, it’s not how they all talk like she says. It’s typical of harsh old haggered queenslanders who have smoked to many ciggies. Emerald are liars, all of them, uninstall, change all your passwords, to everything, be safe