Author Topic: Some Concerns  (Read 4246 times)

0 Members and 1 Guest are viewing this topic.

Offline Fuzzy168

  • VC:MP Veteran
  • *****
  • Posts: 729
  • Programming since 2011
    • View Profile
Some Concerns
« on: November 09, 2013, 05:50:16 am »
I have some concerns regarding the new file transfer feature of 0.4. Given that it will download the files the server owner wants them to, wouldn't that open up a whole new way for irresponsible server owners to transfer Virus/Malware/Trojan/etc to unsuspecting players? I know that it will only transfer a certain type of extension but some cunning server owners will definitely find a way around it.

I suggest you allow the player the option of choosing whether to download the file or not.
I'm beginning to feel like a Lag God, Lag God

Offline MatheuS

  • Made Man
  • ***
  • Posts: 207
  • Pawn And Squirrel Scripter
    • View Profile
    • Brazillian Community
Re: Some Concerns
« Reply #1 on: November 09, 2013, 01:50:32 pm »
I have some concerns regarding the new file transfer feature of 0.4. Given that it will download the files the server owner wants them to, wouldn't that open up a whole new way for irresponsible server owners to transfer Virus/Malware/Trojan/etc to unsuspecting players? I know that it will only transfer a certain type of extension but some cunning server owners will definitely find a way around it.

I suggest you allow the player the option of choosing whether to download the file or not.

+1

Offline stormeus

  • VC:MP Developer
  • VC:MP Veteran
  • *
  • Posts: 1122
    • View Profile
Re: Some Concerns
« Reply #2 on: November 09, 2013, 08:28:59 pm »
VC:MP never executes a file that is downloaded. Files cannot be downloaded to arbitrary locations where they will be automatically executed and are confined to a folder within VC:MP's installation directory.
Do not PM me for support.




Offline maxorator

  • VC:MP Developer
  • Made Man
  • *
  • Posts: 219
    • View Profile
Re: Some Concerns
« Reply #3 on: November 10, 2013, 06:55:55 am »
I will make it ask it when you enter some server with downloads for the first time. So it will give an option to either allow downloads or disconnect.

While executables are not in any way executed, there still remains the risk of various security holes due to how the game loads model files. I've done my best to remove such security holes from VC, but since I do not wish to be responsible in case I've missed any, it's best to leave it up to the user to decide.