Page 1 of 2 12 LastLast
Results 1 to 15 of 23
  1. #1
    Killer Be Killed's Avatar
    Join Date
    Jun 2010
    Gender
    male
    Posts
    212
    Reputation
    53
    Thanks
    2,352
    My Mood
    Asleep

    Exclamation Riigged approved a .sol stealer

    TL;DR Riigged approved a sol stealer, read below to see what the situation is

    What happened?

    Yesterday, a thread titled "[Release] Lithic v1.6b (release 2)" was posted. The thread was approved by Riigged but was not checked thoroughly enough.

    This is the link to the thread: https://www.mpgh.net/forum/showthread.php?t=1440962

    If you follow that link, you will end up on the "Invalid link specified" page. This is not a mistake in the link URL. The post was deleted about an hour ago.

    What was the thread?

    The thread was a release of a program which was "like haveibeenpwnd.com but for RotMG account themselves". Unfortunately I don't have an archive of the thread, but I do have the preview of the link.



    If you want to know what the program looked like/what it did, watch this

    which was included in the post.

    .sol stealer?

    I thought the post looked pretty suspicious, so I downloaded it and did some digging around.

    Turns out, there was really obvious sol stealer built into the program. And I mean really obvious.

    Again, I didn't archive the post, so I don't have my original comment, but the gist of it was:

    The program...

    Tries to start a new (hidden) process when the program is run



    The process which it starts is hidden within some nested folders in node_modules



    That process finds all of your rotmg.sol files, and sends them to a Dis cord webhook.




    Why does this matter?

    Last time there was an account stealer approved on MPGH, it was a big deal. A post was made detailing what happened, and this gave users which might have been affected a chance to take some action, such as changing their passwords. The minion which approved the malicious program was also investigated and eventually demoted.

    Obviously, the last breach had a far greater impact than this one has, so the comparison may be a little contrived, but there are some points that still stand:

    • Affected users have no way of knowing they are affected, unless they were lucky enough to see my original comment in the 2 hours it was there before the thread was deleted.
    • Anyone who didn't see the program or the comment is none the wiser, and the minions reputation remains clean in their eyes, which it is obviously not.


    It is a little suspicious that the thread was approved and no comment was left by the minion which actually approved it. Especially considering how obvious the sol stealer was. I think it's even more suspicious that the thread has now been deleted without a trace of it ever existing.

    It gets worse.

    If you thought it was bad enough that a minion approved a .sol stealer, then your jaw will fucking drop at the fact that this guy posted two versions of the program, and both were approved.

    Yep.

    Here is a link to a cache showing the first time the program was posted.

    Obviously the minions can't catch every single malicious program, and I don't expect them to. But seriously, this sol stealer was ridiculously obvious, and it was approved both times it was uploaded! Was the file never checked at all?

    I hate to be the guy that "CC's in the contractors boss" but seriously, @Ahlwong I think it's unbelievable that the minions can approve two sol stealers, then act like it never happened.

    What about the people who actually downloaded the program and run it? How will they ever know they were affected by a sol stealer if there is no announcement of this event occurring?

    Misc.

    Link to an Imgur album containing screenshots of the sol stealer code.

    Link to a pastebin containing the code of the decompiled program.

    Link to a pastebin containing the Hookblock.exe code that was referenced by the program.

    Link to the cache of the first version posted.


    If nothing else happens, at least make some kind of announcement letting people know that they may have been affected if they downloaded and used this program.
    Last edited by Riigged; 03-27-2019 at 01:09 PM.

  2. The Following 12 Users Say Thank You to Killer Be Killed For This Useful Post:

    059 (03-26-2019),Akira Mado (03-26-2019),AllYourX (03-28-2019),BoredBro (03-27-2019),citydrifter (03-27-2019),crinny (06-04-2019),En236 (03-26-2019),Luverdark (07-23-2019),mr hai (03-27-2019),Plus22 (04-04-2019),RealmServices (03-27-2019),TheFallenBanda (03-26-2019)

  3. #2
    En236's Avatar
    Join Date
    Mar 2019
    Gender
    male
    Location
    msesllers basement
    Posts
    26
    Reputation
    10
    Thanks
    8
    yea i was gonna point out that it seems sketchy but i didnt say something about that since it was mod approved. really comes to show how this place has been lately

  4. #3
    Ahl's Avatar
    Join Date
    Dec 2012
    Gender
    male
    Location
    /modcp
    Posts
    16,599
    Reputation
    3219
    Thanks
    5,383
    My Mood
    Angelic
    Users who downloaded the attachments:

    Lithic 1.6b v1:
    @ @BoredBro
    @ @weetu
    @ @mr hai
    @ @plsbegood
    @ @AllYourX


    Lithic 1.6b v2:
    @ @Sadat
    @ @manchesterek
    @ @Averain
    @ @Maltense
    @ @SnugglyBanana
    @ @citydrifter

    Please secure your account ASAP if you ran this program.

    It is possible the accounts may have lost characters, pets and items already.

    Since the file is a .sol stealer, you just need to delete it from your computer.

    On behalf of MPGH Staff, we're sorry these 2 files got through.
    News Force Head Editor from 09/14/2018 - 03/02/2020
    Publicist from 11/23/2017 - 06/07/2019
    Global Moderator since 09/24/2017
    Minion+ from 04/16/2017 - 09/24/2017
    Market Place Minion from 04/16/2017 - 09/24/2017
    Minecraft Minion from 02/23/2017 - 09/24/2017
    Realm of the Mad God Minion from 11/06/2016 - 09/24/2017

    Middleman from 09/14/2016 - 09/24/2017
    News Force Editor from 08/23/2016 - 09/14/2018
    News Force (Section of the Week) from 03/21/2016 - 07/17/2017
    News Force (User News) from 10/18/2015 - 09/14/2018

    Donator since 03/16/2015
    Realm of the Mad God Editor from 05/20/2014 - 07/08/2014
    Member since 12/23/2012


    Rep Power: 82

  5. The Following 8 Users Say Thank You to Ahl For This Useful Post:

    059 (03-28-2019),Akira Mado (03-27-2019),AllYourX (03-28-2019),BoredBro (03-27-2019),Danny (03-28-2019),Killer Be Killed (03-27-2019),Luverdark (07-23-2019),plsbegood (03-28-2019)

  6. #4
    mr hai's Avatar
    Join Date
    May 2016
    Gender
    male
    Posts
    1
    Reputation
    10
    Thanks
    0
    So.. am I fine if I change my password and delete the file from my computer?

  7. #5
    Ahl's Avatar
    Join Date
    Dec 2012
    Gender
    male
    Location
    /modcp
    Posts
    16,599
    Reputation
    3219
    Thanks
    5,383
    My Mood
    Angelic
    Quote Originally Posted by mr hai View Post
    So.. am I fine if I change my password and delete the file from my computer?
    Yes.

    If you used your RotMG password for anything else, I recommend changing those as well just to minimize any potential risks of this person trying to access other accounts.
    News Force Head Editor from 09/14/2018 - 03/02/2020
    Publicist from 11/23/2017 - 06/07/2019
    Global Moderator since 09/24/2017
    Minion+ from 04/16/2017 - 09/24/2017
    Market Place Minion from 04/16/2017 - 09/24/2017
    Minecraft Minion from 02/23/2017 - 09/24/2017
    Realm of the Mad God Minion from 11/06/2016 - 09/24/2017

    Middleman from 09/14/2016 - 09/24/2017
    News Force Editor from 08/23/2016 - 09/14/2018
    News Force (Section of the Week) from 03/21/2016 - 07/17/2017
    News Force (User News) from 10/18/2015 - 09/14/2018

    Donator since 03/16/2015
    Realm of the Mad God Editor from 05/20/2014 - 07/08/2014
    Member since 12/23/2012


    Rep Power: 82

  8. The Following User Says Thank You to Ahl For This Useful Post:

    plsbegood (03-28-2019)

  9. #6
    citydrifter's Avatar
    Join Date
    Mar 2016
    Gender
    male
    Posts
    653
    Reputation
    32
    Thanks
    2,436
    My Mood
    Yeehaw
    I have the files in recycle bin lol... I also thought it was yoinked since it was scanning in the Macromedia directory but never had the time to fully decompile and check. When something is too good to be true or so useless it probably is so. when he left the node_modules that's a dead giveaway.
    Last edited by citydrifter; 03-27-2019 at 10:11 AM.

  10. #7
    hokko's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Location
    Epic 2818
    Posts
    1,291
    Reputation
    85
    Thanks
    57
    Quote Originally Posted by citydrifter View Post
    I have the files in recycle bin lol... I also thought it was yoinked since it was scanning in the Macromedia directory but never had the time to fully decompile and check. When something is too good to be true or so useless it probably is so.
    How do you know it was scanning in the Macromedia directory?
    What software you used to detect it?

  11. #8
    citydrifter's Avatar
    Join Date
    Mar 2016
    Gender
    male
    Posts
    653
    Reputation
    32
    Thanks
    2,436
    My Mood
    Yeehaw
    Quote Originally Posted by hokko View Post
    How do you know it was scanning in the Macromedia directory?
    What software you used to detect it?
    .Net decompiler
    Actually I'm not sure but It would iterate over all the files in chrome(user data) he could've even stolen cookies if he wanted.
    Form1.resx file (used base64 encode)was the file that created the binary HookBlock once you open it. It looked for the popular rotmg.sol created by the 059.swf
    Last edited by citydrifter; 03-27-2019 at 10:40 AM.

  12. #9
    BoredBro's Avatar
    Join Date
    Jan 2017
    Gender
    male
    Posts
    82
    Reputation
    46
    Thanks
    21
    My Mood
    Amazed
    As I said useless rotmg section minions xD one of the advantages of running programs in sandbox

  13. The Following User Says Thank You to BoredBro For This Useful Post:

    citydrifter (03-27-2019)

  14. #10
    Riigged's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    no
    Posts
    3,846
    Reputation
    401
    Thanks
    10,254
    My Mood
    Devilish
    Quote Originally Posted by BoredBro View Post
    As I said useless rotmg section minions xD one of the advantages of running programs in sandbox
    With that logic, wouldnt everybody be useless? Get it? Because you called me useless for one mistake? And each and every person in the world has made thousands of mistakes? Haha? Hahahaha?

    My point is you are in no position to call anybody useless¿

     








  15. #11
    citydrifter's Avatar
    Join Date
    Mar 2016
    Gender
    male
    Posts
    653
    Reputation
    32
    Thanks
    2,436
    My Mood
    Yeehaw
    Quote Originally Posted by BoredBro View Post
    As I said useless rotmg section minions xD one of the advantages of running programs in sandbox
    tbh you can analyze with fiddler and see what api is the program using like it should be required to use localhost like krelay or run in a VM and take the time to analyze the software if you don't know anything about code too. I hate to admit but I can't agree enough with you.

  16. The Following User Says Thank You to citydrifter For This Useful Post:

    BoredBro (03-27-2019)

  17. #12
    BoredBro's Avatar
    Join Date
    Jan 2017
    Gender
    male
    Posts
    82
    Reputation
    46
    Thanks
    21
    My Mood
    Amazed
    But fiddel is to analyze the traffic among other things in a sandbox this type of malicious program does not represent any threat, and that should be the work of the minions, for example if KBK had not exposed that nothing would have been known, another example the because they banned the publication of CC without further ado, all my comments about the minions are sarcasm but from the moment they applied they should have been aware of this kind of situations everyone knows that a minion is not paid or that they have a life real but they should also be aware of their limitations in accepting a role like this

  18. #13
    Riigged's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    no
    Posts
    3,846
    Reputation
    401
    Thanks
    10,254
    My Mood
    Devilish
    Quote Originally Posted by BoredBro View Post
    all my comments about the minions are sarcasm but from the moment they applied they should have been aware of this kind of situations everyone knows that a minion is not paid or that they have a life real but they should also be aware of their limitations in accepting a role like this
    good way to put it. that is why i am resigning. ive been trying to get this position for 5 years+, back then, i wouldve punched 9 holes in my wall and screamed for 2 hours after getting the minion position, along with spending 10+ hours daily on the site (yes it was ACTUALLY that bad, ask anybody who knew me back then, I was an MPGH ADDICT), but when I got it months ago, it just wasnt as exciting, and up until a few weeks ago, ive rarely even been coming on, just doing a casual moderation check once a night basically, its getting to the point where its not that i dont have time to moderate, but i dont even have time to flip open my laptop unless its for business (i bought the laptop due to being out of the house so much away from my desktop). of course, now i am 20 years old with a management position irl so you can imagine how much time I DONT HAVE, like for fucks sake look at my damn avatar its still christmas themed.

    so when i downloaded this guys file, i decompiled it and skimmed (because i have no time like it really aint a joke i cant stress it enough) the code and saw nothing wrong. i saw that it messed with the .sol file but i didnt know it was being sent outside of the program, mainly because the program i decompiled and read code from, wasnt the program that executed it, there was apparently a hidden program in one of the folders, and i didnt even check the folder so i didnt even know there was a program hidden, so i am sorry to anyone who possibly got affected (pretty sure none, though).

    and i dont think CC got banned from being posted, its just that when CrazyJani is active, only he gets posting privileges since its his creation (why u think 059 clients always posted by 059, hes not always the first to post it, but its his cheat so he gets first), as long as hes not actively posting a CC every update, im pretty sure CC is fine to upload

     








  19. The Following User Says Thank You to Riigged For This Useful Post:

    BoredBro (03-27-2019)

  20. #14
    RealmServices's Avatar
    Join Date
    Aug 2017
    Gender
    male
    Posts
    336
    Reputation
    10
    Thanks
    38
    Rip another minion.

  21. #15
    Riigged's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    no
    Posts
    3,846
    Reputation
    401
    Thanks
    10,254
    My Mood
    Devilish
    Quote Originally Posted by RealmServices View Post
    Rip another minion.
    well i resigned because me having no time to sit down and check files THOROUGHLY is what caused this situation.. and with my schedule i really have no time ever at all so it would be bound to happen in the future again if i stayed on as staff so i resigned lol

     








Page 1 of 2 12 LastLast

Similar Threads

  1. How Illegal would it be to sell custom sol stealers?
    By NitroForgetsHisPassword in forum Realm of the Mad God Discussions
    Replies: 4
    Last Post: 11-23-2016, 12:53 PM
  2. [Help Request] How to remove Sol Stealer
    By sky2868331 in forum Realm of the Mad God Help & Requests
    Replies: 6
    Last Post: 08-19-2016, 07:59 AM
  3. [Solved] Can anyone help me make a sol stealer to get back at a guy who scammed me?
    By sahas10 in forum Realm of the Mad God Help & Requests
    Replies: 2
    Last Post: 08-13-2016, 07:34 AM
  4. Riigged's Sol Stealer
    By krazyshank in forum Realm of the Mad God Discussions
    Replies: 9
    Last Post: 06-27-2016, 07:53 PM
  5. real ********** stealer
    By llvengancell in forum WarRock - International Hacks
    Replies: 4
    Last Post: 09-24-2007, 05:36 PM