Warning: If you play Garry's Mod, your passwould could be stolen

Status
Not open for further replies.

VoiDeD

Famous
Joined
Nov 17, 2007
Messages
540
I just wanted to bring to your attention that a new vulnerability has made public in Garry's Mod.

If you connect to a certain server, your password might be stolen. I'm not sure of what servers run this, but I know it's out there and in the open now.

It works by downloading the clientregistry.blob from your computer to the server's, and then the server operator runs a decryption tool in order to get the password out of it.

Just a word of warning guys.

Small update.
Assuming this is real, I believe using the "Don't save account credentials on this computer" option under File -> Settings -> Account in Steam should protect you.

This is a possible work around, but isn't confirmed 100% to work.
 
Last edited:
This is why I don't go online in gmod. On one hand, being able to totally customise EVERYTHING in the game is awesome, but on the other things like this can happen.
 
I just wanted to bring to your attention that a new vulnerability has made public in Garry's Mod.

If you connect to a certain server, your password might be stolen. I'm not sure of what servers run this, but I know it's out there and in the open now.
It works by downloading the clientregistry.blob from your computer to the server's, and then the server operator runs a decryption tool in order to get the password out of it.

Just a word of warning guys.

Has to deal with stolen accounts, THERE IS always going to be some virus or some thing trying to steal your password always!

If you feel the need to report it, tell a DL or Advisor and they'll decide weither or not it is wrothy of making threads for.
 
The nature of this exploit far exceeds a simple scammer or phishing site. I'm aware of the stickies, I just felt that because this type of exploit could go unnoticed and that it would be helpful to inform people of it.
 
VoiDeD, have you contacted Valve or Team Garry about this? Also, could you add my workaround to the first post?
 
VoiDeD, have you contacted Valve or Team Garry about this? Also, could you add my workaround to the first post?

I have not contacted Valve about this problem because it's not under their control.

The exploit has to do with lua scripts and binary modules running on the server which allow file access to files outside the garry's mod directory.

I've attempted to contact garry but I have not received a response yet.
 
Let's not turn this thread into a debate. The vulnerability is something new and something that people should be aware of. It is not the same as a phishing attempt as it targets you purely for doing something you normally would (ie connecting to a server).

In the future, if someone has a problem with a thread on the forum, I advise that they use the "Report Post" feature (the little red exclamation point button at the bottom of any post). Let the moderators do the moderating. ;)
 
Status
Not open for further replies.

Latest posts

Back
Top