Key Compromise

Author Topic: Key Compromise  (Read 49277 times)

damn i thought this thread was about the keys getting snagged by a nigg(er)a not if forgetadia a good game or not compared to stuffland or roosterblox

guys im new here whats a stuffpost? never heard of it in my life


blokland an birckadia is are both good games


sentry is spitting straight facts




Hey, I wanted to write to tell you guys that I'm the one who made the exploit for celau to use on his server. I wanted to come clean and make things right because that's what I believe a good person would do in this situation. I let Badspot know how everything works a few days ago through e-mail and I told him I would wait a little bit to clear my head before I made a post.

I will make a timeline of the events leading to the key leak and a bit after:

This originally started with Heedicalking and I discussing about the ideas of a fully modifiable game engine that syncs from server to client. But after more reading, he found papers about how easily exploitable game engines are (source, unreal 3), and bet that Blockland had similar vulnerabilities. I wanted to see for myself, so I found one and told him about it and we discussed the severity of this exploit and what could be done. He didn't want to do anything malicious nor did he really care about Blockland anymore, but we discussed ideas like automatically downloading GUIs to clients or making an "NPC Virus" where people's avatars would be forced grey.

I then came to celau and mentioned the possibilities an RCE could have, and we (celau and I) decided together that key stealing would be interesting. My friends mention the spotlight shouldn't be taken away from celau, and that this scenario is similar to "making the gun and celau using it," however I feel like it's more along the lines of "making the gun requested by celau who told me he was going to kill innocents." I still knew what was going to happen and willingly participated, so I'm definitely not trying to avoid blame. I don't hate Blockland nor have some kind of agenda to take down Badspot, that I can say with certainty was celau's mindset.

While keys were being collected over the span of a few days, something interesting with Cca was happening. I am not sure of the innocence of Cca. I believe celau handed him the exploit and requested that a RAT be made in order to target people like Oak for some reason. Cca then started joining celau's servers and crashing constantly as if he was "investigating" the exploit. Slowly information about how it works was being leaked to other people. There's two possibilities here-- either he actually found out how it works through a debugger (extremely unlikely, this exploit was particularly difficult to track down) and he did the right thing by reporting it, or he had the exploit the entire time and tried playing the good guy. I am doubtful it is the former only because celau informed me in voice chat that Cca and his "hacker group" apparently already found this exploit long ago, which was a blatant lie. Cca has also given me fake screenshots of a sophisticated hacking GUI to con me into making something better, a manipulative move that ultimately would have ended him up with a new version of BLHack.

The day came for the leak and celau had quite an arsenal of keys to use. I forwarded the CBM leak list to him as well which enabled him admin access on a few servers. I do not agree with the hateful things he said, and I started feeling a lot of pressure as soon as I saw the damage he and his group were doing. I joined a group of people dedicated to finding the exploit and how it works, and pretended to not know anything to protect my innocence. Interestingly, this group's research was centered around hints given to them by Cca, but apparently StreamShark leaked information about it first (https://i.imgur.com/tjL3gLg.png) so maybe Cca swooped in to cover his ass after he knew this.

This group of people that were researching the exploit were my good friends, so I felt an unbelievable amount of pressure since I knew I was mistreating some very close people. After a long voice chat with celau, with him reassuring me multiple times that I could get away with this if I stay silent, I decided I would do the right thing because I sincerely regret my actions. I told everyone that I did it and how it worked, and they were incredibly supportive. We got the information to Badspot and did our best to straighten the situation out. I want to note that when the leak was happening I got an e-mail from Badspot asking what was going on, and I originally responded acting like I was helping the research team, but later I e-mailed him again just coming clean. So I lied originally but did my best to make up for it.

That about sums the timeline up, I think I got everything, so I'll move on to amend making.

I want to make things right and repay any damages I've done. I'm not sure exactly how to do this, but the first idea that comes to mind is paying back any keys that were lost in this fiasco one way or another. Users may get their keys back from Badspot as mentioned in that development thread, however if any keys are truly lost I will compensate them. I don't have money *yet* but I'll be able to afford this soon.

Thank you for reading and for your time, and I'm sorry I put you through this.



I mean all jokes aside that stuff is a felony better to speak up

was a RAT actually made

-snap-
i appreciate the apology, but it was loving ridiculous to not expect a total loving stuffstorm to emerge after giving it to loving celau. this better damn be a lesson learned.