nik

1.6K posts

nik

nik

@nkrapivindev

Katılım Mayıs 2018
77 Takip Edilen211 Takipçiler
nik
nik@nkrapivindev·
Вы помните, когда зарегистрировались в X? Я — да. #МояГодовщинаВX
nik tweet media
Русский
1
0
0
40
nik retweetledi
Pavel Durov
Pavel Durov@durov·
Telegram was banned in Russia — yet 50M+ Russians still use it daily via VPNs. The government has spent years trying to ban VPNs too. Their blocking attempts just triggered a massive banking failure — cash briefly became the only payment method nationwide.
English
1.4K
1.8K
24.2K
1.6M
nik
nik@nkrapivindev·
Плюсую. Как же задолбали все эти секур буты, сафетинеты, нотаризации, сертификации, верификации, подписи, просто дайте мне программку запустить. Я железяку если купил за свои деньги, должен иметь право делать что хочу *на свой страх и риск.* Если сломал - сам виноват, но не могу!
@[email protected]@grishka11

Я даже могу указать на конкретный момент, когда во владении устройствами всё сломалось — когда они начали размещать начальный загрузчик в масочном ПЗУ на кристалле процессора.

Русский
0
0
0
94
nik retweetledi
ID@Xbox
ID@Xbox@ID_Xbox·
HMUR is a dynamic retro FPS that combines classic style with modern gameplay. Watch the latest trailer and get ready for thrilling challenges. @ValkyrieInitia1 msft.it/6017s3MC9
English
2
10
41
2.7K
nik
nik@nkrapivindev·
@vxunderground All Xbox games run in a hypervisor (Game OS) so even if you were to take control over the game, somehow, the worst thing you could probably do is mess with the savedata and that's it really. If you try to do anything funny, the Host OS will just kill the Game OS VM.
English
0
0
0
47
vx-underground
vx-underground@vxunderground·
I'm seeing a lot of misinformation and confusion from video game nerds regarding this video. As is tradition, I'll provide a high-level overview explaining what is (probably) occurring. Note that I am writing "probably" because without forensic evidence (data logs, debug data, information from the exploit author, the exploit code itself) I can only make an educated guess. An RCE exploit, an acronym for "Remote Code Execution" exploit, is a type of computer exploit in which an attacker is capable of delivering a payload (malicious computer code) to a remote target (your computer for example). More often than not, RCE exploits can possess limitations such as "privileges", such as what it can and cannot execute. These privileges can be the result of several factors such as the application it's exploiting (in this scenario the vulnerable application is Call of Duty WWII) privilege level (running as user or administrator). To answer some basic questions: "Is this possible on Xbox?". The answer is No. The reason why is that Xbox runs a different operating system than the operating system on your computer (for nerds: Xbox uses the Windows kernel "OneCore", the same as Windows 11, but it's still different enough). Basically, the Xbox OS lacks the sophisticated and ... "freedom" of an actual PC to perform an RCE. Even if an attacker successfully performed an RCE on the Xbox OS, it would fail due to differences between the Xbox OS and Windows 10 or Windows 11 OS. Another question: "How did they get the victims IP address?" Historically, video game developers used the P2P (Peer-2-Peer) method of playing video games. From a high-level overview, video game providers provided a service for users to match each other. However, once users were located, their computer networks would directly connect to each other. Back in the day this was the preferred method of multiplayer because it was significantly cheaper. As time progressed video game vendors migrated to a dedicated server model whereas each player would connect to a computer and all video game player actions would be communicated to the server and back to the player. Although this method is more expensive, it eradicated security concerns of P2P based matchmaking which plagued video games such as Halo, Call of Duty, and Gears of War in the mid-2000s. As you can probably assume, Call of Duty WWII is older and does not possess any dedicated servers which means it relies on the more archaic method of P2P based matchmaking. Every game you play you can identify the computer addresses of the people in your lobby. Another question: "What is this exploit doing?" In the footage shown below you can see the target machine spawn a CMD (Command Prompt) window which displays a file download in progress. - CMD title shows C:\WINDOWS\System32, meaning this is probably an administrative privilege. We can assume Call of Duty WWII is running as administrator - The file download in progress shown is from cURL, a command-line tool for downloading files or uploading files - Without forensic evidence we don't know what was downloaded, however we can make an educated guess Following the successful execution of cURL, a secondary CMD window opens up. This results in NOTEPAD.exe spawning and displaying a .txt document. Presumably here is what is happening: "CMD NOTEPAD.exe downloadedfile.txt" This command line means the cURL command downloaded a text file and subsequently executed NOTEPAD.exe to open the text file Additionally, when the Call of Duty WWII application crashes (or the user closes it), the desktop background is changed to show a prominent lawyer who Activision hired to prosecute video game cheaters. It is worth noting that changing the desktop wallpaper is slightly more complex of a task than invoking cURL and invoking NOTEPAD.exe. Which illustrates the attacker is capable of downloading a malicious script and having CMD execute that as well. However, as you can infer, there was nothing in the video which shows the RCE modifying the desktop wallpaper meaning it is possible for an attacker to execute commands remotely without the user visually seeing anything (other than cURL to download the file). The concern in this particular case is that this means an attacker is capable of deploying information stealer malware, a RAT (remote administration tool), or ransomware. Thankfully, it appears this attacker is primarily interested in memeing and fucking with people. There is more I can write to address edge cases, such as how people performed this back on Xbox 360 (that involved JTAGGING, and the Xbox 360 not using OneCore), and blah blah blah. I have to go back to taking care of my newborn son (again) Have a nice day -smelly
Wrioh@WriohEdits

I JUST GOT HACKED PLAYING WW2! EVERYONE DO NOT PLAY WW2 ON GAMEPASS! @Xbox @XboxSupport @Activision @charlieINTEL @CODUpdates @FaZeScope @Mobbing

English
64
201
2.7K
222.8K
nik
nik@nkrapivindev·
Obligatory reminder to sign the stopkillinggames.com Stop Killing Games petition, also fuck Pirate Software.
English
0
0
1
236
nik
nik@nkrapivindev·
@ValdikSS @Cluster_M О, у меня LaserJet P1102s. Вообще конкретно мой принтер спокойно работал со стоковым HPLIP из любого дистрибутива новее 2015-го. Правда почему-то когда печатаешь из винды - шум принтера один, когда из под линукса - шум чуть тише/глуше, как будто скорость ниже. Не знаю почему так.
Русский
0
0
0
42
ValdikSS
ValdikSS@ValdikSS·
@Cluster_M А был бы у тебя принт-сервер, не отваливалось бы :P У тебя P1102, если правильно помню? Какой драйвер?
Русский
1
0
3
664
Alexey Cluster
Alexey Cluster@Cluster_M·
После обновлений принтер опять перестал работать под Linux. Сил моих больше нет снова с ним колупаться, в первый раз это заняло полдня.
Русский
7
0
9
1.9K
nik
nik@nkrapivindev·
@veygax @panley01 I'd agree with you overall 200% if I could be absolutely sure that my bank's certs won't be revoked because of geopolitical pressure or w/e. I agree that normal TLS w/o a custom CA should be enough, but a backup plan is always way better than "oh shit oh shit we're down!"
English
0
0
0
28
nik
nik@nkrapivindev·
@veygax @panley01 Well, to be fair, most banks that have to use this CA for legal reasons tend to bundle a custom TLS library with GOST/Kuznechik support with this CA in their apps instead of asking you to install this CA system-wide, which is a MUCH better sollution. Also,
English
1
0
0
24
Panley
Panley@panley01·
This is actual spyware by the way, they ask you to install a CA. For the love of God do not install a CA ever. There is no good reason to install a CA. You cannot pay me enough to install a CA. This is insane & I have no idea why tech outlets aren't talking about it.
Panley tweet media
English
59
221
2.3K
74.7K
GameMaker
GameMaker@GameMakerEngine·
It's time to vote on your winners of the 2024 GameMaker Awards!! 🎉🏆 Choosing finalists gets harder every year so we want to thank the community for creating amazing stuff! 🔗 gamemaker.io/en/blog/gamema… VOTE CLOSES SEPT 11.
GameMaker tweet media
English
11
21
97
28.4K
nik
nik@nkrapivindev·
@GameMakerEngine Release Mondealy on PS4 and PS5, hopefully...
English
0
0
1
26
GameMaker
GameMaker@GameMakerEngine·
We reaching (crawling towards?) the end of the year! We've had an amazing year at GameMaker but how has your gamedev gone in 2023? What are your goals for 2024??
English
64
8
174
86.8K
nik
nik@nkrapivindev·
@vxunderground what's the password to the hard drive though?
English
0
0
3
260
vx-underground
vx-underground@vxunderground·
The harddrives are now arriving. Individuals residing in the United States should expect the drives by Friday at the latest. And again, as a general liability thing, please for the love of Christ be careful, don't nuke your box
John Hammond@_JohnHammond

oh fuck

English
13
18
549
58K
nik
nik@nkrapivindev·
@Xrayez To quote their own post: "Customers will set forth their team size in our contract...We trust in the honesty of our clients...We also trust they properly recognize their staff in the game credits." But credits can get very large with all the volunteers etc esp. in indies
English
0
0
0
16
nik
nik@nkrapivindev·
Thought I'd share some feedback. Hi, I'm Nikita Krapivin, I work for @ValkyrieInitia1 - a game publisher. And there are several issues I see with the current model. 1) Team members The way Unity does team members is simple yet very effective - 1 seat per 1 Unity ID.
W4 Games@W4Games

We're excited to announce our pricing model for @W4Games Console Ports for @godotengine, which will be released in 2024. We're also opening a second wave of Early Access for #NintendoSwitch and #XboxSeries, planned for public release by end Q1 2024. w4games.com/2023/12/11/w4-…

English
1
0
1
262
nik
nik@nkrapivindev·
3) Remarks It is great that W4 made this initiative, truly, it's awesome. But if less people can afford a product, less people will buy it. And publishers don't really care how complex an engine is, if the price tag is more than e.g. Unity/GM (ref to twitter.com/reduzio/status…)
English
0
0
0
188
nik
nik@nkrapivindev·
2) The pricing itself Given the 1) issue, the current price tag is more expensive than all other engines. I understand that this price might be OK for US legal entities, but not for LATAM or CIS. I hope there will be regional pricing for, uhm, not so rich countries.
English
1
0
0
157