World of Tanks Replay Vulnerable to Malicious Code

Hello everyone,

the following very interesting message was found on WoT Reddit – did you know that World of Tanks replays can be injected with (potentially malicious) code?

Check this out – user KeeperOfTheFeels wrote this:

A couple of months ago I was rooting around within the WoT replay files and their format. I discovered that they way they stored data within certain packets in the replays made it extremely easy to get code execution. After a couple of days working at reliable execution I came upon a reliable way to take any replay file and inject code to execute. This happens very quickly after opening the infected replay file with no way to prevent it once WoT begins reading from the replay.

To my knowledge any replay after May, 2014 is vulnerable to this. It is likely any replays before then are also vulnerable and should not be trusted. A proof of concept replay file that opens a calculator window can be found in the link below. As of now you should not trust any replay files from sources you do not trust, until an official fix is released by WarGaming.

I would advise not directly posting about it on the official forums or linking back to here. You may get your account banned from the forums and your message deleted.

Proof Of Concept: PoC

Well, of course I had to try it out and sure enough, the “proof of concept” replay indeed starts the calculator. I am sure you can imagine the potential joys of having infected replays. According to the original poster, WG is now aware of the issue. Whether they are working on a fix or whether they wait for something bad to happen first is the real question.

SerB Thinking of Investing in Space Industry

Source: http://itar-tass.com/kosmos/1633932

Hello everyone,

today’s article from itar-tass.com news server mentions an interesting piece of information. One of the creators of World of Tanks, Sergei “SerB” Burkatovsky is thinking of investing 5 to 10 million rubles (cca 75k to 150k EUR) in the Russian rocket developer “Lin Industrial” in order to create a super-light rocket “Taymir”.

3914143

The company chief designer Aleksander Ilyin confirms that there are two variants – either buying 5 percent of company shares for 5 million rubles or 10 percent for 10 million. SerB confirmed the intention without mentioning the actual sums. According to his statements, Taymir rockets can carry small objects, such as student satellites to orbit. He stated also that the reason he wants to get involved is because he’s a “fan of space”. He also further states that this might be a profitable venture, as businessmen might be interested in sending various small objects to space. It might be also useful for universities and researchers. The company plans in the first years to launch 3 Taymirs per year, with each earning them net profit of 1 to 1,5 million USD. Ilyin however confirmed that if necessery, the company could produce the rockets as fast as one per week.

So don’t forget to buy the Christmas bundles, SerB needs rockets :)

World of Warships – Weekend Beta For Everyone

Hello everyone,

World of Warships developers decided to allow wider playerbase to play World of Warships for a weekend. This event is apparently shared by all servers (RU, EU, USA), but you have to win an invite code somewhere.

 

 

You can read the whole news here (there are some limits). Certain community contributors recieved a bunch of codes as well, so you can find that stuff on the forums.

You might have noticed from my tone I am not exactly hyped about that entire thing, but if you wanted to be an alpha tester and didn’t get in, now’s your chance. Yay.

Today’s Advent Offer (9.12.2014)

Hello everyone,

today’s advent offer for EU server includes:

- SU-100Y + slot
- large caliber tank rammer

Price: 16,90 USD (13.75 EUR)

Meanwhile on Russian server, today’s offer is: 50 percent discount on crew training and re-training

A word of advice to you: soon, the Christmas marathon will start and common premium tanks like SU-100Y will be on like 30 or 50 percent discount. I strongly suggest you wait a week or two.

FTR Contributor Review

Hello everyone,

it’s time for weekly contributor review. This time, following people donated via Paypal:

Johan M. (Sweden)
Daniel A. T. (Romania)
Ciliaris (Norway)
Glenn W. (New Zealand)
R.Z. (name redacted at the request of the contributor, Israel) – thank you for a very large contribution, much appreciated! :)
Radek M. (Czech Republic)

Thank you, guys. I really appreciate it.

Now, for the Patreon cycle:

Out of the 593,59 USD pledged at the point of the cycle activation:

- 520,10 USD came in successfully (the rest didn’t go through for some reason on the contributor side, insufficient funds on account etc.)
- out of 520,10 USD, after the Patreon and CC fees and all that, 469,88 USD were left for FTR – much appreciated! The list of contributors can be viewed here. Once again, huge thanks for the support to all of you :)

8.12.2014

Check out the Chieftain’s Hatch article on the Ripper camouflage (written for Xbox WoT)

- A-32 will not get its highpenetration HEAT shells back (SS: IIRC A-32 is RU exclusive)
- Storm states that IS-4 armor (during HD rework) will be somewhat improved
- Evilly states that Xbox WoT doesn’t have the same number of players as the PC version, but WG’s not complaining (SS: in the sense it’s not considered a failure)
- developers confirm, that the Panther 88 and other premium vehicles, intended for the premium shop, will not be possible to test on the test servers in the future (funnily enough, in the same thread a day before, the same developer replied that it will appear in the next iteration of the test, later he changed it to the answer outside the brackets)
- M56 Scorpion is still being balanced
- developers confirm: Individual Missions tanks (StuG IV, T28C, T55A and Object 260) do NOT earn more credits (like premium tanks). They earn “as many credits as regular vehicles”

Posted in Q&A