<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: World of Tanks Replay Vulnerable to Malicious Code</title>
	<atom:link href="http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/feed/" rel="self" type="application/rss+xml" />
	<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/</link>
	<description></description>
	<lastBuildDate>Fri, 30 Aug 2019 10:08:59 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.2</generator>
	<item>
		<title>By: 10.12.2014 &#124; For the Record</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-234001</link>
		<dc:creator><![CDATA[10.12.2014 &#124; For the Record]]></dc:creator>
		<pubDate>Wed, 10 Dec 2014 16:53:55 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-234001</guid>
		<description><![CDATA[[&#8230;] them based on the feedback or not. Okay, one more very important piece of news. Remember the &#8220;replay vulnerability&#8221; post? Well, Wargaming just acknowledged the issue by a special portal post. TLDR: replays [&#8230;]]]></description>
		<content:encoded><![CDATA[<p>[&#8230;] them based on the feedback or not. Okay, one more very important piece of news. Remember the &#8220;replay vulnerability&#8221; post? Well, Wargaming just acknowledged the issue by a special portal post. TLDR: replays [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Its_Matra</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233790</link>
		<dc:creator><![CDATA[Its_Matra]]></dc:creator>
		<pubDate>Wed, 10 Dec 2014 08:52:31 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233790</guid>
		<description><![CDATA[Obviously nobody read my comment two above this one!]]></description>
		<content:encoded><![CDATA[<p>Obviously nobody read my comment two above this one!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Baldrickk</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233770</link>
		<dc:creator><![CDATA[Baldrickk]]></dc:creator>
		<pubDate>Wed, 10 Dec 2014 06:46:03 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233770</guid>
		<description><![CDATA[Well, there is executable code in there.

I haven&#039;t looked at it first-hand but I assume that it will be a script for the built in scripting engine inside WOT

Embedding an exe would probably be possible.  Probably easier to have the game connect to the Web and download whatever for you though.]]></description>
		<content:encoded><![CDATA[<p>Well, there is executable code in there.</p>
<p>I haven&#8217;t looked at it first-hand but I assume that it will be a script for the built in scripting engine inside WOT</p>
<p>Embedding an exe would probably be possible.  Probably easier to have the game connect to the Web and download whatever for you though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Baldrickk</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233768</link>
		<dc:creator><![CDATA[Baldrickk]]></dc:creator>
		<pubDate>Wed, 10 Dec 2014 06:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233768</guid>
		<description><![CDATA[There os some good news that hasn&#039;t been mentioned. 

The wotreplays site won&#039;t accept &#039;tampered&#039; replays.

I have not dug into it enough to say how good this protection is (hunch says embedded hash - so possible to break)

It&#039;s a minor thing, but a replay on Wotreplays is (slightly) safer than one from say - dropbox (like the PoC replay) that someone has linked to because, of this limited protection.]]></description>
		<content:encoded><![CDATA[<p>There os some good news that hasn&#8217;t been mentioned. </p>
<p>The wotreplays site won&#8217;t accept &#8216;tampered&#8217; replays.</p>
<p>I have not dug into it enough to say how good this protection is (hunch says embedded hash &#8211; so possible to break)</p>
<p>It&#8217;s a minor thing, but a replay on Wotreplays is (slightly) safer than one from say &#8211; dropbox (like the PoC replay) that someone has linked to because, of this limited protection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pokelightian</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233762</link>
		<dc:creator><![CDATA[Pokelightian]]></dc:creator>
		<pubDate>Wed, 10 Dec 2014 04:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233762</guid>
		<description><![CDATA[Wotreplay that formats hard drive and causes hardware overheating. Or Chernobyl-like symptoms.]]></description>
		<content:encoded><![CDATA[<p>Wotreplay that formats hard drive and causes hardware overheating. Or Chernobyl-like symptoms.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Replaye z World of Tanks napadnuteľné škodlivým kódom</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233712</link>
		<dc:creator><![CDATA[Replaye z World of Tanks napadnuteľné škodlivým kódom]]></dc:creator>
		<pubDate>Tue, 09 Dec 2014 19:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233712</guid>
		<description><![CDATA[[&#8230;] Zdroj: http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/ [&#8230;]]]></description>
		<content:encoded><![CDATA[<p>[&#8230;] Zdroj: <a href="http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/" rel="nofollow">http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/</a> [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MassiveHyperion</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233704</link>
		<dc:creator><![CDATA[MassiveHyperion]]></dc:creator>
		<pubDate>Tue, 09 Dec 2014 19:05:21 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233704</guid>
		<description><![CDATA[Who&#039;s the say that someone didn&#039;t infuct the file, then upload to WoT Replays?]]></description>
		<content:encoded><![CDATA[<p>Who&#8217;s the say that someone didn&#8217;t infuct the file, then upload to WoT Replays?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: akseleo2000</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233702</link>
		<dc:creator><![CDATA[akseleo2000]]></dc:creator>
		<pubDate>Tue, 09 Dec 2014 19:01:41 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233702</guid>
		<description><![CDATA[Oh Ty]]></description>
		<content:encoded><![CDATA[<p>Oh Ty</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Torenico</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233699</link>
		<dc:creator><![CDATA[Torenico]]></dc:creator>
		<pubDate>Tue, 09 Dec 2014 18:52:27 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233699</guid>
		<description><![CDATA[&quot;Dont want virus? dont download replay&quot;.]]></description>
		<content:encoded><![CDATA[<p>&#8220;Dont want virus? dont download replay&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr_Deo</title>
		<link>http://ftr.wot-news.com/2014/12/09/world-of-tanks-replay-vulnerable-to-malicious-code/#comment-233697</link>
		<dc:creator><![CDATA[Mr_Deo]]></dc:creator>
		<pubDate>Tue, 09 Dec 2014 18:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://ftr.wot-news.com/?p=20257#comment-233697</guid>
		<description><![CDATA[I haven&#039;t seen the thing in action, but this has been going on for a while I think.  I downloaded some replays about a year ago that looked fake/edited on the replay site and they wouldn&#039;t launch the client to play said replay.  I watched for open processes and port listening at the time but nothing nasty was there.  I do know that many &quot;Competitions&quot; that go on where players &quot;Submit&quot; replays have had results that just don&#039;t go with what is shown in the game or via noobmeter (those are just basic API pulls I guess?)..

WG will have no choice but to fix it once it becomes public knowledge, else someone will send in a &quot;Ticket&quot; reporting something in game, and the moment they open it then their own internal network can be exposed to a hacker... There in lies the rub..

If Replays were ONLY used by players then they would probably sit on their hands, but as they use them internally too then Hopefully it will spur them on.  There is no reason why the wot exe should be launching external programs anyhow, and if it is then they should be signed in the software.]]></description>
		<content:encoded><![CDATA[<p>I haven&#8217;t seen the thing in action, but this has been going on for a while I think.  I downloaded some replays about a year ago that looked fake/edited on the replay site and they wouldn&#8217;t launch the client to play said replay.  I watched for open processes and port listening at the time but nothing nasty was there.  I do know that many &#8220;Competitions&#8221; that go on where players &#8220;Submit&#8221; replays have had results that just don&#8217;t go with what is shown in the game or via noobmeter (those are just basic API pulls I guess?)..</p>
<p>WG will have no choice but to fix it once it becomes public knowledge, else someone will send in a &#8220;Ticket&#8221; reporting something in game, and the moment they open it then their own internal network can be exposed to a hacker&#8230; There in lies the rub..</p>
<p>If Replays were ONLY used by players then they would probably sit on their hands, but as they use them internally too then Hopefully it will spur them on.  There is no reason why the wot exe should be launching external programs anyhow, and if it is then they should be signed in the software.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
