[DiscordArchive] Warmane has had it for ages but there's no public write up yet?
[DiscordArchive] Warmane has had it for ages but there's no public write up yet?
Archived author: Foe • Posted: 2024-07-28T17:26:11.017000+00:00
Original source
It will help the right people abuse it, but it won't help them with finding a different RCE
Archived author: gee • Posted: 2024-07-28T17:26:29.521000+00:00
Original source
big servers will be patched but smaller ones are screwed
Archived author: Foe • Posted: 2024-07-28T17:26:41.297000+00:00
Original source
It's on a per-player individual client basis
Archived author: [GLFY] Mitche • Posted: 2024-07-28T17:27:00.035000+00:00
Original source
And not to mention the average user will never end up having that client
Archived author: gee • Posted: 2024-07-28T17:27:04.657000+00:00
Original source
Is there a way for a server to stub it on the client on connecting? ie a server side fix for those who won't update?
Archived author: Foe • Posted: 2024-07-28T17:27:09.360000+00:00
Original source
No
Archived author: schlumpf • Posted: 2024-07-28T17:27:28.025000+00:00
Original source
Well, yes, they can exploit it and patch the binary.
Archived author: Nix • Posted: 2024-07-28T17:27:28.190000+00:00
Original source
It was just a bad idea to announce anything
Archived author: Deamon • Posted: 2024-07-28T17:27:28.413000+00:00
Original source
I mean. Initially, the wow client as in provided by blizzard was "proof of concept" that no malicious code is going to be executed on player's PC.
In later expansion, you had to use patcher or launcher to even allow client to connect to server. Which already defeats the purpose.
Now you have the RCE in 1.12 client. And you want simply to close the eyes at it? Doesn't seem to be a wise decision
Archived author: [GLFY] Mitche • Posted: 2024-07-28T17:27:36.292000+00:00
Original source
It's a good bandaid but unless server's start actually providing that client to their user's it will never really help