Insurgency Mod Has Built-in Backdoor

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Shawn Zipay
    Managing Communities 24/7
    • Apr 2003
    • 69279

    #1

    Insurgency Mod Has Built-in Backdoor

    Fabien Chebel, an editor for the French gaming site, Vossey.com, has brought to our attention that a backdoor may have been purposely left in to recent builds of the Insurgency Mod. The allegations of this issue arose some weeks ago when one of the mod's developers was able to kick another player on a public server. The developer allegedly had no admin access and did not have the server's rcon password.

    Subsequent complaints on the matter to the Insurgency Mod team went ignored and were ultimately deleted. A short while after, the mod's project lead, "Dr. Spielmann" issued the following statement.
    However, as a consequence there's been some public discussion regarding the existence of « backdoors » in our mod. We believe that the issue has been artificially magnified and taken out of context, causing unnecessary alarm among a few communities of INS players. There is no malicious code of any kind in Insurgency.

    What is still present in the code, as this is a non-commercial and non-profit project in beta stage, are some debug, development and testing tools that can be used by the developers of the mod to work in the game. Our tools only allow registered developers to execute code that has been approved and accepted by all of you when using Source-engine related software, such as rcon commands.

    When addressing malicious attacks in the past we have been repeatedly asked by server admins to implement anti-cheating measures. To work on those measures we have also had the need in the past to exceptionally execute rcon commands such as kicking a player from a server, particularly in servers without server admins, test servers or promotional servers (such as the ones we've grown used to setting up for free for our community when releasing major updates). That's the only reason why those tools are present.

    We are convinced that this policy has enabled you to have a better online experience until now. However, we are ready to revise it and change / remove some of its functionality.(...)

    While we still believe the tools are useful for that purpose, it's true that they have been incorrectly used in this particular case, so we have decided to remove them in the next update scheduled for mid-August. From now on we will fully and exclusively rely on server administrators to execute those commands and keep their servers free from exploits, aggressive behavior, racist insults or well-known cheaters.

    The developer backdoor is slated to be removed "in the following weeks." In case anybody has caught wind of this issue, we felt compelled to share the story with you to reassure you that nothing malicious will happen on your server. Well, nothing malicious will happen on your server provided the mod's developers play nice.

    We'd like to give a special thanks to Fabien "heffebaycay" Chebel and the Vossey.com site for bringing this to our attention. The original story and letter from Dr. Spielmann can be found at NoFrag.

    Please note that without this appearing on an all-English website, it is hard to confirm or validate some of these claims. As such, we have taken the precaution of tagging this as a potential rumor.
  • Linux
    wat da gah?
    • Sep 2026
    • 382

    #2
    Re: Insurgency Mod Has Built-in Backdoor

    Well that just crappy programming and mod dev. They better fix that crap, this also reminds me of some older news post on the same subject if not the samething?

    Comment

    • kalabalana
      Member
      • Sep 2026
      • 22

      #3
      Re: Insurgency Mod Has Built-in Backdoor

      Originally posted by Linux
      Well that just crappy programming and mod dev. They better fix that crap, this also reminds me of some older news post on the same subject if not the samething?
      Actually, this is a sign of good coding, crappy coders would most likely not think of or know how to implement this sort of functionality. Also, you cannot "fix" something that is not broken.

      Personally, I don't see an issue with the idea, I'd prob do something myself similar given the opportunity and considering the online experience.

      BTW, I thought the same thing, I remember hearing about this a while back... Am I mixing up games?

      Comment

      • Linux
        wat da gah?
        • Sep 2026
        • 382

        #4
        Re: Insurgency Mod Has Built-in Backdoor

        Originally posted by kalabalana
        Actually, this is a sign of good coding, crappy coders would most likely not think of or know how to implement this sort of functionality. Also, you cannot "fix" something that is not broken.

        Personally, I don't see an issue with the idea, I'd prob do something myself similar given the opportunity and considering the online experience.

        BTW, I thought the same thing, I remember hearing about this a while back... Am I mixing up games?
        It depends on the eye of the beholder if its crappy programming or not. Personally I don't install and play a person mod to have them come into my server and control it. Its a security risk I don't wish to take and from my stand point where I work this would be considers a security risk. But again if they fix then all is good.

        Comment

        • AlecJ32
          Site Staff
          • Aug 2008
          • 502

          #5
          Re: Insurgency Mod Has Built-in Backdoor

          Originally posted by Linux
          It depends on the eye of the beholder if its crappy programming or not. Personally I don't install and play a person mod to have them come into my server and control it. Its a security risk I don't wish to take and from my stand point where I work this would be considers a security risk. But again if they fix then all is good.
          The word 'fix' is a bit questionable, though. 'Remove' would be more appropriate, since this was purposefully placed.

          Comment

          Working...