Apparently just running the game can put you at risk, because the in-game chat is vulnerable to HTML-based attacks up to and including external code (read: it can be used to spread malware). Whoops.

Sources:
https://docs.google.com/document/d/1reZz6MGHQg_IFUfX__knCQVkvbDnGv384Afj1E3QU6E/edit
https://forums.enmasse.com/tera/discussion/18877/status-of-potential-chat-vulnerability

If you're playing the game, you might want to not log in until this is sorted.

6 years ago

Comment has been collapsed.

Wouldnt you have to CLICK any html?

6 years ago
Permalink

Comment has been collapsed.

I don't think so, just playing on the server is enough because it is automatically executed. That's how chat works. You don't actually accept or deny any chat messages. Anyone can say whatever they want. At least this is how I think it is. I may be wrong.

6 years ago
Permalink

Comment has been collapsed.

Depends.

  • If it's something nasty that can get piggybacked on a known media type, then no clicking is required.
  • If the chat doesn't guard against embedded javascript, then no clicking is required.
  • If the chat doesn't guard against cross-site scripting, it can make requests to any server on the internet, which opens a whole host of possible attacks.

Finally, even if you do have to click:

  • Enough people are stupid enough to do so in general.
  • Most MMO chats I've seen have ways to link in-game items etc. in chat. Such links can potentially be spoofed, and replaced with harmful stuff.
6 years ago
Permalink

Comment has been collapsed.

Welp, was thinking of heading back in to check out the latest update, but I guess I'll wait. Thanks for the info. :3

6 years ago*
Permalink

Comment has been collapsed.

Video:
YT

6 years ago
Permalink

Comment has been collapsed.

inb4 TERA Online botnet

Edit: Guess they're disabling global chat in 4 minutes, for an hour, while they fix it.

6 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.