Games

what nbm is doing, security report

Założony przez natan_44 97 wpisów ostatni wpis 2 miesiące temu Zamknięty Strona 1 z 5

#1 Edytowano

ZERO HOUR ASSAULT - SECURITY ANALYSIS & DEVELOPER ACTIVITY REPORT
Date: May 27, 2026
Source Type: Official Source Code (Analyzed)
Developer: NBM Studios (NBM Digital Ltd)

================================================================================
1. CRITICAL SECURITY VULNERABILITIES (BACKDOORS & RCE)
================================================================================

[CRITICAL] REMOTE CODE EXECUTION (RCE) VIA PICKLE
- Location: zero_hour_assault.py (Line 1224), zhaserver.py (multiple locations)
- Detail: The game uses the Python 'pickle' module to deserialize data received
directly from the network.
- Risk: 'pickle' is inherently insecure. A compromised server or a malicious
developer can send a crafted packet that executes arbitrary commands on the
player's computer (e.g., deleting files, installing real malware, or stealing
browser cookies). This is a built-in backdoor.

[CRITICAL] INSECURE AUTO-UPDATE SYSTEM
- Location: updater.py, main.py
- Detail: Every time the game starts, it checks for updates and automatically
downloads .exe, .dll, and .zip files from nbmstudios.com.
- Risk: There is NO digital signature or hash verification for these downloads.
If the developer's site is hacked, every player's computer will automatically
download and run whatever malicious file the hacker uploads.

[HIGH] PLAINTEXT CREDENTIAL STORAGE
- Location: server/zhaserver.py, server/chars/*/pass.usr
- Detail: The server stores player passwords in raw, plaintext files.
- Risk: No hashing (like bcrypt/argon2) is used. If the server is breached,
every player's password for every account is instantly compromised.

================================================================================
2. DEVELOPER "ACTIVITIES" & PRIVACY (SURVEILLANCE)
================================================================================

HARDWARE TRACKING (COMPUTER ID)
- Location: network.py, net.py, zhaserver.py
- Activity: The game generates a 'compid' (Computer ID) based on hardware
parameters. This is used to link all accounts created by a single person
and enforce bans.

ADMINISTRATIVE SPYING TOOLS
- Location: zhaserver.py (Admin Commands)
- Activity: Administrators have built-in commands to:
* /seemail: View a player's registered email address.
* /listip: View the real IP address of every connected player.
* /viewplayer: View detailed metadata including creation date and inventory.
* /itemlist: Inspect exactly what items a player has.

INVASIVE ANTI-CHEAT (MEMORY SCANNING)
- Location: anticheat.dll (External binary called by zero_hour_assault.py)
- Activity: The anticheat performs memory scanning. While standard for games,
the lack of transparency and the fact that the DLL is downloaded
unverified at runtime is a privacy risk.

EXPOSED SECRETS IN SOURCE CODE
- Telegram Bot Key: [REDACTED]
- Google API Key: [REDACTED]
- Risk: These keys allow anyone with the source code to hijack official
developer communication channels or consume their API quotas.

================================================================================
3. COMMUNITY REPUTATION & DRAMA HISTORY
================================================================================

MALWARE RUMORS (RATs)
- For years, the audiogame community (audiogames.net, elten.link) has
rumored that NBM Studios' software contains Remote Access Trojans (RATs).
The discovery of the 'pickle' vulnerability confirms the *technical*
existence of these capabilities.

IP THEFT (CLONING)
- NBM Studios is frequently accused of stealing code and assets from
other games like "Survive the Wild."

2023 SECURITY BREACH
- In August 2023, the developers admitted to a major "terrible incident"
(server breach) that exposed the inherent insecurity of their platform.

================================================================================
4. FINAL VERDICT & RECOMMENDATIONS
================================================================================

VERDICT: HIGH RISK
The code is functional as a game but is architecturally "toxic" from a
security perspective. It lacks industry-standard protections and includes
logic that functions as a backdoor.

RECOMMENDATIONS FOR USERS:
1. NEVER use the same password for this game as you use for your email/bank.
2. Be aware that the developers (or anyone who hacks them) can technically
control your computer through the 'pickle' network vulnerability.
3. Run the game in a Sandbox or VM if you value your primary system's privacy.
4. Do not trust the "official" nature of the code to mean it is "safe."

================================================================================
REPORT END
================================================================================

#2 7 polubień

Thanks Chat GPT

#3 7 polubień Edytowano

Lol storing passwords in plain text is crazy though. If that's true ofc.

#4

it is gemini cli

#5 2 polubienia

Ok this is very funny though. You can't steal code from STW because STW was never leaked, every BGT game simply downloads the files from a web server without signature checking them etc. Comp IDs and administrative tools like viewing IP and so on are common standards and if we cry around about this, I can't take you serious.

#6 2 polubienia

If you do that anywhere, you can't be helped anyway. 1. NEVER use the same password for this game as you use for your email/bank.

#7

well, what the rce

#8 3 polubienia

LOL So overdramatized, every audiogame follows those bad security practices. Go give it this as a reference and ask it to do a security audit of dear loved TK and watch the cloner protecting that while bashing NBM studios for the same issues just because they hate them more. This is purely despise-based drama.

#9 2 polubienia

I just have a quick question: why are you posting this here? Sorry, but honestly. Nobody cares what a game developer does who has already drawn attention to himself multiple times for having inadequate security measures. Also, if I were you, I wouldn't just post this AI nonsense here without any explanation. Did you verify everything Gemini said yourself? If not, this document is worthless.

#10 2 polubienia

Why the fuck would you post the api key. Really, really stupid choice.
“The important thing is to not stop questioning. Curiosity has its own reason for existing.” (Albert Einstein)

#11 1 polubienie

OP, you know that if the developer's website gets hacked they can also put the correct signatures for their malicious files? Oh who am I kidding, you just outsourced your thinking to AI and thought people were going to think you were smart.

#12 1 polubienie

Source of city of division probably have worse backdoors ;) - I was bored some months ago, and it's scary how much security stuff is broken there.

#13

It was indeed leaked. I don't have the code or anything myself but just a few days after it went down, a few people have already had the code on their discord.

-- (Jonathan):
Ok this is very funny though. You can't steal code from STW because STW was never leaked, every BGT game simply downloads the files from a web server without signature checking them etc. Comp IDs and administrative tools like viewing IP and so on are common standards and if we cry around about this, I can't take you serious.

--

Όταν θα κοιτάς την θάλασσα
Χωρίς να το θέλεις, θα βλέπεις εμένα
Και τα μάτια σου θα ‘ναι θλιμμένα
Όταν θα ξυπνάς στον ύπνο σου
Χωρίς να το θέλεις, θα σκέφτεσαι εμένα
Και θα νιώθεις μεγάλο κενό

#14 2 polubienia

Has it gotten to the point of you believing cloners? There have been people trying hard to do this, and If we were to ask sam right now I can pretty much asure you the code of stw, other than the sounds, never got leaked.
Or you can show some proof of that of course, interesting it would be indeed.
McOi

#15

Of course I can show proof, but I don't recommend you to download anything that I'm showing because it might be malicious. So be careful.
https://audiowander.com/

Όταν θα κοιτάς την θάλασσα
Χωρίς να το θέλεις, θα βλέπεις εμένα
Και τα μάτια σου θα ‘ναι θλιμμένα
Όταν θα ξυπνάς στον ύπνο σου
Χωρίς να το θέλεις, θα σκέφτεσαι εμένα
Και θα νιώθεις μεγάλο κενό

#16 2 polubienia

This also could be a ripoff just with the sounds and maps copied, see lf.

#17

i'm honestly kind of curious to run this in a virtual machine and see what this is but honestly I can't be bothered to make one and go through the windows installer just for this, is there any premade virtual machines out there

#18 Edytowano

I can see that nothing has changed about backdoors since the days of Real World.
But I can also see that this was generated by AI that doesn’t understand a thing.
Administrative spying tools? That’s actually normal and not spying at all.
Sygnatura to może być w sądzie. Sygnatura sprawy np. :P

#19

that thing in there is life in nature, which, I sadly found out has malware now, I really, really liked that game, and braught my friends there and even paid like 30 dollars on it, for the dev to put malware in it in the end. that's disapointing

#20

OK where's the proof it has malware?
Alex Chapman (Alexoloopios)