Page 1 of 16
1
2
3
11
... LastLast
  1. #1

    PSA ElvUI Users - "ElvUI has a backdoor and how to remove it"





    http://www.reddit.com/r/wow/comments..._to_remove_it/


    I don't think the issue at hand is if Elv did something malicious via this code. Admins / Mods already admit he has mess with people he knew or guildmates in the past. That right there is enough to cause concern in a public release downloaded by thousands of players.



    Personally, I wouldn't want a dev to have the ability to decide if they wanted to mess with me or not when I use their addon. That said I don't use ElvUI and this is just my personal opinion.

    Don't shoot the messenger! :x
    Last edited by Elvine; 2014-10-17 at 10:37 AM.

  2. #2
    Titan Gumboy's Avatar
    10+ Year Old Account
    Join Date
    Mar 2014
    Location
    Lost in Space
    Posts
    11,649
    That is incredibly shady..wth?

    Glad I make my own UI I guess :P
    You're a towel.

  3. #3
    The Undying Slowpoke is a Gamer's Avatar
    10+ Year Old Account
    Join Date
    Sep 2010
    Location
    World of Wisconsin
    Posts
    37,272
    Quote Originally Posted by Gumboy View Post
    That is incredibly shady..wth?

    Glad I make my own UI I guess :P
    That is VERY shady.

    There's no legit reason to put that backdoor in. Essentially you created an army of potential spambots.
    FFXIV - Maduin (Dynamis DC)

  4. #4
    Honorary PvM "Mod" Darsithis's Avatar
    10+ Year Old Account
    Join Date
    Jan 2011
    Location
    Chicago
    Posts
    51,235
    This is really, really unfortunate news. I, along with half my raid, use ElvUI

  5. #5
    That is incredibly slimy.

  6. #6
    Mechagnome intrinsc's Avatar
    10+ Year Old Account
    Join Date
    May 2013
    Location
    Aberdeen Proving Ground, MD
    Posts
    538
    According to Elv, the updated 7.08 version removes this code.

  7. #7
    Thank you for this PSA. So shady....

  8. #8
    Deleted
    This is hilarious. I would LOVE to see this happen to people during a farm raid considering how stale SoO is.

    Reddit comments made me laugh aswell 'inform the police' lmao, someone made me auto follow a person in LFR. You're going to jail now son.
    Last edited by mmoc2233da4339; 2014-10-17 at 05:52 AM.

  9. #9
    Crap.... Am I about to go back to default UI?

  10. #10
    Obnoxious Patriots Fan Darth Belichick's Avatar
    15+ Year Old Account
    Join Date
    Jul 2007
    Location
    Massachusetts
    Posts
    2,460
    Quote Originally Posted by intrinsc View Post
    According to Elv, the updated 7.08 version removes this code.
    Why was it there in the first place though? Glad I never used it and made my own. Very shady.

  11. #11
    7.08 no longer contains this code anymore. I'll use a standalone addon for testing with guildies. Let me put peoples mind at ease. If you update to 7.08 it won't be possible for this to happen.

  12. #12

  13. #13
    Quote Originally Posted by intrinsc View Post
    According to Elv, the updated 7.08 version removes this code.
    Still doesn't explain why it was implemented in a release version to begin with.

    Edit: Just read the explanation that Morllinor linked. I still think it's really slimy, to be quite frank.

  14. #14
    The Undying Slowpoke is a Gamer's Avatar
    10+ Year Old Account
    Join Date
    Sep 2010
    Location
    World of Wisconsin
    Posts
    37,272
    Quote Originally Posted by intrinsc View Post
    According to Elv, the updated 7.08 version removes this code.
    I'd still question why the code existed to begin with.

    Don't use Elv, but if I did I would uninstall it right now and never use it again.
    FFXIV - Maduin (Dynamis DC)

  15. #15
    Quote Originally Posted by intrinsc View Post
    According to Elv, the updated 7.08 version removes this code.
    Regardless of being removed or not, it should of never been in there in the first place in a public release.

  16. #16
    I am the author of ElvUI. I use this as a development tool with guildies it lets me execute things such as changing ElvUI options, getting information for debugging, etc... It clearly outputs to chat what is executed. The code has been there for close to two years. In any case I will simply use a standalone addon from this point forward with them to do this.

    Version 7.08 has had the code removed.

    http://www.tukui.org/git/?a=commitdi...8f11ad122dc11a
    http://www.tukui.org/changelog.php?ui=elvui

  17. #17
    Mechagnome intrinsc's Avatar
    10+ Year Old Account
    Join Date
    May 2013
    Location
    Aberdeen Proving Ground, MD
    Posts
    538
    I think a lot of you are overreacting. If he/she wanted to take people's accounts he/she would have been far, far harder to find and would have done their deed much more quickly. On top of that, it doesn't make sense for he/she to want to "troll" people with it after years and years of work.

  18. #18
    Quote Originally Posted by Elv View Post
    I am the author of ElvUI. I use this as a development tool with guildies it lets me execute things such as changing ElvUI options, getting information for debugging, etc... It clearly outputs to chat what is executed. The code has been there for close to two years. In any case I will simply use a standalone addon from this point forward with them to do this.

    Version 7.08 has had the code removed.
    Fair enough.
    Thanks for the years of development and a quick explanation and fix.
    Feral4Life since 2005
    cpu: Intel i9-9900K mobo: ASUS Maximus XI Extreme
    cooling: BeQuiet! Dark Rock 4 Pro gpu: ASUS RTX-2080 Ti
    ssd: Samsung 970Pro, 960 Evo, 860 Evo sound: sadly onboard
    case: Silverstone Fortress 2 Limited Edition (WRI) (I love that beauty)
    ram: 32G G.Skill 3200 C14 display: ACER X27 (G-Sync HDR IPS)

  19. #19
    Quote Originally Posted by Elv View Post
    I am the author of ElvUI. I use this as a development tool with guildies it lets me execute things such as changing ElvUI options, getting information for debugging, etc... It clearly outputs to chat what is executed. The code has been there for close to two years. In any case I will simply use a standalone addon from this point forward with them to do this.

    Version 7.08 has had the code removed.

    http://www.tukui.org/git/?a=commitdi...8f11ad122dc11a
    http://www.tukui.org/changelog.php?ui=elvui
    Uhhhh, no.

    If you're using it as a development tool, why do you include a method for outputting random messages into chat? Given you're executing arbitrary code, you can pretty quickly write a shiv that hides the message after the first one, it's not very hard.

    Even ignoring all of that, if it's only intended for guildies why is it distributed to everyone who uses the addon, enabled by default and not flagged to only people in your guild? What you did is pretty bad, and manages to fall under gross incompetence at best.

  20. #20
    Quote Originally Posted by Elv View Post
    I am the author of ElvUI. I use this as a development tool with guildies it lets me execute things such as changing ElvUI options, getting information for debugging, etc... It clearly outputs to chat what is executed. The code has been there for close to two years. In any case I will simply use a standalone addon from this point forward with them to do this.

    Version 7.08 has had the code removed.

    http://www.tukui.org/git/?a=commitdi...8f11ad122dc11a
    http://www.tukui.org/changelog.php?ui=elvui
    So this back door has been in ElvUI for the past 2 years is what you're saying?

    lets me execute things such as changing ElvUI options
    That's scary to know you could change the options of any ElvUI users if you wanted to.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •