Thread: Censorship
View Single Post
08/09/17, 07:33 AM   #29
Dolby
Every day I'm shuffling
 
Dolby's Avatar
Premium Member
WoWInterface Admin
Join Date: Feb 2004
Posts: 1,278
We scan all exe's uploaded with virustotal along with our automated clamscan, we also spot check decompile them in a sandbox and compare with the provided source. We make sure the exe's can not update themselves or execute other exe's, etc.

So the issue here is that this exe can write lua, so it can possibly write AddOns or Modify on the fly from the servers API. Some one could possibly compromise that server and at worst make the exe write an AddOn that could possibly delete your items? It can do whatever the ESO AddOn API allows it to do. So the risk is limited to what the ESO AddOn API will allow.

The author has had many successful releases so far, has updated code and re-written things when asked. We are keeping a close eye on this project and will pull it if need be. We even alerted ZOS of this project.

With that said I agree its a good idea to have a warning on any AddOn that we allow that has an included exe because we could miss something harmful, we are human. We don't normally allow them only if the author asks and provides source and does not have a way to update the exe remotely.

Last edited by Dolby : 08/09/17 at 08:11 AM. Reason: updated to make sure to add risk of any exe
  Reply With Quote