HomeVideos

Package Managers Ruin Everything

Now Playing

Package Managers Ruin Everything

Transcript

283 segments

0:00

Now, this channel doesn't often get into

0:01

gaming because the last time I did

0:03

gaming, well, it did not end too well.

0:06

But, it turns out that there is a game

0:07

out right now that had a massive hack to

0:10

it. And the funny part about the this

0:12

hack is that it actually reminds me of a

0:14

different hack that has just recently

0:16

happened to Notepad. For those that are

0:18

not familiar, the game we are talking

0:20

about is Mecha Chameleon. And of course,

0:23

Mecha Chameleon is a game in which you

0:25

attempt to hide in plain sight by

0:27

coloring your body and all that to look

0:29

like the surroundings and see who can

0:31

really actually hide the longest. And of

0:33

course, this game just blew up in

0:35

popularity. Everybody wanted to play. It

0:37

seems like a very fun streaming game.

0:39

It's kind of like Among Us style in

0:41

which people can get together and laugh

0:42

and all that and have fun and

0:44

friendship. I don't know anything about

0:46

that.

0:50

Anyways, the game continued to have such

0:52

popularity because one of the aspects of

0:54

the game is that user-generated content

0:56

was allowed. Users could make their own

0:58

levels and of course, people could play

1:00

those levels. Now, this is how the hack

1:03

happened. Can you believe it?

1:05

Effectively, a package manager for game

1:08

hacked everybody. They're bad in

1:10

TypeScript, they're bad in Rust, and

1:12

they're bad in Mecha Chameleon. So,

1:14

we're going to go over this most

1:15

excellent blog by Kale Kugler. It's a

1:18

two-click remote execution for this

1:21

game. This is our future, by the way.

1:23

Noth- nothing's safe, okay? You just You

1:26

just You can't go on the internet

1:27

anymore, okay? It's disallowed. It's not

1:29

We're

1:30

I In fact, I'm calling it today. We're

1:32

canceling the internet. Before we cancel

1:33

the internet, quick thank you from the

1:35

sponsor.

1:37

>> Hey, Brian.

1:38

Don't forget, scrum planning's later.

1:41

>> [sighs]

1:50

>> No.

1:51

No.

1:54

Can't do this.

2:06

>> Product manager here. We've decided to

2:09

put YOU ON CALL.

2:11

>> [laughter]

2:16

>> I CAN'T DO I CAN'T DO on call.

2:19

>> You're on call?

2:22

>> Lucky.

2:24

>> What are you saying?

2:25

>> With Sentry, on call is so [music] much

2:27

fun. It has all of our errors, logs,

2:30

spans, metrics, replays, [music] and

2:33

even releases in one spot. It has all

2:36

the context we need to solve any bug,

2:38

even if half the time Sentry beats me

2:40

[music] to the fix anyway.

2:42

Just cuz software development's torture

2:44

doesn't mean on call has to be.

2:46

>> Wow, that's amazing. Does Sentry also

2:48

attend my meetings?

2:49

>> Well, that's the best [music] part.

2:51

>> No.

2:52

>> Sentry can't actually make on call fun,

2:54

but it can make it less scary.

2:55

Everything you need to [music] fix real

2:56

issues in one place.

2:59

>> Buckaroo, got that 6:00 p.m. postmortem

3:03

planning. Don't forget.

3:05

>> All right, welcome back. Now, to

3:07

understand how this hack works, you

3:08

first have to understand a little bit

3:09

about how you can generate custom maps.

3:11

Now, the thing about Mecca Chameleon is

3:13

that you don't have to mod the game to

3:15

add new maps. Instead, you can just

3:16

create a new Unreal Engine 5 map, and

3:19

you can put it in you can package it all

3:21

together in a dot pack file. Now, I

3:22

don't know what exactly a dot pack file

3:24

is, but it's an Unreal Engine specific

3:26

item, and then you can upload it to the

3:28

Steam's official workshop for others to

3:30

play. Now,

3:32

what's a workshop? It turns out a

3:34

workshop is really just arbitrary file

3:36

delivery because Steam workshop items

3:38

such as maps are essentially just

3:39

folders. That means you can upload or

3:42

put in whatever you want into a workshop

3:45

item. Now, if you check out Steam's

3:46

official documentation and you're

3:48

looking at uploaded entries from item

3:50

authors, these workshop items, it does

3:52

warn you that your submission tool

3:54

should accept just the file formats that

3:57

your game client expects to load. Now,

3:59

in the case of Mecca Chameleon, it turns

4:02

out they just well, they just accepted

4:04

everything. But, accepting everything

4:06

itself doesn't actually pose any sort of

4:08

immediate risk. That means your workshop

4:10

item can have a beautiful map, it can

4:12

have textures and audios, it can have

4:14

preview images, and it could have very

4:15

destructive or credential stealing bat

4:18

files. All a part of the workshop item.

4:21

And this just will go on to anybody's

4:23

computer that downloads it. Now, none of

4:24

this explains exactly how the hack

4:26

works. So, let's actually go through the

4:27

real part. So, now when a lobby starts

4:30

and the a custom map is selected, those

4:33

that don't have the map are prompted

4:35

with the window that says, "Hey,

4:38

you got to download this custom map."

4:41

So, of course, you go to the custom map,

4:43

you you press the subscribe button, bam!

4:45

And just like that, you get yourself

4:47

hacked. Yes, actually that is the

4:49

moment. Right then and there, that is

4:51

actually how you get hacked. Now, when

4:53

it comes to Unreal Engine, which by the

4:54

way, I don't have any experience in

4:55

this, so I'm not deeply familiar, but it

4:57

turns out there's all these different

4:59

events that you can actually hook into.

5:02

And one of those events is begin play.

5:04

Now, something that begin play can do is

5:06

launch a URL. And now you're probably

5:08

immediately thinking, "Wait a second,

5:10

launch a URL? This kind of sounds like

5:12

that one hack." Yes, it actually sounds

5:14

exactly like that one hack. That one

5:16

hack, of course, is when Windows Notepad

5:19

had a markdown RCE. Yes, Notepad, if you

5:22

did not know, actually ended up changing

5:25

for like the first time in 20 years, and

5:27

they immediately made it exploitable.

5:29

Now, if you do not know the exploit for

5:31

Windows Notepad, it was actually pretty

5:32

simple. You would go to a Notepad, you

5:34

would open it up, it happened to be a

5:36

markdown, and look at that. Look at that

5:37

beautiful little link right there. Well,

5:39

you're going to go and you're going to

5:40

want to go click that link, right? Well,

5:42

it turns out the link doesn't contain an

5:44

HTTP address, instead it contains a

5:48

file, a URI file. Beautiful, right?

5:52

Well, it turns out that if you clicked

5:53

on a link, it would just open anything.

5:57

Now, naturally, this was actually rather

5:59

difficult to exploit because you had to

6:00

get some sort of malicious program onto

6:02

the computer first. And then, by

6:05

clicking the link, so it's kind of like

6:06

this two-step process, get malicious

6:08

package, and then get somebody to link,

6:10

you could take advantage of the Windows

6:12

system. Now, of course, the Mecca

6:14

Chameleon one uses this exact same

6:16

vulnerability, but it was a bit more

6:19

sinister. So, now, when you see this,

6:20

this open URL, you can immediately

6:23

understand where this is going. Yes, in

6:25

fact, the underlying method is almost

6:28

identical. It turns out it ends up

6:30

opening shell execute W. So, whatever

6:34

you hand it, if you hand it a file URI,

6:37

it will just open that up. Now, remember

6:39

just a little bit ago when I told you

6:42

about how these Steam Workshop items,

6:44

they're just folders and you can put

6:46

whatever you want inside of that.

6:48

Remember that? It It was just a moment

6:49

ago. How did you forget? By the way, for

6:51

those that use real operating systems,

6:53

we call these directories, but on

6:55

Windows, Windows, am I right, boys? They

6:58

call them They call them folders, you

6:59

know, because you put files

7:02

in folders, Manila folders actually

7:04

specifically, and then you put those in

7:06

a box that's a hard drive, and then you

7:07

put them

7:08

on the top shelf of your garage never to

7:10

look at them again. So, by using a

7:12

folder, you can upload bat files or EXE

7:15

files to do whatever you want to do, and

7:18

then with the begin a play event that

7:21

gets executed the moment your map gets

7:23

loaded into Mecca Chameleon, hey, no

7:25

restart needed, just go and download it

7:27

there, bucko. The moment that executes,

7:30

botta bing, botta boom, it can open any

7:31

arbitrary file on your system, which

7:33

happens to be a file that it just got

7:35

done downloading, and bam, you're taking

7:37

advantage of, okay, son? You just got

7:39

wrecked. And if you go through Kael's

7:41

blog, that's exactly what you see. He

7:43

ends up just simply doing a a nice

7:44

little who am I. You know, honestly,

7:46

like who

7:47

who who who am I?

7:50

The name?

7:56

What? Now, I think something that is

7:57

actually a lot more dangerous and people

7:59

just need to know about. And the reason

8:00

really why I wanted to do this video is

8:02

that there's a lot of indie games out

8:03

there that allow custom user content.

8:06

And just like Mecha Chameleon, that was

8:08

a mega popular game, but there's a lot

8:10

of these games that probably contain

8:12

identical exploits. Which means you

8:15

should be a little bit more careful.

8:17

Now, you wouldn't install an NPM

8:19

package, would you? That's because

8:20

you're a developer. You're very very

8:22

very very smart. But what you don't

8:24

realize is that installing an NPM

8:26

package could potentially execute a post

8:28

script if you don't have a post install

8:30

script if you don't have all the

8:32

security and things set up for that not

8:34

to happen. And that is how a lot of

8:36

these worms, these Shahhaled worms, have

8:38

been going about. Now, it turns out that

8:40

exact same style of exploit is happening

8:43

with games. So, really the PSA is that

8:46

you're going to get hacked. You're going

8:48

to just stop down- Again, the internet,

8:51

I'm calling it. We're turning it off.

8:52

We're done. We're returning to monkey,

8:54

okay? No more of this crap. But the real

8:56

the actually the real takeaway is that

8:58

agents kind of are scary, right? You're

9:01

downloading and putting things on your

9:02

machine at a rate in which you've never

9:04

been able to put on before, okay? You

9:06

think installing NPM modules was like

9:08

bad. Now, you got agents putting who

9:10

knows what. We have skills in which have

9:12

hidden HTML which can take advantage of

9:15

your system. You have all sorts of ways

9:17

to get prompt injected. You know, so

9:19

just hey, be careful out there.

9:20

Understand what's happening. Understand

9:22

what's being downloaded. And just

9:23

remember, just because a bunch of people

9:26

use something does not mean it's safe.

9:28

Just like Mecha Chameleon, one of the

9:29

hottest games out there. Turns out just

9:31

had a massive vulnerability in which to

9:33

who knows what information was taken.

9:35

Also, I'd like to do a special shout out

9:37

at the end of this blog, which by the

9:38

way, you should go read. It's a very

9:40

excellent blog. He says doing security

9:43

research like this is often a thankless

9:45

job. So, this goes out to you, Kale.

9:47

Really appreciated the blog. Awesome

9:50

write-up. The name

9:51

is the Prime Agent. Okay, that's not

9:53

what it looks like. Okay, that's not

9:55

what it looks like. What I was going to

9:56

show you, okay, I didn't mean for this

9:58

to happen, but what I was going to show

9:59

you is that I can draw really straight

10:00

lines. I bet I'd be pretty good at Mecha

10:02

Chameleon, okay? Agent.

Interactive Summary

This video examines a critical security vulnerability found in the popular game 'Mecha Chameleon,' which allows for remote code execution. By leveraging the game's Steam Workshop support for custom maps, attackers can deliver malicious files that are automatically executed via Unreal Engine's 'begin play' event. This exploit functions similarly to a past vulnerability in Windows Notepad, highlighting the risks inherent in games that allow unchecked user-generated content and the broader danger of blindly downloading packages or assets.

Suggested questions

3 ready-made prompts