The Gold Road Chapter – which includes the Scribing system – and Update 42 is now available to test on the PTS! You can read the latest patch notes here: https://forums.elderscrollsonline.com/en/discussion/656454/
Maintenance for the week of April 29:
• PC/Mac: No maintenance – April 29

DO NOT use updated ATLAS addon!

Alphashado
Alphashado
✭✭✭✭✭
✭✭
Rumor has it that the updated version has a malicious code that will mail all the gold in your bag to someone. I don't have any details atm, but I will update this thread when I do. It may be just a rumor, but until confirmed either way, do not use this addon.

Mods, please DO NOT move this to the addon forum because this is IMPORTANT and will effect many people that need to see this.

EDIT: The download for this addon has been disabled. Sounds like it's only the updated version that is causing problems. So as long as you are using the outdated version (pre 1.5.2)(1.32), you should be safe.

UPDATE: "Removing the malicious version that had been uploaded earlier and replacing it with the last version that had been uploaded by CrazyDutchGuy, which was safe. If you got version 1417671638, remove it and re-download this safe version. If you didn't get the malicious version, you don't need to download this one. ~ Cairenn" http://www.esoui.com/downloads/fileinfo.php?id=486&so=&page=6#info

Safe travels.
Edited by Alphashado on December 4, 2014 3:17PM
  • leeux
    leeux
    ✭✭✭✭✭
    Is not a rumor, it is in fact hacked. I downloaded it from ESOUI and the code has the malicious sendmail with all your gold in it.

    I was hesitant to create the thread myself, so thanks for creating it. If you need proof, you can download the ZIP from ESOUI with your browser and look at the Atlas.lua file:

    I shaded the name of the account to which the mails were sent to avoid the Naming and Shaming clause:

    5aROpjn.png


    The green lines are commented code, but they're are harmless as those were original code by the author that sent valid content on demand (slash command)

    EDIT: Fixed image link
    Edited by leeux on December 4, 2014 4:05AM
    PC/NA - Proud old member of the Antique Ordinatus Populus

    My chars
    Liana Amnell (AD mSorc L50+, ex EP) =x= Lehnnan Klennett (AD mTemplar L50+ Healer/Support ) =x= Ethim Amnell (AD mDK L50+, ex DC)
    Leinwyn Valaene (AD mSorc L50+) =x= Levus Artorias (AD mDK-for-now L50+) =x= Madril Ulessen (AD mNB L50+) =x= Lyra Amnis (AD not-Stamplar-yet L50+)
    I only PvP on AD chars

    ~~ «And blossoms anew beneath tomorrow's sun >>»
    ~~ «I am forever swimming around, amidst this ocean world we call home... >>»
    ~~ "Let strength be granted so the world might be mended... so the world might be mended."
    ~~ "Slash the silver chain that binds thee to life"
    ~~ Our cries will shrill, the air will moan and crash into the dawn. >>
    ~~ The sands of time were eroded by the river of constant change >>
  • Alphashado
    Alphashado
    ✭✭✭✭✭
    ✭✭
    @leeux

    Thank you for the verification. I've been doing a lot of digging ever since a guild member warned us about it and have yet to find much.
    Edited by Alphashado on December 4, 2014 4:08AM
  • leeux
    leeux
    ✭✭✭✭✭
    No problem man, all we can do now is warn people so they don't get caught by this.

    At least until someone contacts the ESOUI team so they remove it from the store :(

    I'm not an addon developer and not a member on the site... I'll try to post a message on their forums, though.

    EDIT: typo
    Edited by leeux on December 4, 2014 4:14AM
    PC/NA - Proud old member of the Antique Ordinatus Populus

    My chars
    Liana Amnell (AD mSorc L50+, ex EP) =x= Lehnnan Klennett (AD mTemplar L50+ Healer/Support ) =x= Ethim Amnell (AD mDK L50+, ex DC)
    Leinwyn Valaene (AD mSorc L50+) =x= Levus Artorias (AD mDK-for-now L50+) =x= Madril Ulessen (AD mNB L50+) =x= Lyra Amnis (AD not-Stamplar-yet L50+)
    I only PvP on AD chars

    ~~ «And blossoms anew beneath tomorrow's sun >>»
    ~~ «I am forever swimming around, amidst this ocean world we call home... >>»
    ~~ "Let strength be granted so the world might be mended... so the world might be mended."
    ~~ "Slash the silver chain that binds thee to life"
    ~~ Our cries will shrill, the air will moan and crash into the dawn. >>
    ~~ The sands of time were eroded by the river of constant change >>
  • Drasn
    Drasn
    ✭✭✭✭
    On the ESOUI page they have disabled the download due to this. Pretty much means it's confirmed.
  • ers101284b14_ESO
    ers101284b14_ESO
    ✭✭✭✭✭
    ✭✭✭
    Man those gold botters are relentless.
  • Amsel_McKay
    Amsel_McKay
    ✭✭✭✭✭
    Sendmail should not even be an option for UI addons...
  • leeux
    leeux
    ✭✭✭✭✭
    Yeah, totally agreed.
    PC/NA - Proud old member of the Antique Ordinatus Populus

    My chars
    Liana Amnell (AD mSorc L50+, ex EP) =x= Lehnnan Klennett (AD mTemplar L50+ Healer/Support ) =x= Ethim Amnell (AD mDK L50+, ex DC)
    Leinwyn Valaene (AD mSorc L50+) =x= Levus Artorias (AD mDK-for-now L50+) =x= Madril Ulessen (AD mNB L50+) =x= Lyra Amnis (AD not-Stamplar-yet L50+)
    I only PvP on AD chars

    ~~ «And blossoms anew beneath tomorrow's sun >>»
    ~~ «I am forever swimming around, amidst this ocean world we call home... >>»
    ~~ "Let strength be granted so the world might be mended... so the world might be mended."
    ~~ "Slash the silver chain that binds thee to life"
    ~~ Our cries will shrill, the air will moan and crash into the dawn. >>
    ~~ The sands of time were eroded by the river of constant change >>
  • Alphashado
    Alphashado
    ✭✭✭✭✭
    ✭✭
    Sendmail should not even be an option for UI addons...

    I agree as well. Scary. Makes me want to go and bury all my gold in a hole behind Riften somewhere :/
  • Elsonso
    Elsonso
    ✭✭✭✭✭
    ✭✭✭✭✭
    Sendmail should not even be an option for UI addons...

    That is extreme and sending mail from an addon is a useful function.

    However, I think that sending attachments should be something that is not an option.

    I do hope that the person the gold is being sent to is the person responsible for this and they get banned. I just hope that the recipient is not some innocent that is wondering why he is getting tons of gold all of a sudden.

    PC NA/EU: @Elsonso
    XBox EU/NA: @ElsonsoJannus
    X/Twitter: ElsonsoJannus
  • leeux
    leeux
    ✭✭✭✭✭
    @lordrichter‌

    I haven't thought of that, and you're right... let's hope it's not the latter.
    PC/NA - Proud old member of the Antique Ordinatus Populus

    My chars
    Liana Amnell (AD mSorc L50+, ex EP) =x= Lehnnan Klennett (AD mTemplar L50+ Healer/Support ) =x= Ethim Amnell (AD mDK L50+, ex DC)
    Leinwyn Valaene (AD mSorc L50+) =x= Levus Artorias (AD mDK-for-now L50+) =x= Madril Ulessen (AD mNB L50+) =x= Lyra Amnis (AD not-Stamplar-yet L50+)
    I only PvP on AD chars

    ~~ «And blossoms anew beneath tomorrow's sun >>»
    ~~ «I am forever swimming around, amidst this ocean world we call home... >>»
    ~~ "Let strength be granted so the world might be mended... so the world might be mended."
    ~~ "Slash the silver chain that binds thee to life"
    ~~ Our cries will shrill, the air will moan and crash into the dawn. >>
    ~~ The sands of time were eroded by the river of constant change >>
  • Izzban
    Izzban
    ✭✭✭
    I do hope that the person the gold is being sent to is the person responsible for this and they get banned. I just hope that the recipient is not some innocent that is wondering why he is getting tons of gold all of a sudden.

    I don't know how other players do things, but if I receive something in the mail I am not expecting, I send it back.

    Thanks for the heads up.
    Edited by Izzban on December 4, 2014 4:59AM
  • Heishi
    Heishi
    ✭✭✭✭✭
    I wonder if it was malicious or botched coding. It wouldn't be a terrible idea to have a donate button for people who enjoy the add-on and want an easy way to show appreciation.

    Mess up or malicious, I suspect someone's gonna have some explaining to do though.
    And so did many brave men, women, and beast fall to the end of Beta, never to be heard from again. All that is left, is whispers of the adventures they had.
  • Kevinmon
    Kevinmon
    ✭✭✭✭
    If you have the ATLAS addon installed delete it immediately. If you have Minion, do not update it. If you do, malicious code within the new update will steal your gold and mail it to someone else.
  • Karnus
    Karnus
    ✭✭✭✭
    Alphashado wrote: »
    Sendmail should not even be an option for UI addons...

    I agree as well. Scary. Makes me want to go and bury all my gold in a hole behind Riften somewhere :/


    Could you be more specific please? ;)

    Seriously though, it's not surprising but sad that malicious game add-ons might become more common place.
    Formerly Karnus, the Marauder in Warhammer.
  • Hime
    Hime
    Soul Shriven
    Kevinmon wrote: »
    If you have the ATLAS addon installed delete it immediately. If you have Minion, do not update it. If you do, malicious code within the new update will steal your gold and mail it to someone else.

    Way to steal my exact quote in-game in zone chat! :p Anyways I'm relieved the download for it is disabled now. Warned everyone I could.
  • yodased
    yodased
    ✭✭✭✭✭
    ✭✭✭✭✭
    wait, so they allow unsolicited non user input sending of mail and in game items but they don't allow passive connection to a webserver?

    ***?

    Maybe it's just me, but why don't we just download the LUA and XML, edit it out and then resubmit it to ESOUI, its not like its that hard.
    Tl;dr really weigh the fun you have in game vs the business practices you are supporting.
  • NadiusMaximus
    NadiusMaximus
    ✭✭✭✭✭
    Seriously though, it's not surprising but sad that malicious game add-ons might become more common place.


    Good! If this is the length they have to go to get gold, then we can say ESO effectively killed botters . Good job guys.

  • Alphashado
    Alphashado
    ✭✭✭✭✭
    ✭✭
    Karnus wrote: »
    Alphashado wrote: »
    Sendmail should not even be an option for UI addons...

    I agree as well. Scary. Makes me want to go and bury all my gold in a hole behind Riften somewhere :/


    Could you be more specific please? ;)

    I decided to bury it in the oak island money pit instead. Goodluck :)
    Karnus wrote: »
    Seriously though, it's not surprising but sad that malicious game add-ons might become more common place.

    I'm no programmer. I don't even pretend to be one on weekends or after I sleep at a Holiday Inn. But it seems to me that if it were easy to use addons for malicious intent, then it would be more prevalent by now in games like WoW where addons have been used for 10 years. This sounds more like an isolated event. Perhaps even an accident.

  • Elf_Boy
    Elf_Boy
    ✭✭✭
    I can see the use of an add on having email access.

    I have one for example that lets my guild members bounce email automatically.

    I can defiantly see this is being misused.
    ** Asus Crosshair VI Hero, Ryzen 1800x, 64GB DDR4 @ 3000, GTX 1080 ti, 4K Samsung 3d Display m.2 Sata 3 Boot Drive, m.2 x4 nvme Game Drive **
  • drschplatt
    drschplatt
    ✭✭✭✭
    Wouldn't it be a funny little ploy if the person, being the jerk they obviously are, simply wanted to 1. screw with people by taking their gold, and 2. screw over some innocent guy by putting their @account name into the addon to make it look like they're part of it. You could put any name in that addon and it would automatically look guilty and get you banned.
    Foräois - Imperial Sorcerer of Ineptitude.
    Widoch - Nord Dragon Knight of Ignorance.
    Billy Bob - Dunmer Templar of Chicken and Noodles.
    Blades of Vengeance
  • Razzak
    Razzak
    ✭✭✭✭✭
    I hope this all turns out to be just smoke, but if it's not ... then it's essential that ZOS steps in and makes a commitment to fix this and other similar ways of cheating until the next patch. Or we might be seeing more such attempts in the future. After all, this situation just told all those shady characters that there is an official way of getting gold in huge quantities.
  • Misa
    Misa
    ✭✭✭
    when I started studying programming my teacher made us swear that we'd never use our powers for evil stuff, guess this guy didn't have the same teacher as I did ^^
  • TehMagnus
    TehMagnus
    ✭✭✭✭✭
    ✭✭
    Prreeeetty stupid though, since the name of the culprit is in fact in the addon code xD. Or the person someone wanted to get banned ^^.
  • TehMagnus
    TehMagnus
    ✭✭✭✭✭
    ✭✭
    Addon has been updated and the "hack" has been removed. Just update it and you'll be fine.
  • Beesting
    Beesting
    ✭✭✭✭
    This is some pretty serious stuff though, i am surprised there is no response from @ZOS_AlanG‌ or @ZOS_AmeliaR‌ or other moderator about this.

    And what happened to the players affected, did they get their gold back?
    Beesting, Bosmer Magica DK, AD EU, crafter
    Slager, Dunmer Magica DK, DC EU, pvp
    Farmer, Dunmer Magica DK, AD EU, trials build

    Every major patch looks like the end of the world but somehow i just cannot stop playing.
  • ers101284b14_ESO
    ers101284b14_ESO
    ✭✭✭✭✭
    ✭✭✭
    Beesting wrote: »
    This is some pretty serious stuff though, i am surprised there is no response from @ZOS_AlanG‌ or @ZOS_AmeliaR‌ or other moderator about this.

    And what happened to the players affected, did they get their gold back?

    Yes they did. There was a guy on Reddit who didn't even know it was bugged and a GM showed up to tell him to get rid of the add on and restored the gold that was taken.
  • Alphashado
    Alphashado
    ✭✭✭✭✭
    ✭✭
    magnusnet wrote: »
    Addon has been updated and the "hack" has been removed. Just update it and you'll be fine.

    It wasn't updated. The newest versions was removed and the addon was reverted to the previous outdated version my the moderator on ESOUI:

    "Removing the malicious version that had been uploaded earlier and replacing it with the last version that had been uploaded by CrazyDutchGuy, which was safe. If you got version 1417671638, remove it and re-download this safe version. If you didn't get the malicious version, you don't need to download this one. ~ Cairenn" http://www.esoui.com/downloads/fileinfo.php?id=486&so=&page=6#info


    Beesting wrote: »
    This is some pretty serious stuff though, i am surprised there is no response from @ZOS_AlanG‌ or @ZOS_AmeliaR‌ or other moderator about this.

    And what happened to the players affected, did they get their gold back?

    Yes they did. There was a guy on Reddit who didn't even know it was bugged and a GM showed up to tell him to get rid of the add on and restored the gold that was taken.

    To put it nicely, it's disappointing that ZoS Moderators once again seem to focus more attention on Reddit than their own "official" forum. At least they were nice enough to leave this thread in general discussion where people stand a reasonable chance of seeing it.
  • Sindala
    Sindala
    ✭✭✭✭✭
    This is the reason that I NEVER use any addon, they should not even be supported or even allowed in a game that costs real cash to play.
    The worse thing is that this is legal and even if you 'emailed' all you gold away the only thing the Dev's can do is say Sorry.
    You technically 'gave' your gold away as a gift so it is not theft and i'm sure if you read the small print in the addon it will be legally covered so that it's not classed as theft as well.

    Addon's have to be downloaded to your computer first so if you lose some pixel gold and that's the worst thing that happens then count your blessings as they could do way more than just mess up your game.

    User beware.
    Being First is not the prize, it just mean's everyone can stab you in the back.
  • TehMagnus
    TehMagnus
    ✭✭✭✭✭
    ✭✭
    Sindala wrote: »
    This is the reason that I NEVER use any addon, they should not even be supported or even allowed in a game that costs real cash to play.
    The worse thing is that this is legal and even if you 'emailed' all you gold away the only thing the Dev's can do is say Sorry.
    You technically 'gave' your gold away as a gift so it is not theft and i'm sure if you read the small print in the addon it will be legally covered so that it's not classed as theft as well.

    Addon's have to be downloaded to your computer first so if you lose some pixel gold and that's the worst thing that happens then count your blessings as they could do way more than just mess up your game.

    User beware.

    Am, no, it's not legal. And the devs ain't gonna say sorry, since they'll never speak to you. The GM will give you back your money though.

    You didn't give your gold away, your addon gets updated and then does funky stuff. It's like the Appstore or Playstore apps that get updated with malicious code and Google or Apple end up removing. People to whom this happened ingame got their gold back.

    And addons are limited by the API from the game so they actually can't do more than mess up your game.

    I agree that addons shouldn't be allowed though, the game shouldn't need addons to be playable.
    Edited by TehMagnus on December 4, 2014 3:13PM
  • Sindala
    Sindala
    ✭✭✭✭✭
    They have a disclaimer stating you use addons at your own risk. They WONT give you your gold back as it wasn't anything to do with them or their game.
    Being First is not the prize, it just mean's everyone can stab you in the back.
Sign In or Register to comment.