Jump to content

Gharuk

Members
  • Posts

    3
  • Joined

  • Last visited

Nexus Mods Profile

About Gharuk

Gharuk's Achievements

Newbie

Newbie (1/14)

  • First Post
  • Week One Done
  • One Month Later
  • One Year In

Recent Badges

0

Reputation

  1. The most important thing of all, in my view, is that the site continues to work without having to download and execute javascript from third party servers. As long as I can use a web site without pulling untrusted stuff from half a dozen other hosts, I'm generally pretty appreciative of whatever effort people have put into their site's design.
  2. In response to post #41198720. > there was no money to be had for the effort I think a significant danger is the use of hijacked mods to distribute malware (ie: to grow botnets). If I were a nexus coder, I'd build some kind of tripwire into the nexus that would be set on any account that had more than N downloads a day on it and post an email to moderators to check out uploads if they came from IP addresses that the account owner had never uploaded a mod from before, or something like that.
  3. In response to post #41222915. It's an issue because some mods contain executables, and those that do not can be modified to add executables. An account with a popular mod downloaded by many people can be extremely valuable to a botnet owner: They download the mod, insert some malware, upload the trojaned mod to the account they have chosen to hijack, and sit back while a couple hundred unsuspecting people download and install their malware. This particular method of distributing malware is amenable to distributing one-off custom malware as well, meaning that no virus scanners will spot it because none of them will have seen it yet. If you're an old hand with VMware and wireshark and whatnot, you probably defend against this sort of thing out of habit all the time because you expect unauthorized outbound packets to start trying to get out of your machine at any moment, but if you're just a regular mod-using Joe that didn't consider the above nefarious use of a hijacked account of a popular mod maker, a way to defend against it is to check the last updated date on a mod - if a mod is a couple weeks old and has been download by a thousand people, you're probably good. If it's a popular mod and a fresh upload just appeared without any apparent reason for having been uploaded, you might want to hold off for a little bit.
×
×
  • Create New...