• Login
  • Register
  • Dolphin Forums
  • Home
  • FAQ
  • Download
  • Wiki
  • Code


Dolphin, the GameCube and Wii emulator - Forums › Dolphin Emulator Discussion and Support › Support v
« Previous 1 ... 125 126 127 128 129 ... 1197 Next »

serious security hole
View New Posts | View Today's Posts

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Thread Modes
serious security hole
05-25-2020, 09:52 PM
#1
andreasaspenberg
Unregistered
 
in a previous version i ran i could run dolphin for more than a week before i got hacked through it. the latest version however i can not run for more than a few days before i get hacked through it. hackers takes complete control over my pc when i run dolphin and use hypernation mode in windows.
Reply
05-26-2020, 06:58 AM
#2
mstreurman Offline
Above and Beyond
*******
Posts: 1,239
Threads: 11
Joined: Nov 2015
(05-25-2020, 09:52 PM)andreasaspenberg Wrote: in a previous version i ran i could run dolphin for more than a week before i got hacked through it. the latest version however i can not run for more than a few days before i get hacked through it. hackers takes complete control over my pc when i run dolphin and use hypernation mode in windows.

Dude... Reinstall your Windows... you have an exploit somewhere in your system and Dolphin is not the cause, Dolphin is 100% safe and anyone can see the source code. If there would be a hack inside Dolphin it would have to be put in there by the developers and then everyone would be able to see that they did that. No... Your problem lies elsewhere in your system.
Check my profile for up to date specs.
Find
Reply
05-26-2020, 08:18 AM
#3
andreasaspenberg
Unregistered
 
if anybody can see the source code, it is easy for hackers to know what to look for. there is also a vulnerability in the cpu(other programs have been hacked too) but, i am going to contact intel regarding that(i tried today but, they did not have any available ataff in the cpu support department and had to get back to me). one solution for the dolphin team is to create a version with absolutely no net code(all network functions disabled). security holes is a common problem however.
Reply
05-26-2020, 08:21 AM
#4
JosJuice Offline
Developer
**********
Developers (Some Administrators and Super Moderators)
Posts: 8,946
Threads: 7
Joined: Oct 2014
(05-26-2020, 08:18 AM)andreasaspenberg Wrote: one solution for the dolphin team is to create a version with absolutely no net code(all network functions disabled).

If you want that, you can set up the Windows firewall to block all connections for Dolphin.
Find
Reply
05-26-2020, 10:45 AM
#5
mimimi Offline
Senior Member
****
Posts: 720
Threads: 1
Joined: May 2014
The only way i see for a computer to get hacked by using Dolphin, would be to install a manipulated auto-update. But if that is the case, 1. disable auto-updates in Dolphin, and 2. and much more important: Your network is compromised and any download of any program would get your hacked. Now, if that's the case, disable your wifi, use a wired connection and get a VPN.

Are the files downloaded by the auto-updater signed? I just love how public-private-key encryption could fix that potential issue, and you could even download the update from a compromised network. Worst case then would be that the update fails, because it notices that the update was manipulated.
Find
Reply
05-26-2020, 06:47 PM
#6
andreasaspenberg
Unregistered
 
i have already disabled my wifi. i did that years ago.
Reply
05-27-2020, 01:29 PM
#7
mbc07 Offline
Wiki Caretaker
*******
Content Creators (Moderators)
Posts: 3,577
Threads: 47
Joined: Dec 2010
Whatever hacked you, definitely didn't come from Dolphin. The emulator source code is public and the few network-related communications it does are handled through widely known, free libraries, like PolarSSL.


(05-26-2020, 10:45 AM)mimimi Wrote: Are the files downloaded by the auto-updater signed? I just love how public-private-key encryption could fix that potential issue, and you could even download the update from a compromised network. Worst case then would be that the update fails, because it notices that the update was manipulated.

The files itself aren't signed, but the manifest containing the file hashes are, so even on a compromised network the updater would notice tampered files and abort. There's a document here that explains better how the updater works...
Avell A70 MOB: Core i7-11800H, GeForce RTX 3060, 16 GB DDR4-3200, Windows 11 (Insider Preview)
ASRock Z97M OC Formula: Pentium G3258, GeForce GT 440, 16 GB DDR3-1600, Windows 10 (22H2)
Find
Reply
« Next Oldest | Next Newest »


  • View a Printable Version
  • Subscribe to this thread
Forum Jump:


Users browsing this thread: 2 Guest(s)



Powered By MyBB | Theme by Fragma

Linear Mode
Threaded Mode