#[Updated] Addressing a Security Vulnerability

1 messages Β· Page 1 of 1 (latest)

rain girder
#

https://theindiestone.com/forums/index.php?/topic/92297-addressing-a-security-vulnerability/

Update (2026-05-03) - The Legacy branches have been restored with the exception of the 42.13.1 branch which was due to be deleted anyway. The team still needs to patch Build 38's server so it currently will not work, but that should be resolved in the next couple of hours, tomorrow at the latest.

supple canopy
#

πŸ‘πŸ»

pulsar jungle
#

Interesting. Glad the community has the interest and ability to report this properly.

weary warren
#

Killed

rain girder
waxen ivy
#

(Copy/pasting my comment from the reddit post, but figure doesn't hurt to cross-post it here for discussion);

Thanks TIS and @rain girder

Getting advance notice of an imminent patch is fantastic and I really encourage this to become the norm moving forward. We run one of the largest Aus/NZ PZ multiplayer communities and unannounced/unexpected wipes can be quite disruptive as I'm sure you understand.

As best as you're able to share right now, is it likely that MP servers running 42.14.1 will be able to simply update to 42.15.1 without requiring a fresh-wipe? Is there anything changing on the backend in this patch that is likely to necessitate a wipe?

Thanks so much in advance!

rain girder
# waxen ivy (Copy/pasting my comment from the reddit post, but figure doesn't hurt to cross-...

It is always recommended to wipe on every new update. It's possible that your save will work, but we can never guarantee that and there are always chances for unexpected bugs. I said something like this similar elsewhere

Every update will break your save. You might not notice the break, but every update will break something

Unstable really isn't designed for long playthroughs. We are in the home stretch of unstable though, and once B42 stable is launched the multiplayer community will be a lot happier.

sweet rampart
#

I’m just wondering if 42.15 is really coming next week as mentioned, because our server is currently affected after running on 42.13.2. bored

rain girder
#

Unless a significant issue is discovered between now and then, it is.

quick cradle
pulsar jungle
quick cradle
muted bone
quick cradle
#

Also about 42.16 when??

oblique lance
pulsar jungle
oblique lance
#

I liked mine better

muted bone
#

Sweet, thanks guys

pulsar jungle
oblique lance
#

something better

muted bone
#

So hopefully home stretch means before 2027 πŸ™πŸ»

pulsar jungle
thorn cliff
sonic bronze
#

Security fix is good but servers near top 10 are being extorted and ddosed constantly with no solution provided by hosts or devs

oblique gorge
#

What are the Devs supposed to do about a Hardware/Network issue of the hoster?

#

genuienly, that is between you and your service provider and if they dont offer any form of ddos protection, you might want to switch away from them

sonic bronze
oblique gorge
#

other than that it's pretty much keeping your own community clean, i really dont see how this is on the devs

sonic bronze
#

I am not blaming the devs, they just gotta get more proactive on this before Zomboid has the same reputation Roblox has for their inaction combating this behavior

oblique gorge
#

Roblox is a service provider with a overarching moderation system, Zomboid is a game with community game servers, more akin to Minecraft, that implement vastly different moderation styles

#

there really isnt anything a dev can do, report those players to relevant law enforcement and remove them from your community, for network issues talk with your hosting provider and/or switch hosting providers when they dont want to offer basic services

#

When you host a server and associated communities with it, no data is leaving your system, so you generally take the responsibility to moderate that community and that does include sorting out people not fit for being in any form of community, thats sadly the reality of it

slate raptor
#

Heyyy I was right, it was related to modding pz_nerd

slate raptor
ocean umbra
#

Project Rootkitzoid

slate raptor
#

Project Arbitrary Codezoid

slate raptor
devout pumice
bold mesa
#

Roblox is a multi billion dollar corporation, TIS is an indie studio. There is a slight difference

oblique gorge
slate raptor
#

no need to cross that out drunk

harsh folio
#

Darn there goes my bitcoin mining scheme

bold mesa
#

We missed a golden opportunity to put a trojan in the horse mod πŸ˜”

tawdry pilot
# muted bone What does home stretch means here? Thanks

The β€œhome stretch” is the final part of a race track, the last curve on the way to the finish line. In this context it's used in its figurative sense, which refers to the final effort towards achieving a goal. i.e., they are getting close to moving to stable

sinful token
bold mesa
#

🐴

slate raptor
glad nebula
#

are you telling us we almost had an incident like people playground?
πŸ™ godbless that guy who reported it

somber smelt
#

No no, stop being positive, don't you understand? Reddit told me to be negative!

visual leaf
#

"We are in the home stretch of unstable" πŸ‘€

warped tide
slate raptor
#

Sully putting an ETA on 42.15 in there was bold

quick cradle
glad nebula
# devout pumice What happened theres

someone put a virus in a mod that spread to a bunch of other mods
the virus deleted all achievements and saved stuff
it got to a point where they had to disable the workshop

devout pumice
#

Oh wow that sucks

rain girder
#

That's not what happened. A security vulnerability was reported. It was a bad one. We put out an emergency patch and nuked all the old public builds until they can be patched (we are working on that atm).

glad nebula
rain girder
#

Oh I guess it helps if I read up lol

supple canopy
# glad nebula

Wow, that's crazy. That flaw in PZ could cause something like that, but TIS was quick to fix it :)

glad nebula
oblique gorge
#

i do kinda wish we'd get a write up what happened when its fully fixed and some time has passed that most people should be on a patched version

devout pumice
#

It was knoxd up

rain girder
#

We won't be going into details. Highlighting a vulnerability, even one that is now patched, bring attention to potential attack vectors

#

best to be as vague as possible

oblique gorge
#

I'd just assume something went wrong with the lua implementation that allowed code to be run that shouldnt have been possible

#

but its more about being curios, than any need to know, i enjoy reading up how people find vulnerabilities like this

#

see the Linux one last year, someone was peeved it took a few ms longer than it should kek

bold mesa
#

While I am curious, discussing the nature of a potential cyber attack is a terrible idea

heady schooner
#

why are the comments on the forums the worst takes known to man

bold mesa
#

Its kind of funny

oblique gorge
#

did reddit figure out they can create forum accounts?

heady schooner
#

i read a few of em and its like real people had no part in writing it

rain girder
glad nebula
heady schooner
#

yeah i saw that its wild

oblique gorge
bold mesa
#

We were talking with someone in the modding server who was mad at TIS letting this problem happen despite the fact that this patch made the problem not happen

oblique gorge
#

how the hell do you even have fun on a server with 600 people...

oblique gorge
#

he might loose his mind at whats out there

bold mesa
#

I asked him if he was using Windows 11 and he never responded

glad nebula
bold mesa
#

You have way more security issues on that than a silly zomboid mod

heady schooner
#

Dont tell people who insist on using a hundred mods that every update can brick their save, and they get really upset when their save inevitably bricks every update.

can we go back to unstable being used to try out new content early and help the devs by patching bugs

oblique gorge
#

no, i think that ship has sailed

#

apparenetly people are also review bombing?

#

not that it'll do much steam will delete em for spam and bonk the accounts

heady schooner
#

i lost a 8 month world a couple months ago, and i was just excited because of the new patch

bold mesa
#

The Zomboid communuty has some of the best people ive met online, which is why its so funmy that a masdive portion of the playerbase is so... interesting

heady schooner
#

spent like 3 hours in debug

glad nebula
#

macOS - cant play anything
Windows - breaks every update from ai coding

bold mesa
#

Reveiw bombing bc you fixed a security issue is interesting

glad nebula
heady schooner
#

are people actually review bombing

oblique gorge
#

lemme check

heady schooner
#

theres no shot

bold mesa
#

There was an attempt but its not going anywhere

#

Because its stupid

#

And they should be emberassed

oblique gorge
#

i am gonna censor it, but...

#

wat

#

proceeds to play another 6 hours in under 24hours

bold mesa
#

In all fairness that playstyle isnt for everyone

heady schooner
#

those are mostly as a joke

#

people like to "badly" review games they play alot because its funny

supple canopy
bold mesa
#

Thats one of the more legit negative reveiws buts its more of a difference in taste

heady schooner
#

they seem to like the game, given their hours

#

and the post itself is almost certainly sarcastic

oblique gorge
#

i miss the time people actually used reviews to review

#

and well, guides for that matter

glad nebula
oblique gorge
glad nebula
oblique gorge
#

no, i just dont generally want to put people on blast

#

you dont know whos reading and some people are unhinged

oblique gorge
#

Like i was on the fence back the pre rona times about this game, because watching friends play it just looked odd, only really after watching a "beginners guide" just showcasing the what feels like 400 different systems working did i really get into it

flat fulcrum
rain girder
#

lmao

bold mesa
#

I feel like that list is probably not finalized haha

rain girder
#

1342

bold mesa
#

Ok nvm lol

flat fulcrum
#

Good enough for me.

#

Larger than 42.14.1 changelog is always great.

rain girder
#

Can confirm it is definitely larger than 42.14.1's changelog

flat fulcrum
#

Good

#

I'm happy, content, moisturized, silky, waxed.

heady schooner
#

ayo

#

im not sure how i should feel about that

slate raptor
bold mesa
#

Keep your expectations low, as theyve said

rain girder
quick cradle
#

Gosh the first gif for hop on project zomboid is wild

harsh folio
#

Ugh do i have to wait for ANOTHER update

devout pumice
slate raptor
#

Fair

#

Tbh large servers can be really fun, you can meet some excellent people

slate raptor
#

Especially if they have a trade hub somewhere where people can show off their wares is pretty cool

bold mesa
#

I wanna play Zomboid mp at some point

slate raptor
#

It's super fun

devout pumice
#

Its fun , i played and was driving my car down muldrag and stopped and was like man i hope someone doesnt run into me lolsure as shit happened, past 4 hours were quiet

oblique gorge
#

maybe i host a lil invite only server for stable, gonna depend on how motivated i am

devout pumice
visual leaf
#

Especially now that you can get run over as a pedestrian

devout pumice
#

Yeah lol , i cant wait to get hit by a car

somber smelt
oblique gorge
#

I'd assume thats for the next build, no?

somber smelt
#

There are still some map updates left, at least for bugs

compact pulsar
#

Will we receive any new documentation for modders in 42.15? Or is that being saved for. 42s full release?

waxen ivy
rain girder
# waxen ivy Okay now I am excited for .15

Just in case, 42.14.1's changelog was very small as it was a hotfix. Any content patch will be bigger than that. Was shitposting. It'll have some new content. I think people will enjoy it. I do. But temper expectations as always

waxen ivy
#

Too late. My expectations could not be higher.
I cannot wait to see the gigabytes of new systems and content that .15 will surely introduce.
I can't believe we are finally getting kangaroos. Knox County has never been more realistic.

bold mesa
#

Cant believe theyre adding Tokyo as a second map in 42.15

#

So excited

waxen ivy
devout pumice
#

lmao, were finally going to space?!

#

careful someones gonna ss and post it somewhere

quick cradle
waxen ivy
#

But... Lisa needs braces

ionic wing
ocean musk
#

has this been fixed

#

its still gone for me

pulsar jungle
ocean musk
#

the other bulids

#

like 42.13

pulsar jungle
#

They are working their way through the builds applying the patch. I dont think 42.13 is coming back though with 42.15 coming next week

ocean musk
#

oh so the just took them off

quick cradle
#

Only the old legacy builds will return like 38, 39 and 40 I think

bold mesa
#

B42.13 was planned for removal anyway

ocean musk
#

just wwanted to make sure i didnt get hacked lol

bold mesa
#

No ur fine haha

ocean musk
ocean musk
bold mesa
#

The exploit didnt happen, but the possibility of it was pointed out so theyre patching it out

pulsar jungle
#

We have put forth an emergency patch to deal with a security vulnerability that was indentified. We fully intend to bring back the legacy builds if possible, however the 42.13 builds were intended to be removed with the next update anyway, so it would not be an efficient use of developer resources to patch those builds.

still ingot
#

AAHHH THE UNSTABLE BRANCH IS UNSTABLE ALL OF OUR PCS ARE HACKED EVERYONE RUN AROUND IN CIRCLE AND START SCREAMING IMMEDIATELY!!!!!!!

#

Oh nvm it's fixed

#

Good work TIS boys and girls

graceful marsh
fast thunder
#

@rain girder will there be an update on discord/somewhere when 42.12.3 is patched and live again on Steam? Just wanted to know what to look for when it's added back thanks!
#1478612731882897592 message

bold mesa
#

Are they bringing back 12.3?

#

Was that outdatedunstable?

fast thunder
slate raptor
#

Sully and nasko said outdatedunstable will always be one build behind so when 42.15 comes out 42.14 will go to outdatedunstable

fast thunder
#

What I'm really curious about is how long 42.12.3 will stay on Steam even after the patch, that dev said their policy is: B41, 1 latest Unstable, 1 previous version Unstable.... but by that logic after 42.15.x drops next week 42.12.3 will be replaced with B42.13.2... whereasin the past theyve seemed to keep like +-3 Unstable branches live + B41. So I dunno, I'm prob gonna end up running that SteamDB Manifest version of B42.12.3 either way as I paly completely offline, -nosteam modded version anyway.

vocal wadi
fast thunder
slate raptor
#

Just move the files out of steamapp folder, easy

fast thunder
slate raptor
#

no

#

there is no "drm"

#

I literally can play any of these

fast thunder
#

oh snappy

slate raptor
#

the only thing that it will do is check the workshop on launch if you don't have -nosteam

fast thunder
#

yeah I run a -nosteam local save

slate raptor
#

so then you are fine

#

just move the folder, make your shortcut point to where the files are

bold mesa
slate raptor
#

Spiffo be praised spiffo ❀️

fast thunder
# slate raptor so then you are fine

So when they reupload 42.12.3, I should just copy the local /steamapps/common/Project Zomboid/ folder and run the exe from that directory and be gucci??

slate raptor
#

if you haven't updated it you should already be able to do that

#

and then just ignore it through steam

#

or if you want the vulnerability fix then yea you would do that

fast thunder
# slate raptor if you haven't updated it you should already be able to do that

Well the "dont update until game launch" isnt the same as ZERO updates from the game itself - whenever they push a new branch/delete an old one Steam still pushes a mandatory update even if I dont launch the game. That being said the 1st thing I did when I saw the news was run another full backup of the game, among other backups every ~week or so for my 42.12.3 game iinstall/local mods/saves.

slate raptor
#

if you move the folder though it will not be able to push that update to it

fast thunder
fast thunder
slate raptor
#

then you should be good to go πŸ™‚

fast thunder
#

but since theyre saying theyre pushing a security patched 42.12.3 tomorrow anyway, I'll just make sure to copy that /steamapps/ version immediately when it goes live, hence my 1st post wondering if they'll announce its back up/what they'll call it haha

#

cus im assming the current "outdatedunstalbe" isnt 42.12.3 yet

#

unless.... they already patched it and didnt say anything haha it would be a very small portion of the playerbase and totally get why they wouldnt say anything to silently patch it

slate raptor
#

it was 42.13.2 and won't be back to 13.2 again as 15 comes out next week

#

so it will be 14.1 when they release a new build onto it

fast thunder
slate raptor
#

that was from the forum post from sully

#

now 42.12.3 might return patched, but it won't be under the outdatedunstable branch

#

it would be it's own seperate one

fast thunder
#

Yeah totally that what I thought it would be too

slate raptor
#

they might do the same for 13.2? I am not sure

#

both Nasko and sully said that, maybe they have more up to date information than Beard

fast thunder
#

since there's always been like 3-4x B42 branches up til this week

slate raptor
#

yup yup

#

Oh you were on Crusader Strike drunk me too

#

I miss SoD so very much

fast thunder
#

I also did a full game backup thru Steam's backup option on 02/12/26 and again after this patch was released before I laucnhed the game to update it.. is that the same as copying the local /steamapps/ folder? I only dread what handful of mods I added (that worked on B42.12.3) would still work or not.... or if my save file created after those backups would crash or not iif that makes sense? (I only play with -nosteam mods)

fast thunder
slate raptor
#

Lolllll 100% I pray they do good things with C+ eventually

slate raptor
#

but granted I have only used that function once and it was for transfering files between two computers on a network

fast thunder
#

well FINGERS CROSSED they do actually release 42.12.3 on Steam again like that other dev seemed pretttyyyy confident they do, ill do what ya said and just copy he full directroy to another drive and launch it locally not through steam. theres nothing else I need to do for that launch method?

#

i waited like almost 2 years after B41 to finallllly play again cus i had no idea Stable would be that far off, and knew Id hold on to it until B42 Stable but im in no mans land now of like 6 month save haha

slate raptor
#

nope just move the folder, and then personally I create a shortcut (as you saw in the picture) for the different launch options

fast thunder
#

(or felt like 2y lol)

slate raptor
#

and then you are good to go πŸ™‚

fast thunder
#

ahh yeah the shortcut is how you add the "-nosteam" perameters outside of steam?

slate raptor
#

yea -nosteam and ram increase in target

fast thunder
#

OH GOD yeah

slate raptor
#

and then personally I do a second one with the same but also -debug as well

#

so I can do testing

fast thunder
#

I have mine set to 32GB lmaoo

slate raptor
#

daaaang loll

fast thunder
#

I mayyyyy slide into your DMs if they decide not to relaunch 42.12.3 πŸ˜‰

slate raptor
#

np πŸ™‚

fast thunder
#

πŸ‘‘

#

naw but im sure they'll do it just make it a different branch name, and yeah i knew id toss this save after Stable, I still have my priv server set to B41 cus I knew the headache it would be to not wait til B42 Stable... just needed that SP fix and caved like 6mo ago haha

#

Also Lok'tar, find us if they do C+ πŸ˜„

slate raptor
#

πŸ˜„ ❀️

#

totally fair, I was going back and forth for a bit (playing B42 for SP, and then 41 for MP) prior to B42's mp release

#

still fun, but damn there was stuff I missed every time

fast thunder
#

Yeah B42 has been massive fun, I'm glad I did it.

slate raptor
#

small things... like the shout/breathing noises

fast thunder
#

OH YEAH

rain girder
#

And when I say it will stay 42.14.1, I don’t mean permanently. It will lag 1 minor update (the middle number) behind unstable

rain girder
#

lmao love that gif

waxen ivy
#

is it "next week" yet?

#

surely it is.
get on with it.

rain girder
#

Updated] Addressing a Security Vulnerability

#

[Updated] Addressing a Security Vulnerability

#

Legacy branches restored

rain girder
somber smelt
#

cool

#

You're making a reddit post to please the masses, right?

hardy kite
#

πŸ”₯

oblique gorge
rain girder
#

People are already posting

somber smelt
#

That's true, other people posting about it helps get the word out

somber smelt
oblique gorge
#

i wish you the best, sully, may the minor update be bug free

oblique gorge
somber smelt
#

If they spammed random letters for the lagging behind unstable name, people would be forced to google it lol

harsh folio
#

Sully when will I find happiness?

rain girder
#

When you stop looking for it

rain girder
#

They're all live now btw (except Build 38 server)

fast thunder
devout pumice
heady schooner
slate raptor
#

That is excellent

reef glacier
wild patio
devout pumice
somber smelt
#

@slate raptor notice I didn't post the delay the update gif for these updates drunk

slate raptor
#

I did indeed notice that lolll

somber smelt
#

Yeah, I totally didn't just pass out early, I knew what I was doing

flat fulcrum
#

pz_sob Chat is no longer concentrated in 1 chat thread... making it hard to follow.

graceful marsh
rain girder
peak panther
fresh vector
#

so how long until I can play my zomboid

slate raptor
fresh vector
#

not loading

slate raptor
#

πŸ‘€

#

Is it a save from a previous version?

#

I was playing last night with no issues loading

fresh vector
slate raptor
fresh vector
#

dont know

#

prob

slate raptor
#

From my understanding that isn't coming back, everything else should be back now

slate raptor
# fresh vector fuhhh

Time for a fresh run I suppose. In the future if you are serious about keeping a run going on a specific version copy the PZ folder out of the steamapps location and launch it manually, it will not be able to self update in that case

fresh vector
#

yeah I hope they make it so previous saves can be reloaded

slate raptor
#

Doesn't look like it will be

fresh vector
#

trust bro we got this

bold mesa
#

Im sure bro

fiery timber
#

oh no security vulnerability

#

will pc get exploded to bits

round swallow
#

N3na3

fiery timber
#

oh hello InsOmniumWOlf

round swallow
native root
still ingot
fiery timber
#

he's calling me out for having it in my about me section πŸ₯΄

round swallow
#

lol yeah I’m just messing with N3na3 (hello N3na3)

fiery timber
#

hmph i've already said my salutations, (omghiinsomniumwolf)

thorn light
#

hello i don't see the unstable 42.14.1 into the properties, how i play the unstable?

bold mesa
#

Its just the main unstable option in the betas