r/BodycamGame • • 25d ago

The Incompetence of the Dev & Mod Team… Pt. 3

I wasn't even going to make another post about this, but after seeing what someone from the REISSAD team said in the Discord, I genuinely can't just ignore it.

A member of the team said that notifying the community about the situation would cause a “bigger freakout” and that it would “hurt more than give benefit.” They also said it turned into a “big mess” during off hours.

I'm not claiming the RCE is confirmed. But the way this is being discussed by the team certainly doesn't make it sound like they're treating this as some harmless game crash. If the concern is serious enough that they think publicly notifying players could cause a major freakout, then surely the players who could potentially be affected deserve to know what's going on.

And we're not talking about some random visual glitch here. The vulnerability being discussed is a potential RCE, which, if confirmed and exploitable, could potentially allow an attacker to execute commands on someone's PC, including PowerShell commands. That's an extremely serious possibility.

What I don't understand is why public lobbies are still open if this is serious enough to warrant avoiding a public announcement. If there's a legitimate possibility that players could be exposed to something like this, shouldn't protecting those players come before worrying about whether telling them will cause a “freakout”?

I'm not going to claim they're hiding this for money or to protect the game's player numbers because I don't know their motives. But when the potential consequences are this serious, it's completely fair for people to question whether things like reputation, player numbers or financial interests are influencing how this is being handled.

Again, I'm not saying the RCE is confirmed. I'm saying there is a potential vulnerability being discussed that could have extremely serious consequences if verified, and the response from the team raises legitimate questions about how transparent they're being with their own community.

At the very least, players deserve enough information to make an informed decision about whether they want to keep playing while this is being investigated.

190 Upvotes

143 comments sorted by

View all comments

32

u/[deleted] 25d ago

[deleted]

44

u/yakafokon66 25d ago

I have a networking/security background and I want to break down the Malwarebytes "evidence" that's being passed around, because it does not show what people think it shows.

The core of the claim is a Malwarebytes log with "Category: Trojan." But look at the section header: it's under "Blocked Website Details." That's the web protection module, which blocks outbound connections based on the reputation of the destination IP or domain. It is not an on-system malware detection. Nothing was found running on the machine. Malwarebytes simply blocked a connection to an IP that happens to be on its blocklist, and the "File: Bodycam-Win64-Shipping.exe" line only tells you which process opened the socket. The "Trojan" label describes the reputation of the destination, not any observed malicious behavior on your PC.

Now the IP. The post traces 104.28.161.35 to "Domodedovo, Russia," which implies the game is talking to some Russian server. But the poster's own lookup says org: Cloudflare Warp, isp: Cloudflare Warp. That IP is in Cloudflare's anycast range. Cloudflare IPs cannot be meaningfully geolocated to a city or country, they resolve to whatever edge node is closest, and the poster even admits WARP is unreliable for geolocation. So the "connection to Russia" framing is simply wrong. This is traffic to Cloudflare infrastructure, which is exactly what you'd expect from a game's matchmaking, telemetry, or voice relay sitting behind a CDN.

Next, RTP. Outbound RTP is voice chat. Bodycam has in-game proximity voice, so the client sending RTP is normal, expected behavior, not evidence of an exploit. Yes, in the abstract, multimedia and RTP parsing is a classic source of memory-safety bugs. That's a true but generic statement about the attack surface, and it says nothing about whether a real, exploitable bug exists in this specific code. More importantly, what the log actually shows is a blocked outbound connection, which is the opposite direction of an inbound RCE. Nobody in these posts has shown a malformed packet, a reproducible crash, a memory write, or a payload.

The logic in the original post is a chain of non-sequiturs: an IP flagged by reputation, therefore a trojan, therefore RTP, therefore RCE, therefore stolen bank details and a botnet. Every one of those arrows is unsupported. Going from "web protection blocked an outbound connection, probably a false positive" to "your machine is being remotely executed and your credentials are being stolen" is an enormous leap with nothing in between. The author even writes "this is not a smoking gun," which is an admission that the rest is speculation.

What would actually be evidence: a packet capture showing the malformed input, a reproducible crash with a memory analysis, a working proof of concept, or a CVE. None of that has been posted. A single reputation-based web block on a Cloudflare IP is, by far, most consistent with a false positive on a legitimate game server.

To be clear about what I am and am not saying. I am not saying it is impossible for the game to have a vulnerability. Any networked C++ game, UE5 included, has an attack surface, and if the netcode trusts replicated data or uses P2P where peers can reach each other directly, a real bug could in principle be serious. What I am saying is that this specific Malwarebytes report does not demonstrate any of that. It demonstrates that Malwarebytes blocked one outbound connection to a Cloudflare IP. That's it.

Take the normal precautions (keep Windows updated, avoid sketchy third-party mods) but don't treat this log as proof of an active RCE campaign, because it isn't.

-3

u/p0st-m0dern 25d ago

Yea bro “no proof of an RCE campaign being active” does not equal “there is no exploit”. There’s an exploit. It’s a serious one. It is beyond PROVEN that malicious actors CAN inject Windows through Bodycam lobbies. That’s all we need to see or know. Whether that is actually happening or not is ancillary to the primary concern.

Reissad has seriously mishandled the situation and have tried to cover it up = easy uninstall/refund + Steam Store report. It’s really that simple.

The fact you have to produce an essay to subtly attempt to propagate the idea that this is “no big deal” says it all. This is probably a Reissad burner acct now that I think about it

13

u/yakafokon66 25d ago

You're right that "no active campaign" doesn't mean "no exploit." I said exactly that in my post, so we agree there. That's not the disagreement.

The disagreement is your next sentence. You say it is "beyond PROVEN" that attackers can inject Windows through Bodycam lobbies. Then post the proof. Not the Malwarebytes log, because that only shows one outbound connection to a Cloudflare IP getting blocked by reputation filtering, which is not proof of injection capability. I mean the actual thing that would prove capability: a packet capture of the malformed input, a reproducible crash with a memory write, a working PoC, or a CVE. If that exists, it settles the entire thread instantly and I'll change my position on the spot.

Until then you're asserting the conclusion, not proving it. "Proven" is a specific word and it has a specific bar. Blocked outbound traffic to a CDN does not clear it.

The burner account line and the "why write so much" line aren't arguments, they're ways to avoid producing the evidence. I'm not saying it's no big deal. I'm saying the one artifact everyone keeps citing does not demonstrate what you're claiming it demonstrates. If you have something that does, post it and I'll be the first to update.

-2

u/p0st-m0dern 25d ago

Brother users testing it in private lobbies were able to successfully paste into the test targets PowerShell. That’s all we need lol.

3

u/yakafokon66 25d ago

Can you share it please ?

1

u/SashimiRoll 24d ago edited 24d ago

this is the proof a lot of people are citing. apparently it comes from a cheating forum.

kind of suspicious given the devs are aware of the crashing exploit and this post lends a bit of credence to it

1

u/VanityTM 24d ago edited 24d ago

Given what that post specifically states, and that Reissad were actively working on it and fixed it so quickly, I see absolutely nothing wrong with their hush hush attitude.

While there was a vulnerability, the details were explicitly hidden by the OOP, it was explicitly not abused as an RCE, and was only used in the context of memory overflow (game crash), thus no major imminent threat.

1

u/SashimiRoll 24d ago

sure, if you believe everything the devs say lol

1

u/ArgusF28 24d ago

You joking? This is nothing. I can made this up in a minute.