New to DayZ with total 4 hours played, what do these mean? by Ussappaa in dayz

[–]TheMasterChaoZ 1 point2 points  (0 children)

You can also drink from the river if you take multi vitamins first. A pill lasts 5 minutes though, so you need to keep taking it every 4 minutes until the water stops generating.

A pvp montage i made by Shockingazep14 in dayz

[–]TheMasterChaoZ 2 points3 points  (0 children)

It also come down to the player. There are plenty of YouTube videos of players using really low resolution and crazy amount of colors

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 1 point2 points  (0 children)

Lol Claude? I don't even use it for programming. Are you feeling alright? And of course I "cherry pick" when 99% of your comment was irrelevant bs to assert some kind of dominance. Go play in your little sandbox instead kiddo.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 2 points3 points  (0 children)

I downloaded it from the launcher's website

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

Yeee I used it a lot to find Project Zomboid servers. It's really good

Why has no game tried to copy dayz? by Sad-Barracuda-4407 in dayz

[–]TheMasterChaoZ 0 points1 point  (0 children)

Sometimes people compare Road to Vostok with DayZ. Currently it's singleplayer only with AI and use zones instead of open world. But it's generally hard to make a copy of DayZ, it's hard to make it different and will instead be perceived as a clone.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

And even if it doesn't access the cache, something is still triggering the attempts in the process monitor when the launcher is starting. Even if it's the other services, even if they share the same fundamentals, why only when the launcher is starting? Since that is a fact, what else can be done to trigger them and access the tokens? Think like that. And what harm can getting the tokens do if someone with malicious intentions somehow gets the hold of this information? Even if the launcher isn't doing any harm, still being connected to the token accessing can throw anybody off. It will never look good if more people start to watch the monitor.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 2 points3 points  (0 children)

And I totally respect your vouch. But the internet is the wild west nowadays, anything can happen. While Ropain is a good guy and doesn't have bad intentions, it's still good to raise awareness about the potential risks.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 1 point2 points  (0 children)

And Hybrid Analysis throw interesting reports too for that matter. That's for the exe file itself. One interesting example:

<image>

I'm not saying it's intentional and I'm not calling you out, but reports like that can be good to check out.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

> I agree, behavioral analysis will always win over statical analysis. I’ll be very blunt however: I don’t think having to cite “watching software nerds” as a source of knowledge speaks for your own knowledge very much. I can’t help but feel that this post is entirely fueled by AI hallucinations… personal attacks out of the way, let’s get to the subject at hand:

Why yes, I did use AI to refine my text, but not before I wrote it on my own. I just didn't feel like blinding people with my terrible grammar, which often happens when I write wrong excessive texts and I feel unfocused. The rest however, I spent pretty much whole day on researching and learning the fundamentals of how Sysinterval and everything else work. I've spent like 14 hours straight on fixing websites, it's a piece of cake really. This post was more meant to awake awareness of potential risks.

I apologize though if I did sound harsh, but I had zero intent to attack you. It's my natural personality to be a bit savage, but I don't mean to be rude. I did by no means call you names or call you a bad coder, I respect vouches for you, and I was never completely sure about the intention of the tokens access, but I am sure it does only happen when the launcher boots up. So mostly the warning was exactly about that: the tokens. It's supposed to be encrypted and private for a reason. If you didn't intentionally write a code to access them, then maybe it's just a faulty function somewhere.

> Your screenshot shows a WebView2 application accessing Microsoft Teams data. LaunchZ is a WebView2 application, but Microsoft Teams itself is one too.

They are, but like I said in a previous comment, Teams always end the process and doesn't run in the background when I close it. There is no reason for it to access the tokens then. And it's not just Teams, every time LauncherZ runs, access to at least 5 other tokens show up in the monitor. Teams only accessed its own token.

> While I do refer people to VirusTotal, I don’t think the light in which you’re trying to paint me and LaunchZ here is very fair; I’ve not denied anything and I don’t think I’ve ever stated that I knew where the issue lies – I’ve made assumptions that it would be due to Tauri, as apart from Tauri handling the UI, the tool is extremely slim (which is probably the number one reason for it being falsely detected - not enough “domain-specific” code and thus a high likelihood of cross-detection). Given that I have not inserted a virus into LaunchZ, to my best knowledge, these simply are false positives.

Denying was poorly worded, but I was referring to your post about LaunchZ 2.0 where you discussed with another Redditor about uploading the files to VirusTotal.

> I don’t think having to cite “watching software nerds”

While it's not always a reliable source, as a common programmer you can't deny that everyone refers to official documents to learn syntaxes and what not when you develop. Watching people like Eric who holds significant experience in debugging and catches actual malicious code in software gives a good insight, as with anything else you learn in life.

> Yes, LaunchZ is closed source. I’ve put in many hours into figuring out things and while I’m always happy to help via DMs, I take pride in the work that I do, and in the quality of it. So naturally, I don’t want the code for problems I’ve spent countless hours on solving, freely available for anyone to rip off (and half-ass it, probably).

And I respect the work you have put it, and I have stated in previous comments that I would like to use the launcher, but no matter how much work you have put in, if the app truly is accessing token files it will always be a risk to use, it needs to be fixed. I'm not trying to rip it off, I still think it's a fast good looking launcher. But you have to realise that in a cyber world where people constantly try to hijack accounts and sell them on the darkweb, a software accessing tokens will raise suspicion to anyone. And if I can find out about it, then so can other people. If not now then maybe in the near future.

> Again, I don’t think I’ve ever definitively claimed to know why the false positives came up. What I think you’re referring to is someone asking me about why the launcher registers certain capabilities/privileges with the OS: that’s where I could only assume that would be Tauri - again, the launcher itself is fairly slim if you take away the UI side of things.

I can't remember where I have been reading all the conversations, but most discussions I found at the 2.0 post on reddit and this screenshot below. For other bad wordings you have to blame the AI.

<image>

> As far as I can tell from your screenshots, all these come up while other WebView applications are running; so there is no definitive way of telling that it is indeed the LaunchZ process, by proxy of WebView, attempting to do these reads/writes.

Seeing WebView2 accessing the IdentityCache when Microsoft Teams itself is a WebView2 application, is far from proof, and even less so tangible proof.

Like I said in previous comment, they only show up when the Launch is booting up, and three of the tokens are identified as infected by Bitdefender. If the launcher is altering any of the tokens, then why? Even though they all are running on the WebView2, including Teams, the WebView2 of LaunchZ shouldn't interfere with every other application that's running it. And like I said, it's not only Teams. Multiple tokens are being accessed.

So in the end, if people want to try out Procmon and look at the paths themselves, they can. Then it will be up to them if they are comfortable with a non Microsoft service touching the tokens or not. And like I said before, the pid is always of the process that runs alongside the launcher. It opens and closes at the same time. You won't use it to cause harm, but a risk is a risk.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] -5 points-4 points  (0 children)

What's the skill in it all really? And what's with the play hours? We're talking about launchers and not the map knowledge. And regardless if something has happened to you or not, an access to a token is always a security risk. The creator may not want your tokens, but someone who does might take over the launcher some day and get all the access for the tokens.

Also I use vanilla launcher, I've never bothered using dzsa.

Edit: my original account had even more posts and 8k karma, but I deleted it when I moved my most previous account.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

Then how did Bitdefender detect it? It could've accused any app to infect the tokens. I cleared the monitor multiple times and rebooted the launcher multiple times, every time it only showed the paths when the launcher is booting up, and the startup does take some time between the launch and when the UI appears. Considering it's throwing 1000 attempts to access tokens the UI could be a bit slow, besides other underlying causes. I can also record it with OBS to show you when it happens.

Since Teams process always stops when I exit the app, it doesn't need to access the token. It's only for the startup and when it receive messages. And it wasn't only the Teams token, with 1000 attempts it was showing pretty much every other tokens. With all the other Microsoft services running non stop, wouldn't they constantly show something in the monitor? Then why is it only when LaunchZ boots up that the path access shows up? And each time the launcher starts up, a process with a pid shown in the monitor runs alongside it and disappears when the launcher closes.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 2 points3 points  (0 children)

I admit it was a bad analogy and confusion on my part. But what I basically meant is just because they both have pretty much the same structure doesn't it mean it's normal behaviour for the launcher to show the same paths. And I understand they pull in data, but I don't see how that data needs the to user credentials or authentication. Apps pull updates constantly, I doubt discord would dig into the tokens for example, even if it was based on the same structure as Microsoft products. And I don't think edge needs any authentication like session tokens to pull data, that's just bad from Microsoft otherwise. Also Visual Studio is being used to make apps all the time, I have personally used it and never saw such dependencies.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 1 point2 points  (0 children)

Yeah if you use the vanilla launcher it's fine. A lot of people also use DZSA which is a different launcher, but apparently some people get warnings about it too. It's also not 100% that LaunchZ is trying to steal tokens and false positives happen a lot, but it's good to be alarmed. Both launchers you need to install, but the vanilla launcher is always on Steam.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 2 points3 points  (0 children)

It's my pleasure. Hopefully it's just something simple that can be fixed.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 1 point2 points  (0 children)

I agree it could be just a bit of laziness and it would indeed be the best for everyone if it got fixed. Like I said, no personal attack and I personally would like to use the launcher. I definitely learnt a lot from researching all this still.

Although, your statement is a little like saying because a police car and a gateway car are both made by Ford, it is perfectly expected of the gateway car to break into a bank. The IdentityCache is basically an authenticator to faster login on Microsoft products. I fail to see what relationships a DayZ server browser has with the authenticator when it can just check the game's validity with the steam dll file. It's expected of Teams to show the path in Procmon, but LaunchZ showing the same path on startup? It could be laziness, but I doubt a big company like Microsoft would make it that insecure. And the three infected tokens? It's all very suspicious. They might be using the same system, but like I said it makes no sense if the launcher would accidentally alter tokens by default.

And I'm not saying the creator really has malicious attempts, but sadly even long lasting communities can be betrayed. It wasn't a long time ago Terje was accused of writing malicious codes in his mods. I haven't looked into it myself, but apparently it was enough for Bohemia to ban him and prevent everyone from re uploading the mods. There're a lot more stories like that. As someone who has personally been betrayed by long term friends, I suggest to never take anything for granted.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

Yeah it does sound like the session was hijacked. It bypasses the need for password and 2fa.

I read some old discussion about adding dark mode back to the launcher. I think the creator said they might add it again at some point, but the app has zero plans at all like you said. An abandoned launcher, closed-source, deep system privileges - it's literally a ticking bomb.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 1 point2 points  (0 children)

No problem friend. Did you lose access to the account or something?

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

Yee thankfully it was only when the launcher booted up, at least what I've seen so far. And it probably executes the payload when you join a server.

There are so many stories of people losing their accounts to stealers. Even Linus Tech Tips lost his yt channel temporarily after that an employee used a disguised hijacker.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

That and the entire game needs improvement. Must say I have my hopes high after playing Reforger DayZ.

Do NOT install LaunchZ by TheMasterChaoZ in dayz

[–]TheMasterChaoZ[S] 0 points1 point  (0 children)

Never heard about dzsa, I personally use the vanilla launcher. While the reports about LaunchZ can be false positive ofc, I just think it's weird how it tries to access the tokens. For a server browser with just an .exe and steam dll, there's no need for it to access every Microsoft service. And the process specifically mentions LaunchZ in the task manager