TERA's Chat System Reportedly Leaves Game Open For Exploits

QuintLyn Bowers
By QuintLyn Bowers, News Editor Posted:
Share:


**UPDATE** Nov. 13

Although not explicitly stated by En Masse, it appears that the hotfix did go through on the 11th and chat has been returned to normal. That said, players logging on after the hotfix have noted that their personal settings for the game have been undone. So, just to be on the safe side, you might want to turn your volume down before logging into the game.

**UPDATE** Nov. 10

En Masse Entertainment posted a response to this later in the day yesterday stating that they are "taking these claims very seriously, but as of this time, [they] have no evidence" that the exploit is being used in the way described or that it's compromised player information.

In the meantime, they've applied a patch that will prevent all chat except guild chat as a precaution while they investigate.

**Original Post** Nov. 9

Using chat in TERA may not be the safest thing to do. No, I don't mean due to general toxic community behavior. Rather, I mean that it can apparently be exploited by players due to the fact that it uses HTML.

Recently Redditor Gosukek made note of the fact that the way En Masse Entertainment handles the game's chat leave players open to a wide variety of questionable activity. These include things like sending clickable links or external images -- even on megaphone. This means that every connected client opens images, whether the chat is visible or not; something which could result in less savory people having access to everyone's IP address.

Other alleged activities believed to be allowed would be to crash people's clients using the whisper feature, or even by spamming it in global. And even more nefarious, someone could possibly delete other player's characters or items, although Gosukek refrained from explaining exactly how that works.

The document Gosukek put together also references Remote code execution, stating:

"Remote code execution This is the big one, if you skip past everything else PLEASE READ THIS. Due to several factors that I will not go into detail with, there is a very real possibility that this could be used to remotely execute code on clients computers. This means the potential for this to be used to spread malware, viruses, keyloggers, all kinds of juicy shit, is VERY REAL and VERY VERY VERY VERY VERY F* SERIOUS. This is a HUGE deal and I cannot f* state that enough. This is beyond a simple data breach and the fact that it has been swept under the rug is appalling (I will talk about this more in the drama section). I know that this is scary, but you should be f* scared, this is potentially a very serious issue. I have not tested it myself as it's 2spooky even for me, however by all accounts it should work."

Needless to say, if true, there appears to be a lot of risks associated with using the TERA in-game chat, and apparently there's not a whole hell of a lot you can do about this -- unless you want to make use of tera-proxy as a mode of protection. But let's just say that option is ethically questionable. Not that this matters to everyone since the whole banning incident back in May.

However, just in case there is a solution in the works, we have reached out to En Masse Entertainment for comment (in addition to the post they already made.) Should they respond, we will update this post. In the meantime, you can read Gosukek's writeup on the issue and check out any comments on the Reddit post.

Share:
Got a news tip? Contact us directly here!

In this article: TERA, En Masse Entertainment.

About the Author

QuintLyn Bowers
QuintLyn Bowers, News Editor
QuintLyn is a long-time lover of all things video game related will happily talk about them to anyone that will listen. She began writing about games for various gaming sites a little over ten years ago and has taken on various roles in the games community.

Discussion (1)

Preciel 5 years ago
there are still people not avoiding enmasse? lmao


Read Next

Dreadnought Makes It Easier To Fight -- And Keep Fighting -- With Friends

Dreadnought Makes It Easier To Fight -- And Keep Fighting -- With Friends

Update 1.9.5 for the open beta of Dreadnought has just gone live for PC players.

By Jason Winter - 5 years ago

You May Enjoy

Get Your Magic: The Gathering Arena 5th Anniversary Celebration Rewards Now

Get Your Magic: The Gathering Arena 5th Anniversary Celebration Rewards Now

There's also events coming up.

By Matthew D'Onofrio - 5 days ago
New Letter From Throne And Liberty Producer Shows Off Never-Before-Seen Bosses And Areas

New Letter From Throne And Liberty Producer Shows Off Never-Before-Seen Bosses And Areas

I can't even front...this stuff looks incredible.

By Matthew D'Onofrio - 4 days ago
New World Teams Up With Content Creators For A "New And Returning" Player Guide

New World Teams Up With Content Creators For A "New And Returning" Player Guide

Now's a great time to jump into New World.

By Troy Blackburn - 5 days ago
TGS 2023: Yoshi-P Provides More Details On Patch 6.5 In PLL 79

TGS 2023: Yoshi-P Provides More Details On Patch 6.5 In PLL 79

You have about a week to get all your pre-patch stuff done.

By QuintLyn Bowers - 1 day ago
Our Most Played MMORPGs In 2023

💣 Feature | Our Most Played MMORPGs In 2023

Here's what the MMOBomb staff have been playing this year.

By Troy Blackburn - 3 days ago
Dead By Daylight Developer Update Addresses "Face-Camping" And Drones

Dead By Daylight Developer Update Addresses "Face-Camping" And Drones

There's also improvements for the Shattered Square and MacMillan Estate maps.

By Matthew D'Onofrio - 1 week ago