Nothing new here.
Nothing new here.
It's like saying that any program running on my computer could exploit a remote code execution bug... I mean, yes, it could. But why would it, when it already has local execution rights?
The installation of an add-on shouldn’t inherently give it free reign, with the only possible defense being trust & source-code review.
It's just a game, so they don't take it very seriously, I guess. They could just revert transaction using their moderator powers if something bad happens.
This works with API functions also, which is why this works.
Yes, don't run untrusted code as a user, but also developers should be practicing defense in depth[0]. This isn't like pasting something into a web browser's dev console or a Bash prompt, WoW has the ability to just outright turn this behavior off.
Look at something like the Signal source code, they flat out turn off webviews entirely[1]. So an entire class of phishing attacks just vanishes, regardless of what they're doing to block XSS or malicious links.
WoW should do the same thing - your chat window should not have access to its host environment, if it even needs the ability to run scripts in the first place.
[0]: https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%...
[1]: https://github.com/signalapp/Signal-Desktop/blob/development...
The "chat" window in WoW is more like a shell interface/CLI than a pure chat window and it's been that way since the inception of WoW. The mod system is loosely dropped on top of it: basically add-ons in WoW amount to bash scripts.
It's a pretty hacky system that seems like it was made to add modding capability as quickly as possible during development. The fact that such an integral system has never been rewritten isn't hard to believe.
This is coming from someone who doesn't play WoW; is it common for a mod to expose custom commands in chat or something? Or are mods maybe using it as a buffer to send commands?
I guess if they're detecting and popping up a warning prompt, but they're not willing to get rid of the prompt and just always escape the input, there must be some stuff out there that utterly depends on players clicking "allow". That's baffling to me, but I am often baffled.
Yes, it's quite common for mods to expose custom commands, although these are not raw Lua functions but rather "slash commands", e.g. /foo
Other than for messaging/chat, the chat box can also be used for various commands for actions your character should perform, e.g. /wave, /target, /sleep and the game also has a built-in macro system that lets you combine several of these into a "macro" that you can then execute by pressing a single button. But these are all "safe", i.e. they don't eval raw Lua code.
There are some WoW quest-tracking websites that will sometimes give you little snippets of Lua to execute via /run that will e.g. query the game about whether you completed the given quest, but in general normal users shouldn't need to use /run, it's more of a feature for mod developers.
The system might come off as insecure, but frankly that flexibility added a lot of value to WoW over its lifespan.