Page MenuHomeFeedback Tracker

ASAP Security, Sensisitive Data may be availabe to Public, Reopen! http://feedback.dayzgame.com/view.php?id=11041
Closed, ResolvedPublic

Description

DayZ.mdmp files can contain sensitive and private data.

Details

Legacy ID
2073538647
Severity
None
Resolution
Fixed
Reproducibility
Always
Category
Other
Steps To Reproduce

Have Steam running and be logged in make dayz crash... Search the minidumpfile
DayZ.mdmp for "SteamUser" for e.g. You may find the username in plain text there.

Additional Information

It could be that not always sensitive data is in the minidump file. For me it was. I can send you my minidumpfile from a dayzcrash to your e-mail adress. Any risk of sensitive data to get public must be removed asap.

Event Timeline

vatixerid edited Additional Information. (Show Details)
vatixerid set Category to Other.
vatixerid set Reproducibility to Always.
vatixerid set Severity to None.
vatixerid set Resolution to Fixed.
vatixerid set Legacy ID to 2073538647.May 8 2016, 6:03 PM
vatixerid edited a custom field.

Hi,

like I already said once - our dump files do not contain any sensitive information. I have checked four random dump files for usernames and have not found any. Even if a username WAS there, usernames are not really sensitive information. Passwords would be a different matter.

Please upload a dump file which you think contains a username and I will have a look at it. Otherwise I will close this issue as well.

Hi,

I apologize, this ticket got overlooked a bit. I will see what can be done.

Thanks for bringing this to our attention.

Hi,

guests and reporters are unable to download or otherwise access or modify any files submitted to the feedback tracker.

Can you please let me know if you (as a ticket author) can manipulate the file that you have uploaded to this issue?

Thank you!

Everything is working as it should then. I will now close this issue.

Thank you for your feedback once again!