Heads Up For Blender Users

I found a thread on reddit today, apparently hackers have found a way to leverage blender's python integration to infect systems with some malware payloads. I think you only have to worry if you set your blender up to autorun python scripts. If you have blender set to autorun python scripts, I would consider turning that feature off.
https://www.reddit.com/r/blender/comments/1l4426b/regarding_the_recent_virus_circulating_around_in/
https://www.reddit.com/r/blender/comments/1l4426b/regarding_the_recent_virus_circulating_around_in/
! REPORT
It's incredible how imaginative hackers are when it comes to inventing things to annoy people.
It would be great if they put their skills and imagination into creating free, reliable, and practical software in underutilized computing areas!
It would be great if they put their skills and imagination into creating free, reliable, and practical software in underutilized computing areas!
REPLY
! REPORT
Is autorunning python scripts something one must deliberately set up? I only use blender to make model meshes. I don't even know how to render a picture in Blender, let alone do any animation or such. So what are the chances I have scrip autorunning on?
REPLY
! REPORT
V8Infinite
Karma: 13,133
Sat, Jun 07Go to: Edit --> Preference --> Save&Load. The "Auto Run Python Script" box must be unchecked 

lukon
Karma: 5,678
Sat, Jun 07Thanks, V8Infinite.
I do 95% of my model makin' in Blender 2.79, which apparently does not even have the option to autorun python scripts.
And I checked in on my Blender 3.XX installations, and they already have the option un-checked, apparently by default.
I do 95% of my model makin' in Blender 2.79, which apparently does not even have the option to autorun python scripts.
And I checked in on my Blender 3.XX installations, and they already have the option un-checked, apparently by default.
V8Infinite
Karma: 13,133
Sat, Jun 07With pleasure, anything goes then 
As they say on Reddit, they're probably targeting studios. Blender is increasingly used by big studios, and they're targeting big machines, probably to mine crypto... Really vicious...

As they say on Reddit, they're probably targeting studios. Blender is increasingly used by big studios, and they're targeting big machines, probably to mine crypto... Really vicious...
It's unfortunate, but this issue affects any software that supports plug-ins or script execution, including programs like Microsoft Word and DAZ Studio. The best approach is to download content, whether plug-ins or scripts, only from trusted individuals or vendors before running it on your computer.
REPLY
! REPORT
That can be made to work for good. I know of a creator (a brilliant gent!) who included some script in his Studio character then loaded it onto a pirate site. The script would not set off anti-virus programs but when loaded in Daz, it slowly hosed the pirate's computer while he was busy making weird porn renders. At some point the computer would shut down and when it was rebooted, it wouldn't. The script deleted everything it could, data, programs, and content.
The fun part is that it took the effing pirates a while to figure it out and the site eventually died because of accusations of poisoned files being shared.
The fun part is that it took the effing pirates a while to figure it out and the site eventually died because of accusations of poisoned files being shared.
REPLY
! REPORT