Skip to content
TORNLIFE More

Ezlira: forum

Ezlira [4037017] Level 16 Ruined Chaos PF Knight

Forum posts (Torn's count)
2 observed
Archived posts
6
Threads started (archived)
1

Boards

From the 6 newest archived posts.

Threads started

Most-liked posts

Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.

Selling RW Weapons · · 3 likes

bump

trusted trader

[API Leak] Stealth Attacker Identity Exposed via API / Discord Bot · · 2 likes

Hi,

 

I have discovered a potential API leak/exploit regarding stealth attacks and data exposure.

 

As you can see in the attached screenshots, when a player (Duncan679) is mugged with a successful stealth attack, the in-game UI correctly masks the attacker's identity, displaying "Mugged by someone".

 

However, our Discord bot, which pulls hospitalization/attack data from the Torn API, completely bypasses this stealth mechanic and explicitly reveals the attacker's real name (DavidH99) for the exact same event.

 

Furthermore, to rule out any coincidences, I also verified through the faction logs that the player was not mugged by anyone else during that specific timeframe. This confirms without a doubt that the bot and the in game UI are displaying the exact same attack.

 

The Issue: The API seems to be leaking the attacker's identity even when the attack was a successful stealth attack. This effectively renders the stealth mechanic useless, as anyone with a Discord bot or API access can easily see who attacked them.

 

Proof:

  • Image 1: Bot correctly parsing the API and showing the exact attacker (DavidH99).

  • Image 2: In-game profile showing the attacker is hidden as "someone".

 

Could you please look into why the API is exposing stealth attacker data? Let me know if you need more details or specific API logs.

 

 

 

Recent archived posts

[API Leak] Stealth Attacker Identity Exposed via API / Discord Bot ·

Hi again,

 

I tried to retrieve the historical raw JSON for that specific attack, but I am unable to provide it for two reasons:

  1. Our bot processes the API data in real-time and we strictly do not store or keep logs of raw JSON payloads to save storage and respect privacy.

  2. I attempted to manually fetch the past attack log via the /user/4130073?selections=attacks endpoint using my API key, but I received an HTTP 403: Forbidden error (which is expected, as the API restricts viewing other players' attack histories retroactively).

 

However, the screenshot I provided in the original post is a direct output of what the API delivered to our bot at that exact timestamp. The bot simply maps the attacker_name and attacker_id fields. If the attack was properly stealthed at the API level, those fields should have been empty or masked, but they clearly weren't.

 

Moving Forward: I have now added a temporary logging mechanism to our bot's code. The very next time a stealth mug happens within our scope, I will capture the exact raw JSON payload and share it here for your debugging process.

Please let me know if the current screenshots are enough for your team to investigate the /faction/ or /user/ endpoint logic, or if you prefer to wait for my next raw data catch.

[API Leak] Stealth Attacker Identity Exposed via API / Discord Bot · · 2 likes

Hi,

 

I have discovered a potential API leak/exploit regarding stealth attacks and data exposure.

 

As you can see in the attached screenshots, when a player (Duncan679) is mugged with a successful stealth attack, the in-game UI correctly masks the attacker's identity, displaying "Mugged by someone".

 

However, our Discord bot, which pulls hospitalization/attack data from the Torn API, completely bypasses this stealth mechanic and explicitly reveals the attacker's real name (DavidH99) for the exact same event.

 

Furthermore, to rule out any coincidences, I also verified through the faction logs that the player was not mugged by anyone else during that specific timeframe. This confirms without a doubt that the bot and the in game UI are displaying the exact same attack.

 

The Issue: The API seems to be leaking the attacker's identity even when the attack was a successful stealth attack. This effectively renders the stealth mechanic useless, as anyone with a Discord bot or API access can easily see who attacked them.

 

Proof:

  • Image 1: Bot correctly parsing the API and showing the exact attacker (DavidH99).

  • Image 2: In-game profile showing the attacker is hidden as "someone".

 

Could you please look into why the API is exposing stealth attacker data? Let me know if you need more details or specific API logs.

 

 

 

Selling RW Weapons · · 3 likes

bump

trusted trader

Buying or selling trains? ~Advertise Here~ ·

found

Buying or selling trains? ~Advertise Here~ ·

  • Manual labor: 2.162
  • Intelligence: 521 
  • Endurance: 4.738
  • Total 7.421

looking for trains message me to discuss prices

Where are u from guys? :D · · 3 likes

Hey! Nice thread idea 🙂

I’m from Turkey. Been playing Torn for a while now and it’s honestly cool to see how global the community is. I never expected players from so many different countries when I first started.

 

Torn really does reach everywhere. Cheers from Turkey and good luck in-game!🇹🇷🇹🇷