Server Bugs

• Use concise, precise descriptions
• Do not include sensitive information.
• Create a support ticket at https://support.secondlife.com for individual account issues or sensitive information.
URGENT SECURITY VULNERABILITY – UNAUTHORIZED EJECTS AND FALSE OBJECT ATTRIBUTION
URGENT SECURITY VULNERABILITY – UNAUTHORIZED EJECTS AND FALSE OBJECT ATTRIBUTION I am reporting what appears to be a serious security vulnerability in Second Life involving unauthorized parcel ejects. Residents are being forcibly ejected from parcels by users who do not appear to have the required land ownership, estate, or administrative permissions. This is not limited to a single incident or a single parcel. Multiple residents and lands appear to be affected. A particularly concerning aspect is that the system appears to attribute the action to an innocent object. When an eject occurs, the victim or nearby residents may see a local chat message such as: “The object 'Void - Demure Lashes (Avalon)' at Dearheart (196,46,2338) cannot teleport the parcel owner home.” The referenced object is a cosmetic attachment with no eject or teleport function. There is nothing in the object intended to eject, teleport, or remove users from the parcel. Nevertheless, the system displays the object as if it were involved in the action. This creates the appearance that a legitimate object caused the eject, while the actual source of the action appears to be something else. In one ongoing case, a resident has reportedly been ejected repeatedly, potentially dozens of times per day, across different locations. Entire groups of visitors on a parcel have also been forcibly ejected without authorization. We have already submitted multiple Abuse Reports and contacted Live Support, but the underlying issue remains unresolved. We urgently request that Linden Lab investigate this as a potential Second Life security vulnerability or exploit, rather than treating each incident as an individual land-management issue. Please review the server-side logs associated with the affected parcels and accounts, including: • The exact timestamps of the eject events • The account or system component actually triggering the eject • The permissions involved • The source of the eject request • Why an unrelated object is being displayed as responsible • Whether the same mechanism is being used across multiple regions and parcels If possible, please reproduce the behavior in a controlled environment and investigate how a resident without the appropriate permissions can cause another resident to be removed from a parcel. This issue is creating serious harassment and security concerns for residents and landowners. We need the technical/security team to identify the underlying cause, fix the vulnerability, and prevent unauthorized users from abusing this functionality. This report concerns a suspected platform-level security vulnerability, not a normal parcel eject performed by an authorized land manager.
12
·
needs info