Exploiters can access new PlayerDataService key

Exploiters can access new PlayerDataService key which is poorly protected and gives them access to export player data under that key. I was recently researching sm1 named “numerology” or “74235” including their youtube channel where they frequently post about things related to roblox exploiting and exploiting certain things that roblox had left over in memory, so with that happening we can say hyperion is useless overall? Because the impact is huge due to his subscribers and members of the server are available to access new things since he posts tutorials there to modify roblox memory in order to access these new things and exploit server-side limited functionality. You can take a look at the screenshots because clearly the source of the scripts he utilizes are basically all opensourced and shown (he doesn’t even hide what he’s doing)



On the screenshots you can clearly see that a new datastore key for PlayerDataService is being imported into DataStoreService as a “DataStore” which means he can access it including the fact that its purely NEW and maybe it utilizes unprotected opencloud functionality which causes him to be able to load player records under unprotected key (unlike globaldatastore key)

Expected behavior

They should’ve expected to have error “Player:GetData() is not yet enabled!” thing, but yet they had bypassed even the serverside check to access it :slightly_frowning_face:

A private message is associated with this bug report

1 Like