Players arbitrarily get full developer access to our game and have access to server scripts

UPDATE: This was not an innocent bug. Someone has completely stolen the entire game (server scripts included) and republished it. Here’s a video of the bug in action: - YouTube


Hello!

Recently, we (Skate Central) have been receiving an alarming amount of reports from our userbase stating that players are randomly receiving the hammer icon in our game. We also received reports that they were getting access to the server console, however, we were able to (thankfully) verify that this was false. The issue of the icon still appearing is still very much so prevalent in our game.

Screenshots



We’ve checked all of the permissions/anything that could be causing this to happen, but are left scratching our heads. The permissions for the game’s access are properly configured (for context, only 3 people have studio access out of our development team of 12 people) — here’s a screenshot. Because this happens to such a small subset of our playerbase, we haven’t been able to identify any constants or steps to reproduce besides the fact that it happens to people in one specific rank in our group (Elite Skater).

Another thing that has happened is that a player has tried to scam other players and use the status of “developer” to persuade them to buy them things like Roblox gift cards. So far we haven’t heard of the bug happening in any other games, but if this has happened in yours please feel free to add on to this post. Here’s a link to our game.

Any advice is appreciated. Thank you for your time!

73 Likes

This has happened to me before. Chances are, said user might have been a developer in the past. If you disable team create and enable it again, you can probably find their user in the Permissions tab in Game Options.

4 Likes

I wish this was the issue, however at no point were any of the users getting it developers in the group. We’ll try disabling/re-enabling team create though and I’ll edit this post with the results. Thanks for the suggestion! Hopefully I can return with good news.

2 Likes

Scratch that. I have checked using Roblox’s endpoint as suggested to me in the past by @TheGamer101. The user you mentioned doesn’t seem to have edit permissions: https://api.roblox.com/users/36073178/canmanage/5881468

I’ve reread your post and I’ve actually misread. I thought the user was getting access to the server console. This seems like a leaderboard bug indeed.

2 Likes

Oh! That’s actually a really clever idea, I wouldn’t have even thought to check using that. At first we were told that they did have access to the server console which caused a (justifiably) large amount of panic within our development group, but we think they might’ve just assumed because they could see f9 they had access to the server logs. Thankfully we were able to work with one of the people and they didn’t have access.

3 Likes

Adding on to this, it appears people can also see various developer related options on the website.
Despite not being a developer and not having any type of edit permissions on the game. Users can’t actually access or use any of these options it appears, but regardless this is pretty sketchy.

4 Likes

Update: The bug is still happening, and because of Roblox’s inaction, someone has managed to steal our game.

Video of someone being able to do this (timestamped): https://youtu.be/aqrvUJ-QSUA?t=890

1 Like

We were wrong, players were actually able to access the developer stats & download our game because of this.

Player was able to shutdown all our servers and edit the game. We have quadruple checked our permissions for every roleset and checked it for the game itself.

1 Like

I’ve never seen anything like this before. Are you 100% sure these players don’t have any permissions? Someone on the dev team could be sneaking them permissions?

This is very odd and potentially dangerous.

1 Like

We have checked 10x times no one has edit access other than us.

4 Likes

This is scary. Not trying to fear-monger but what if this happens large-scale and people are able to copy paid-games like ER:LC, bloxburg etc.

4 Likes

A serious issue, ROBLOX is needing to fix this problem fast and now. If this spreads it can become a big problem.

This is very serious for all the Developers of Skate Centeral. You guys should reach out to Developer Relations ASAP. I will try and help you guys by reaching out to Developer Relations on Discord, I wish for the best.

And you’re 100% sure no one on your team is sneaking people permissions? I don’t think it’d be unheard of.

The reason I’m doubting this is a bug is because this doesn’t appear to be happening to any other games, and I haven’t heard of a bug like this happening in years.

2 Likes

To add to this, the people who do have access is limited to only 3 individuals (StarMarine614, retro_mada, and mrflimflam) which hopefully illustrates how locked down we’ve tried to make our game.

1 Like

And how do you know this doesn’t affect a plethora of existing games? I don’t foresee something like this being isolated to one game. Also… the ability to shutdown all servers, gain full edit access, and save changes to production when you have no ties to said place isn’t a critical issue that needs immediate recourse…?

1 Like

Because we haven’t seen this? In ANY other game?

There are much more profitable games to target. So why haven’t they been?

1 Like

Skate Park made well over 200,000 USD last month, so plenty of reason.

I would like to point out in the video posted above, when the person refreshes their page they have completely different options. Sometimes they have every option that a normal developer would see, and sometimes they don’t have anything, and sometimes they just have a fancy edit button.

There is nothing in audit logs, no changes in-game to permissions and the only people who can change those permissions are StarMarine, MrFlimFlam and I.

StarMarine has been away for 3 weeks on a business trip, and MrFlimFlam would never in a million years think about touching those even for a video. Also, unless I’m changing these settings with mind control, I’ve never touched them.

4 Likes

If this is still spreading, and users are still getting permission. I would say the best thing to do is currently have the game shut down until this is solved. These users must be getting developer permission IN-GAME.

The only other way users are getting permission is a developer giving someone permissions.

1 Like