AmberCutie's Forum
An adult community for cam models and members to discuss all the things!

How to deal with malicious CB apps?

  • ** WARNING - ACF CONTAINS ADULT CONTENT **
    Only persons aged 18 or over may read or post to the forums, without regard to whether an adult actually owns the registration or parental/guardian permission. AmberCutie's Forum (ACF) is for use by adults only and contains adult content. By continuing to use this site you are confirming that you are at least 18 years of age.
Sep 2, 2024
25
3
1
This is a question I hope that @punker barbie can help with, please.

I have clear proof that there is malicious functionality contained in one or more CB apps. I know the username of an alt account used by the developer to execute said functionality and a list of the apps running in a room where this functionality was executed. Using the list of apps I can narrow down who the developer actually is.

My question is: even with clear proof of malicious behaviour by apps, how can one get CB to take it seriously enough to take action, i.e., to remove the apps and ban the developer?

Thank you!
 
You act like you're the first person to ever find malicious backdoors in apps. Just report it and move on.
 
Upvote 0
Hi,
What apps/bot are in question? I would like to know so that I can conduct my own research and possibly warn any models who I have managed.

What malicious issues do you have proof of? The Legacy and new API have many limitations. It would be extremely difficult to do much of anything other than disrupt chat/games or provide free ticketshow tickets from within apps/bots offering related features. Apps and bots can not reference, control, or execute code from another app or bot. Unless that app/bot is making calls outside the site and executing external code, you really should have nothing to worry about.

Cheers,
Cexmental
 
Upvote 0
@punker barbie I've contacted CB Support about malicious apps in the past but their information about apps is fundamentally incorrect. I hope you might be able to suggest how a request to them should be phrased to get the right response. You have also interacted with one of the alt accounts for the developer in question on this forum and you have linked the alt account to their main account in CB tickets.

@cexmental I'm quite familiar with CB apps. The app in question is a V1 app with undocumented but demonstrated commands to allow the app author (not the model or moderators) to mute users in rooms it runs in by setting the X-Spam flag on all a user's messages to true. It also contains a blacklist to mute any user on it in any room the app is running in. That's a massive infringement on users' abilities to use the site and certainly meets my definition of malicious. I can DM you on CB if you would like; I don't want to name apps publicly yet.
 
Last edited:
Upvote 0
@punker barbie I've contacted CB Support about malicious apps in the past but their information about apps is fundamentally incorrect. I hope you might be able to suggest how a request to them should be phrased to get the right response. You have also interacted with one of the alt accounts for the developer in question on this forum and you have linked the alt account to their main account in CB tickets.

@cexmental I'm quite familiar with CB apps. The app in question is a V1 app with undocumented but demonstrated commands to allow the app author (not the model or moderators) to mute users in rooms it runs in by setting the X-Spam flag on all a user's messages to true. It also contains a blacklist to mute any user on it in any room the app is running in. That's a massive infringement on users' abilities to use the site and certainly meets my definition of malicious. I can DM you on CB if you would like; I don't want to name apps publicly yet.


Are any of these apps by any chance "insy" and "piglet" or something like that, who is the same creator and I think there are more?
I know of these ones that are there and still there being used by models and do the same as you have said, and it allows the creator to also spy on all shows free and I think more.
 
  • Wat?!
Reactions: MarieElise
Upvote 0
@punker barbie I've contacted CB Support about malicious apps in the past but their information about apps is fundamentally incorrect. I hope you might be able to suggest how a request to them should be phrased to get the right response. You have also interacted with one of the alt accounts for the developer in question on this forum and you have linked the alt account to their main account in CB tickets.

@cexmental I'm quite familiar with CB apps. The app in question is a V1 app with undocumented but demonstrated commands to allow the app author (not the model or moderators) to mute users in rooms it runs in by setting the X-Spam flag on all a user's messages to true. It also contains a blacklist to mute any user on it in any room the app is running in. That's a massive infringement on users' abilities to use the site and certainly meets my definition of malicious. I can DM you on CB if you would like; I don't want to name apps publicly yet.
Name names or take it off site. Otherwise this is just shit-stirring.
 
Upvote 0
@Vixxen81 You've posted 3 times on this thread already but you've contributed nothing. You want to accuse others of stirring things up while doing exactly that yourself. Maybe reconsider your stance on this forum and try to be HELPFUL instead of ANNOYING.

I wrote here seeking input on how to deal with this app, particularly from @punker barbie who has dealt with this developer before. I'm not going to publicly name anyone or any app until I'm 100% certain.
 
Upvote 0
@Vixxen81 You've posted 3 times on this thread already but you've contributed nothing. You want to accuse others of stirring things up while doing exactly that yourself. Maybe reconsider your stance on this forum and try to be HELPFUL instead of ANNOYING.

Im sorry to say that in this situation you are the annoying one and vixxen is just trying to get you to say the app names which you should have done from the start.

Edit: is the source code viewable for this particular app?
 
Upvote 0
I can DM you on CB if you would like; I don't want to name apps publicly yet.

Hello,
If you would like to pass me the name of the apps/bots either via DM there (I am "mentalcex" on CB) or PM here, I would be happy to conduct a deeper investigation. What you are describing is possible.

Cheers
Cexmental
 
Upvote 0
LOL You can literally look up their name and see the apps.
 
Upvote 0
Under normal circumstances it would make sense to plug in the username and see what bots come up. However, the bots in question are from various developers and it's an assumption as best which of the of bots is related to the account in question. This person is using a second account in chat different from the app/bot authors name in an attempt to remain anonymous.

Cheers,
Cexmental
 
Upvote 0
Under normal circumstances it would make sense to plug in the username and see what bots come up. However, the bots in question are from various developers and it's an assumption as best which of the of bots is related to the account in question. This person is using a second account in chat different from the app/bot authors name in an attempt to remain anonymous.

Cheers,
Cexmental
Yes, this is correct.
 
Upvote 0
This is surprising news. The Menu was my main competitor when I offered Tip Menu 50 for free. It pushed me to add new features in an effort to gain popularity, until it become obvious that popularity doesn't pay the bills.

Please let us know what CB has to say and how this all plays out.

Cheers,
Cexmental
 
Upvote 0
This is surprising news. The Menu was my main competitor when I offered Tip Menu 50 for free. It pushed me to add new features in an effort to gain popularity, until it become obvious that popularity doesn't pay the bills.

Please let us know what CB has to say and how this all plays out.

Cheers,
Cexmental
I haven't contacted CB Support about this yet. It's the reason I had hoped for input from @punker barbie because previous correspondences with CB Support show that they do not understand app development on CB.

In particular, CB Support stated in a reply to a previous ticket I had opened that ALL app development on CB is open source and therefore CB does not need to manage the activities of app developers. This is factually incorrect. I'm not saying this to be critical of CB; I truly hope that CB Support can gain a proper understanding of app development and will actually take an active role in rooting out malicious behaviour on the platform.
 
Upvote 0
I haven't contacted CB Support about this yet. It's the reason I had hoped for input from @punker barbie because previous correspondences with CB Support show that they do not understand app development on CB.
That isn't the kind of help that the punker barbie account gives here. You'll have to contact support, then the punker barbie rep will just verify that they've received it.
 
  • Like
Reactions: cexmental
Upvote 0
I haven't contacted CB Support about this yet. It's the reason I had hoped for input from @punker barbie because previous correspondences with CB Support show that they do not understand app development on CB.

In particular, CB Support stated in a reply to a previous ticket I had opened that ALL app development on CB is open source and therefore CB does not need to manage the activities of app developers. This is factually incorrect. I'm not saying this to be critical of CB; I truly hope that CB Support can gain a proper understanding of app development and will actually take an active role in rooting out malicious behaviour on the platform.

That was surprising for me to read. In my experience, CB Staff has been very technical and extremely helpful with apps/bots. I've had some excellent correspondences with them. On a couple of occasions they have worked to help solve a few major issues.

I hope you give them another try.

Cheers,
Cexmental
 
Upvote 0
Hi I'm going to be the pill in this party, but on what level do you charge to give people access to apps on CB and on what level do you get paid to make apps?
 
Upvote 0
The blacklist would really only be a problem for non-tippers. Tell us why you are on it...
You have the wrong understanding of what a blacklist is in this context. Say he puts your big tippers on his blacklist, and when they find themselves being ineffective in your room because no one is responding to their chat (because no one but themselves can see their chat messages) then they would feel disrespected and leave and you would lose their patronage. That's the real harm: not individual users losing their ability to chat, but models not having control of their rooms.
 
Last edited:
  • Helpful!
Reactions: Vixxen81
Upvote 0
Say the app records purples passing through your preferred model's room without tipping. Over time you could collect those names and blacklist them in every OTHER room that runs your app. In addtion to any TOS vioations this would violate this V2 requirement:

2.2 - Hidden behavior​

Apps should not contain any hidden features that provide unintended benefits to or deny benefits from groups of users in any way that is not clearly communicated to broadcasters in the app’s description.

v1 apps do not have such a stated requirement as far as I know.

Eventually I would expect CB to remove all v1 apps and bots, maybe next year? Hence the recent Hackathon.
 
Upvote 0