AmberCutie's Forum
An adult community for cam models and members to discuss all the things!

Another long-time CB developer using backdoors: cbbotdev

  • ** WARNING - ACF CONTAINS ADULT CONTENT **
    Only persons aged 18 or over may read or post to the forums, without regard to whether an adult actually owns the registration or parental/guardian permission. AmberCutie's Forum (ACF) is for use by adults only and contains adult content. By continuing to use this site you are confirming that you are at least 18 years of age.
Oct 29, 2024
76
106
6
Chaturbate Username
smoker919
The app is called rolling notifier and it is again access to the limitcam that proves vulnerable. The author of this app (cbbotdev) is very unsophisticated and makes mistakes in other parts of the code, but he still nonetheless sets it up so that an alt account (clickdickpic) is silently given access to the limitcam when it enters a room running the app.

A screenshot of the app code showing the backdoor routine:

Screenshot 2025-08-05 at 2.13.51 PM.png
 
Hello @smoker919 For assistance with Chaturbate, please contact support@chaturbate.com

@punker barbie I don't want to be pugnacious, but the last time I submitted a report on an app with a backdoor -- in April -- I got no response from CB Support and you didn't reply to the thread here even though I tagged you multiple times. This is why I didn't tag you this time but just made this thread as a public service. I'm more than happy to try for a reset if you wish; the previous thread is here.
 
Upvote 0
they should really add required permissions for limit cam
I just suggested this a couple days ago to Chaturbate staff in a meeting. Apparently better control over Limitcam shows is planned. Idk if it will be in only V3 apps though and I don't have a timeline for completion. Hopefully the easy changes get implemented soon.

I also mentioned the following with help from Smoker:
  • Automatically labelling apps with the "Limitcam" category if they add Limitcam users anywhere in the code. Helps spot malicious apps that may be hiding backdoors
  • That banning a single user often doesn't work if they have alt-accounts attached.
  • I think they're working on a better way to report apps I don't know what format that will take but a button with common reasons for reporting apps seems like a good idea.
  • Always sending a notification showing who has been added to a Limitcam show so a Performer knows.
 
  • Like
Reactions: omni
Upvote 0
Maybe I'm too far removed and maybe customer support staff turnover is fast-food frequent...but it seems there are *many* **significant** safety/security issues at CB that are being either slow-walked or not moved at all towards the front of the line for being addressed and/or rectified.

From afar, but having an idea of how long many issues have been raised by the community of users/creators/coders, it's disheartening to watch.
 
Upvote 0
I'm going to plug my own apps here because I don't think any other apps do this:

The ticket and hidden show components in my apps do two-level security checks to make sure that the only users viewing the shows are the ones that were added by that app, and any users who are detected having access to the limitcam from other apps are alerted to the broadcaster. I'll reuse an image from another thread here as an example:

screenshot-2025-04-22-at-11-03-35%E2%80%AFpm-png.103110
 
Upvote 0
Think theres at least one, i remember seeing a screenshot a while back about mentioning unexpected viewers.
Might have been my screenshot from here, but if not please share if you find it.
 
Upvote 0
Might have been my screenshot from here, but if not please share if you find it.
 
Upvote 0
This sounds to me like a ticket show app that doesn't clear the limitcam access list properly. I know this is true of several V1 ticket show apps that rely on the app being turned on and off for ticket shows rather than fully maintaining their state, and the limitcam state, internally.
 
Upvote 0