URGENT SECURITY VULNERABILITY – UNAUTHORIZED EJECTS AND FALSE OBJECT ATTRIBUTION
complete
Devil Mother
URGENT SECURITY VULNERABILITY – UNAUTHORIZED EJECTS AND FALSE OBJECT ATTRIBUTION
I am reporting what appears to be a serious security vulnerability in Second Life involving unauthorized parcel ejects.
Residents are being forcibly ejected from parcels by users who do not appear to have the required land ownership, estate, or administrative permissions. This is not limited to a single incident or a single parcel. Multiple residents and lands appear to be affected.
A particularly concerning aspect is that the system appears to attribute the action to an innocent object. When an eject occurs, the victim or nearby residents may see a local chat message such as:
“The object 'Void - Demure Lashes (Avalon)' at Dearheart (196,46,2338) cannot teleport the parcel owner home.”
The referenced object is a cosmetic attachment with no eject or teleport function. There is nothing in the object intended to eject, teleport, or remove users from the parcel. Nevertheless, the system displays the object as if it were involved in the action.
This creates the appearance that a legitimate object caused the eject, while the actual source of the action appears to be something else.
In one ongoing case, a resident has reportedly been ejected repeatedly, potentially dozens of times per day, across different locations. Entire groups of visitors on a parcel have also been forcibly ejected without authorization.
We have already submitted multiple Abuse Reports and contacted Live Support, but the underlying issue remains unresolved.
We urgently request that Linden Lab investigate this as a potential Second Life security vulnerability or exploit, rather than treating each incident as an individual land-management issue.
Please review the server-side logs associated with the affected parcels and accounts, including:
• The exact timestamps of the eject events
• The account or system component actually triggering the eject
• The permissions involved
• The source of the eject request
• Why an unrelated object is being displayed as responsible
• Whether the same mechanism is being used across multiple regions and parcels
If possible, please reproduce the behavior in a controlled environment and investigate how a resident without the appropriate permissions can cause another resident to be removed from a parcel.
This issue is creating serious harassment and security concerns for residents and landowners. We need the technical/security team to identify the underlying cause, fix the vulnerability, and prevent unauthorized users from abusing this functionality.
This report concerns a suspected platform-level security vulnerability, not a normal parcel eject performed by an authorized land manager.
Photo Viewer
View photos in a modal
Log In
This post was marked as
complete
Maestro Linden
updated the status to
tracked
Devil Mother
Maestro Linden
There is also a very recently created avatar, Empadinha123 Resident, which appears to be less than one day old. Even after I remove the malicious objects, they appear to replicate themselves and continue performing the same attack. This is especially concerning because a newly created account appears to be associated with objects or contents that I never owned or possessed. Please investigate how these objects are replicating, how they are being introduced into my land, and the connection between this new account and the previously identified suspicious accounts and objects.
Photo Viewer
View photos in a modal
Devil Mother
Maestro Linden
I want to clarify an important point because I believe it is essential to understand the seriousness of this situation.
I personally witnessed this activity taking place. This is not based solely on suspicion or speculation. I observed the mechanism being deliberately operated and witnessed discussions through Voice directly related to its use. Unfortunately, Voice conversations do not provide the same type of reportable record as text chat, making it difficult to provide a transcript of what was heard.
What I witnessed indicates that this is not simply an automated object left somewhere to eject everyone who enters a parcel.
The mechanism is being deliberately controlled. It can be turned on and off and used against specific targets. I personally witnessed it being used selectively against particular residents.
This changes the nature of the abuse completely. The mechanism is not simply being used for automated griefing; it can be used as a tool of intimidation, retaliation, and coercion against residents and land owners.
If a resident does not comply with what the people controlling the mechanism want, it can be activated against that resident, causing them to be repeatedly ejected and teleported home. This can continue potentially 24 hours a day, preventing the targeted resident from remaining on the land or carrying out normal activities.
The people controlling the mechanism can effectively behave as though they have the power to decide who is allowed to stay, who may enter, and who must leave a land. It can be used as a form of punishment: “If you do not comply, you will be ejected and sent home.”
This distinction is extremely important. The issue is not merely that an object can eject avatars. The issue is that this capability can be deliberately controlled and selectively used against people as a means of intimidation and coercion.
Maestro Linden
updated the status to
under review
I think there's a general issue here that it's difficult to identify objects that are ejecting avatars from a parcel with
llTeleportAgentHome
or similar functions. As we saw in this case, simply sending the name of the object with the ejected agent is not very helpful, since object names are not unique and may change dynamically.
One possible room for improvement is to inform the object owner when a change is made. The
llManageEstateAccess
function does something similar to this when it doesn't have PERMISSION_SILENT_ESTATE_MANAGEMENT - the owner gets a message like this, which includes object name, position, and details of the operation:The object 'llManageEstateAccess test' is removing agent cc7c5f33-b228-4d2b-aaee-70e4f337e240 from the estate ban list. [webRTC1 (129,129,22)]
Devil Mother
Maestro Linden
Feature request: Add object-level identification to avatar ejection events, including the object UUID, owner, position, object name, and affected agent UUID. This should apply consistently across private estates, Mainland parcels, and non-full-region parcels, so land owners and estate managers can quickly identify and remove objects being used for griefing.
And honestly, if it weren't for you, Maestro Linden, I would never have been able to find this object. Your help was what finally allowed me to identify where the problem was coming from.
Could you explain how you were able to locate the object that was responsible for doing this?
Would an ordinary land owner have access to the same information and be able to identify the object using the normal tools available in the viewer, or did you have access to additional tools or information that a regular user would not have?
Maestro Linden
Devil Mother: I had looked at the server logs to see activity related in time to the teleport home events to find it.
But now that we know the attack objects take control over HTTP, the best way to find them is to probably open About Land -> Script Info, then sort by URLs to see objects with >0 URLs, as shown in this screenshot. If you see some object owned by you that you don't recognize and don't believe should be communicating with the outside world, you can return it from that floater.
Photo Viewer
View photos in a modal
Devil Mother
Dear Maestro Linden,
Thank you for helping me understand a serious problem I was facing. Your help allowed me to investigate it properly. At first, I believed this could be a security breach, but I believe it may involve social engineering, griefing, and unauthorized movement of objects between parcels.
Other Brazilian landowners may also be affected.
The residents I currently suspect may be involved are Pedro Alpha and Narutex Belmonte. During my investigation, I also identified two creator names associated with suspicious objects and scripts:
Maanddyss Resident
Maanddys Resident
I am not claiming these names alone prove malicious activity. I believe they are indicators that Linden Lab should investigate through object, asset, account, ownership, and movement history.
The technique appears to involve physical prims or objects ending up on neighboring parcels. These objects may contain scripts or other objects that the legitimate landowner never intentionally placed there. This is dangerous because the object can appear to belong to the landowner, making it seem that the landowner is responsible for ejecting or teleporting residents.
During my investigation, I identified suspicious contents including:
mayhem
New Script – No Copy / No Modify
Object – No Modify
sisay – No Modify
Maanddyss Resident and Maanddys Resident are creators of particular interest, but other creators should also be investigated if they have the same content or behavior.
This caused serious problems for me, including part of my land being returned. I opened support tickets #2551703 and #2541989. At that time, I did not yet understand the full situation.
Maestro, I would be grateful if you could forward this information to the appropriate Trust & Safety, Governance, or security team. Linden Lab may be able to determine whether the same objects or creators appeared on multiple Brazilian lands and identify their asset and movement history.
I am not asking Linden Lab to act against anyone based solely on my accusations. I am asking for the technical evidence to be investigated.
Thank you again, Maestro Linden, for your help and attention. Your assistance allowed me to understand what may have happened to my land. I believe this information could help protect other Brazilian landowners. I can provide screenshots, object names, locations, timestamps, and other evidence if needed.
Devil Mother
URGENT – POSSIBLE COORDINATED MALICIOUS ACTIVITY
I have already filed an in-world report against Mandy (Maanddys Resident) regarding this suspicious activity.
The new evidence raises additional concerns. The screenshot shows Mandy (Maanddys Resident) and Pedro Alpha appearing together in the object information, while other objects associated with my land are also visible.
Based on the evidence and the repeated incidents, I am concerned that Pedro Alpha may be assisting Mandy, including possibly rezzing or placing objects associated with her, or otherwise participating in the same process.
I want Linden Lab to investigate whether these two avatars are coordinating to place or create unauthorized objects on my land, particularly objects that could be used for ejecting residents, forced teleports, or other malicious interference.
I am Devil Mother, the land owner, and I have never authorized Mandy or Pedro Alpha to create, rez, or place such content on my land.
I have already reported Mandy in-world, but the activity appears to be continuing. Please investigate the server-side logs, object creation/rez history, ownership, creator information, and any scripts or Experiences involved.
This may represent coordinated abuse or exploitation of a security/permission mechanism, and I urgently request a technical investigation.
Photo Viewer
View photos in a modal
Lucia Nightfire
Devil Mother
These objects were rezzed by something you were given which you then rezzed or wore. As a land owner, I never rez or wear things over my own land without first inspecting them in a public sandbox, especially if they are from strangers.
Devil Mother
Lucia Nightfire
You're wrong, I've never prayed on those objects or placed those objects inside those objects where some of them appear to me as the owner, and another thing, I've seen those same people able to cross an object to a land even without praying powers, they put the object in physical mode and when it falls on the other side it's as if it were on the next ground with Rezz, please don't say what you don't know, they are griefers and they know very well how to enter objects and attacks in the lands
Devil Mother
I FOUND IT WAS INVISIBLE THIS ONE YOU SAID TO ME AND I WILL DELETE NOW THANKS
Photo Viewer
View photos in a modal
Maestro Linden
Devil Mother: Thanks for confirming that you were able to return the objects.
Devil Mother
The most serious issue is that certain users appear to have the ability to eject residents and force them to return home from parcels where they have no land-owner, estate, or administrative authority.
This is happening every day, across multiple Brazilian lands, including my own. They appear to be able to target and remove any resident they choose, even when the actual land owners have not performed the eject.
Residents and land owners are extremely frustrated and many are already outraged by this situation. We have reported these incidents, filed Abuse Reports, and contacted Live Support, but the behavior continues every day and nothing has stopped it.
Now we are also seeing unauthorized prim creation attempts on our land when we are not creating anything ourselves.
Screenshot 1 shows the repeated system message:
“Cannot create large prims that intersect other residents. Please re-try when other residents have moved.”
Screenshot 2 shows the message:
“The object ‘Void - Demure Lashes (Avalon)’ at Dearheart (170,4,2099) cannot teleport the parcel owner home.”
These incidents strongly suggest that something beyond normal parcel permissions may be allowing these actions.
We urgently need Linden Lab's security/technical team to investigate this at the server level. Please determine how these users are able to eject or send residents home from different lands, create or interfere with objects, and repeatedly perform these actions without the appropriate permissions.
This is happening every day. We have already reported it and contacted Support. We urgently need someone to investigate and stop this.
Photo Viewer
View photos in a modal
Devil Mother
i tried everything to find those objects including creating a script to locate them but i could not find its invisible when i go there
OBJETO 1
UUID: f6c810e1-3d5f-8097-2cf9-d347d2c5abe9
Posição: <211.30110, 79.18565, 2970.01000>
➡ TELEPORTE: Dearheart (211,79,2970)
[20:47] Object:
OBJETO 2
UUID: 6fb3211e-ebe2-f496-9e3a-6cd223b61c52
Posição: <216.43730, 22.19163, 2338.00000>
➡ TELEPORTE: Dearheart (216,22,2338)
if its possible can you show me in world or mark with an object or something so i can return after , i really tried area search and the other way you said and it doenst show the objects
Devil Mother
Hi, thank you for looking into this. I want to clarify what we are experiencing and provide additional evidence.
Incident – Avalon Evergarden
Agent: Avalon Evergarden
Region: Dearheart
Original location: Dearheart, approximately 196, 46, 2338
Date: August 28, 2026
Time: approximately 06:20 AM SLT
Result: Avalon was successfully teleported/ejected home without authorization.
This is not isolated. Residents are being ejected or teleported home by objects with apparently random names, even though those objects do not normally have any eject or teleport-home function.
When they attempt this against me, as the parcel owner, Second Life displays:
“The object 'Void - Demure Lashes (Avalon)' at Dearheart (196,46,2338) cannot teleport the parcel owner home.”
This object is only my cosmetic eyelashes and has no eject function. The system appears to attribute the action to an innocent object, while the real mechanism remains unclear.
My land is in Dearheart:
We believe griefers are exploiting a security vulnerability in the Second Life teleport/eject system. The same behavior appears to affect multiple Brazilian lands and residents, including people with no land, estate, or administrative permissions.
This has been happening repeatedly, essentially 24 hours a day. Linden Lab personnel were present in the region for several hours, and the activity stopped while Governance2 Linden was present. After Governance2 Linden left, the unauthorized ejects/teleports resumed. This suggests the perpetrators are deliberately monitoring and repeating the behavior.
I have already submitted multiple Abuse Reports, opened tickets, contacted Live Support, provided suspected account names, and documented timestamps and viewer messages. The issue remains unresolved.
I am requesting a server-side investigation into who is actually initiating these teleport/eject requests and how they are being triggered without the required permissions. Please review the simulator logs, including llTeleportAgentHome calls, object UUIDs, script owners, initiating agents, timestamps, and request sources.
This appears to be a platform-level security vulnerability being actively exploited across multiple lands, not a normal parcel-management issue. Please escalate this to the Security/Engineering team and investigate urgently.
Photo Viewer
View photos in a modal
Maestro Linden
Devil Mother: Thank you for the details. I see the teleport home events.
Maestro Linden
Devil Mother, Okay, I found the objects. You are the owner of bad objects on the parcel which call llTeleportHome and other parcel management functions based on HTTP commands from the open internet. These same objects can also rename themselves to other names like 'Void - Demure Lashes (Avalon)' - hence the confusion about your unscripted lashes.
Anybody on the internet
may be communicating with the objects to trigger the return. Because you have parcel management permissions in the group, your objects are able to perform the functionsThe objects are currently invisible and named "Object". Here are there details, which I resolved using a basic llGetObjectDetails script:
Object details for f6c810e1-3d5f-8097-2cf9-d347d2c5abe9:
_NAME: Object
_DESC: (No Description)
_POS: <211.301100, 79.185650, 2970.010000>
_ROT: <0.000000, 0.000000, 0.000000, 1.000000>
_VELOCITY: <0.000000, 0.000000, 0.000000>
_OWNER: 9868c3b6-c736-4efc-9e4d-34acf0bd8849
_GROUP: 3a21a118-ab0c-a462-52f4-baab21184335
_CREATOR: 6e1194ca-942f-41df-b57b-2cc502ca9304
Object details for 6fb3211e-ebe2-f496-9e3a-6cd223b61c52:
_NAME: Object
_DESC: (No Description)
_POS: <216.437300, 22.191630, 2338.000000>
_ROT: <0.000000, 0.000000, 0.000000, 1.000000>
_VELOCITY: <0.000000, 0.000000, 0.000000>
_OWNER: 9868c3b6-c736-4efc-9e4d-34acf0bd8849
_GROUP: 3a21a118-ab0c-a462-52f4-baab21184335
_CREATOR: 6e1194ca-942f-41df-b57b-2cc502ca9304
Note that the script inside the object rezzes copies of it, so new objects may be added. I suggest you derez these objects immediately using Build -> Pathfinding -> Region Objects.
Maestro Linden
updated the status to
needs info
Load More
→