For my paper in my security class, I've decided to write about security in online games (possibly focusing exclusively on Maple, not sure about that yet). I'd like help in creating a list of security-related events (hacking epidemics, glitches like bigfoot and glitch opq, etc) that have occurred, the approximate date or time period they occurred, and, if possible, a high-level overview of how the security hole was exploited.
Mods, remove the specific information if you think it crosses the line.
Please correct any factual errors.
Guild hack - Around 5/20/08 - An attacker was able to kick any person from a guild without even needing to be in the guild because the server didn't do an authorization check
PG hack - 3/7/08 to 3/20/08 (??) - Power Guard skill was exploited by people who didn't necessarily even have the skill to do enormous amounts of damage. The hack was made public, and the exploit involved sending large numbers of packets, effectively DDoS'ing the game by greatly slowing down server response time.
Combination of several security holes:
- powerguard damage reflection
- invincibility (take no actual damage to player)
- stance (not knocked back by hits)
- vacuum (monsters go to player, only client sided)
- fast hit (normally it's about 1 second between taking damage, they reduced it to near 0)
- monster damage hack (monsters could do any damage the hacker wanted)
Bigfoot glitch - Beginning of CWK patch (8/16/08?) to ??? - Bigfoot was released without the boss flag on, possibly intentionally to allow for unique strategies. This also made it poisonable and shadow webbable, allowing f/p mages and hermits to gain experience at ridiculous rates. Playtesting on a test server could probably have brought attention to the oversight.
Glitch opq - ??? to ??? - ???
Various types of vacs - editing memory(?)
Private servers
PQ smuggling
Heal hacking - editing game data files
Diamond glitch - Do part of a quest to get exp, restart it
autoclickers
Thanks in advance!
Mods, remove the specific information if you think it crosses the line.
Please correct any factual errors.
Guild hack - Around 5/20/08 - An attacker was able to kick any person from a guild without even needing to be in the guild because the server didn't do an authorization check
PG hack - 3/7/08 to 3/20/08 (??) - Power Guard skill was exploited by people who didn't necessarily even have the skill to do enormous amounts of damage. The hack was made public, and the exploit involved sending large numbers of packets, effectively DDoS'ing the game by greatly slowing down server response time.
Combination of several security holes:
- powerguard damage reflection
- invincibility (take no actual damage to player)
- stance (not knocked back by hits)
- vacuum (monsters go to player, only client sided)
- fast hit (normally it's about 1 second between taking damage, they reduced it to near 0)
- monster damage hack (monsters could do any damage the hacker wanted)
Bigfoot glitch - Beginning of CWK patch (8/16/08?) to ??? - Bigfoot was released without the boss flag on, possibly intentionally to allow for unique strategies. This also made it poisonable and shadow webbable, allowing f/p mages and hermits to gain experience at ridiculous rates. Playtesting on a test server could probably have brought attention to the oversight.
Glitch opq - ??? to ??? - ???
Various types of vacs - editing memory(?)
Private servers
PQ smuggling
Heal hacking - editing game data files
Diamond glitch - Do part of a quest to get exp, restart it
autoclickers
Thanks in advance!

