Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Maple Security
#1
For my paper in my security class, I've decided to write about security in online games (possibly focusing exclusively on Maple, not sure about that yet). I'd like help in creating a list of security-related events (hacking epidemics, glitches like bigfoot and glitch opq, etc) that have occurred, the approximate date or time period they occurred, and, if possible, a high-level overview of how the security hole was exploited.

Mods, remove the specific information if you think it crosses the line.

Please correct any factual errors.

Guild hack - Around 5/20/08 - An attacker was able to kick any person from a guild without even needing to be in the guild because the server didn't do an authorization check

PG hack - 3/7/08 to 3/20/08 (??) - Power Guard skill was exploited by people who didn't necessarily even have the skill to do enormous amounts of damage. The hack was made public, and the exploit involved sending large numbers of packets, effectively DDoS'ing the game by greatly slowing down server response time.

Combination of several security holes:
- powerguard damage reflection
- invincibility (take no actual damage to player)
- stance (not knocked back by hits)
- vacuum (monsters go to player, only client sided)
- fast hit (normally it's about 1 second between taking damage, they reduced it to near 0)
- monster damage hack (monsters could do any damage the hacker wanted)

Bigfoot glitch - Beginning of CWK patch (8/16/08?) to ??? - Bigfoot was released without the boss flag on, possibly intentionally to allow for unique strategies. This also made it poisonable and shadow webbable, allowing f/p mages and hermits to gain experience at ridiculous rates. Playtesting on a test server could probably have brought attention to the oversight.

Glitch opq - ??? to ??? - ???

Various types of vacs - editing memory(?)

Private servers

PQ smuggling

Heal hacking - editing game data files

Diamond glitch - Do part of a quest to get exp, restart it

autoclickers


Thanks in advance!
Reply
#2
BF was also demonable i think
Reply
#3
Holypie Wrote:BF was also demonable i think

has nothing to do with the security of maple, though.

You should include the time a guy managed to get into a GM's account and terminated e.g. top player (rip our little 100+ cleric)

And what about the fuzz where MapleSEA accounts were hacked from China?
Reply
#4
I have a SS from March 7th of PG Hack, and I believe it was stopped during the server check of March 20th.

I'm guessing that the 7th was near the start of it (Maybe somebody else has an earlier record of it?) because it wasn't really known then.
Reply
#5
Is this just GMS, or does MapleSEA count as well?
Reply
#6
If you're going to add that to a more official paper, you should know that there is a difference between a glitch and a bug. Most people today use the term glich when they actually should have used the term bug.

In short:
- Glitch -> An error that incidently happens (not all the time)
- Bug -> An error that keeps happening all the time

For example, the whole BigFoot thing, was in fact a bug, since the "error" was hardcoded in the maplestory sourcecode and could be repeated time after time. Smile
Reply
#7
The powerguard hack combined several things
- powerguard damage reflection
- invincibility (take no actual damage to player)
- stance (not knocked back by hits)
- vacuum (monsters go to player, only client sided)
- fast hit (normally it's about 1 second between taking damage, they reduced it to near 0)
- monster damage hack (monsters could do any damage the hacker wanted)


Pretty impressive set of holes, really...
Reply
#8
unless specifically asked for, i dont think you need an exact date. just approximates (months). since its a paper, cite valid sources. it proves you arent make stuff up.
Reply
#9
There was one incident (guild hack to be precise) to which I remember hearing stories on behind-the-scenes. Specifics aside, the original hack developer, who proved to be way too smart for Nexon, didn't intend for one of his friends to betray his trust, and the friend started being a total douche to the rest of MapleStory. In an effort to stem the damage, the developer emailed Nexon the source code and instructions on how to patch the hack.

Guess what happened?

Nexon phails yet again. I think their excuse for not acting on this information was that "it wasn't important".
Reply
#10
KajitiSouls Wrote:There was one incident (guild hack to be precise) to which I remember hearing stories on behind-the-scenes. Specifics aside, the original hack developer, who proved to be way too smart for Nexon, didn't intend for one of his friends to betray his trust, and the friend started being a total douche to the rest of MapleStory. In an effort to stem the damage, the developer emailed Nexon the source code and instructions on how to patch the hack.

Guess what happened?

Nexon phails yet again. I think their excuse for not acting on this information was that "it wasn't important".

I heard this on a number of occasions. That people have found an exploit, let nexon know about it only for nothing to happen. First few times I heard it, I assumed it was hearsay, etc. But then I started hearing it from people who know how to code...
Reply
#11
Devil Wrote:If you're going to add that to a more official paper, you should know that there is a difference between a glitch and a bug. Most people today use the term glich when they actually should have used the term bug.

In short:
- Glitch -> An error that incidently happens (not all the time)
- Bug -> An error that keeps happening all the time

For example, the whole BigFoot thing, was in fact a bug, since the "error" was hardcoded in the maplestory sourcecode and could be repeated time after time. Smile

Nexon uses the term glitch for playing in a way not intended by the creators by abusing flaws in the game, which is not intended by the creators. [1] Nexon mix around on these sometimes though...

A bug is rather a flaw in the game, but it does not give anyone advantages if abused.[1]
Reply
#12
I dont really see the bigfoot glitch (or whatever) as being a security concern because it wasn't manipulated by an outside force -- purely nexon not testing new content

unless you wanna take it a step further and talk about the false bannings as a reaction to the bigfoot glitch -- however this would also be nexon incompetence rather then outside forces -- faulty security measures

vac hacks

a/c which are still prevelant

"flying" hacks -- saw one last night actually

the fame hacks -- dont know if that got patched or not

was there a dc hack -- or was that related to auto-clicking -- where they would spam you til you dc'd

o and duping -- cant forget about that -- no clue on a timeline for that -- think it was before my time

all i can think of off the top of my head

edit: cant forget about pservers -- reverse engineering -- all that good stuff --

to a lesser extent even fiels extractor -- bypasses security measures and has been in use now for a long time

2nd edit -- smuggling -- also still prevelant -- try making a party in hene pq w/o a smuggler and watch everyone leave

if you are going with glitches then dont forget about the diamond glitch

idk if any of this is even helping so im gonna stop for now as ive started just listing the various hacks and im not sure if you need more specifics or not -- im pretty sure the ave mapler could have formed this list
Reply
#13
For the purposes of my paper, bigfoot was a security issue because it damaged one of Nexon's assets (player perception of a fair game, especially with regards to the yellonde contest and with yellonde being a new server).

Some definitions straight from my notes from the class: Vulnerability: A system attribute that can be exploited to produce a threat to an asset

Asset: Something you care about

Threat: Something bad that can happen to an asset

Attack: A series of steps designed to exploit a vulnerability

A short summary of the attack would be nice. Stereo's for PG hack was excellent.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)