Slashdot Mirror


Shadowbane Servers Hacked, Chaos Ensues

Vanguard(DC) writes "There was a major hacking incident last night on the servers of Shadowbane, a newly released MMORPG by UbiSoft/Wolfpack. The attackers wreaked havoc on at least one game server, with apparent god-like capabilities in-game. There's already an official statement on the forums - 'Ubi Soft and Wolfpack Studios are now working with law enforcement, and we promise all of you that these individuals will be prosecuted to the full extent of the law.'" There's a little more information via a post on the SBCatacombs messageboard - apparently the carnage (including many less powerful players getting killed) involved "..teleporting people all over the world, teleporting hostile guards into the safe-holds, bringing in hordes of special event monsters, and teleporting everyone to a city at the bottom of the sea."

22 of 773 comments (clear)

  1. Re:game world != real world... by no+reason+to+be+here · · Score: 5, Interesting

    why should anyone that found a way to compromise security for a game be prosecuted in real life?!
    if that will happen, then WHO will take responsibility for all the holes in Windows?!

    well, not exactly. they're not going after the people for breaking into a game, but for breaking into a server. Nor are they going after the people responsible for the lousy security on their servers (as your windows comment might suggest), but rather the ones responsible for exploiting that lousy security. This is pretty much standard in the real world. I break into a system, I get caught, I get prosecuted.

  2. unfortunately this is par for the course by agrounds · · Score: 5, Interesting

    For those of us that have been playing this game regularly, this is only the icing on the cake for a plague of problems. This was a game that was touted for it's massive guild vs guild and player vs player capabilities. Massive warfronts and assaults utilizing seige weapons and a slew of powerful spells and powers. None of this has come to pass. The game lag is too terrible to support even the smallest of battles. PvP is almost impossible during primetime hours due to the inability of most casters to launch spells in a timely manner. (Although you -can- watch your nukes launch 45 seconds after your death)

    Server downtime is extreme. Login is at times completely impossible. Rollbacks are nightly. The attrition rate among players is amazing. I've watched my guild vanish over the last few weeks as the host of problems drive out all but the most staunch of players. Ubi/Wolfpack blatantly reject petitions with no regard or consideration for the players. Every patch makes the client actually worse that it was before. This has been a nightmare for most of us. To see news like this only confirms the worst. Bad management, bad hosting, bad coding, and bad customer care have driven most from what I considered to be one of the better games to come out this spring. Just another account cancelled in a long line of departing players.

    1. Re:unfortunately this is par for the course by Graff · · Score: 4, Interesting
      AFAIK, every server has had at least one battle that would put some of EQ's big raids to shame.

      Perhaps so but with pretty much every one of those big battles you have more than 1/2 the participants either lagged to death or forced out of the game due to client or server crashes. It happens just about every time there is a battle of 50+ people.

      It is not a matter of having a good computer or connection. The servers themselves start to lag in big battles. There have been many times when I've been on a completely different continent and I've heard of a big raid on a city. Sure enough the server lags horribly just about then and sometimes even crashes. Now maybe on some of the less populated servers this is not as evident but I played on Deception, which is one of the top 3 most populated of the servers.

      Not only that but the client sucks too. I'm on a computer that handles Unreal Tournament 2003 at over 50 fps with all the eye candy turned up and in huge fights. The graphics of Shadowbane don't even come close to comparing to UT2003 and they barely pass 40 fps when nothing is going on. If I wander into a city with lots of walls, people, and other objects then the frame rates drop into the teens even with all the graphics turned down. Make this a huge battle and many people start getting 1 frame every few seconds. There are some pretty substantial memory leaks and so the game starts to lag even harder once it exhausts your physical RAM and begins to need to page to disk. On top of all of this the client crashes randomly and often.

      The kicker is that once you crash or need to re-log into the game due to the buggy client you will often need to try to get back in for 1/2 hour or more because the login servers are horrible. God forbid that more than a few dozen people need to log in at once, you could be there all night trying to get back into the game. A typical night of playing Shadowbane would be: sit down at computer and attempt to log in, 1/2 hour later get to character selection screen, select character and wait 15 more minutes to get on the game server, play for an hour and then get bumped out of game for some odd reason, rinse and repeat.

      I know that I'm not alone in this because there have been droves of people leaving for pretty much the same reasons I've stated here. Just look at the message boards and you'll see plenty of people saying the same thing I just have.

      I'm not going to even get into the gameplay issues such as amount of farming needed to support a city, unbalanced classes, missing game features, horrible interfaces, lack of content, game exploits, the hard "soft" cap of level 60, the extreme tendency of servers developing uber-guilds that make it nearly impossible to have more than 1 major nation per server, etc.
    2. Re:unfortunately this is par for the course by Lightwarrior · · Score: 2, Interesting

      > ...with pretty much every one of those big battles you have more than 1/2 the participants either lagged to death or forced out of the game due to client or server crashes.

      I've crashed a few times in biiig raids (100+ / side). I've gotten low framerates, but I lean towards IQ over FPS. Hell, I've even been on when the server has gone down for a reboot.

      But saying that it happens most of the time when battles involve > 50 people is silly. That might be true on your server - I don't have any characters on Deception - but it's simply not true on Dread.

      Maybe try turning the System channel off? That's one thing I hope they implement soon, server-side message filters.

      > The servers themselves start to lag in big battles.

      There have been some large-scale assualts that I wasn't a part of, and I noticed nothing of the sort.

      > UT2003

      What's the largest number of people you've played against on an UT2k3 server? 32? How about the map size? Either of those come close to the number of players on a Shadowbane server (1k+) or the size of their world? Hell, even the largest-scale of these games - Battlefield 1942 with 60 people - just can't compare in scope.

      I hate it when people bring up random benchmarks with no statistical information. Is 50 your max? Average? Are you running FRAPS, did you save replays to disk and analyze those? Is this a number you took off the top of your head? What resolution are you running? What OS? What's the speed of your process, your motherboard's model number, your video card? What drivers are you running? And that's just the tip of the iceberg.

      I don't find Shadowbane to exhibit the same functionality as you. I've got an AthXP 1300+, Asus A7V266, 2x256mb crucial PC2100 (NOT enough for XP, got a 512 stick on the way), a Radeon 8500 retail running @ 285/285 and the 2.4 Catalysts, all under WinXP Pro SP 1 with dx9a. I've also got XP installed on an old 2gb ata33 drive, and SB on a 80gb WD on the same chain (yeah, stupid, but I haven't accepted XP yet). And I STILL don't experience the problems you're having. Sure, I drop terrain detail, texture detail, spell effects, and terrain size down to zero during big raids, but I'd be playing AC2 if I only wanted eye candy.

      Your Shadowbane experiences have been sub-standard, and I greatly question the quality and stability of your computer (if your accusations are true).

      Typically for me, from pressing "Play to->Crush" to taking my first couple steps takes less than 10 minutes - probably closer to 5. Are you *SURE* you don't have some horrible loading problem? Bad RAM, less than 100mb free space, slow CPU, old motherboard? 45 minutes is about the maximum amount of time it's ever taken me to get into the game when the login servers were up.

      > ...there have been droves of people leaving...

      Droves? Check the message boards? I'm a bit of a board warrior (like you couldn't have guessed, I do post on /.), and I don't recall anything resembling 'droves' of comments about actual cancelled accounts. Complaints aren't the same, you know. Even so, 50 posts stating "I'm quitting" may look like a lot on the boards, but amounts to a tiny portion of the population.

      > gameplay issues

      Aw, hell, while we're here, why not? Gold is needed to support a city. There are no other resources. Since the purpose of this game is GvG / siege warfare, would you prefer to be out cutting wood, hewing stone, and fashioning them into usuable materials? I'd rather kill a few mobs and get XP + the chance for a nice drop, myself. Free cities = stupid.

      Casters + Shields = stupid, that's first on my list of complaints. Missing game features? Like what? Server travel? I'm thrilled there's no server travel, it gives us time to prepare for Ebonlore and R30s, etc. The interface is skinnable, get a clue. Lack of content? I'm confused here; do you mean there's not a rich

      --
      Mods: Disagreeing with me != my post Offtopic / Flamebait.
      World without hate or war, invaded. Tragic?
  3. It's The End !!! by da5idnetlimit.com · · Score: 4, Interesting

    Armaggedon !!!

    Gosh, I do Hope the poor admin had regular backups 8)

    Well, the game was trashed by people that took the time to get WELL into the system before trashing the hell out of it.

    Like an "Organized" Attack...

    I'm not implying anything, but who gets benefits from this ? Competitors ?

    From the forums it seems users are quite unhappy, but then possibly the editor will have another chance, and deply the same "anti-cheat" tech as in Counter Strike and Quake...

    --
    It takes 40+ muscles to frown, but only four to extend your arm and bitchslap the motherfucker
  4. If everything is in game then deal with it there. by Mick+D. · · Score: 4, Interesting

    If they only screwed around in the game world itself and left the real world alone (eg. credit cards, account data, etc) then the company should do the same. From the sound of it, they just showed that 'there is no spoon' to the rest of the game world. We love the movie and the character for doing so, but when someone does the same thing in a 'Real Life' virtual world then they get mad.

    Man, this world is getting WAY too many levels to it when I have to destinguish the 'real world's' game world, and the movie world's game world and doing 'real' things in a particular game world and...Ah my brain just gave up.

    --

    Is this the end yet?...How 'bout now...how 'bout now...how 'bout now?
  5. Re:I just can't get mad about this one... by cliffiecee · · Score: 2, Interesting

    I remember reading a book about the history of computers... seems the old PDP computers had a 'crash' command that did exactly that. The reason it existed was to discourage hackers from trying to crash the PDP- why write a program like that when the command already exists?

    So why don't game companies build this type of feature into their games? Choose a random person maybe once a week and let them stir things up a bit; and don't 'record' any of the damage that was
    done (sorta like a parallel universe).

    Even if someone hacks into this feature, all they'll do is cause temporary damage. Then all the other players can just roll their eyes and laugh derisively at the 'K3WL H4XX0R', and get on with their gaming after the idiot gets smacked down.

  6. Re:law? by WPIDalamar · · Score: 5, Interesting

    Acutally... that's kind of insightful.

    Ubisoft is calling it a hack, of course they will to save face... but what if it's just a bug or flaw in the game. What if they did all this through the game client? Is exploiting one of these flaws in a game against the law?

    What if I'm playing EQ, and I find a spot in a zone where mobs can't get to. Then I kill things from there. I'm exploiting a bug to become more powerful. Is that the same?

    What if I'm playing, and find out if I crouch and jump at the same time I can kill anyone I want? It's obviously cheating, but is it ILLEGAL for me to exploit that?

    What if these guys found out if you hit the Ctrl-alt-f3-f4 keys while running north gave them these powers? Then is what they did illegal?

    What if these guys used a special piece of software that ran the game in a special mode? Is that illegal? I mean, EVERYONE uses software (your OS) to run the game in a "special" mode (namely, a mode that works properly). Is this worse than exploiting the bug through the normal game interface?

    Is this only a problem because is affected other people?

    (Remember... big difference between illegal, immoral, and just plain annoying)

  7. The EverQuest "Mass-Kill" - Yes, it happened! by Blackwulf · · Score: 4, Interesting

    I was a Guide (volunteer CS rep, like an Advisor in Anarchy Online or a Counselor in Ultima Online) for two years in EverQuest, and during that time, one of the other Guides on one of the other servers decided that it would be cool to go out with a bang.

    So, she zoned into the Temple of Veeshan (at that time, the highest level zone in the game) and went right in front of Veeshan herself (the uber dragon.)

    And then she did a "/who all 50-60" to get all of the high level players on the server.

    Then she started /summoning them to her location, and then binding them to that location when they appeared.

    Well, when they appeared, Veeshan struck them down with about 2 or 3 blows. And since they were just bound there, they respawned, naked, right in front of Veeshan.

    Whack, boom, dead. Reappear, whack, boom, dead.

    In EverQuest, when you die, you lose experience. And in EverQuest, you can lose levels if your experience dips down too low.

    Some people got deleveled from level 58 to level 53 before the GM staff came in to clear the carnage, and ban the Guide. I know they were considering persecution against this Guide, but I'm not sure if they really went through with it or not.

    I believe about 25-30 high-level characters with months of /played time were affected.

    I thought it was funny, but it sure made my job as a Guide harder because the playerbase no longer trusted us to keep our cool, and they were calling for the entire Guide program to be disbanded since we were now "too powerful" all of a sudden.

    Not the same as hacking the server, but it had the same effect of destroying the games of a segment of the playerbase.

  8. Every MMORPG learns the same lessons by Speare · · Score: 5, Interesting
    Every time I see a new MMORPG, I am saddened to see that the designers don't learn the well-publicized lessons of their predecessors and competition.

    Never trust anything a client gives the server.

    Isolate the backend servers from the Internet.

    Never trust anything a client gives the server.

    Patch management isn't as trivial as one would think.

    Never trust anything a client gives the server.

    Lag isn't under your control so design around it.

    Don't rely on a client hiding anything from the user.

    Lag isn't under your control so design around it.

    Never trust anything a client gives the server.

    Don't include "God" tools in every client, nor accept God logins from untrusted addresses.

    And most of all, never trust anything a client gives the server.

    The server must be the adjudicator of everything, the data master, the sole arbiter of discrepancies. Assume the client is fully hacked or written from scratch to do anything the user wants. Assume the client sees no walls, sees all invisible objects, sees every spawn point, and can filter on anything your server tells your client.

    --
    [ .sig file not found ]
  9. Re:game world != real world... by jackb_guppy · · Score: 3, Interesting

    And if the "break-in" was not really a server break-in but a software bug that allow a player to become GOD?

    Like an undocumented bit/byte pattern in the interface.

    Anyone remember the the undocumented instructions in 8085? or the Z-80? or IBM Midranges?

  10. Why do people pay for MMPORPG Betas? by cgenman · · Score: 5, Interesting

    The computer game industry has been earning a reputation for releasing buggy code these past few years, and now it has come to a situation where what should be an internal release now costs money. Unlike retail games where occasionally Beta testers are charged, but given the full retail game later, Beta testers on MMPORPG's are not given additional months of play for the priviledge of paying to be guinea pigs. They are not compensated with reduced pay rates or additional in-game powers. In short, they pay to fill a necessary position in the production cycle, then they pay again for the retail product. Many, of course, don't pay for the retail product, and go on diatribes about how unplayable and unbalanced the game (they paid for) is.

    How has it gotten so bad that we now release not only buggy games and expect to patch them later, but charge for development releases in addition to charging for final retail releases? We're giving ourselves a bad name here.

    If your game is unfinished but in need of stress testing, don't charge for it or you will alienate your potential best customers. If you *must* charge for bandwidth because your manager didn't budget for such costs (and should be rightly as fired as if s/he forgot to budget for artists), then charge a bare minimum until the game is ready for prime time. Don't develop the game on the dime of your testers, or you will find that once you are ready to ship you don't have any customers.

    10 dollars a month for our volunteers to do our jobs? We should be ashamed.

  11. Different zone, different dragon - I'm stupid. by Blackwulf · · Score: 4, Interesting

    As several replies have pointed out, I got the wrong zone and the wrong dragon.

    The zone was Veeshan's Peak (the Luclin expansion with ToV was not out) and the dragon was whoever the end of it was.

    People can still believe I'm full of shit, but I did find this:

    Former Guide Tweety mentioning the incident

    WEEKLY UPDATE: 11/22/00 - The Guide of Veeshan's Peak

    I wanted to post yesterday, about the guide who went bananas on the TT server. I wanted to, I really did. But what's the point in posting if the sum total of your reaction is:

    BWHAHAHAHAHAHAHA!

    Put the unlicensed handguns away, it's not that I don't feel sorry for the innocent victims. There were probably several harmless bystanders who got whooshed into a really BIG dragon's ass, and those people didn't deserve to lose the three weeks that it took them to earn their four lousy pixels of experience. I hope that Verant has as promised checked the logs and restored all the folks involved to their previous levels of exp. If they don't, well, don't bother calling the paramedics because I sure won't have a heart attack over the shock of Verant being too pathetic to touch their testicles AND provide customer service.

    Remember my little rant entitled "Try Being a Guide"? The ONLY reason I typed a rant instead of hauling some d00ds into VP was because I'm just a big mush ball at heart. I kept thinking that maybe Mr. 58th Level Douchebag had just had a bad day when he was ripping into me. Maybe he didn't really MEAN to call me names and tell me how stupid I was. Remember, I'm the big fan of thinking of the fellow behind the keyboard when it comes to actual interaction - I try to always keep in mind that I don't know the kind of day the other guy is having.

    I was also afraid that if I tried that summoning trick, I'd accidentally summon "Pimps," who hadn't ever talked to me, instead of "Pimpz," the intended recipient. Mistakes like that happen, and I didn't want to make one.

    But I'll bet you a million dollars that at least half the people still picking dragon teeth out of their asses were the sort of people who said, "fuk you d00d, Ive done this 4 ever, its not an xpl0it" and "wtf u mean u wont rezz me, it's a fucking bug, you stupid twat."

    Oh, and yes, it does sound EXACTLY like a normal "event," except that the guide should have convinced someone to let him become a dragon to prevent the players from losing exp (clue alert - a guide-controlled NPC NEVER takes experience from you when he kills you). That's what good little guides do when they want to kill players.

  12. Re:I just can't get mad about this one... by mcspock · · Score: 1, Interesting

    That was my thought too. When the Matrix Online comes out, this will give a whole new meaning to 'hacking the matrix'

    --
    -- Patience is a virtue, but impatience is an art.
  13. moot by Kirby-meister · · Score: 2, Interesting
    While I agree the security measures taken by Ubi were probably pretty poor, it does not mean the hackers aren't liable for damages they caused.

    The difference between your car exploding tale and this is that the people who "crashed into you" (ie hacked the server) knew what was going to happen.

    If I were to spot one of the cars you mentioned, and blatantly crash into it only because I knew the gas tank would explode, I would have some liability in what I have done. Likewise, the hackers knew what was going to happen when they hacked the server and (comically, I might add - hackers tend to have a sense of humor) teleport everybody to the sea.

    There's a difference in accidentally causing someone's "car" to "explode" and purposely causing it.

  14. Every April Fool's Day by johnjay · · Score: 2, Interesting

    What if a MMORPG did this every April Fool's day? Then, on April 2nd, the admins could restore the March 31st backup and the game would continue as normal. The people who wanted to be part of WRATH OF GOD day could log on and those who didn't like the idea would stay away.

    It would be like being on the receiving end of a SimCity disaster.

  15. Someone to Dethrone Rainz by screwballicus · · Score: 2, Interesting

    For further information on events as they happen, check The Shadowbane Scorn Server Board and Shadowbane Main Boards on IGN.

    I think this will remind a lot of people of the last time a player had a truly drastic and unpredictable effect on an MMORPG gameworld, when Rainz, an Ultima Online Player, killed Lord British, character of Richard Garriott, when this was supposed to be impossible.

    Rainz threw a firewall scroll at Lord British. Seemingly, Lord British's invulnverability flag was not on, and Rainz killed him.

    If we ever figure out exactly who did this, he'll be in the running with Rainz for most notorious MMORPGer of all time.

  16. Re:because it's just a fucking game by syukton · · Score: 2, Interesting

    This has nothing to do with misplaced orcs. This has to do with an invasion of private property, known as "hacking" or "criminal trespass" or even under the Homeland Security act, "cyber terrorism" ... Who knows what trade secrets they stole about the game engine or server or network or security or etc while they were inside of the system? So in reality, it could be both criminal cyber-tresspass and theft. Also harassment... also..... C'mon, use your frickin' head.

    This isn't "just a fucking game"; It's a business. When a serious security flaw is discovered in an application and that flaw is made public knowledge, the application publisher's reputation takes a beating--as does its' stock. Not to mention the loss of investor confidence and the loss of the customer base and etc. Most pay-for-play subscription based MMORPGs rely upon recurring income; even if only 10% of their customers say "fuck this" in response to this hack, that's 10% of their recurring income down the drain.

    The players have no recourse. For them, yes, it is just a game. The admins can roll everything back 24 hours and let the players play on. On the business side of things though, it's much more complicated; for the reasons outlined above.

    --
    Reinvent the wheel only at either a lower cost, greater effectiveness, or your own personal enrichment and satisfaction.
  17. Re:Wow... by Arkhan · · Score: 3, Interesting


    >Or consider the result of walking up to folk playing chess in the park and overturning the board.

    >In each case, legal action is both warranted and acceptable.

    IANAL. This is a genuine question.

    Can either criminal charges or a civil suit really be brought against you for overturning someone's chess board in a public location? Sure you're a jerk, but what law did you break?

    How would you be charged or for what would you be sued?

  18. A great idea by chainsaw1 · · Score: 3, Interesting

    You just need to take it a bit further...

    Supposed you have a game & server concept similar to this, but programmed in a way to not take game security dead-serious. In fact, as the cheats, etc. came out this would not be shunned, but instead part of the game. The people with the best cheats take the cake, can gather clanmates and share what they know. Your clan is then defined by the abilities they have aquired through manipulation of the game workings (in addition to the standard tags, skins, etc.)

    I'm sure you could develop a program in a way to separate out abilities (such as speed, gravity, damage types) such that any crack wouldn't give up everything else

    Which brings on two negative points:

    -It sure wouldn't be appealing to newbies, who start on ground zero

    -Anyone who successfully gets full access ("GOD")
    may be unsurpassable and ruin the game for everyone. This can be overcome by having the game focus include things other than Power by Might (i.e. killing sprees), such as trade, etc.

    If there ever was a prime canidate for an open-source friendly game, this concept would be it :)

    --
    - Sig
  19. Re:Forcing him to quit is a bad idea by sw155kn1f3 · · Score: 2, Interesting

    Actually you had no choice - probably something was so disturbing for you in those years that you better addicted to game and escape a real world than get some very bad things to your mind.
    Addictions won't grow without some seed - you just quickly become bored, and that's all.
    That's just some thoughts i came to analyzing my own habits (IANA psychoanalyst).
    Anyway - that's a part of your life - live with it, and nowhere near it's because of thet stupid game.

    --
    - Arwen, I'm your father, Agent Smith.
    - Well, you're just Smith, but my father is Aerosmith!
  20. Servers not hacked... by Anonymous Coward · · Score: 1, Interesting

    The servers were not hacked like some slashdotters tend to think, it's clearly an INGAME exploit that happened last night.

    IMHO, in the case of an hacked servers, the result would be more like character loss, or character boost, stuff would tend to disappear/appear.

    In that case yesterday, it was clear that someone was in control ingame... God, you should have seen that...

    I heard rumors that some guild had produced a modified client that would allow them to do that kind of stuff...

    That situation is more scary since it might take longer to fix if the problem lies in the code than it would take if the issue was an exploit of ssh or such...