Critical Vulnerabilities In Call of Duty: Modern Warfare 3, CryEngine 3
hypnosec writes with news that two security consultants have found vulnerabilities in Call of Duty: Modern Warfare 3 and the CryEngine 3 graphics engine that could harm game makers and players alike. Presenting at the Power of Community (POC2012) security conference, the researchers demonstrated how a denial-of-service attack could affect Modern Warfare 3, and how a server-level attack on CryEngine 3 allowed them to "create a remote shell on a game-player's computer."
"'Once you get access to the server, which is basically the interface with the company, you can get access to all of the information on the players through the server,' Ferrante said. In general, game companies don't seem to be very focused on security but rather on performance of the game itself, Ferrante said. Adding security checks can slow down games, and if the companies don't deem the problem a very critical issue, it will usually be ignored. 'These are games that have a very large market,' Auriemma said."
Well of course they care only about performance Its all their user base really cares about.
Imagine a beowolf.... where am I?
If there only was a way to remedy this problem, a "patch" if you will.
post the video or it didnt happen
The game makes can install arbitrary code on the user's computer anyways by way of updates. (Anybody remember Sony's root-kit?). A remote shell is therefore trivial to implement.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Well of course they care only about performance Its all their user base really cares about.
To be fair...nobody is interested in security until things go wrong, they will and they do. Then its look for a scapegoat, and the solution is to remove rights and privacy of the individual for the illusion protection, throw in a few laws, that only affect the law abiding and decent. Then we live in fear.
I have to do triple double or level security passes, including a one time security token, to get into quite a few MMOs. They had to; many RMT organizations made a profit hacking and looting accounts by using keyloggers to obtain passwords.
Occasionally living proof of the Ballmer peak.
Wouldn't the rest of the series down to the original COD also be affected?
... by you know having LAN and private servers again so hacks don't take down the community. Security wouldn't be an issue for Diablo 3 if you could play the fucking game offline. But corporate greed and the dumb masses that feed the move to "online only" games this will become more frequent.
On Tuesday the patch for MW3 will be released. Some know it as Black Ops II but it will practically ensure that nobody is left playing MW3.
Isn't there an exploit in the CoD4 dedicated server that allowed easy DDoS'ing? The last patch for CoD4 (on PC anyway) was back in June of 2008. I doubt they'll patch any expolit, unless it's the current game. Hell, I even doubt that.
They pretty much are. Some of these exploits have existed since the original id Tech 3 engine, from which Modern Warfare 3's engine is originally based. I've been using Luigi's proof of concept tools to do testing on old id Tech 3 engine games that I used to host servers on for years. With his advice I was able to work around certain problems, but not all of them.
I am not sure how bad the vulnerabilities have become, but back then it was generally buffer overflow exploits that allowed player clients to be crashed, servers to be crashed or even the master server to be crashed. There weren't any exploits that I would consider critical, but they were highly annoying.
The common will always serve the main. Please continue to serve up your shiny hardware for use, as if you even had a clue to what it means to open up ports to arbitrary root level apps. Bitches.
This isn't about getting access to information through logging into an account, but abusing a wide back door that many people have to gather more personal information than even a MMO may have.
Anyone know if the Dunia codebase forked from CryEngine before or after this vulnerability was introduced? I'd really like to enjoy some FarCry 3 during my year end holiday but I'd prefer not to get hacked.
HA! This is yet another piece of proof that consoles are better! NAH NAH :-)~ :) Go ahead, hack my console. Whatyagonnado? Jack up my Skyrim campaign. *Feigned Horror Scary Face* :O
Either way, its client server model hacking practice.
Most malicious hackers start out by breaking online games because it's easy to make a name for yourself in a game community when you're feeding everyone free hacks. Also, games can have the best of security for you to practice breaking. I've seen games that are not only protected by an anti-hack/debugger program, but also encrypted and run totally in a Themida VM. Have fun breaking that shit. If you do, you could probably get a job in security fairly easily.
captcha was "shelled" thought that was funny.
It's so quaint they think anyone cares.
Luigi Auriemma doesn't play the security researcher game properly, doesn't notify the software vendors about security issues, he just releases them. Often he releases them right after a patch has been released, and then claim that the vendor still hasn't fix the issues.
You will have to pay our software or you will get all of your computers cracked to the bones. We made sure that a hole was there for that matters. After all if a customer's computer gets penetrated, that's ... collateral damage. Besides you all accepted no guarantees when you purchased and you are the only ones who are going to suffer the consequences of our actions. So who cares :).
The MW3 Staff
Vulnerable to hacks indeed. WELL... if these Call of Duty Black Ops server thingies have become a problem, a way to hurt people I say maybe we should call it a day and just shut them down.
'Cause we don't want to hurt people now do we.
Do we??
<blink>down the rabbit hole</blink>
Hello!! Fashion,low price,the good shopping places, Cheap wholesale and retail Gucci/Shoes $45, ( Discount UGG/Boots ) LV Shoes $46, DG Shoes $46, BURBERRY Shoes $46, LACOSTE Shoes $46, Women Boots $55, handbags(Coach lv fendi d&g/Gucci) $39, Sunglasses(Oakey,coach/Gucci,Armaini) $25, free shipping and quantity discount, Accept credit card and PAYPAL ==== http://www.cbssbase.com/ ==== ==== http://www.cbssbase.com/ ====