| Mail |
You might also like: WoW Insider, Joystiq, and more

Reader Comments (14)

Posted: Feb 1st 2011 2:17PM cforciea said

  • 3 hearts
  • Report
The depressing thing is how fundamental a lack of basic design this demonstrates. We learned a long time ago that if you want players to not cheat on your game, you have to assume that all traffic coming from the client is suspect and perform every meaningful calculation possible on the server. There shouldn't have been a packet to forge at all.

Posted: Feb 1st 2011 4:23PM Scuffles said

  • 2 hearts
  • Report
Or at the very least it would have been smart to have any attack that registers as a negative number resolve as either one or zero dmg.

Regardless it was poor design, you have to assume that some of your users are going to try to exploit something and you need to outflank them.

Step 1) Think of a cool idea that you could implement in the game
Step 2) Think of ways people could potentially explode said coolness
Step 3) Deal with said exploits before they happen.

Knowing that packet forging was an issue they should have seen this coming a mile away. At least it makes an interesting read and possibly demotivational poster fodder.
Reply

Posted: Feb 3rd 2011 8:10PM TestAXC said

  • 2 hearts
  • Report
@cforciea

Lol this doesn't surprise me. They have had issues with hacking since beta and they still haven't learned from their mistakes.
Reply

Posted: Feb 1st 2011 2:40PM Berzerk said

  • 2 hearts
  • Report
The fundamental flaw here is that the CLIENT tells the SERVER how much damage was dealt. If the client says "hey I was hit" then the server says "ok, this is how much HP you have" then this would never have been possible.

Also, you have to assume that all of your players are cheating bastards, and will get around any checks you have. The only solution is to not let them make the checks in the first place. (It may cause more lag, but it also won't destroy your entire game).

Posted: Feb 1st 2011 3:23PM cforciea said

  • 2.5 hearts
  • Report
@Berzerk
Even that is backwards. Ideally, the only thing your client would tell the server is what direction you are trying to move and whether you are doing anything (attacking, etc). The server would tell your client that you were hit, and it would update your displayed health bar accordingly. Realistically, there are some problems with this (loss of sync, etc) that have to be checked out by other methodology, but the base methodology should be to get the game client as thin as possible so that the only thing it handles is I/O.
Reply

Posted: Feb 1st 2011 2:59PM sauceofmagic said

  • 2 hearts
  • Report
Welcome to Aion!... ah wait

Posted: Feb 1st 2011 9:52PM Skie said

  • 2 hearts
  • Report
Why Europe? What about the US MS? We had the same thing happen.

Couldn't play at all yesterday, by the time I decided to log in, the game was already down...

Posted: Feb 1st 2011 10:00PM Brendan Drain said

  • 2 hearts
  • Report
@Skie Reportedly, Maple Global had this problem a long time ago, and they successfully patched it then performed a server rollback.
Reply

Posted: Feb 1st 2011 10:18PM Skie said

  • 2 hearts
  • Report
@Brendan Drain

It had this problem last night. :P http://forum.nexon.net/MapleStory/forums/thread/6710670.aspx

Same exploit as far as I know.
Reply

Posted: Feb 2nd 2011 12:11AM Danieros said

  • 2 hearts
  • Report
You can't fix this without a rollback. The damage spreads too quick for any attempt of case-by-case analysis and punishment, not to mention the economy corruption will make way too much people become candidates for punishment.

Posted: Feb 2nd 2011 12:12AM Danieros said

  • 2 hearts
  • Report
@Danieros Not to mention the issue has gone public yet the exploit wasn't fixed...
Reply

Posted: Feb 2nd 2011 4:00AM pcgneurotic said

  • 2 hearts
  • Report
Whatever happens, it's another case of a small percentage of players pointlessly wrecking thousands of people's fun. Man, the ego on some people.

Posted: Feb 2nd 2011 5:44AM Fabius Bile said

  • 2 hearts
  • Report
typical F2P game management

Posted: Feb 2nd 2011 10:09AM Xilmar said

  • 2 hearts
  • Report
/care

Featured Stories

Engadget

Engadget

Joystiq

Joystiq

WoW Insider

WoW

TUAW

TUAW