When EVE Online's new forum went live on Thursday, April 7th, it wasn't long before someone discovered a gruesome exploit. The cookie used by the forum wasn't encrypted, putting the user's character ID and signature in plain text. The forum software also didn't have the required validation procedures, meaning users could change the user ID in their cookies to any character's ID and they'd be able to post as that character. Moderator tools and private forums for EVE developers, volunteers and the CSM were also allegedly exposed.
In a new devblog, CCP Sreegs has explained the extent to which the exploit compromised security. In addition to being able to post as any user and edit any post, users abusing the exploit were able to inject arbitrary HTML into their forum signatures. Several players have been very vocally outraged by this, as the potential for someone to insert javascript into a forum page could be extremely damaging. Sreegs assured players that javascript inserted into the signature was sanitized and would not execute.
At least one player who reported the exploit was banned for subsequently abusing the exploit in an effort to force CCP to take action. In his devblog, Sreegs re-iterated the correct steps for getting in touch with CCP's security department if an exploit or security hole is discovered. Player response to the devblog has been largely positive, but questions still remain. CCP has yet to comment on why it decided to base the new forum on open source software Yet Another Forum and why it didn't inform players that it was using a pre-made package.
Reader Comments (11)
Posted: Apr 12th 2011 10:14AM b3n said
I think CCP SHOULD use a pre-made forum package so that they can focus their own development work on the game of EVE.
However they need to use a BETTER pre-made forum.
"Yet Another Forum" is built with Asp and/or .NET so I'm not surprised that the forum is insecure as I've never liked those technologies.
Personally I think it would be better to use a PHP forum like vBulletin or SMF but I believe CCP use a lot of Microsoft hardware and software - but that shouldn't be a problem really.
However they need to use a BETTER pre-made forum.
"Yet Another Forum" is built with Asp and/or .NET so I'm not surprised that the forum is insecure as I've never liked those technologies.
Personally I think it would be better to use a PHP forum like vBulletin or SMF but I believe CCP use a lot of Microsoft hardware and software - but that shouldn't be a problem really.
Posted: Apr 12th 2011 2:07PM SgtBaker1234556 said
@b3n
No really, YAF is just fine - it's just that they ripped out the YAF authentication mechanism and replaced it with their own :lolcookie: system with characterID's.
The security issue has very little to do with YAF being pre-made open source package and it has everything to do with sheer incompetence of the CCP webteam who coded the cookie-authentication thingy.
And of course there's the small matter of CCP saying they've put 72000 man-hours into the development of this fantastic, in-house coded, pinnacle of forum software evolution.... and it turned out to be re-skinned, butchered opensource turd.
That stings.
Reply
No really, YAF is just fine - it's just that they ripped out the YAF authentication mechanism and replaced it with their own :lolcookie: system with characterID's.
The security issue has very little to do with YAF being pre-made open source package and it has everything to do with sheer incompetence of the CCP webteam who coded the cookie-authentication thingy.
And of course there's the small matter of CCP saying they've put 72000 man-hours into the development of this fantastic, in-house coded, pinnacle of forum software evolution.... and it turned out to be re-skinned, butchered opensource turd.
That stings.
Posted: Apr 12th 2011 10:24AM CaffinatedOne said
Given the news that I always see for it, it's like EvE is a honeypot MMO to capture the most abusive online miscreants.
Posted: Apr 12th 2011 10:39AM (Unverified) said
@CaffinatedOne
Clearly, you've never inhabited WoW trade chat before.
Reply
Clearly, you've never inhabited WoW trade chat before.
Posted: Apr 12th 2011 1:06PM CaffinatedOne said
It's been awhile since I've played WoW, so I'll admit that I'm not entirely up to date there. My recollection was that the issue with WoW chat (and forums) is the typical "anonymous internet user" syndrome where people act like spoiled 6yr olds. That's sadly, quite common, even outside of WoW.
EvE seems to be different in that it actively encourages being a sociopath, and apparently that behavior extends outside of the game here.
Caveat: I'm sure that there are many kind and wonderful EvE players, but the nature of the game seems to encourage the worst in some types of people. Given what I've read, that's some of the game's charm, but it seems to me to be qualitatively different from the usual internet immaturity.
Reply
EvE seems to be different in that it actively encourages being a sociopath, and apparently that behavior extends outside of the game here.
Caveat: I'm sure that there are many kind and wonderful EvE players, but the nature of the game seems to encourage the worst in some types of people. Given what I've read, that's some of the game's charm, but it seems to me to be qualitatively different from the usual internet immaturity.
Posted: Apr 12th 2011 2:35PM Calfis said
@CaffinatedOne
You are right, EvE is the internet's favorite Darwinian Dystopia. People act out the smug douche they cannot be IRL. Because EvE does not conform to the social norms of the real world, many people feel it gives them free license to be all the jackass they can be. It is the ultimate avenue of e-peen measurement.
Nothing says my dick is bigger than yours like blowing up another guys hard earned ship. Especially if you do it in a smaller ship. It is also the ultimate forum for the internet tough guy because it has a permanent kill record outside the game in the form of killboards. Suddenly a threat of impending EvE doom sounds more credible when you look up the guys name and see that he has racked up 1000 kills in the past year.
The fact that there are many decent EvE players that do not indulge in this culture and only ever mine or PvE makes more a great farming population for some of the more unscrupulous players.
However, all of this is arguably part of the allure of EvE because it exposes players to challenges that are not entirely developer created/guided. Everyone can have a high level character in WoW with every item in the world if they grind hard enough. There are no real setbacks that can stop a players progress, no fear of some unforeseen challenge. In EvE, if you can accomplish much despite the cut throat environment, that makes that feeling of accomplishment all the more satisfying.
Besides its better to have people rape and pillage like a sociopath in a game than IRL. One can even argue games like this are a great avenue for people to vent their frustrations rather than go postal at work.
Reply
You are right, EvE is the internet's favorite Darwinian Dystopia. People act out the smug douche they cannot be IRL. Because EvE does not conform to the social norms of the real world, many people feel it gives them free license to be all the jackass they can be. It is the ultimate avenue of e-peen measurement.
Nothing says my dick is bigger than yours like blowing up another guys hard earned ship. Especially if you do it in a smaller ship. It is also the ultimate forum for the internet tough guy because it has a permanent kill record outside the game in the form of killboards. Suddenly a threat of impending EvE doom sounds more credible when you look up the guys name and see that he has racked up 1000 kills in the past year.
The fact that there are many decent EvE players that do not indulge in this culture and only ever mine or PvE makes more a great farming population for some of the more unscrupulous players.
However, all of this is arguably part of the allure of EvE because it exposes players to challenges that are not entirely developer created/guided. Everyone can have a high level character in WoW with every item in the world if they grind hard enough. There are no real setbacks that can stop a players progress, no fear of some unforeseen challenge. In EvE, if you can accomplish much despite the cut throat environment, that makes that feeling of accomplishment all the more satisfying.
Besides its better to have people rape and pillage like a sociopath in a game than IRL. One can even argue games like this are a great avenue for people to vent their frustrations rather than go postal at work.
Posted: Apr 12th 2011 2:51PM SgtBaker1234556 said
@Calfis
Uh. I seriously hope that was written with irony laden tongue firmly in cheek.
Also, way to derail the topic...
Reply
Uh. I seriously hope that was written with irony laden tongue firmly in cheek.
Also, way to derail the topic...







