7 ms·
Interesting read - This is actually how a ton of game trainers/bots are made (especially ones used by Chinese gold farms in MMORPGs), along with private servers
by movover 8y ago
Interesting read - This is actually how a ton of game trainers/bots are made (especially ones used by Chinese gold farms in MMORPGs), along with private servers (except the other way around, where you send packets to the client). For some games, the bots are advanced enough where they can interact with all of the game's network protocol and behave similarly to a human, all while just being a 'terminal' for the game that sends custom packets. Hacking games via packet manipulation is nothing new either - I remember one of the big MMOs ~10 years ago having an exploit which would allow anyone to delete anyone else's in-game guild, and similarly, log into any user's account under some specific conditions.
- deleted 8y ago[deleted]
- simongr3dal 8y agoEpisode 7 and 8 of the Darknet Diaries podcast has ~ 25 min each talking about hacking and exploiting games in this way. https://darknetdiaries.com/episode/7 https://darknetdiaries.com/episode/7 https://darknetdiaries.com/episode/8 https://darknetdiaries.com/episode/8
- arca_vorago 8y agoOn the opposite end, I have used a program that does image recognition called sikuli to a act as much like a human as possible instead of doing the low level thing. My favorite hack I feel responsible for was the wow zeppelin hack (zeppling fly points were stored client side ) so you could change them and the zepplin would take you somewhere else!
- Mononokay 8y ago> My favorite hack I feel responsible for was the wow zeppelin hack (zeppling fly points were stored client side ) so you could change them and the zepplin would take you somewhere else! Wait, really? I'm surprised I hadn't heard of this.
- arca_vorago 8y agoIt was back in the vanilla wow days. I was active over at some german run wow hacking forum, did some reverse engineering, and posted about finding the values being stored client side in ram. A few months later someone did it... and then it was patched almost immediately. It's entirely possible they weren't related and whoever did it found the values themselves, but that's not as fun a story to tell myself or others so I stick to my version. Now you have me feeling all nostalgic for the day wow went from beta to live... and those early vanilla days of 40 man raids.
- Mononokay 8y agoSo weird that they're bringing back Vanilla servers - maybe that'll be possible again?
- Kiro 8y agoIs it though? This exploit causes a buffer overflow by sending malicious packages, giving full remote code execution. Trainers and bots just send normal packages.
- zython 8y agotheres a really good defcon talk on this I believe its this one: https://www.youtube.com/watch?v=hABj_mrP-no https://www.youtube.com/watch?v=hABj_mrP-no
- ttsda 8y agoThere's Manfred's talk, but it is not available on Youtube due to some unpatched GW2 exploits if I recall correctly.