14 ms·
Valve accused of ignoring existing RCE vulnerability in Source games for 2 years
- xyst 5y agoThis is why I have a separate machine for "gaming" and "work" Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Even with their best efforts, cheaters will still prosper. Might even go a step further and firewall my gaming machine off from the rest of my network.
- Guest19023892 5y agoThis is one of the reasons I like gaming on GeForce NOW. I can use my primary laptop, play any game without having to install anything, instantly alt-tab back to the desktop between rounds without any weird bugs or crashes, etc.
- invokestatic 5y agoNo, anti-cheats in ring0 haven't eliminated cheaters, but that was never the point. The point is to make it more difficult to cheat. And they have succeeded in that. Check any cheat forum like unknowncheats. You'll see that most hackers now have to chain multiple (complex) exploits together to get their cheats working, only to get it patched by the anti-cheats a few days/weeks later. This is way more difficult and prone to detection than ReadProcessMemory was before anti-cheats went ring0.
- mhh__ 5y agoSurely the end state is cheats that even ring0 can't see i.e. read the display directly, act through the mouse. Maybe we should we run the entire OS in the games hypervisor?
- zinclozenge 5y agoI was actually thinking that you should be able to build a bot for MMOs and other kind of games that require farming with a raspberry pi or arduino acting like a mouse with a camera for image recognition. Don't know how feasible that is, but that would be undetectable by anti-cheat software.
- EamonnMR 5y agoNot really, some anti-cheat analysis is server-side and designed to catch people acting bot-like.
- Natsu 5y agoYeah, even if someone made a physical robot that did everything, they'd notice when it did stuff like playing for 1,000 hours without ever taking a break or talking to anyone.
- sp0rk 5y agoBots have long been designed to account for these types of checks by having scheduled hours and jittered breaks. Private messages and name mentions can alert the bot owner so they can respond manually. I've even seen bots that will pipe private messages to an IRC channel so that any number of restricted people can respond to the messages. It's been a long time since I've worked with game bots so I'm sure they're even more advanced now.
- Natsu 5y agoYeah, I know it's always an arms race, but the trick is to always give them something they weren't anticipating that's hard to deal with in code. There are always methods that would alert a human to something odd going on that don't alert the bot's methods for perceiving its surroundings. One of the best tricks is to show them messages via a method outside of normal chat which a normal player would see on their screen, but which a bot would not receive as 'chat'.
- 5y ago
- tedunangst 5y agoA lot of cheats involve reading in memory game state to see through walls, which your screen grabber won't be able to do.
- charcircuit 5y agoYou can use DMA to read memory in an undetectable way.
- walrus01 5y agoIt seems that a lot of people forgot about things like sony installing rootkits on peoples' PCs. Now it's accepted for gaming anti cheat software?
- rstat1 5y agoIn my mind there's a huge difference between the 2. The sony rootkit was installed in secret, full of security holes, hard to remove, and made by a vendor that appeared to give 0 shits about said security holes. All of the anti-cheat solutions I've seen that run in kernel mode are none of those things. They make it well known that they're installing, are made by vendors that actively care about the security of their products, and are trivially easy to remove once they're no longer needed.
- philistine 5y agoHopefully, Microsoft is going to follow in Apple's footsteps and close the access to the kernel for any and all programs. Yes, we will lose a lot, since Apple right now cannot cover all use cases of kernel access through new APIs, but we will gain so much in security and reliability. I'm of the opinion that easy kernel access for all apps and games is ultimately not putting me in control of my computer.
- pjmlp 5y agoThey already kind of did, I only install PC games via the Windows store.
- rstat1 5y agoAccess to kernel mode on Windows is already pretty restricted as it is. As far as I understand, you either have to run your whole machine in a special "Test Mode" or have a specific kind of (expensive) code signing certificate. But beyond that, I don't see how "more restriction" == "more control for the user"
- ladyanita22 5y ago
- fpgaminer 5y agoThis is the way. Many games package in outright spyware that siphon all kinds of data off your machine including browsing history. Kerbal Space Program was infamous for this (they removed the spyware at some point but I haven't checked recently if it was ever added back in).
- matheusmoreira 5y ago> Many games package in outright spyware that siphon all kinds of data off your machine including browsing history. Please post details. Were they literally mining user data?
- fpgaminer 5y agoThe spyware is called Red Shell and it got packaged with a bunch of popular games. Yes, it mines user data.
- matheusmoreira 5y agoThanks for the reference.
- sseneca 5y ago> Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Why are separate machines required, rather than dual-booting? (i.e. Windows for games, Linux for everything else)
- pstrateman 5y agoYour computer is really a bunch of computers pretending to be a single computer. Most of the components have firmware that can itself be loaded with malware.
- sseneca 5y agoAh. So, if a Windows application runs in ring 0, it can put malware in a place such that it can then interact with the Linux install? Is there _any_ way to bypass this, apart from separate machines? I didn't know this was possible.
- rincebrain 5y agoTheoretically - and vice-versa. Depends on what the avenue of exploit you're worried about is. You can disable BIOS flashing from the OS in the BIOS, but that might still be theoretically vulnerable to, say, compromising the Intel ME environment and flashing from there; a rootkit loaded in SMM could hang around until the machine is cold power cycled (and theoretically compromise the bootloader(s) to load itself and then chainload the "real" bootloader every boot); if you want to get really invasive, you could theoretically start flashing various microcontrollers attached to the system (say, a USB flash drive, or your HDD/SSD controller) to do malicious things. These get increasingly unlikely (and unreliable, without knowing and targeting the specific hardware you're using) as your attacker model includes less resources, but not impossible. Intel ME code execution, BIOS and SMM rootkits, malicious USB flash drive firmware and HDD firmware have all been demonstrated (I haven't seen malicious SSD firmware, but there's nothing theoretically stopping it other than the controller doing a lot more on them), and a couple have even been found in the wild.
- 120391583 5y ago
- JUNGLEISMASSIVE 5y agoI hope those separate machines are also on separate network segments without a route in between.
- matheusmoreira 5y agoGame companies literally think they have the right to own your machine. This is the kind of garbage they force gamers to install on their machines: https://www.theregister.com/2016/09/23/capcom_street_fighter_v/ https://www.theregister.com/2016/09/23/capcom_street_fighter... https://mobile.twitter.com/TheWack0lian/status/779397840762245124 https://mobile.twitter.com/TheWack0lian/status/7793978407622... Their software also takes screen shots, walks the file system, scans people's processes... Any similarities to malware may or may not be mere coincidences. They're also known for false positives: banning people for receiving special strings via text message, unknowingly installing mods with hacks bundled in or due to the presence of development tools such as debuggers or even virtual machines. Good luck trying to reverse such a ban, the entire gaming community has already been conditioned to accept any decision as final and to even defend this practice. When coupled with DRM, this essentially means your license to play the game has been revoked with no refunds.
- mxscho 5y agoAccording to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2]. It is currently unclear whether there is a publicly available PoC or any exploitation going on in the wild. [1] https://twitter.com/AntiCheatPD/status/1380873722966503426 https://twitter.com/AntiCheatPD/status/1380873722966503426 [2] https://twitter.com/killa/status/1380872852090540032 https://twitter.com/killa/status/1380872852090540032
- pityJuke 5y agofloesen has posted a screenshot of the open ticket back in December. [1] [1]: https://twitter.com/floesen_/status/1337107178096881666 https://twitter.com/floesen_/status/1337107178096881666
- pricechild 5y ago> There are also other reports of Valve not reacting to HackerOne reports appropriately I'll second that. I discovered and reported a vulnerability with the Steam client's Bluetooth pairing process via hackerone. The issue was confirmed but decided "out of scope" as apparently "within bluetooth range" runs afoul of the bug bounty's "require physical access" exclusion. 8 months later (I haven't exactly kept on top of this) they're still demanding I keep it confidential. I'll follow it up...
- yjftsjthsd-h 5y agoSurely that's a contradiction? Either it's a security problem by their criteria, or it isn't; if it is, then they should pay up and fix it, if it isn't then they have no legitimate reason to care if you put full details on the front page of $MAJOR_NEWS_SITE.
- veeti 5y agoJust release it. Maybe Valve will have to do something once folks start losing their precious CS:GO skins?
- gsich 5y ago2 years? Just leak it. At some point "responsible" disclose is not worth it.
- anonymousab 5y agoMoreso, at some point it may be more responsible to exert real pressure and a time concern on them to fix it by revealing the flaw. It depends on whether you think there's a reasonable chance that someone may be using that exploit by now. Carrot and stick approaches do not work without a reliable stick. Edit: I suppose it also depends on how much you value going through the exact same process with valve for other bugs in the future. But in a situation like this it seems like little would be lost.
- BlueGh0st 5y agoAbsolutely! Going public is an important part of responsible disclosure
- dafelst 5y agoI have a friend who used to work at Valve as a software engineer - he mentioned to me that the entire source networking stack is chock full of unchecked buffers and all sorts of potential for fairly trivial RCEs, but due to Valve's internal structure (or lack thereof) there really isn't any incentive for anyone to fix them. This was 5-6 odd years ago and he no longer works there, so things might have changed, but based on this tweet it seems unlikely.
- atat7024 5y agoGame devs don't optimize for security, because they're not incentivised to.
- pjmlp 5y agoAnd then their MMO/MMORPG server gets p0wned, with everyone taking advantage of extra virtual money, adding assets to their characters for free and auto aiming packet correction.
- serf 5y agoand, as evidenced by Grand Theft Auto and Counter-Strike, players continue playing with hackers. There is even reason for (say, for example) Rockstar to leave hackers alone in GTA : they act as artificial whales to lure real players into buying in-game currency in order to keep up/seek revenge. There are a few games I can think of off the top of my head that have a symbiotic relationship with hackers.
- gameswithgo 5y agoThe kind of hacking that happens in first person shooters has nothing to do with security failures. It is fundamentally impossible to stop aim bots. All you can do is continually play cat and mouse games to make it harder.
- happyconcepts 5y ago
- sodality2 5y agoDozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn't care about the source engine. Any new CSGO player will tell you the anti-cheat doesn't work, I know first-hand. The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat. The anti-cheat is trivial to reverse (several PUBLIC bypasses have existed for years on github, with zero patch), the engine source has been leaked, reverse engineered, and fiddled with by thousands of 14 year old kids. It is pathetically easy to bypass, for example, by changing a single byte in memory you can see through walls, see enemy money, etc. See this video I found about how miserably broken it is: https://files.catbox.moe/8e3bxz.mp4 https://files.catbox.moe/8e3bxz.mp4 It is in my opinion the greatest loss to gaming that a classic, legendary game like Counter-strike got completely ruined by lack of care by a company that profits millions off of the case unboxings.
- sseneca 5y agoThe outrageous profit Valve make from skins and the like is only half the story imo, their internal structure is the rest. Some of the stories ex-devs share from that place are just... idk, they explain the company’s apparent ineptitude
- skim_milk 5y ago>and fiddled with by thousands of 14 year old kids People think you're kidding, but it's really that easy on Source! For a while, the most popular TF2 (a Valve Source game) hack was created by a 15 year old. He made at least a million dollars in profit too! (can't remember if this factoid was verified or not, but he can definitely pay for college now) I wasn't as nearly as talented but I made some hacks for fun when I was 15 or 16 years old.
- chc4 5y agoVideo game cheats and anti-cheats are almost completely disjoint from remote code exploits like what are reported in the OP.
- sodality2 5y ago
- Aissen 5y agoTotally believable. Someone I trust in the RE community told me about similar shenanigans when trying to report issues to Valve.
- deleted 5y ago[deleted]
- guidovranken 5y agoThere's a place for being patient and lenient, but HackerOne consistently seems to not shut down malfunctioning programs that never pay rewards and flat out stop talking to you, yet continue to collect bugs. Such a relationship is commonly called fraud so I suggest reporting HackerOne to the Federal Trade Commission as I have. The premise of bug bounties is that the reward amount is at the discretion of the program host and that the time incurred by developing a fix will influence the moment of payout, but refusing to pay and even communicate (for years!) for clearly eligible submissions is well beyond a reasonable interpretation of the conditions, and to consistently keep facilitating this abuse is simply fraudulent.
- tgsovlerkhgsel 5y agoThis matches my experience. Additionally, they prohibit disclosure in such cases, effectively making them complicit in delaying (best case) or in many cases completely suppressing disclosure.
- deleted 5y ago[deleted]
- lgats 5y agoCVE Assigned https://cve.report/CVE-2021-30481 https://cve.report/CVE-2021-30481
- dkarras 5y agoIt would be a shame if an "anonymous hacker" "hacked" @floesen_, found their notes about the RCE and released it to public, accidentally of course.
- sneak 5y agoIt would probably also be a shame when floesen_ got sued for an NDA violation and had to spend tens of thousands of dollars in civil court explaining that they got hacked and it's not their fault.
- tgsovlerkhgsel 5y agoSomeone would have to do the suing though. Who would that be? It could be either Valve, or HackerOne. HackerOne is almost certainly smarter than doing that because this would immediately ruin their reputation as a bug reporting platform (and expose that they're complicit in suppressing disclosure). They're much more likely to just ban the H1 account or issue some limited penalty. Valve could potentially try, but the risk here also seems minimal: They also have a reputation to uphold, are experienced enough to know that suing security researchers paints a really bad picture and would draw attention to their vulnerabilities, and especially if their software is full of holes, this would almost certainly cause many people to disclose information about those.
- zokier 5y agoSource engine itself is at least 16 years old, and has pretty direct lineage to the original 21 year old Quake engine (Quake (-> Quake II) -> GoldSrc -> Source). I would be more surprised if there weren't lots of RCEs in it.
- rasz 5y agoImagine you are Valve - why would you fix anything? Your money printer goes Brrr regardless, and legal assures you H1 deal prevent participants from leaking anything.
- breakingcups 5y agoAt this point, just leak it to Project Zero anonymously and let them wring Valve's hand for you. There's a small chance you might still get the bounty, because you reported it first. And if not, because it's already disclosed by another party, you can cry foul on social media.
- DanAtC 5y agoUnless you have the clout of Project Zero, "responsible" disclosure is anything but. Full disclosure or no disclosure.