5 ms·
I love CS:GO, but the Source engine has been a leaky faucet of critical bugs, and the developers haven't taken them seriously enough over the years. The disclos
by pityJuke 3y ago
I love CS:GO, but the Source engine has been a leaky faucet of critical bugs, and the developers haven't taken them seriously enough over the years. The disclosure timeline in this blog post seems to be the norm for them. For this tranche of bugs, it took significant public pressure for them to do anything.
I mean, it's not quite MW2 (2009), which I believe has multiple known RCEs that'll never be patched. But still not good enough for an actively developed live service game. One hopes that Source 2 has better standards for it, but I'll believe it when I see it.
- Pozzuh 3y agoThe whole Call of Duty series is riddled with bugs similar to the one in this article. This makes sense of course since their engines are based on the same principles, they all originate from the Quake engine. One example of an exploit found in the Quake engine in 2006 [1], also related to the “fast download” functionality, has been present in Call of Duty games such as MW2, and Black Ops - so at least 4 years after the exploit was found. It seems like Activision does not allocate any development time to their older games, even if critical vulnerabilities are found. Black Ops 3 (2015) has a number of remote code execution vulnerabilities in its peer-to-peer networking code, making it completely unsafe to play - even though it is readily available on Steam. Of course, these exploits are fixed by the community in custom, modded, clients. Sadly Activision likes to send cease & desist letters to developers of these clients. Personally I’ve found an exploit in CoD4 (2007) that will leak the CD-key of a person joining your server. This was reported to Activision in 2009 (ish), but also never (officially) fixed. It uses similar CVar leaking concepts as the one discussed in this article. Probably that would also make for an interesting write-up. [1] https://web.archive.org/web/20080517095348/http://www.securityfocus.com/archive/1/archive/1/433349/100/0/threaded https://web.archive.org/web/20080517095348/http://www.securi...
- deleted 3y ago[deleted]
- cinntaile 3y agoThe original Half Life engine (goldSrc) was based on the Quake engine, on Wikipedia it is mentioned that it was heavily modified. Half Life 2 used the Source engine and it doesn't necessarily mean that a lot of Quake engine artifacts are left, no?
- beebeepka 3y agoIt doesn't have to be a lot, though. After all, Valve was hacked like an year (sorry but it's been literally 20 yeas) before HL2 was released and yes, some Quake code was identified immediately.
- ikekkdcjkfke 3y agoJust make a MITM node.js app to filter out anything not supposed to be there Edit: a raspberri pi that filters out bad packets from old games
- scrlk 3y agoIMO, this is one of the drawbacks of Valve's famous flat structure + compensation being tied to stack ranking. Given the drawn out timescales for getting critical bugs fixed, working on security is seen as boring or low value by Valve devs. Due to compensation being tied to stack ranking system, people are dissuaded from fixing these bugs as a result.
- jsheard 3y ago> But still not good enough for an actively developed live service game. Not just actively developed, but the most popular game on Steam by far, with ongoing revenue of around $50 million per month (peaking at >$100mil recently). https://steamcharts.com https://steamcharts.com https://www.dexerto.com/csgo/players-reportedly-spent-100-million-on-csgo-cases-last-month-2102744/ https://www.dexerto.com/csgo/players-reportedly-spent-100-mi... They especially have no excuse for not pouring resources into security.
- zaroth 3y agoHas anyone tried filing a class action lawsuit? How about an FTC complaint for unfair and deceptive business practices? This seems like a great case.
- dontlaugh 3y agoThe money keeps coming in, why would they expend and effort?
- jsheard 3y agoThey'll get away with it until they suddenly don't. There have been a multitude of server-to-client and client-to-server RCEs in Source, in the worst case scenario someone could have deployed a worm which infected servers which infected their clients which infected more servers and compromised practically the entire active playerbase. They're just lucky it hasn't happened yet. What it would actually mean for Valve if they allowed that to happen is hard to say, since they're in such a firmly entrenched position with a near-monopoly on PC game distribution, but every CS:GO player getting cryptolocker'd wouldn't be good for their brand to say the least.
- a20eac1d 3y agoThis is really fascinating to me because MW2 was, and still is, one of my favorite games. Can you tell me more about these RCEs, how they work, or some technical analysis on this game?
- pityJuke 3y agoHere is a GH repo about two (now patched) MW2 exploits: https://github.com/momo5502/cod-exploits https://github.com/momo5502/cod-exploits.