3 ms·
How exactly does it show that?
by lrem 3y ago
How exactly does it show that?
- pjmlp 3y agoBy showing a 0-day for a game server.
- bogwog 3y agoOn the other hand, this is the most successful multiplayer FPS of all time, you rarely see articles like this, and I can't remember ever seeing an article talking about an exploit like this actually being used. How many high value targets are installing games on their machines with sensitive data, and connecting to random private servers? Hopefully not enough to justify developing an exploit like this.
- pjmlp 3y agoOnly because sadly, liability still isn't a thing in many places. Too many people are happy buying shoes that explode, taking their feet away, if the shoe laces are tied on the wrong order.
- jsheard 3y agoCS:GO skins can sell for thousands of dollars, using an exploit like this for spear-phishing attacks against whales flaunting their expensive inventories could easily net more than the $7500 bounty which the OP received for responsible disclosure. It's probably already happening, highly targeted attacks aren't likely to make the news, and even if they are publicised it's hard to determine exactly how they were achieved. https://www.kaspersky.co.uk/blog/cs-go-two-million-usd-inventory-hack/24600/ https://www.kaspersky.co.uk/blog/cs-go-two-million-usd-inven...
- lrem 3y agoWhat were the consequences of this?
- Narishma 3y agoI think they meant to say that security practices should matter in game development, not that they actually do in practice.