I miss these kinda posts, so rare now. I know XSS is dying due to CORS and DLL injection is mooted by ALSR, that API's are usually authenticated and authorized, but damn... I wish there was a more collective place to showcase modern exploits, they just hit nice in the feelies.
Hacking GTA V RP Servers Using Web Exploitation Techniques
11–20 of 40 posts
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#12it's nice seeing someone open with telling everyone that GTA V is some of the most poisoned online gameplay with regards to cheating. I don't agree with the conclusion that it's because it's peer-to-peer. that's not why -- it's because of lazy developer methods and a lower prioritization of security effort. the biggest genuine effort that Rockstar puts into anti-cheat effort is an occassional memory-structure shuffle…
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#13it's nice seeing someone open with telling everyone that GTA V is some of the most poisoned online gameplay with regards to cheating. I don't agree with the conclusion that it's because it's peer-to-peer. that's not why -- it's because of lazy developer methods and a lower prioritization of security effort. the biggest genuine effort that Rockstar puts into anti-cheat effort is an occassional memory-structure shuffle…
This post is about private servers using a 3rd party mod called FiveM. How do you expect Rockstar to police them?
I stopped playing when some cheater impersonated me in the game chat and then crashed my game, after I insulted them (mostly out of curiosity to see what else their cheats can do). It's just so far beyond what happens with cheats in other online games. I've also heard of people being followed by cheaters across game sessions and being DDOSed.
The only thing that's similarly bad to the cheats in GTA Online is (the original) Modern Warfare 2 which has had RCEs.
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#14And this is also our fault, e.g. due to the explosion of dependency hell in npm libraries.
This is probably the best intro to modern supply chain attacks and detection techniques, just shared with my team this week:
(edit: removed youtube tracking)
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#15The „good news” is that code injections are still widely popular in a form of supply chain attacks. And this is also our fault, e.g. due to the explosion of dependency hell in npm libraries. This is probably the best intro to modern supply chain attacks and detection techniques, just shared with my team this week: https://youtu.be/3pLfkutz1x8 (edit: removed youtube tracking)
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#16That was a very nice write-up!
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#17I miss these kinda posts, so rare now. I know XSS is dying due to CORS and DLL injection is mooted by ALSR, that API's are usually authenticated and authorized, but damn... I wish there was a more collective place to showcase modern exploits, they just hit nice in the feelies.
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#18Earlier quoted context omitted.
This post is about private servers using a 3rd party mod called FiveM. How do you expect Rockstar to police them?
True, but the main game is similarly plagued by some of the worst cheats I've ever encountered in an online game and I'm almost certain there are some serious security vulnerabilities to be found there. I stopped playing when some cheater impersonated me in the game chat and then crashed my game, after I insulted them (mostly out of curiosity to see what else their cheats can do). It's just so far beyond what happens…
Why is it even possible for a player to change the entire map for all players on the server to winter? Why is it even possible to "attach" a helicopter to someone's head? Why is it even possible for players to spontaneously burst into flames, even after dying and respawning?
These are dumbfounding "cheats" that only exist to troll players. I have no idea why the client/server even accepts these environment changes. It seems really easy to prevent...
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#19The „good news” is that code injections are still widely popular in a form of supply chain attacks. And this is also our fault, e.g. due to the explosion of dependency hell in npm libraries. This is probably the best intro to modern supply chain attacks and detection techniques, just shared with my team this week: https://youtu.be/3pLfkutz1x8 (edit: removed youtube tracking)
Re: Hacking GTA V RP Servers Using Web Exploitation Techniques
#20it's nice seeing someone open with telling everyone that GTA V is some of the most poisoned online gameplay with regards to cheating. I don't agree with the conclusion that it's because it's peer-to-peer. that's not why -- it's because of lazy developer methods and a lower prioritization of security effort. the biggest genuine effort that Rockstar puts into anti-cheat effort is an occassional memory-structure shuffle…
Yeah, they absolutely don't care. It cannot be hard to detect griefing and obnoxious cheating by just looking at player behavior. How hard can it be to detect 90000000000 in-game dollars to be added to players, how hard can it be to detect that someone is blowing up everyone in the server, ... They just don't care, and it's a shame because GTA V still holds up as a fantastic game even after all these years.
Don't give them ideas ;) You either get a small loan of a billion dollars from a friendly cheater, or they try to bleed your wallet dry with Shark Cards. Rockstar are incapable of coming up with a balanced and rewarding progression system because it's in direct conflict with their financial goals.