Addressing Serious Hacking Issues
#61
If they only had 1 active GM per server this game will be cleaned out, you can pretty much find any hacker in game using Friend Finder as long as you're in level range of them and on the same channel.
Reply
#62
This post reminded me of the MWLB or whatever they called it.

What happened to them? I remember there used to be inaugural posts of each new member every month or so. Flopped?
Reply
#63
Idea flopped just like their previous "Volunteer group" idea and other crap. Remember they chose a couple of level 200's 2 years ago as like, game mods w/ no power or something, ya that flopped.
Reply
#64
RIPGobies Wrote:Nexon can start by banning based on string detection, that will get rid of most of the major hacking in game.

I have to agree with this. It'll certainly deter the majority of script kiddies that turn relatively containable exploits into huge issues.

It's not going to solve anything the wrong run, but it'll slow them down.

Also:

案山子 Wrote:But Sarah, they're sorry.
[video=youtube;BeP6CpUnfc0]http://www.youtube.com/watch?v=BeP6CpUnfc0[/video]
Reply
#65
Justin Wrote:This. They need to start shutting down the blatantly obvious public hacking sites, and that will cool things down a BIT. But they need to step their game up. HARD. At least they're admitting they're sucking major ass right now.

I don't think that would work. I remember a response from a hacking site to Nexon arguing something like "stupid fools, if Blizzard hasn't been able to stop us, you think your sh'itty company can?" or something like that. Made me feel frustrated in Nexon's place and wanted to burn them down.

I agree with Nesso though, they needa go after the hacks themselves. How hard would it be for Nexon to pretend to be a VIP user from these popular hacking sites, download their current MS hacks and develop a fix based on what the hack does? Like how biologists make vaccines out of studying the virus or an antidote out of a poison. Usually a hack stays private for weeks before going public for the scrip kiddies.
Reply
#66
0^2 Wrote:@RIPGobies That would be a glorious day when only true hackers could effect the game and not just a bunch of fools with scripts. Monocle

Until the "true hackers" incorporate code to change the strings, in the scripts they distribute.


A tool I found useful for finding hackers was Southperry's own ETL, sorting by descending exp/day. ETL is on hiatus now, but Nexon has their own version with the "weekly" Rankings.
Just take a good hard look at anyone who is gaining significantly more exp/day than the average active player of the same level. Some hardworking legit grinders do get more exp/day at LHC than any ToT botter, so I'm not saying to auto-ban anyone leveling fast, but take the top of the weekly rankings as a list of characters that a GM should pay a visit to.
Reply
#67
0^2 Wrote:Exactly my thought on this "State of the Game" address.
@RIPGobies That would be a glorious day when only true hackers could effect the game and not just a bunch of fools with scripts. Monocle

There are some 'true' hackers out there. They just keep everything private. If you heard of Cam, you would know he's a true exploiter.
Reply
#68
I`ll believe it when i see it.
but gl nexon.
Reply
#69
SaptaZapta Wrote:Until the "true hackers" incorporate code to change the strings, in the scripts they distribute.


A tool I found useful for finding hackers was Southperry's own ETL, sorting by descending exp/day. ETL is on hiatus now, but Nexon has their own version with the "weekly" Rankings.
Just take a good hard look at anyone who is gaining significantly more exp/day than the average active player of the same level. Some hardworking legit grinders do get more exp/day at LHC than any ToT botter, so I'm not saying to auto-ban anyone leveling fast, but take the top of the weekly rankings as a list of characters that a GM should pay a visit to.

Though the worst issues the lame arse hackers create isn't about exp and leveling. It isn't even the meso botting. It is the bloody posers that act legitly but dupe their hats off when they can or buy from said guys. That is what ruins the economy and make any form of competition meaningless.
Reply
#70
I won't be surprised if their "more advanced hack prevention and detection tools" ban more legits than it does hackers.
Reply
#71
CarrionCrow Wrote:Though the worst issues the lame arse hackers create isn't about exp and leveling. It isn't even the meso botting. It is the bloody posers that act legitly but dupe their hats off when they can or buy from said guys. That is what ruins the economy and make any form of competition meaningless.

True, but I was talking about what GMs can do while programmers are (hopefully) working on changing the way the database works so that channel crashes don't result in duped items, and similar deep-seated issues.

Also, "any form of competition" includes competition for exp and levels. Especially in new servers, like this upcoming Chaos one, but also in older ones.

Finally, botters might not hurt the economy (what economy?) too much, but their effect on player morale is huge. Most players are blissfully unaware of duped white scrolls or 27 att shoes, but when they see the same botter at the same map day in and day out, or blatantly ks'ing them out of their training map, they know who's in charge of this game. And it isn't the mythical GMs or Nexon. Makes people far less inclined to eschew hacked goods or avoid hacking or at least abusing glitches.
Reply
#72
It's way too hard to report hackers... and I assume that's cause the GMs don't have any good tools for sorting through the reports, since it's fairly obvious Nexon's not all that competent. So they need to cut down on the number of reports they get, and this means raising the barrier to reporting.

I know OdinMS had several heuristics that helped GMs find hackers (and autobanned people who were obviously cheating) but it's possible Nexon doesn't employ anyone able to build a similar system.

Independent verification of packet contents would go a long way towards fixing the problem. If it fails the sanity checks (buying an item the NPC wasn't selling, trading negative numbers of items, sending spouse chat to someone you're not married to or whispers to someone with whispers blocked) then temp-ban the account immediately. If it's within bounds, but is unusual behavior (mobs behaving out of the ordinary, like always moving towards the player when it should be random. Player changes channel very frequently, like every time someone else enters the map) then send a GM to look at them.

And playerside limits should be reflected by serverside ones. Otherwise you have a game where legitimate players are at a disadvantage over hackers on even minor things, like being able to change channels quickly or enter the cash shop.

When someone reports a player, it should be possible to start recording the reported player's actions. Save the packets and timing, then the GM has evidence to go on, even if they can't immediately zap themselves to the hacker's location. Making reporting more effective means fewer reports, and if someone does abuse the privilege, remove it.
Reply
#73
Stereo Wrote:It's way too hard to report hackers... and I assume that's cause the GMs don't have any good tools for sorting through the reports, since it's fairly obvious Nexon's not all that competent. So they need to cut down on the number of reports they get, and this means raising the barrier to reporting.

I know OdinMS had several heuristics that helped GMs find hackers (and autobanned people who were obviously cheating) but it's possible Nexon doesn't employ anyone able to build a similar system.

Independent verification of packet contents would go a long way towards fixing the problem. If it fails the sanity checks (buying an item the NPC wasn't selling, trading negative numbers of items, sending spouse chat to someone you're not married to or whispers to someone with whispers blocked) then temp-ban the account immediately. If it's within bounds, but is unusual behavior (mobs behaving out of the ordinary, like always moving towards the player when it should be random. Player changes channel very frequently, like every time someone else enters the map) then send a GM to look at them.

And playerside limits should be reflected by serverside ones. Otherwise you have a game where legitimate players are at a disadvantage over hackers on even minor things, like being able to change channels quickly or enter the cash shop.

When someone reports a player, it should be possible to start recording the reported player's actions. Save the packets and timing, then the GM has evidence to go on, even if they can't immediately zap themselves to the hacker's location. Making reporting more effective means fewer reports, and if someone does abuse the privilege, remove it.

There are ways to generate fake packet signatures and circumvent checks like you suggested. Easily, in fact. Been there done that, I'd say what you're saying is wholly true and it boils down to this: More human investment into the damn game. Period. Whether it's direct through GMs or through better infrastructure like you said. Better systems for automatically detecting stuff like this. While they'll always come back because that's what they do (they circumvent everything), it's better than letting it get so far out of hand like this and the last big PG hack release.

I'm convinced Nexon has pretty detailed logs of what's going on but they choose not to utilize them correctly/efficiently. If I a GM can tell me in a ticket with logged knowledge that I was running hacking programs then they obviously have the capability but not the competence. These programs aren't rootkitting themselves or anything and if MS is monitoring what is going on outside of the game and logging it, that can and should also lead to some effective solution. All they have to do is stay on top of these blatantly public programs.

I feel like it's harder to work from inside the game, ironically enough. They should take the fight to their security system and prevent them from even being able to enter the game with anything like that initialized. I believe that's how most other games are doing it. I know for sure Warden (similar to HS but more integrated/unannounced) in Blizzard games is some tough pomegranate. Even if you get away with map hacking in SCII, which is deathly easy to do, your program usage is logged constantly and you're almost always banned within a couple weeks.
Reply
#74
xLeviathan Wrote:I feel like it's harder to work from inside the game, ironically enough. They should take the fight to their security system and prevent them from even being able to enter the game with anything like that initialized. I believe that's how most other games are doing it. I know for sure Warden (similar to HS but more integrated/unannounced) in Blizzard games is some tough pomegranate. Even if you get away with map hacking in SCII, which is deathly easy to do, your program usage is logged constantly and you're almost always banned within a couple weeks.

lol now that you mentioned warden, i remember 2-3months ago when blizzard banned over 5000 accounts because of arch/farming booting, people in this hacking forum were complaining about how the hack tool promissed to bypass the warden security and it was ban-free(you had to pay for said hacking tool), 1 month later, everyone that used said tool got banned and went to cry on blizzard forums.

as how eos said:

Eosian Wrote:because like 90% of their game they tried to minimize their hardware cost by making the client handle everything. This is why hacking is so bad - Your client defines the world instead of simply interacting with it. The entire paradigm is wrong and I don't think they'll ever try to fix it because it'd be costly and require them to admit they're fundamentally flawed.

They need to rewrite the entire client to stop the hacking. theres no such thing as packet editing on WoW, because the server just don't accept packets that are send outside the client, the game crash instantly if you even try.
Reply
#75
xLeviathan Wrote:There are ways to generate fake packet signatures and circumvent checks like you suggested. Easily, in fact.

Not in a useful way. Even if the packet is signed right, if the server refuses to swap the player's item/meso for the requested item, there's nothing they can do about it. That's the kind of check I'm talking about. The only way to get around it then is to find a loophole in the server's limits, and that's trickier. (like say it's whitelisted maple items to trade for silver coins, then unless another item ID accidentally gets on the list, there's no way to sell arrows for coins)
Reply
#76
Nesso Wrote:They should be going after the hack programs themselves, not just 'improving security.'

Do you try to stop rain from being a possible weather pattern or do you water-proof your house?

When you're under siege do you try to kill the army that has you surrounded and outnumbered, or do you fortify your walls further and try to wait them out and keep them from finding ways in?

Stereo Wrote:Not in a useful way. Even if the packet is signed right, if the server refuses to swap the player's item/meso for the requested item, there's nothing they can do about it. That's the kind of check I'm talking about.

Essentially the same problem & answer CrazyNomad quoted me on from over a year ago.
It's not having what you want - It's wanting what you've got.
Reply
#77
Eosian Wrote:Do you try to stop rain from being a possible weather pattern or do you water-proof your house?

When you're under siege do you try to kill the army that has you surrounded and outnumbered, or do you fortify your walls further and try to wait them out and keep them from finding ways in?

A good offense is a good defense. I don't know if you've played a real time strat war game, but, although it's great to have a defense, it's also nice to keep cutting at their army before they reach your defense. Attack the websites, cutting down the numbers from the source, then let their numbers walk into the defenses only to step on mines Biggrin
Reply
#78
That only works when you have numbers to support it. ten versus ten million does not make that practical in the slightest.

You're also overlooking the fundamental flaw that modding isn't illegal in most cases. Violating the terms of use of a video game is not a crime.

They're under seige, they're outnumbered, and they're unarmed. What offensive are you expecting here, exactly?

They have only two options; Surrender or Learn Defense.
It's not having what you want - It's wanting what you've got.
Reply
#79
KhainiWest Wrote:A good offense is a good defense. I don't know if you've played a real time strat war game, but, although it's great to have a defense, it's also nice to keep cutting at their army before they reach your defense. Attack the websites, cutting down the numbers from the source, then let their numbers walk into the defenses only to step on mines Biggrin

It's situational, and in this situation you expect them to spend most of their time trying to track down every hacking site/program?

It's better to first build up the defenses of the game since the game itself is as strong as wet paper as far as ''security'' goes, which is why so many different hacks exist for it, and just about anything you could think of can be done through illegitimate means.
Reply
#80
KhainiWest Wrote:A good offense is a good defense. I don't know if you've played a real time strat war game, but, although it's great to have a defense, it's also nice to keep cutting at their army before they reach your defense. Attack the websites, cutting down the numbers from the source, then let their numbers walk into the defenses only to step on mines Biggrin

they tried it already, they tried to close cheatengire forum, so cheatengire removed the maplestory subforum, but doing that, at least 3 new hacking forum appeared, w8(most of the programmers there were from cheatengine, cam, bizzaro), gk, sns, etc etc etc. closing a website just make it worst.

Just look at torrent sites, when one get shut down, at least 5 new open with the same content. They need to rewrite the whole game code so it wont accept dll injection with hackshield up. because you know, most of the hacks you inject in the game with hackshield up, meaning hackshield do nothing at all.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)