Major hack of the MOULa server this evening?

Anything that isn't directly related to Age Creation but that might be interesting to Age developers.

Re: Major hack of the MOULa server this evening?

Postby OHB » Sat Jan 22, 2011 8:37 pm

One solution might be to add a layer between the client and the server which acts as an API. It has specific exposed functions for specific things. Instead of going in and attaching a vault node, you'd have to use something like a sendKIMail() or sendKIPhoto() function which would do it for you. Build all the security into the API. Of course, then re-write the client...so yeah.
User avatar
OHB
 
Posts: 143
Joined: Sat Jul 03, 2010 11:50 am

Re: Major hack of the MOULa server this evening?

Postby Karkadann » Thu Feb 03, 2011 11:49 am

Ive been wondering about this on and off for a while now, and Im not sure it was a major hack

RAWA wrote:The MO:ULagain service is back online. :)

Note: If any remaining security holes continue to be exploited on the main server, the service may be taken down indefinitely until all the holes can be plugged. That would be a Bad Thing (tm), and would require much longer downtime.

Thanks for your patience and cooperation.


Cyan has been very Silent about the whole thing, and the only shut down was the monthly reboot. I had a feeling that the mischief may have come from within Cyan as some type of Birthday celebration for Randi that just went the wrong way.
The Optimist see's the glass half full, The Pessimist see's the glass half empty.
Its the Realist who see's the glass is half full with air, half full with water
User avatar
Karkadann
 
Posts: 1223
Joined: Sun Aug 02, 2009 10:04 am
Location: Earth

Re: Major hack of the MOULa server this evening?

Postby Branan » Thu Feb 03, 2011 12:05 pm

It was not internal to Cyan, and RAWA was very not happy about it.

Rand was in the City at the time, and enjoyed the "festivities". I think had he not been there, and had this been just RAWA responding to another hack, the response would have been quite a bit worse.
Image
Your friendly neighborhood shard admin
User avatar
Branan
Gehn Shard Admin
 
Posts: 694
Joined: Fri Nov 16, 2007 9:45 pm
Location: Portland, OR

Re: Major hack of the MOULa server this evening?

Postby Karkadann » Thu Feb 03, 2011 2:02 pm

OK like I posted earler I was told it was not Cyan and it was not a security breach, and if it was not an individual from Cyan then someone with known access to Cyan severs could have been resposible. What I cant understand is they spent so much time with this mischief that has all been for not why didn't they do something useful like open the gates add terrain and UVmap texture to the stairs and rooftops near Tocatah Ally.
The Optimist see's the glass half full, The Pessimist see's the glass half empty.
Its the Realist who see's the glass is half full with air, half full with water
User avatar
Karkadann
 
Posts: 1223
Joined: Sun Aug 02, 2009 10:04 am
Location: Earth

Re: Major hack of the MOULa server this evening?

Postby D'Lanor » Thu Feb 03, 2011 2:57 pm

Again, no servers were hacked. All of this was done by ordinary game messages each client is allowed to send, and SHOULD be allowed to send for ages to function properly. Like it or not, that is how Plasma works.
"It is in self-limitation that a master first shows himself." - Goethe
User avatar
D'Lanor
 
Posts: 1980
Joined: Sat Sep 29, 2007 4:24 am

Re: Major hack of the MOULa server this evening?

Postby Karkadann » Thu Feb 03, 2011 4:11 pm

Ya mean like (/jump 100) in the off line version??

:lol: wow thats interesting,
The Optimist see's the glass half full, The Pessimist see's the glass half empty.
Its the Realist who see's the glass is half full with air, half full with water
User avatar
Karkadann
 
Posts: 1223
Joined: Sun Aug 02, 2009 10:04 am
Location: Earth

Re: Major hack of the MOULa server this evening?

Postby diafero » Fri Feb 04, 2011 7:51 am

Exactly. Remember me to show you some of the Offline KI admin functions at some point (or try them out offline) - seen from the server, this is all legitimate client activity. Including linking a player to another age, using flymode on objects or players in the age I am, making your hair green, running the female dance animation on your male avatar. The server doesn't care, it just forwards the message my client sends to your client - and if the message says "make that guy's eyes purple", your client will do so happily.
I prefer e-mails to "diafero arcor de" (after adding the at and the dot) over PMs.

"Many people's horizon is a circle with a radius of zero. They call it their point of view."

Deep Island Shard | Offline KI
diafero
Deep Island Admin
 
Posts: 2966
Joined: Mon May 05, 2008 5:50 am
Location: Germany

Re: Major hack of the MOULa server this evening?

Postby Chacal » Fri Feb 04, 2011 8:25 am

And if this situation doesn't change in the server Zrax's team is building, we'll still be in trouble.
Chacal


"The weak can never forgive. Forgiveness is an attribute of the strong."
-- Mahatma Gandhi
User avatar
Chacal
 
Posts: 2508
Joined: Tue Nov 06, 2007 2:45 pm
Location: Quebec, Canada

Re: Major hack of the MOULa server this evening?

Postby diafero » Fri Feb 04, 2011 8:36 am

Unfortunately, I don't see a really good way out. That's how Uru is designed. Maybe the server could notice attempts of modifying other players' avatar's, but as D'Lanor mentioned, much of this is happening in normal gameplay. The server does not even know the age things are happening in, all it got is the .age files (for the sequence prefix to age name mapping, basically), and the SDL files for storing the permanent age state. Since it has no notion of (in)valid states, nor does not it know if and where there are any kinds of buttons or whatever, it can't even tell whether a user setting an SDL does this legitimately or not, for example. Player avatars are just SDL objects, like kickables or animations (okay, they are attached to a clone instead of a simple object, but those are used for NPCs like Yeesha, Zandi or the Quabs as well). Changing this would basically require a re-write of the state management and syncing part of the protocol.
I prefer e-mails to "diafero arcor de" (after adding the at and the dot) over PMs.

"Many people's horizon is a circle with a radius of zero. They call it their point of view."

Deep Island Shard | Offline KI
diafero
Deep Island Admin
 
Posts: 2966
Joined: Mon May 05, 2008 5:50 am
Location: Germany

Re: Major hack of the MOULa server this evening?

Postby N. Sigismund » Fri Feb 04, 2011 9:00 am

Cyan appear to have accepted the inevitabiltiy, anyway.

http://mystonline.com/forums/viewtopic.php?t=24068
http://forums.drcsite.org/viewtopic.php?t=2923

Smart move, I suppose.
For reference:
IC: Nye Morgan
OOC: Sigismund, Nye, Huw Dawson
N. Sigismund
 
Posts: 212
Joined: Tue Jun 08, 2010 10:39 am

PreviousNext

Return to Off-Topic Discussion

Who is online

Users browsing this forum: No registered users and 0 guests