† Wolfgang H. Franke

feedback links search [web, newgroups] Heute heise.de wired.com webmail banking {jjaf-admin} spam-handling distributed.net-stats picture gallery internet-monitor

[counter]

jjaf.de/security/incidents

jjaf incident note IN-200101122006:
xatrix kingpin kpl Most Wanted invisible player

Original release date

2001-02-20

Last revised

2001-02-22

Source

*CHAFF*

A complete revision history can be found at the end of this file.

Systems Affected

Server in incident was running Most Wanted v10.16.00 by Chief_SohCahToa (KingPin Life Mod Development).

Overview

Player *CHAFF* suspects player orion to be invisible for him killing people by using leadpipe in a game on 2001-01-12T20:06 recording a demo of that incident being on a most_wanted-server.

Description

2001-01-12T20:06

*CHAFF* recorded a demo of this incident where in fact orion killed others several times using the leadpipe. Here is an grep -i orion qconsole.log filtering all orion-related incl. a suspicious chat-line you can also read out of the full generated qconsole.log:

*CHAFF* was severely dented by orion + 90 bucks
:orion: ima ghost
*CHAFF* was severely dented by orion + 90 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
silent bob was severely dented by orion + 10 bucks
:orion: wwwooooowooowwowo oo
:orion: gg

2001-02-22T00:56

A recording was done showing players blimey and aledgedly core exploiting this vulnerability. A full generated qconsole.log of this recording is also available.

Impact

Being invisible is an enormous advantage over visible players.

Solution

With help from lefty! the incident could be reproduced and a greater vulnerability of Most Wanted than first expected could be found.

Currently an advisory is in progress with access restriced to implementors of a fix and Chief_SohCahToa confirmed working on that.

Appendix A. – References

forum posts

  1. First Cheater Spotted!!!
  2. "[…] saw a guy run right out of a wall […]" (dead link)
  3. anybody else been piped to death by the invisable man?

links

Revision History

2001-02-22

added Chief_SohCahToa-confirmation. additional recording 2001-02-22T00:56

2001-02-21

added links to most_wanted; incident reproduced!

2001-02-20

Initial release

If you have feedback, comments, or additional information about this incident, please send us email.

This work is licensed under a Creative Commons License Valid XHTML 1.0! Valid CSS! privacy policy