Wait, seriously though? They don't filter that kind of behavior server-side at all? This shouldn't be possible on multiplayer games because as a server designer you need to always assume the client is compromised. Nintendo needs a slap on the wrist for this one.https://twitter.com/Morukutsu/status/1000743600127279105 …
-
Show this thread
-
Like, it's not easy to understand what's going on in the video, but I'm pretty sure they've upped the fire rate and range of the blaster to be impossibly high. That's an easy tweak for local things but should be trivially caught if taken online. Smdh.
4 replies 0 retweets 7 likesShow this thread -
Replying to @hedgeberg
Online games are *never* designed this way. Seriously. Everyone trusts the client. When the client gets compromised, people try to implement bolted-on attestation and cheat detection mechanisms. I'm surprised you're surprised. This is *entirely* expected.
1 reply 0 retweets 4 likes -
Replying to @marcan42 @hedgeberg
AKA game designers have bigger things and deadlines to worry about than doing the entire game and netcode design around the assumption that every client may be malicious and break the rules. I'm not aware of any typical console game designed like this.
2 replies 0 retweets 0 likes -
Replying to @marcan42 @hedgeberg
At *best* one of the players is the "server" and mostly takes input from the others, which reduces the potential for hacks like this... unless you're the server, and then all the hackers need to do is get themselves to be the server.
1 reply 0 retweets 0 likes -
Replying to @marcan42
Honestly now part of me wants to try bug-bountying potentially remote-exploitable splatoon issues, because tbh the idea of remote bricking using unverified inputs worries me a lot.
2 replies 0 retweets 2 likes -
-
Replying to @marcan42 @hedgeberg
ISTR you used to be able to send WiiConnect24 messages with the special metadata that Nintendo normally use themselves. And there's a whole... javascript... bytecode... interpreter in IOS. That'll run remote code. They started filtering this stuff but... yeah.
1 reply 0 retweets 5 likes
We joked about making a self-replicating version of the Homebrew Channel for a while. I don't think anyone ever actually tried to see if this was exploitable, but I think the chances are high.
-
-
Replying to @marcan42
Find me a javascript bytecode interpreter that isn't exploitable and I'm sure you and I have a business opportunity that will make us filthy rich.
0 replies 0 retweets 2 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.