TechCrunch News 2024年11月08日
Hacker says they banned ‘thousands’ of Call of Duty gamers by abusing anti-cheat flaw
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

《使命召唤》的反作弊系统Ricochet存在漏洞,被黑客Vizor利用,导致数千名玩家被误封。黑客通过发送包含特定关键词的私信,触发Ricochet系统误判,将玩家标记为作弊者并封禁。该漏洞利用了Ricochet基于字符串匹配的检测机制,黑客只需发送包含“Trigger Bot”等关键词的私信即可触发封禁。黑客Vizor表示,他利用这一漏洞进行了数月的恶意封禁,并能够轻松绕过Activision的更新。最终,Activision修复了该漏洞,并解封了误封的玩家。此事引发了对游戏反作弊系统安全性的担忧,也凸显了开发者在设计反作弊系统时需要考虑的潜在风险。

🤔黑客Vizor利用《使命召唤》反作弊系统Ricochet的漏洞,通过发送包含特定关键词的私信,导致大量玩家被误封。

🔎Ricochet反作弊系统使用硬编码字符串作为“签名”来检测作弊行为,例如“Trigger Bot”,黑客正是利用了这一机制。

🎮黑客能够自动运行脚本,发送包含特定关键词的私信,从而实现批量误封玩家,并持续数月进行恶意操作。

⚠️Activision在发现漏洞后修复了该问题,并解封了误封的玩家,但此事也暴露了反作弊系统设计的潜在风险。

👨‍💻一位前Activision员工表示,Ricochet扫描特定签名的方式存在安全隐患,容易被黑客利用,并批评了Activision的安全措施。

In October, video game giant Activision said it had fixed a bug in its anti-cheat system that affected “a small number of legitimate player accounts,” who were getting banned because of the bug. 

In reality, according to the hacker who found the bug and was exploiting it, they were able to ban “thousands upon thousands” of Call of Duty players, who they essentially framed as cheaters. The hacker, who goes by Vizor, spoke to TechCrunch about the exploit, and told their side of the story. 

“I could have done this for years and as long as I target random players and no one famous it would have gone without notice,” said Vizor, who added that it was “funny to abuse the exploit.”

TechCrunch was introduced to Vizor by a cheat developer called Zebleer, who is familiar with the Call of Duty hacking scene. Zebleer said he had been in touch with Vizor for months, and as such had knowledge of the exploit, which he said he saw Vizor using.

For years, hackers have targeted online video games to try to find flaws capable of installing and using cheats that give players an unfair advantage. Some cheat developers, such as Zebleer, sell their programs as a service, sometimes making millions of dollars. In response, video game companies have been hiring cybersecurity specialists to develop and fine tune their anti-cheat systems to catch and ban game cheaters. In 2021, Activision released its Ricochet anti-cheat system, which runs at the kernel level in an attempt to make it even harder for cheat developers to get around it. 

Vizor said they were able to find a unique way to exploit Ricochet, and use it against the players it was supposed to protect. The hacker realized Ricochet was using a list of specific hardcoded strings of text as “signatures” to detect hackers. For example, Vizor said, one of the strings was the words “Trigger Bot,” which refers to a type of cheat that automatically triggers a cheater’s weapon when their crosshair is over a target. 

Vizor said they could simply send a private message — known as a “whisper” in the game — that included one of these hardcoded strings, such as “Trigger Bot,” and get the player they were messaging banned from the game. 

“I realized that Ricochet anticheat was likely scanning player’s devices for strings to determine who was a cheater or not. This is fairly normal to do but scanning this much memory space with just an ASCII string and banning off of that is extremely prone to false positives,” said Vizor, referring to how the game was effectively scanning for banned keywords, regardless of context. 

“The same day I found this, I got myself banned by sending a whisper message on Call of Duty to myself with one of the strings in the message contents,” said Vizor.

Do you develop or sell cheats? Or do you work on anti-cheat systems at a video game company? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Vizor said that at one point they developed a script — “join a game, post a message, leave the game, join a new game, repeat repeat repeat,” as Vizor put it — that would run automatically and ban random players, which allowed them to go on vacation and still ban players. Vizor said that over the months that they were doing this, Activision would add new signatures to its anti-cheat system, which they would find soon after and use to ban players. 

“I was most active with the trolling when [the] Ricochet anti-cheat team would add new string signatures. So if I check the [memory] region and see a new string, I will go crazy with it so they think they are detecting real cheaters,” said Vizor. 

Activision did not respond to a request for comment. 

A person who used to work at Activision, and still has knowledge of the work that the security and anti-cheat team do at the company, told TechCrunch that Ricochet was scanning for certain signatures and “that may have been weaponized against the anti cheat,” essentially the technique Vizor was exploiting.

“If you know what signature the anti-cheat is looking for, I find a mechanism to get those bytes in your game process and you get banned,” said the person, who asked to remain anonymous. “I can’t believe [Activision] are banning people on a memory scan of ‘trigger bot.’” That is so incredibly stupid. And they should have been protecting the signatures. That’s amateur hour.”

Apart from random players, Vizor said they targeted some well-known players, too. In the period of time Vizor was using the exploit, some video game streamers posted on X that they had been banned, and then unbanned, once Activision fixed the bug.  

The company was alerted of the existence of the bug when Zebleer published details of the exploit on X. 

“It was nice to see it get fixed and see unbans,” said Vizor. “I had my fun.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

使命召唤 反作弊 Ricochet 漏洞利用 误封
相关文章