Researchers find vulnerability in Call of Duty: Modern Warfare 3
Luigi Auriemma and Donato Ferrante of ReVuln also showed a vulnerability in the CryEngine 3 gaming platform
IDG News Service - Researchers have found a serious vulnerability in the game "Call of Duty: Modern Warfare 3," and another in the CryEngine 3 graphics platform on which many games run.
Luigi Auriemma and Donato Ferrante of security consultancy ReVuln presented their findings at the Power of Community (POC2012) security conference in Seoul on Friday.
Vulnerabilities in games pose particular opportunities for hackers and even other gamemakers, who may be interested in trying to steal a competitor's players, Ferrante said. Shutting down a competing game could be particularly lucrative for another gaming company.
"This is something we have seen," Ferrante said. "We have a lot of companies that ask for these kinds of denial-of-service attacks to attack competitors. This is really a big concern for companies."
The first problem the pair presented is a denial-of-service vulnerability in Call of Duty: Modern Warfare 3, made by Activision. Auriemma showed in a video how the server administrator received a warning when he remotely crashed the server running the game.
Auriemma masked some details in his presentation so as to not give too much information away, but he and Ferrante are planning to release advisories on the two vulnerabilities next Tuesday, the launch day for "Black Ops II," the latest game in the Call of Duty series. Ferrante said they are willing to work with Activision but aren't going to volunteer the information, since their research is part of their business.
The second problem relates to CryEngine 3, a graphics engine developed by Crytek for use in its own and other companies' games.
Auriemma's demonstration showed an attack on CryEngine 3 within the game Nexuiz. The attack, at the server level, enabled him to create a remote shell on a game-player's computer.
In the demonstration, Auriemma caused a graphic of cat riding a rocket to be displayed on the victim's computer.
"Once you get access to the server, which is basically the interface with the company, you can get access to all of the information on the players through the server," Ferrante said.
In general, game companies don't seem to be very focused on security but rather on performance of the game itself, Ferrante said. Adding security checks can slow down games, and if the companies don't deem the problem a very critical issue, it will usually be ignored.
"These are games that have a very large market," Auriemma said.
Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Forrester Report: IT Leaders Must Regain Trust and Become a Strategic Partner in Commerce Read this report to get the results of a survey of nearly 400 business leaders in commerce-related roles and learn about the new...
- Beyond Cost Savings: Four Compelling Reasons to Expand Virtualization of Your IT Environment In this eBook, find out how other VMware customers have extended their virtualization deployment and have uncovered significant benefits, such as simplified IT...
- The Great Video Conferencing Debate: Cost Vs. Quality With new video conferencing solutions available for small and medium businesses, it is possible to have a higher standard of video conferencing without...
- The Cisco Unified Workspace The Apple iPad started something. While revolutionary in itself, it was also a tipping point for many industry trends that had been emerging...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Consumerization of IT White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!