Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length

 
Advanced search

27117 Posts in 1549 Topics- by 1992 Members - Latest Member: pokemon

May 22, 2013, 04:34:42 PM
Team Meat ForumsSuper Meat BoyMeat TalkSuper Meat World has been hacked...
Pages: [1] 2 3
Print
Author Topic: Super Meat World has been hacked...  (Read 15531 times)
Two Hacks
Level 1
*
Posts: 138


Steam: Two Hacks


View Profile
« on: December 22, 2011, 07:15:10 PM »

What the hell? This isnt good news, but I dont know what to think of it... 

« Last Edit: December 22, 2011, 08:24:20 PM by Two Hacks » Logged

Try my chapter Unholy Mountain: http://supermeatboy.com/forum/index.php/topic,2203.0.html

Other chapters of mine:
Instantanious
The Collection
Dude What
Crust-Lee-Smile
TunnelingEffect
Level 2
**
Posts: 287


Goodbye


View Profile
« Reply #1 on: December 22, 2011, 07:31:54 PM »

Aww sheeyit, for real? Is there an article somewhere?
Logged

Hello
Two Hacks
Level 1
*
Posts: 138


Steam: Two Hacks


View Profile
« Reply #2 on: December 22, 2011, 07:33:59 PM »

Look at Super Meat world. No article. Saw this for myself. Also: http://twitter.com/SuperMeatBoy

last few posts were some guy talking to ed about why Super Meat Boy uses MySQL.

EDIT: Proof: http://steamcommunity.com/id/112233112233/screenshot/630734416928593105
« Last Edit: December 22, 2011, 07:43:33 PM by Two Hacks » Logged

Try my chapter Unholy Mountain: http://supermeatboy.com/forum/index.php/topic,2203.0.html

Other chapters of mine:
Instantanious
The Collection
Dude What
Crust-Lee-Smile
StealthAngel667
Level 4
****
Posts: 442


^More tea, sir?


View Profile
« Reply #3 on: December 22, 2011, 08:08:04 PM »

Seems pretty harmless, since the main game isn't affected. I think we should just avoid the hacked SMW levels for now. Probably just some guy doing his best at proving a point.
Logged

Jookia
Level 0

Posts: 5


View Profile
« Reply #4 on: December 23, 2011, 04:16:19 AM »

Hey guys, I'm Jookia from the Facepunch forums. Specifically, the programming subforum of it. You can read about what happened here, but I'll sum it up: Team Meat didn't keep their database login server side and restrict what users could do, and swift and shift AKA charliesome found out the login details to the database (it's in the game's data files).

Unfortunately when he notified Team Meat via Twitter, they replied as if this wasn't a problem, so he posted it on the forums to show this (we programmers find these kinds of things funny), and so a user by the handle of 'high' posted the full login details (charliesome hid them from his screenshots) since Team Meat wasn't going to do anything, and we all pretty much stared at the details wondering who would screw up the database, us being too polite to do that kind of stuff.

I spotted this on Twitter, showing that Team Meat acted as if this wasn't a security hole. I personally took away from this (and I'm sure a few others did to) that Team Meat didn't care about people being able to screw over other players.

Then 'Parad0x0217' did what you're all concerned about. Fortunately, 'high' (the guy who released the login details) had made a backup of the entire database earlier and uploaded it to the forum. I'm not sure if this was on purpose or because he tried after I failed at doing a backup myself before all this went down.

Anyway, we have the backups (they're publicly avaliable here), so I guess we're in luck.

But the problem is that Team Meat doesn't actually seem to care that this was possible to do. This is a common thing, you may see it in the news with Microsoft Windows' zero day bugs, where Microsoft neglected fixing them until something bad actually happened.

Hopefully Team Meat will release an update with a more secure front which will limit what the user can do (possibly by a PHP API, I'm not sure), but the current way isn't the right way to do things.
Logged
Tobba
Fresh Meat

Posts: 1


View Profile
« Reply #5 on: December 23, 2011, 05:53:20 AM »

Someone blanked out all names with a -, and then I became incredibly bored and did this:


I'm still suprised Team Meat didnt know better, any developer that even thinks about doing what they did should burn in hell
« Last Edit: December 23, 2011, 05:55:42 AM by Tobba » Logged
geel9
Fresh Meat

Posts: 1


View Profile
« Reply #6 on: December 23, 2011, 09:18:55 AM »

Vulnerable bro
Logged
Kaede
Level 0

Posts: 54


View Profile
« Reply #7 on: December 23, 2011, 11:34:27 AM »

This is sad (devs reaction to the security issues). Hopefully there will be a happy ending, but it could have ended with a no database backup scenario and all levels being lost.
But tbh the whole level portal was sad from the very start.

edit : (sorry I edited my post which mentionned Steam cloud, my rant was kind of useless) nah there is no Steam cloud support (at least on PC), check better.
« Last Edit: December 23, 2011, 12:01:13 PM by Kaede » Logged
Genesis
Level 0

Posts: 80


View Profile
« Reply #8 on: December 23, 2011, 11:56:25 AM »

Sorry for offtopic.
But I think Steam Cloud works for my SMB.
At least it says so.
I hope they'll finally try to fix some issues in their game, it crashes very often.
Logged
TheGreatFreshLOL
Level 0

Posts: 57



View Profile
« Reply #9 on: December 23, 2011, 12:38:31 PM »

Wow.
Just. Fucking. WOW.
Team Meat just casually disregarded a guy who hacked into their database?
Either 1. Team Meat is goddamn retarded or 2. They just don't care. And it's probably the latter.

And thus...
*facepalm into oblivion*
Logged
Two Hacks
Level 1
*
Posts: 138


Steam: Two Hacks


View Profile
« Reply #10 on: December 23, 2011, 03:24:24 PM »

Would it have actually been better if they overreacted and raged? 
Logged

Try my chapter Unholy Mountain: http://supermeatboy.com/forum/index.php/topic,2203.0.html

Other chapters of mine:
Instantanious
The Collection
Dude What
Crust-Lee-Smile
Sr. Domi
Level 4
****
Posts: 418



View Profile
« Reply #11 on: December 23, 2011, 03:40:36 PM »

Would it have actually been better if they overreacted and raged? 

Are you like, defending Team Meat? What you say its stupid. Its not about how they acted calm, is that they didnt care at all and made a system with a very low security.

Seriously, SMB is awesome, but has a lot of negative stuff.
Logged

TheGreatFreshLOL
Level 0

Posts: 57



View Profile
« Reply #12 on: December 23, 2011, 04:03:50 PM »

Would it have actually been better if they overreacted and raged? 

Yes. That would show that they care.
Logged
Two Hacks
Level 1
*
Posts: 138


Steam: Two Hacks


View Profile
« Reply #13 on: December 23, 2011, 07:30:47 PM »

Would it have actually been better if they overreacted and raged? 

Are you like, defending Team Meat? What you say its stupid. Its not about how they acted calm, is that they didnt care at all and made a system with a very low security.

Seriously, SMB is awesome, but has a lot of negative stuff.

No, I'm not trying to defend them, but I'm just saying you guys may be overreacting to what isnt a very big deal. Apparently the people who hacked into the server were able to change the name of the levels, and where they're put, but they couldn't delete anything. Also, its pretty evident that Tommy was already aware of this security problem, he just doesn't think its worth spending his time on. I don't agree with this how he's doing this, but I'm not going to get angry at them.
Logged

Try my chapter Unholy Mountain: http://supermeatboy.com/forum/index.php/topic,2203.0.html

Other chapters of mine:
Instantanious
The Collection
Dude What
Crust-Lee-Smile
bullexcrements
Level 1
*
Posts: 199



View Profile
« Reply #14 on: December 24, 2011, 07:31:30 AM »

I'll quote Edmund:

Have you seen this thread talking about your SQL database on something awful http://forums.somethingawful.com/showthread.php?noseen=0&threadid=2803713&pagenumber=258

Yeah, sadly that really fucked things up for a few hours in super meat world but it was all fixed before i even woke up today.

it sucks when people attempt to destroy the awesome creative things people make, and even more so when other people went out of their way to make this tool for fans as a thank you, asking nothing in return.

the good news is tommy had full backups of everyones levels, so even after they deleted everyones work he was able to return them with a single click and fully block all incoming attacks.

in the indie game the movie trailer im quoted saying that i desperately want to make friends but i dont want the actual interaction because i probably wont like them. this is one of many reasons why i feel that way.

there are a lot of sad people out there that love to destroy things to make themselves feel better, in the end it doesnt make them feel better but makes things worse for everyone else.

it really sucks that people are like this,
merry xmas i guess.



EDIT: and personally I'm sick and tired of people who always want to prove somtehing. Sit down, jerk off and fuckin relax. That's my advice
« Last Edit: December 24, 2011, 07:35:36 AM by bullexcrements » Logged

Pages: [1] 2 3
Print
Jump to:  

Theme orange-lt created by padexx