DEF CON 25 - Manfred - Twenty Years of MMORPG Hacking Better Graphics and Same Exploits

แชร์
ฝัง

ความคิดเห็น • 88

  • @JanbekOzturk
    @JanbekOzturk 2 ปีที่แล้ว +129

    Don't forget to grab yourselves a cup of YORKSHIRE TEA gents

  • @Gastell0
    @Gastell0 2 ปีที่แล้ว +34

    The first 10 minutes is like really reading Ultima Online protocol specification =))

    • @adia.413
      @adia.413 2 ปีที่แล้ว +1

      This is exactly how we used to hack into Maple Story as well

  • @Ozmala1
    @Ozmala1 2 ปีที่แล้ว +147

    Bet this gets a few more views due to spiffs video 😄

    • @Chlorate299
      @Chlorate299 2 ปีที่แล้ว +9

      Guilty as charged.

    • @xFallenRagex
      @xFallenRagex 2 ปีที่แล้ว

      Partially, while yes the spiff vid, it was a game he exploited and played i remember that drew me to find out more information on him. And I rememeber that event clearly lol

    • @MickHaggs
      @MickHaggs 2 ปีที่แล้ว +2

      Reporting in
      07

    • @JaredNagle
      @JaredNagle 2 ปีที่แล้ว +4

      love how innocently he says "close your eyes" and just trusts the internet won't pause the video

    • @pauljones9150
      @pauljones9150 2 ปีที่แล้ว

      I'm here

  • @elbarto8282
    @elbarto8282 ปีที่แล้ว +7

    He had his lawyer on the phone constantly telling him what not to talk about🤣🤣🤣

  • @IGM_Dex
    @IGM_Dex 8 หลายเดือนก่อน +2

    Brilliant presentation even three years on.

  • @hippopotamus86
    @hippopotamus86 ปีที่แล้ว +14

    I once used the negative integer exploit... on a bitcoin exchange and it worked. This was back when bitcoin was worth $2 each. I did it with $400 as my first test and then told the exchange. Got to keep the money. Stupidly sold it for beer money.

  • @rolerroleris533
    @rolerroleris533 2 ปีที่แล้ว +27

    Just when i started playing ff14...
    Also, quite strange how runescape isn't in here.

    • @noneofyourbusiness8625
      @noneofyourbusiness8625 2 ปีที่แล้ว +7

      Glad I'm the only one thinking about runescape, he must be hiding a huge exploit he knows and this his real bread and butter 😂

  • @DomaninNicola
    @DomaninNicola 2 ปีที่แล้ว +2

    you said he posted on his TH-cam him hacking the game live? where can I see the videos? i can't find his channel

  • @Stejin
    @Stejin 2 ปีที่แล้ว +13

    WoW private Server, fun with package editing: character creation with a space inside... makes you unbanable with ingame commands... Or stuff like, you "reuse" some action and execute a AOE spell in rapid fire... (killed a invisible gm following me... was fun XD)

  • @NightfallChease
    @NightfallChease ปีที่แล้ว +1

    Which tools do you use to change packets u send from ur client to the server

  • @ramsaybolton9151
    @ramsaybolton9151 2 หลายเดือนก่อน +1

    It's sad that people do this to destroy the experience for other players. This is why I believe in violent punishment.

  • @asmongoldsgold2402
    @asmongoldsgold2402 2 ปีที่แล้ว +4

    i understood nothing and was still interested.

  • @rjbrake
    @rjbrake ปีที่แล้ว +2

    The VLC installer is sitting onthe thumb drive

  • @ZippyChannelgaming
    @ZippyChannelgaming 2 ปีที่แล้ว +2

    45:19 45:31 dude in the background is getting schwifty

  • @subtomeiwillsubtoyou4682
    @subtomeiwillsubtoyou4682 3 ปีที่แล้ว +5

    wow

  • @schotic
    @schotic 5 วันที่ผ่านมา

    I'm going to learn how to do this.

  • @BraveLittIeToaster
    @BraveLittIeToaster 6 หลายเดือนก่อน

    Is that vista?!

  • @Sneybrot89
    @Sneybrot89 10 วันที่ผ่านมา

    Help people; How do I contact him? it's for a task

  • @wcbuerste7
    @wcbuerste7 2 ปีที่แล้ว +3

    How come the games don't encrypt their packets properly?

    • @givvygvidon7279
      @givvygvidon7279 2 ปีที่แล้ว +8

      They do, but the weakness is the client has functions/routines that are responsible for encrypting and decrypting the packets or the game wouldnt function correctly. A reverse engineer can locate those functions and intercept them using hooks which eliminates all of that work.. you don't need to understand how the encryption works fully to do a MITM attack.

    • @iUUkk
      @iUUkk ปีที่แล้ว +5

      A game shouldn't rely on packet encryption though. As a developer you need to logically prevent exploits on the server side because anything client side is just a cat and mouse game.

    • @Neffins
      @Neffins ปีที่แล้ว +2

      @@givvygvidon7279 Is there a place/source to learn more on this?

    • @jesuschrist1501
      @jesuschrist1501 5 หลายเดือนก่อน

      because that's pretty much impossible. no matter how much you encrypt the packets client-side wise you will always lose to a motivated hacker who will reverse engineer the game's source code and hook the functions. the video goes over the part about the game call rift online, he said they got a gold star for encrypting their packets but the very beginning function that does it all you can basically hook them and that's gg. now this isn't all doom and gloom, mmo game companies need to not be lazy and do server side security. it isn't much to tell the server that it will not be accepting negative values, idk why they don't do that.

  • @michaelchappell6305
    @michaelchappell6305 ปีที่แล้ว

    Accelerando!!

  • @michaelchappell6305
    @michaelchappell6305 ปีที่แล้ว

    Manfred Macx?!

  • @yanastase
    @yanastase 2 ปีที่แล้ว +6

    This guy is fucking amazing

  • @birdzbeeztreez4248
    @birdzbeeztreez4248 ปีที่แล้ว +1

    What was the name of the Gm, who coined the name Manfred? that name could be interesting

  • @mriananderson
    @mriananderson ปีที่แล้ว +3

    This dude is a genius, but the real secret with him is to play his videos at 1.25 x- 1.5x speed ;)

  • @noepopkiewicz901
    @noepopkiewicz901 ปีที่แล้ว +4

    He was reverse engineering MMO game clients and creating own tools for real time DLL hooks, as a teenager, for shits and giggles (at first)? Sounds like this story is missing some parts.

    • @savedmage
      @savedmage 11 หลายเดือนก่อน +1

      Darknet Diaries featured him and his story in two episodes. He goes much more in-depth there.

  • @drygordspellweaver8761
    @drygordspellweaver8761 2 ปีที่แล้ว +5

    anyone have any idea how to build the 'client side dll hook' he mentioned?

    • @ricardonacif5426
      @ricardonacif5426 ปีที่แล้ว

      Yes

    • @drygordspellweaver8761
      @drygordspellweaver8761 ปีที่แล้ว +1

      @@ricardonacif5426 comment was a year ago, I've pretty much figured it out by now haha

    • @yunusaydin5177
      @yunusaydin5177 10 หลายเดือนก่อน

      @@drygordspellweaver8761 so how

  • @Netbase2000
    @Netbase2000 2 ปีที่แล้ว +1

    I imagine because of the a player hosts a game network warframe might be another good contender

  • @mannycalavera121
    @mannycalavera121 ปีที่แล้ว

    Wish I were smarter

  • @ShadoSpartan44
    @ShadoSpartan44 ปีที่แล้ว +2

    it was hard to get through that beginning, he sounded so bored and bummed to be there. lucky for him the topic is worth hearing about

  • @Netbase2000
    @Netbase2000 2 ปีที่แล้ว +1

    I wonder if he ever got into eve online. You could make a fortune if anything like this works on eve. And I imagine he could. Eve are just numbers

    • @1000_Gibibit
      @1000_Gibibit ปีที่แล้ว +3

      EVE developers created their own os to run the game servers. I doubt they forgot to do server side checks on all the command that you can send

    • @nogaxeh6
      @nogaxeh6 ปีที่แล้ว

      A bit late, but while it may be possible to have fun with warframe, I know of friends who have tried to hack the game several ways (mostly in Solo, so hosted locally), and most of the time their accounts ended up getting banned. so there definitely are checks in place.

  • @3vilL33T7
    @3vilL33T7 2 ปีที่แล้ว +3

    "provide service that puts the bot farmers out of business?" Nice to see people still believe in Santa Claus 🎅😂

    • @ZacklFair
      @ZacklFair ปีที่แล้ว +1

      I mean technically if you can mute bots for everyone or straight up kill them (especially on a pvp grief server)...

  • @jamestomlin5525
    @jamestomlin5525 2 ปีที่แล้ว +7

    With all the crap going on at wow now, hackers need to hit the servers hard and break the game.

    • @jamestomlin5525
      @jamestomlin5525 2 ปีที่แล้ว

      @@itdepends604 this
      Let people solo mythic raids lol

    • @Neceros
      @Neceros 2 ปีที่แล้ว +1

      what is happening?

    • @jamestomlin5525
      @jamestomlin5525 2 ปีที่แล้ว

      @@Neceros ...... look it up man is all I can say, it's baaaad

    • @Neceros
      @Neceros 2 ปีที่แล้ว +1

      @@jamestomlin5525 how can I when you won't tell me

    • @jamestomlin5525
      @jamestomlin5525 2 ปีที่แล้ว

      @@Neceros just look it up dude, you're either trolling or your head is in the sand

  • @Neceros
    @Neceros 2 ปีที่แล้ว +14

    Not the best speaker, but the information was very interesting

    • @klarnorbert
      @klarnorbert 2 ปีที่แล้ว +7

      Not everybody is extrovert. He's clearly have knowledge, he just not used to talk to big crowds.

    • @drygordspellweaver8761
      @drygordspellweaver8761 2 ปีที่แล้ว +8

      WDYM he's a great speaker. Clear, relaxed, Had the audience cracking up.

    • @adamkatt
      @adamkatt ปีที่แล้ว

      @@klarnorbert He clearly has knowledge unlike you.

  • @jamestomlin5525
    @jamestomlin5525 2 ปีที่แล้ว +24

    >be ethical
    Lol dude, hacking someone's plot of land and removing them and then turning around and selling that plot of land for 2k dollars is about as far from ethics as you can get in a game 🤣

    • @zippolight2002
      @zippolight2002 2 ปีที่แล้ว +23

      He did say that he did some unethical things early on. That's what he was talking about.

    • @jamestomlin5525
      @jamestomlin5525 2 ปีที่แล้ว +2

      @@zippolight2002 true. Still, this is nuts man

    • @DarakayGamingStudio
      @DarakayGamingStudio 2 ปีที่แล้ว +4

      @@jamestomlin5525 he said he would do that to houses abandoned for over 5 week, that were ready to collapse, so he wouldn't destroy houses from players who were playing, i think for 2 reasons, 1 ethics, 2 avoid suspicion

    • @jamestomlin5525
      @jamestomlin5525 2 ปีที่แล้ว +7

      @@DarakayGamingStudio I know I know lol I'm just being a little shit. Really, props to the guy. He's incredibly smart to have not only done this but been paid for it as well

  • @GNParty
    @GNParty 2 ปีที่แล้ว

    "Same" exploits. 😑

  • @vast634
    @vast634 ปีที่แล้ว +3

    Sound like he lives off of lazy Server programmers, that dont check any packet for plausible parameters and what players they are linked to...

  • @skata100
    @skata100 ปีที่แล้ว

    Bunch of leaked methods all compiled into one presentation lmao

  • @Netbase2000
    @Netbase2000 2 ปีที่แล้ว +4

    Awful audience

  • @whizzingbye
    @whizzingbye ปีที่แล้ว

    Hold tight my little bit to old socially awkward mmo guys. Slayer by day looking for weird bots and porn at, the rest of the time. While hiding your 2.7 year login time on runescape.#nolyfefml

  • @ColorfulEscapades
    @ColorfulEscapades 2 ปีที่แล้ว

    You are just an actor

  • @victorygo
    @victorygo 2 ปีที่แล้ว +2

    He's a criminal lol don't sugarcoat it