 |
|  |
 |
|
Googlie
|
 |
Commanding Officer, CRYPTEIA
Apr 1999 time: 21:30
|
|
Somehow a hacker has broken the encryptions of the passwords in the gamesave file, and has e-mailed them to Tassadar, who immediately contacted me. (Tass does not know the identity of the hacker, but that individual did reference the posts surrounding "the Tassadar Manouever" and prefaced his e-mail - which Tass forwarded to me - with "You'll find this of interest"
Disbelieveing that this could be done, he tried them, and to his amazement they worked. To my amazement as well, when I tried them after responding to tass "but they are nor the correct passwords"
We (Tass and I) have been discussing what to do for the past couple of hours.
With one exception, the hacked passwords are not the actual ones that I set (and which I sent to faction leaders) but they do open the turns). To verify this I have (will) send the alternate hacked password to each leader and you can confirm this.
As a result, Tass will immediately have to quit the Hive.
The role once envisioned for him to assist me as co-moderator will be revived, and he and I will work together to ensure the best gaming experience for the players.
(The timing is appositre as well, as I will be off for three weeks from Sept 2nd with almost no internet access)
So Tass will soon be applying to each faction for accreditation, and I am asking the private forum moderators to give him the same rights and priveleges that I have.
Feel free to post comments in this thread after you have confirmed the alternate password
Googlie
|
|
|  |
 |
|  |
 |
|
Googlie
|
 |
Commanding Officer, CRYPTEIA
Apr 1999 time: 21:30
|
|
Well - to amswer a number of questions:
the "informant" is:
hackerz0r@yahoo.com
or at least it displayed as: (RazorBlade:hackerz0r@yahoo.com)
The Hive's was the one that matched the original
And while some may be able to live without succumbing to temptation I think for most of us the instinct would be to try them to see if Razor blade was full of it or not.
My theory (unproven, but having "slept on it") is that RB knew the Hive password, and from that knowledge deduced where in the file the password interrogation and answer lay, and added these alternate passwords, as they bear little resemblance to the originals.
I have (will) also e-mail them (their respective ones) to the alternate turn-players, Maniac, Kody (oh - no need to as that didn't have an alternate, being the original), johndmuller et al
And Archaic: Tass already (now) has access to the PUT gameturns - it's only the Private Forums he can't visit.
I did test these alternate passwords on a number of extant PBEMs I had on file to see if they were "backdoor" generic, and none worked (see Buster's reasoned reply in the CGN forums, reproduced below):
***************************************
quote: Originally posted by Buster in the CGN Froum
This is a problem of course but not exactly surprising. I don't imagine Reynolds used a very heavy encryption scheme so knowing how the basic file-structure looks I imagine a determined probably would be able to break it in a reletively short time.
The reason this is the first time it comes up is probably that noone with the needed skills bothered to try to break it yet.
The fact that other passwords than the actual one works could be either because they are backdoors (generic passwords that always work), this could be tested by checking some other pbems that contain the same factions, or because the password has to match some check or pattern stored in the file rather than the original in which case there would potentially be several fits besides the original and you could find one by bombarding it with a dictionary.
The last is the least worrying as at least it means that you need a hacker with skills and special software to crack the passwords of a given game. If the first is true we have a situation where if the pws get out every game is compromised.
Suggest you check it by creating a pbem using same factions but other passwords. Check if the wrong but working passwords you were given also work on the other game. If so you have a backdoor and these passwords should be kept secret and tassador should take whatever action he can to ensure they do not get out. If they don't work - it is simply a mattter that there are several matches besides the original. In this case all we now know is that the passwords can be cracked if you know how and have the tools.
As said the last is not really surprising and the reason we have not heard of it getting done before is probably that the measures needed are beyond what users without special skills can do.
If this hacker guy were to make a "how to easily extract a password in three easy steps" guide or a program doing it automatically and release it we would now have all pbems open to everyone.
Tassador should urge him not to do so. He will not earn fame inside the small AC community who will be the only ones who cares. As said - if you are a skilled hacker I don't imagine AC saves are any kind of major challenge compared to whatever else they manage to crack out there and his efforts won't get him any appreciation.
All it will be is just be another nail for the games still undeserved coffin.
So far we have been nicely free of savegame editors, password extractors etc. because I guess the ones interested were a small group so the few in the group who could potentially do such were decent enough not to. Lets hope it stays that way. |
Last edited by Googlie on 25-08-2003 at 18:23
|
|
|  |
 |
|
johndmuller
|
 |
Capitol Hill, Colony of DC
Feb 2001 time: 00:30
|
|
Well isn't this fun?
I must have read Googlie's email about this just before Poly went down for the day, cause it seems that I've had entirely too much time to think about this, mostly reinventing the wheels that have already been posted here.
In our (pirates) case, the alternate password is so appropriarte that the notion that it just happened to parse into the same encrypted internal representation as the real password is incredibly difficult to believe, unless the encryption is so totally simplistic that thousands of alternate passwords exist and the hacker could have his pick. I don't know about the rest of your alternates (and don't tell me what they are either), but ours was every bit as directly related to our faction as the ones the Googster himself assigns in games he CMN's, so if yours were also closely related to your faction, then the odds would infinitely surpass astronomical. Of course, only the PUT and ourselves have factions that a non SMAC person would easily understand, so oddly tangential passwords might qualify too - in fact, any non-gibberish alternate pw is most unlikely in this scenario. Perhaps your alternate pw's are all gibberish, and ours was a once in a million lifetimes coincidence, but somehow I expect you all to have Googlie style passwords.
I tested our alternate out in 1 other PBEM .sav file I had and to my relief it did not work, but that doesn't really rule out there being a modest set of alternate pw's for each faction that rotate according to some arbitrary determinent that each game generates and saves, so until a lot of people have tried out a lot of games, the possibility of there being hardwired passwords of some sort can't be completely ruled out (although evidence to date is encouraging).
I can imagine that the game could have some kind of undocumented (and presumably unused) provision for alternate passwords - it would actuallly be useful - a provision that didn't survive the final cut, but much of whose code is still in the program. I can easily imagine a hacker armed with a real password tracing the code while it executed the password check and figuring out what it did. If there was such vestigial alternate pw code in there, it would make it very easy for the hacker to use that info to know how &/or where to stuff their new ones.
Having had too much time to think about this, I even thought of a scenario where a very good hacker (and at this point you have to ask yourself why a very good hacker would bother with this) could modify the save file in such a way as to create a backdoor into our computers (using one of those techniques you read about like buffer overflows, however they do their thing) - and this would be one of the hard to believe parts - and having gotten this backdoor into our computers while we are running this modified save file, the hacker uses his control of our computer only to fool it into accepting one of these alternate passwords, not to attack Microsoft or the Pentagon, or to transfer our life savings to his Swiss Bank account (Have you checked yours today?), but just so they can impress Tass with how good a hacker they are.
Assuming that the Pandora's box of hardwired backdoor passwords has not been discovered here, that it is some hack or other that would have to be done to each each PBEM separately - assuming that, the next most disturbing thing is that if this exploit entailed somehow inserting these alternate passwords into the game file, that implies the complicity of one of the players with access to the turn file that ultimately is used as the "real' turn and passed along through the chain. Unless some of the factions have strange (and probably prohibitively time consuming) turn handling procedures, we are talking about a very limited number of people, especially if it were to develop that this exploit only worked after a certain point in the game, and save files from before that point would not respond to the new pw's.
The point here is that if this required the modification of the save file to work, which seems possible, and maybe even probable, then it also required some one of us to do it consciously (i.e. the hacker is one of us) or else it required one of us to knowingly replace the game file with one they had gotten from a Hacker and then send it on to the rest of us unsuspecting innocents to run on our machines with potentially really unpleasant consequences. How irresponsible can you get? I really hope that one of those incredibly unlikely scenarios is true instead.
|
|
|  |
 |
|
Comrade Tassadar
|
|
Greetings!
Yes, this was quite shocking as I thought it was from someone (maybe Looniversity or Drones) wanting to flame me, but when I opened it...The words shocked me.
Maniac: I would not have taken the email seriously had the passwords not worked.
MWIA: Unfortunately, the only virus I have a sample of is SirCam, but thats not effective enough for this infidel 
Archaic: Googlie and I suspected this, however all I need is access to your save files which I now already have. Your forums are unimportant to me.
Hercules: I do appreciate you upholding democracy and if I do indeed get access to your forums, I will wave a magick wand and near a certain base, a fountain of Xenorum shall appear which shall feed all of Peace!!!
I don't know why anyone would take the time to hack an ACDG file. It seems that there are more important targets out there, and obviously someone in the ACDG (probably in the Hive) did set out to hack these files.
As I asked GooglieGod: Why would they send them to me? I do know that certain peoples propaganda against me did give me a reputation of a cheater, however I've already turned myself in once...It makes no sense.
And who could it be? The few people I suspect (and have talked with GooglieGod about) are HIGHLY unlikely. For a moment, I did suspect someone, in a twisted plot to try to get me thrown out of the ACDG, did this.
Anyway, I am deeply shocked and appaled at the actions of this person and if they thought they were doing me any favors....I did not and do not want them. If you are reading this...Heed my call. While I may become a god due to your actions, they have tainted the game and if your intentions truely were to please me in some perverse way, I would be more pleased if you did not do any other actions of this sort.
Googlie: I doubt that the passwords were created through a generator as the password for CyCon and the backdoor for it were too different. However I may be wrong.
Last edited by Comrade Tassadar on 26-08-2003 at 02:58
|
|
|  |
 |
|
johndmuller
|
 |
Capitol Hill, Colony of DC
Feb 2001 time: 00:30
|
|
I tested several of the earliest files I had in my archives and had the following results.
Using a turn said to be 2102 from the original cut of the game, I was unable to open our game file with the alternate password.
Using a turn said to be 2102 from the restarted version of the game, I was able to open the turn with the alternate password.
I'm not sure what this proves, as the restarted version of the game had different passwords and being a restart could also have created different backdoor hardwired passwords if the game has something like that already built in by Firaxis. So if it needed the file to be altered for the hack to work, it happened in the first turn, before it got to us.
Since we are one of the last factions in turn order, about all I think I can say for sure is that Buster and the Drones are definitely innocent of altering the file, as they had not yet had a chance to touch it. I know that I didn't insert any funny stuff into the save file, but it would take a save file from earlier in turn to show that - certainly if Googlie still has the original file he sent out, that could be very revealing.
|
|
|  |
 |
|
Comrade Tassadar
|
|
Hmm...That leaves the Hive as the most likely to have someone whom altered it, with the next being possible and the next being highly unlikely.
|
|
|  |
 |
|  |
 |
|  |
 |
|
johndmuller
|
 |
Capitol Hill, Colony of DC
Feb 2001 time: 00:30
|
|
quote: Originally posted by Maniac
quote: So Buster's theory that there are prolly several combinations that work with any one "official" password would seem to hold true. |
I don't understand what that means. Do you mean that for example if "victory" was the official password, that "yrotciv" would also work? How then can the complete non-resemblance between the official and alternate passwords be explained? |
If you're still wondering about this mechanism, consider this simplistic version:
Say the password is "hack', that is represented in memory as some string of bits, recognizible as "hack" if considered to be a string of letters. At the same time, it could be considered also as a string of bits representing a number and operated on mathematically, say by multiplying it by 37. The computer saves your password as whatever that string of bits would be ("hack" * 37), or perhaps only selected bits of that result, like the rightmost 8 bits.
Most likely it would no longer be translatable into regular alphabetic characters anymore and would be difficult for anyone to locate in a dump of the file and recognize as a password. Even if someone did, they would not necessarily know how to work backwards to the original "hack". Thus, you have reasonably decent security without needing a PhD.
Given a simple enough algorithm and/or especially if you save only a portion of the result, it is entirely possible for another input, like "wild card" to also generate the same internal representation ("wild card" and "hack" are just an example and in all likelihood do not generate the same result when multiplied by 37 and stripping selected bits).
Anyway, if the hacker read the code and discovered the 37 multiplier, the bit selection and the storage location for the encrypted version of the passwords, they could conceivably work backwards to figure a string which would generate that encrypted result. In all likelihood, it would be gibberish-crap, but with the right software and a dictionary-like file, it would be possible to locate any real words or phrases that fit the bill, if any exist, and they could then take their pick and email them to Tass, who has demonstrated a willingness to go public with such info. (If they had mailed them to the Pirates, maybe the Cuspidore would suddenly act like he knew what he was doing (as well as what everyone else was doing) instead of acting like a normal boorish lout!)
So what we need to ask in this witch hunt is: Who is playing like they know what they are doing .
Last edited by johndmuller on 26-08-2003 at 04:26
|
|
|  |
All times are GMT. The time now is 05:30. Apolyton Time is 00:30. |
top of page
|
| archivepost |
|
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is ON
vB code is ON
Smilies are ON
[IMG] code is ON
|
|
|
|
|
|