@DevSlashNulled
上周日,我们向一位研究员颁发了迄今为止最大的一笔赏金——20,000 美元。
当天,Hytale 安全团队收到警报,发现 Hytale 客户端存在一个安全漏洞。我们立即采取了分类处理和调查措施。
我们在同一天推送了修复补丁,经过彻底调查后,未发现任何证据表明该漏洞曾被用于针对任何玩家。
该问题出在客户端如何处理服务器发送的某些图像(PNG)上。恶意或被入侵的服务器可以发送一个特制的图像,在最坏情况下,可以利用它在连接玩家的机器上执行代码。
在修复该问题的同时,我们还对整个代码库进行了多轮额外审查以进一步加强安全,并且正在实施新的检查和流程,以便更早地发现此类问题。
研究员 @0x90sh 撰写了一篇精彩的技术详解文章,完整细节在此:https://0x90.sh/threads/how-a-png-became-a-20-000-hytale-rce.57/
安全和保密性是我们和玩家的首要任务,我们持续在内部投入资源,不断改进我们的游戏和平台。
其中一部分工作是与第三方安全研究员合作。如果你是研究员,有兴趣参与我们的漏洞披露计划,请访问:http://hytale.com/security
@slikey
感谢安全研究员和白帽黑客通过我们的赏金计划让 Hytale 变得更加安全。
我也为我们的团队感到自豪,他们在不到 24 小时内完成了从报告到修复(包括支付赏金)的全流程。
我们将继续致力于赏金计划,并快速处理各类报告。
原文:
上周日,我们向一位研究员颁发了迄今为止最大的一笔赏金——20,000 美元。
当天,Hytale 安全团队收到警报,发现 Hytale 客户端存在一个安全漏洞。我们立即采取了分类处理和调查措施。
我们在同一天推送了修复补丁,经过彻底调查后,未发现任何证据表明该漏洞曾被用于针对任何玩家。
该问题出在客户端如何处理服务器发送的某些图像(PNG)上。恶意或被入侵的服务器可以发送一个特制的图像,在最坏情况下,可以利用它在连接玩家的机器上执行代码。
在修复该问题的同时,我们还对整个代码库进行了多轮额外审查以进一步加强安全,并且正在实施新的检查和流程,以便更早地发现此类问题。
研究员 @0x90sh 撰写了一篇精彩的技术详解文章,完整细节在此:https://0x90.sh/threads/how-a-png-became-a-20-000-hytale-rce.57/
安全和保密性是我们和玩家的首要任务,我们持续在内部投入资源,不断改进我们的游戏和平台。
其中一部分工作是与第三方安全研究员合作。如果你是研究员,有兴趣参与我们的漏洞披露计划,请访问:http://hytale.com/security
@slikey
感谢安全研究员和白帽黑客通过我们的赏金计划让 Hytale 变得更加安全。
我也为我们的团队感到自豪,他们在不到 24 小时内完成了从报告到修复(包括支付赏金)的全流程。
我们将继续致力于赏金计划,并快速处理各类报告。
原文:
@DevSlashNulled
Last Sunday we awarded a researcher with the largest bounty yet, $20,000
On that Sunday the Hytale security team was alerted to a security vulnerability in the Hytale client. We immediately took steps to triage and investigate.
We shipped a fix the same day, and after a thorough investigation we found no evidence it was ever used against any players.
The issue was in how the client handled certain images (PNGs) sent by a server. A malicious or compromised server could send a specially crafted image and, in the worst case, use it to run code on a connected player's machine.
While we were in there we made several additional passes over the entire codebase to harden it further, and are implementing new checks and processes to catch these earlier on.
The researcher @0x90sh, wrote up an amazing write up with the full technical details here: https://0x90.sh/threads/how-a-png-became-a-20-000-hytale-rce.57/
Safety and security is a top priority for us and our players, we're constantly investing internally in ways to improve our game and platform.
Part of that is working with 3rd party security researchers, if you're a researcher and are interested in getting started with our Vulnerability Disclosure Program: http://hytale.com/security
@slikey
Thanks to security researchers and ethical hackers using our bounty program to make Hytale safer.
I am also proud of our team handling this from report to fix including payout in less than 24 hours.
We remain dedicated to our bounty program and handle reports quickly.
Last Sunday we awarded a researcher with the largest bounty yet, $20,000
On that Sunday the Hytale security team was alerted to a security vulnerability in the Hytale client. We immediately took steps to triage and investigate.
We shipped a fix the same day, and after a thorough investigation we found no evidence it was ever used against any players.
The issue was in how the client handled certain images (PNGs) sent by a server. A malicious or compromised server could send a specially crafted image and, in the worst case, use it to run code on a connected player's machine.
While we were in there we made several additional passes over the entire codebase to harden it further, and are implementing new checks and processes to catch these earlier on.
The researcher @0x90sh, wrote up an amazing write up with the full technical details here: https://0x90.sh/threads/how-a-png-became-a-20-000-hytale-rce.57/
Safety and security is a top priority for us and our players, we're constantly investing internally in ways to improve our game and platform.
Part of that is working with 3rd party security researchers, if you're a researcher and are interested in getting started with our Vulnerability Disclosure Program: http://hytale.com/security
@slikey
Thanks to security researchers and ethical hackers using our bounty program to make Hytale safer.
I am also proud of our team handling this from report to fix including payout in less than 24 hours.
We remain dedicated to our bounty program and handle reports quickly.