Skip to main content
GameDev.net gamedev.net
🔒 Locked

Keeping files safe

Started by Fixxer Aug 16, 2005 at 5:26 PM 13 replies 1.7k views
Original Post
Fixxer
Fixxer
How can I make my own pack files or cabs so that my programs can access the files, but the user cannot?
Sneftel
Sneftel
This comes up a lot. Some of the points that are always made:

* It is utterly impossible for you to protect your game data from a determined hacker.

* It's not especially useful to try to protect your game data. Note that many commercial games don't bother to obfuscate their assets in any way, and very few try for any real sort of encryption.

* If you reeeally want to foil people who might want to steal your game data but don't know very much about computers, just put your data in a ZIP file with a different extension or something.
Fixxer
Fixxer
Well I already know one way of preventing people from editing the script files and playing online, the server will check the last edited dates on the script files and if they are different from what the server is instructed to check for then it will re-download the files and then log the user in. I suppose your are right, its just that my favorite game is being ruined by people who are just editing the game scripts after they have logged into the server, and I want to try to prevent that from happening, or atleast make it harder.
Sneftel
Sneftel
Quote:
Original post by Fixxer
Well I already know one way of preventing people from editing the script files and playing online, the server will check the last edited dates on the script files and if they are different from what the server is instructed to check for then it will re-download the files and then log the user in.

This is moderately easy to overcome, by altering the portion of the code that checks the last-edited dates.
Quote:
I suppose your are right, its just that my favorite game is being ruined by people who are just editing the game scripts after they have logged into the server, and I want to try to prevent that from happening, or atleast make it harder.
The way you do this is by designing your game not to trust clients to maintain game state. All game state should be maintained by the server, and all changes to the game state should be checked by the server to ensure that they are feasible.
Fixxer
Fixxer
yea like if a user is sending packets that contain the data for 100 new bullets since the last packet was sent (suggesting that the user has edited the script to allow them to shoot at an unreasonable rate, clearly not the rate the game has set) then to auto ban them.
Oluseyi
Oluseyi
Why auto ban? Just reject the data, send a message to the user and disconnect the client. Keep those subscriptions rolling!
Toolmaker
Toolmaker
Quote:
Original post by Fixxer
yea like if a user is sending packets that contain the data for 100 new bullets since the last packet was sent (suggesting that the user has edited the script to allow them to shoot at an unreasonable rate, clearly not the rate the game has set) then to auto ban them.


Did you ever think about latency? Most games use UDP, and UDP(And neither does TCP) care about the packets you send. If during the update loop 20 packets arrive in 1 giant lump, UDP will just take the data, stick it together and hand it over to you.

You'll then need to filter and split the data. So if latency occurs, you might need to split a bunch of packets and process it. However, if these packets together contain 100 gunfire events, you ban a user that has done nothing wrong.

Just do as many others suggested: Check all the data the client sends to the server on the server aswell. Never trust the client. Just reject the exessive amount of data(So, it might be tuned down to 5 bullets fired, instead of 100). You might want to keep a tolerance filter, so if it happens 10 times per minute, you could kick the user because of possible cheating. Don't ban users because of that, since your game will be so popular noone plays it.

Toolmaker
 
w00f
w00f
I'd like to point at stuff like MacroQuest as examples that no game is safe. The EQ security team worked fairly hard to secure the game, including encrypting lots of data in RAM and server-side validation and all that. And Sony are fairly experienced as MMOs go.

Probably the easiest way to pack your game data so that the user can't edit it is just to put it in your own binary format. Not foolproof, but it prevents casual meddling. Of course, casual meddling can be a lot of fun (like tweaking unit definitions in RTS games or weapon defs in JK2 or etc), so keep that in mind.

Anyway, AFAIK the reason most games put stuff in .pak or .cab files is just so that the data is clumped on the HD and can be read faster.
e-u-l-o-g-y
e-u-l-o-g-y
Here are some links on anti-hacking/cracking

http://www.gamasutra.com/features/20000724/pritchard_pfv.htm
http://www.gamasutra.com/features/20011017/dodd_pfv.htm
my-eulogy - A blog about coding and gfxsdgi - Semi-Daily Game IdeaChunkyHacker - Viewer for Relic chunky formats (used in DOW)
Fixxer
Fixxer
thanks for all the tips and links.
Leo_E_49
Leo_E_49
Quote:
Original post by Sneftel
Quote:
Original post by Fixxer
Well I already know one way of preventing people from editing the script files and playing online, the server will check the last edited dates on the script files and if they are different from what the server is instructed to check for then it will re-download the files and then log the user in.

This is moderately easy to overcome, by altering the portion of the code that checks the last-edited dates.
Quote:
I suppose your are right, its just that my favorite game is being ruined by people who are just editing the game scripts after they have logged into the server, and I want to try to prevent that from happening, or atleast make it harder.
The way you do this is by designing your game not to trust clients to maintain game state. All game state should be maintained by the server, and all changes to the game state should be checked by the server to ensure that they are feasible.


Isn't it possible to create a hash of the relavent data to ensure that it's not edited and check the hash with the one on the server to validate it?
OrangyTang
OrangyTang
Quote:
Original post by Leo_E_49
Quote:
Original post by Sneftel
Quote:
Original post by Fixxer
Well I already know one way of preventing people from editing the script files and playing online, the server will check the last edited dates on the script files and if they are different from what the server is instructed to check for then it will re-download the files and then log the user in.

This is moderately easy to overcome, by altering the portion of the code that checks the last-edited dates.
Quote:
I suppose your are right, its just that my favorite game is being ruined by people who are just editing the game scripts after they have logged into the server, and I want to try to prevent that from happening, or atleast make it harder.
The way you do this is by designing your game not to trust clients to maintain game state. All game state should be maintained by the server, and all changes to the game state should be checked by the server to ensure that they are feasible.


Isn't it possible to create a hash of the relavent data to ensure that it's not edited and check the hash with the one on the server to validate it?

But it's easy to spoof a packet with a 'correct' hash which is still using an altered resource. Again, trusting the hash is an accurate representation of the resource is still trusting the client, just in a different way.
Fixxer
Fixxer
How would I use a zip to atleast give my game files some protection?
Leo_E_49
Leo_E_49
Quote:
Original post by OrangyTang
But it's easy to spoof a packet with a 'correct' hash which is still using an altered resource. Again, trusting the hash is an accurate representation of the resource is still trusting the client, just in a different way.


Suppose you're right, but it would certainly be a step in the right direction.

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.