HTML <img> tag usable in chat - can use to link any in game image

Partially fixed. If you are determined enough you can still exploit their poor architecture. They need to add server side validation.

What about the people who used this to inject code to gain infinite gold & exp?

At best we will be told they will ban people, but literally no one will be banned and no gold will be taken from anyone, that’s what happened with the server transfer gold dupe.

Do you think Christoph Hartmann would hear our complaints if everyone’s characters were suddenly deleted?

You guys should probably start working on server side validations.

How the hell was this even in the game? What are you guys doing in AGS? Are the developers really that dumb? Do you even comprehend how big of a mistake this was? Imagine if hyperlinks were allowed, someone could have injected malware via this bug. I’m done with the game, this isn’t just a small “oops”. This is massive mistake that could have ended really badly.

I agree its a serious oversite, but frankly they fixed it rather quick with no restarts. Good on them for stepping it up, other games I played let it get to the point of malware.

It’s similar to when they first released their Amazon website. Everything was in a get parameter in the url. So you could make your checkout amount be zero in the URL and buy everything for free. Amazon is notoriously bad at security.

Dude, did you just inpect their Website code? Is plenty of blank white lines, inline Javascripts and CSS and weird stuff like these commented scripts and “developer notes”:

image

image

image

image

Damn. Sounds like you want to talk to the manager

Apparently still works on South America servers…
I sent in the local chat to test

Sent it over to the team for :eyes:

That’s odd, I just tested the code posted in the first post and it didn’t work. SA server as well.

We just fixed it! Thanks for letting us know!

1 Like

Yuup! Now it doesn’t work anymore! :smiley:

@Luxendra This is still working. As i see a giant sausage in my chat right now. :slight_smile:

2 Likes

image

It has not in been fixed, may be multiple ways to do this

Hail the snail

Server side validations. Add them. Or hire someone who knows what that is.

Where I work we do both server side and client side validation, because we store medical information and if that was stolen we would literally be sued into non existence.

1 Like

Oh boy. Gonna need a fix for that fix. I wonder what 3 things it broke. Btw it can also duplicate gold in chat messages and crash other players clients.

Then again… what doesn’t dupe gold these days. RIP market

2 Likes

Yup, and there is an item dupe too, RIP economy

I just found the workaround and let me tell you… it’s ridiculously stupidly easy to get around.
You’ll be seeing big sausages soon.

Edit: they fixed the workaround now.

1 Like