Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Hacking Second Life

MarkByron Falta
Just an average bird
Join date: 16 Jun 2007
Posts: 168
04-03-2008 10:16
Here's a video with Michael Thumann, the CSO of ERNW GmbH (a German based security company) discussing various vulnerabilities of Second Life - enlistening stuff. It's in English.

http://www.net-security.org/article.php?id=1125
Bluesman Wycliffe
Registered User
Join date: 19 Feb 2008
Posts: 74
04-03-2008 10:46
OMG Nikto for SL .. SLikto , a web vulnerability scanner,
Also possibilities of SQL injection & Cross site scripting.
Fairly easy to steal someones money..... (Identity Theft.)
Attacks on websites using SL Client...

The bit that made me chuckle though is the bit saying its almost impossible to cheat in SL ..(haha LL Priorities.)
Depending what side of the line you live on that Vid, is either frightening or will make you smile...Either way its an eye opener ...
foehn Breed
More random than random
Join date: 16 Jan 2006
Posts: 1,142
04-03-2008 11:20
Thanks for the post MarkByron :)
_____________________
You have no friends online at this time. "Excellent!"

Einstein "I never think of the future. It comes soon enough."
Day Oh
Registered User
Join date: 3 Feb 2007
Posts: 1,257
04-03-2008 11:33
It seems that guy focused on sending spam and attacking web servers instead of the Second Life protocol. Saying it's nearly impossible to "cheat" makes it sound like the protocol isn't full of holes. o.o In reality, if you play with the protocol, you'll find something interesting at every corner.

A couple of things that were discovered and fixed only this past month:

* You could grant run time permissions to a script without it asking, overwriting the previous permissions mask (meaning you could disable vendors or camping chairs, or take control of someone's car or flight attachment)
* Simulators randomly sent private information to clients instead of to other simulators, such as script bytecode and session ID's that you could use to take control of accounts

Those are the *fixed* things o.o

Indeed, security specialists should be interested in taking a harder look at Second Life
_____________________