Written by: Tiur, the Gnosis
Date: Monday, December 2nd, 2019
Addressed to: Everyone
Last night, while investigating lag occurring across all IRE games, we discovered an unmitigated SQL injection vulnerability in the gamefeed processing on the games' websites, which was being actively used by an attacker. In an abundance of caution, we disabled the gamefeed functionality across all games and sinkholed the vulnerable API endpoint. We have now fixed the faulting code and reenabled the gamefeed.
We are still investigating the full impact of the vulnerability, but at this time it does not appear any customer data was accessed. It appears to have been a blind attack that didn't get beyond an attempt to identify access limitations, so no critical information was accessed whatsoever.
Special thanks to Razmael of Aetolia for identifying the initial impact, and Phaestus of Achaea and Eoghan of Imperian for identifying the SQLi and creating a mitigation.
Penned by my hand on Closday, the 14th of Lanosian, in the year 484 MA.
Discuss this post on our forums:
http://forums.aetolia.com/discussion/3360/announce-post-3038-recent-lag
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.