haxball / haxball-issues

114 stars 43 forks source link

Fake rooms flood #1508

Open swizzhax opened 2 years ago

swizzhax commented 2 years ago

Hey @basro,

Your mailbox seems to be out of range, I am asking you for all of us - could you somehow implement room name verification during the process of POSTing new room to your API?

Since always there is a problem with it and we are all suffering because of this.

Basically a person with minimal coding knowledge can modify headless code and open as much fake rooms as proxy servers available - I guess it is not that hard to implement such a feature to avoid this (at least in 99% cases).

If someone would be determined enough and prepared hundreds of proxies, it could end up bad for whole Haxball and its community!

As an example, here is my rooms network that has been attacked: Fake rooms flood

SoftJakJus commented 2 years ago

His app collects user data from the drive and asks Basro if he can ban her, It's a punishment for him. https://swizzhax.cf/app

swizzhax commented 2 years ago

His app collects user data from the drive and asks Basro if he can ban her, It's a punishment for him. https://swizzhax.cf/app

meme

ghost commented 2 years ago

So using socket.io just for testing purposes? XD

https://paste.ee/p/moMzn

swizzhax commented 2 years ago

So using socket.io just for testing purposes? XD

https://paste.ee/p/moMzn

If you would look better, then you would see, that socket.io is used to display count of players using the app in the application title:)

oghb commented 2 years ago

Hey @basro,

one of my rooms is being faked right now, it's not the first time it happens to me and it had already happened the year before to someone else.

I hope you can do something about this... thanks!

screen