haxball / haxball-issues

113 stars 42 forks source link

modified client & security vulnerability #1680

Open modifiedclients opened 1 year ago

modifiedclients commented 1 year ago

https://gaxball.com this website is selling a modified haxball client which makes the game unplayable. the guy behind the site is someone playing with the nick "Galvan" in the israeli servers. (he is also exposing users identity in his server by revealing their IP address and their location which haxball should hide)

security vulnerability: Gaxball have an option to reconnect after a ban- it is spoofing the ip in the WebRTC protocol. (altough he states in the website that it uses proxy it does not)

how can it be fixed?

Nellty commented 1 year ago

it is spoofing the ip in the WebRTC protocol

How is that possible? Sounds like nonsense

Phantomat0 commented 1 year ago

The client is only making client side changes, so his fake ping or changing teams colors isn't doing anything more than the chrome extensions that let you change your avatar you press x. Client is nonsense