Popular Online Game Shut Down Due to Attacks...

Anyway a week ago another partner website took over the server list so everything is pretty much back to normal, except theres nothing going on with future versions of SA:MP.
 
AN UPDATE:

SA-MP.com said:
SA-MP Closure - 7th June 2008

On the 2nd of June 2008 former SA-MP developer 'Jacob', who also goes by the name Simon Jacob Dis, decided to form a hacking group called Zytronics. The purpose of this group was to leak parts of the SA-MP source code and confidential information online and take full credit for it.

With a hacking group such as Zytronics in control of the SA-MP source code we can no longer guarantee the safety and security of SA-MP clients and servers, and for this reason we now advise against using this software.

A deal was initially reached with Jacob, after he published the SA-MP client source code online, that he would delete the SA-MP source code and information he had access to and remove himself from any involvement. Jacob did not keep this agreement.


Information

Mods like SA-MP can not operate while people like Jacob and his Zytronics group freely break the law and show complete disregard for intellectual property rights and the security, safety and privacy of online gamers. For this reason, I recommend that action should be taken against him and his Zytronics group to protect any future game mods from being victimized like SA-MP has been.

After looking up the WHOIS info on website that was published with the source code, I found the following information:

TRC Roofing and Siding
3811 Rogers Avenue
Fort Smith, Arkansas 72901
United States
479-561-9572
479-287-9459
email: cmcjacob@gmail.com, jacob@trcroofingandsiding.com

Jacob appears to have registered his Zytronics group under the name of his business TRC Roofing and Siding.

While there are clearly other people who were involved in the escalations which lead up to this, Jacob has taken the final action which requires SA-MP's closure.
I'll most likely be interested in taking action against Jacob myself at some point. By removing the copyright notices from all of the SA-MP source files before he leaked them, he basically deprived the entire team credit for the years of work they had put in. This is unacceptable. If you find more information about this Jacob person please e-mail it to team@sa-mp.com

Background

SA-MP was one of the most popular online game modifications ever created. From the website statistics there appears to have been between 100,000 and 130,000 active players at the time of writing – from almost every country on the planet. Record concurrent player counts were reached earlier in 2008 with over 9000 concurrent players and over 8 million downloads have been recorded.

Vulnerability/Threat Disclosure

The SA-MP 0.2 clients are capable of downloading and executing arbitrary code as part of the SAC (SA-MP anti-cheating) system. The SAC system can be activated from an SA-MP server by the server operator. If an SA-MP server requests a client to authorize to SAC, no user interaction can stop the downloading and execution of the SAC code.

The security mechanisms in the SAC client module require that the code be signed with a private encryption key only available to SA-MP developers.

The private encryption key used to sign SAC client authorization code is now in the hands of the hacking group Zytronics. This group has shown a willingness to disclose all private information and SA-MP source code to the public. The source of the SAC module is no longer limited to the code signed by SA-MP developers.

License Termination

The owners of SA-MP.com, and those mentioned as part of the SA-MP Team, no longer accept any liability for the use of the SA-MP software.

Under the following section of the license agreement: “The author(s) of this software retain the right to modify this license at any time.” All licenses to use the SA-MP client or server are revoked.

Well now this sucks even more. Both the internet lists and the official server lists are taken down...the only way to play is to add a server to your favorites from game-monitor.com. OH WELL! Now onto Race Driver: GRiD :D.
 
Well it's back!

The website and master server lists have been reopened. For now, the security situation appears normal. You can continue to use the SA-MP software if you wish and we'll be releasing some further security updates within the next two weeks. We'll also be monitoring the security situation and news will be posted here if there are any threats.

Before this new 0.2.2 security update is made available, please adhere to the following recommendations:
* Only play on trusted servers.
* If anyone asks you to add auth.sa-mp.com or auth2.sa-mp.com to your windows ‘hosts' file, ignore the request.
* If you notice the Internet and Official lists disappear again, please check this website for information.

It has been decided that, although the actions of the former developer are damaging to the project, the responsibility for preventing something like this was my own. There should have been more strict criteria for allowing someone to enter the team and access the source code and encryption keys. Signed agreements should have also been in place. These will be part of the new rules for any SA-MP developer that has access to the source code.

I apologize for any inconvenience caused during the downtime and hopefully this situation will be completely resolved after the next software update.

Kind regards,
KySA-MP Lead Developer
 
Back
Top Bottom