Fix !debug showing everyone's IP address

Currently you can type !debug and it will show everyone’s IP address in the game. For example, playing Legion TD custom map, someone types !debug in chat and everyones IP address is now shown. This is not a good idea, this needs to be removed / fixed ASAP for obvious reasons. Get it in the next patch.

Thanks.

3 Likes

Bro im not scared. Ya’ll can come at me. I’ll be waiting on my computer

Since topic creator did not mention any reasons why knowing someone’s IP address is not a good idea for online play…

Using the public IP address in theory other players could launch a DoS attack against the player’s network infrastructure, such as by using a potential paid cheat service. Even if local firewalls refuse all incoming unsolicited connections it should still be possible to overload the infrastructure between the firewall and the ISP. This often has very limited bandwidth if using older connection types such as ADSL variants so a bot network or a few distinct servers could do it easily. Due to internet equality laws in many countries requiring all packets be treated equally this could cause WC3 server response packets to be dropped or excessively delayed which becomes effectively a lag/disconnect hack.

Of course this is all theoretical. I do not know if ISP’s DoS protection might already prevent such attacks or if it even works in practice. The topic creator is free to suggest any other form of attack but as far as I am aware there are not others assuming people keep their infrastructure and computer systems up-to-date so do not have any well known old vulnerabilities to exploit.

4 Likes

that could be bad. this situation is quite the mess.

Great, now I can use my gigabit fibre upload speed to DDOS my opponents. Thanks Acti-Blizz!

1 Like

It’s not theoretical, it has been done in the past just to drop people. ISPs don’t usually care of small attacks like these^^
The problem is that once you disconnect someone, there is no way to reconnect to the game, so, basically, once it’s done it’s done.

Anyway, besides this, knowing someone’s IP is usually easy. Security should not rely on it.

The main issue is that in this use case it encourages such attacks which are detrimental to gameplay.

If the server doesn’t disconnect you first^^

Anyway, I’m for hiding it in ladder and let to host to know in custom games. Basically like in the good old times…

Personally I am against hosts with such power. Disconnecting specific players was bad enough.

That is what saved a whole community. If you think that you have been treated unfairly just change host, who cares, you can find many.
The main purpose of a host back then was to provide enjoyable games. If games were full of trolls and so on hosts would lose credibility quite easily.
It is a natural process.
Sticking someone in a game and pretending him to play at least X minutes otherwise punishing him with time or permanent bans is just pathetic.
But anyway, besides this, host should be aware of who joins the game and being able to drop unwanted players.

bumpy bump. bump bump.

ddos attakcing game warcraft3

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.