Thunks from hacking games
ID: 252ef304-fdda-5354-92d6-0871312c3fa1
STIX ID: report--252ef304-fdda-5354-92d6-0871312c3fa1
Feed Name: SensePost Blog
The document reflects on security lessons from Greg Hoglund and Gary McGraw’s *Exploiting Online Games*, drawing parallels to traditional web and financial systems by highlighting TTPs such as logic abuse (“hacking inside the game”), collaboration/cheating, bot detection and CAPTCHA evasion, DoS in auctions, failures at system edges (SSO and cross-server state), race conditions between processes and technology (e.g., account creation vs. billing), and risks of client-side state; it underscores the need for deep domain understanding and structured threat modeling to anticipate attacker objectives and avoid fragile design choices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
