The majority of gamers assume that cheaters utilize either "cracked" programs or shady mods, whereas in fact most of the cheating occurs on the back end, in the backend systems that manage the game.
The backend of a game is where all of the important information is kept statistics, currency, matchmaking, inventory, leaderboards and if the backend systems trust too much of the information that is sent from the game client, then it is bad news.
Historically, Game APIs have been created with speed in mind, as no one wants to lag, however this is also the benefit that attackers exploit.
When testing APIs we often discover several weaknesses, including:
1. The backend accepts values sent by the client without proper verification or validation.
2. Weak Authorization, allowing one player to modify another player's information by simply changing the player's id.
3. Missing Rate Limits: The API allows thousands of requests to be made every second with no limitations.
4. Debug end points left behind after testing, e.g. test features unintentionally sent to production.
Common Examples of Cheating in Video Games
1. Abuse of APIs to repeat game sights.
2. Modification of Item Lists through Payload Changes in Requests
3. Abuse of matchmaking by pushing low-raised goals onto others
4. Usage of automated scripts to generate leaderboards Frauds.
There is a case where a mobile video game has trusted the client's win flag based solely on what was sent from the client to the server. If a client sent a "you won" message, then the server agreed to that victory. Then some very good competition noticed and caused a stir in the community as well as the game itself.
Why Video Games Are Such a Target for Cheaters
1. High numbers of players: An exploit that is found can be utilized by hundreds or thousands of players overnight.
2. Monetary Incentives: Several Items in the Video Game can have Real Money Value.
3. Fast Development Cycles: The time allotted for security testing typically comes after the initial launch date.
4. Young Attackers: Many children become curious about games and end up being accidental pentesters.
Automated Abuse of Online Game APIs can not only be used for cheating but also attracts anyone interested in automating, abusing, and profiting from these types of exploits.
How to Cheat in a Video Game
It does not require special tools. The following steps are typically taken to exploit a game:
1. Interception of the Game's Traffic through a Proxy Server.
2. Analysis of the Game's API during standard Game Play.
3. Use of Replay and Modification of Requests.
4. Automating the Previous Three Steps via the Use of Scripts.
Exploiting the game's backend when developers did not properly enforce strict design logic and rules; if this type of exploit was discovered, the magnitude of this exploit is unlimited.
Practical Methods for Securing Game Back End Infrastructure
1. Always Assume the Client Can Be Compromised
You should consider all requests, including those from your own application, to be potentially untrustworthy.
2. Implement Server-Side Business Logic
Backend only calculations should be made for all winnings, rewards, and Item Inventory changes.
3. Implement Strong Authentication/Authorization for All Player Actions
Confirm identity and ownership of all players before they are allowed to perform any action.
4. Implement Rate Limit/Abuse Control to Detect Automated Plays
Bots click faster than humans can.
5. Monitor for Unexpected Anomalies
Signs of unexpected currency spikes or statistically impossible numbers should raise a flag. Based on experience, most game exploit methods exploited were not very creative but were based on unchecked assumptions made by the game developer.
So, Ultimately:
Game security isn't about preventing "hackers" from getting to your system, but about preventing bad "logic" from becoming an exploit; if you build your backend to blindly trust the client application developers, you will ultimately cause players to realize the potential for exploitation, and thus some of them will cheat, some of them will build automated cheating systems, and the few that do will share their methods with the entire gaming world. Building a secure API does not ruin games; in fact, building a secure API will ensure all players play fair, and peace-of-mind for your Customer Support Team!