1980's 1985 3 storms. 80's Metal 80's movies A Crystalline Prophecy A Realm Reborn A Relic Reborn Adaman Hauberk Aion AMC Anashti Sul ArcheAge Artemis Bow Ascalonian Catacombs Azure Drake Bard Battlecrab BBC Best MMO Blogs Beta Beta Leaks Big Trouble in Little China Bill & Ted's Excellent Adventure Black Desert Online Blazing Lazers Blazing Lazers Soundtrack Blazing Wings Bloodbathed Frostbrood Vanquisher Blue Drake Bowl of Embers Brackenspore Bravura Breaking Bad Buckaroo Banzai Cabal Capes Character Creation Character Customization Chocobo Christopher Guest Cloaks Crafting Dalmatica Darkmoon Faire Death Knight Defending Ring Destruction Warlock Disc of Dreadful Omens Dr. Emilio Lizardo Dragon Ball Dye System Dynamis Beaucedine Egg Shenn Enervated Sedition Enhancement Shaman Epic Weapon Quest Everquest 2 EverQuest Next Felwithe Mansion Final Fantasy XI Final Fantasy XIV Fractal Capacitor Fractals of the Mists Frost Death Knight Frost Mage Fury Warrior Galakras Gamebreaker TV Garona Halforcen Garrison Followers Garrosh Hellscream General Nazgrim. Gleaming the Cube Global Agenda Greatest 80's Movies Greenscale Greenscale's Blight Guardian Guild Wars 2 Guild Wars 2 World vs. World Gunslinger Hagun Hailstorm Hallow's End Halloween Hammerknell Headless Horseman's Mount Hellscream's Decapitator Highmaul Hoelbrak Holographic Shattered Dragon Wings Holy Trinity Hong Kong Cavaliers Housing Hulking Shield Hunter Immerseus Intermezzo Liberte Iron Citadel Iron Juggernaut Iron Maiden Jack Burton Jeff Loomis John Bigboote John Parker Kargath Bladefist King Arthro Landmark Legendary Cloak Level 100 Liberator of Orgrimmar Lo Pan Looking for Raid Lord of the Rings Online Lost Shores Magitek Armor Malkorok Mercenary Michael Amott Mind Your Head Mini Holographic Axe Wielding Destroyer Mini Holographic Branded Minotaur Mini Holographic Corrupted Wolf Mini Holographic Risen Knight Mining MMO Blogs MMO Housing MountQuest Mounts National Geographic Channel Neverwinter New Jersey Nigel Tufnel Norushen One-Eyed Wiley Osmium Armor Paragons of the Klaxxi Penny Priddy Perfect Tommy Pride and Duty Protection Warrior Pureblood Fire Hawk RaiderZ Raptr Rawhide Red Flying Cloud Reins of the Amber Scorpion Reins of the Golden King Rift River of Souls Runes of Magic Say Anything Sci-fi Spaceships Sedition Sentinel Sha of Pride Shadowknight Siege of Orgrimmar Siegecrafter Blackfuse Skyshrine Slayer of the Lifeless Sleeper's Tomb Smell the Glove Spellfire Longsword Spinal Tap Splitting Heirs Spoils of Pandaria Star Wars Stonehenge Theories Super Adventure Box Tanks Tears of Veeshan Temple of the Faceless TERA Terrible Names The Axe of Crags The Butcher The Dreamer The Elder Scrolls Online The Fallen Protectors The Force Awakens The Nexus Core The Old Republic The Shatterer The Wizard The Young Ones Thok the Bloodthirsty Throne of Fear Titan Transmogs Trickster Rogue Turbo Grafx 16 UI Unholy Death Knight Up the Irons Vanguard: Saga of Heroes Vitreous Stone Drake Void Storage Warlock Green Fire Warlock. Warrior Waves of Madness WeakAuras 2 Website's Down Wildstar World of Warcraft World vs. World Young Ones Mike Young Ones Neil Young Ones Rick Young Ones Vyvyan Zenith Weapons



I honestly didn't know what to say when i heard about this on Friday.  At first i thought it was just a joke or someone screwing around with us.  There's a thread over on Bluegartr forums discussing the entire issue since all of the official forum posts seem to have been deleted.  It's sad, depressing, and i can't say I'm all that surprised looking back on SE's history with FFXI.

Essentially there are no security measures in place protecting FFXIV's database and anyone can go in and do as they will.  I'll quote the image i have linked in case it's difficult to read to give a better idea of what's really going on.

Apparently by simply sifting through the Lua scripting that FF14 uses, people were able to figure out a JSON query that would retrieve your character's information from the character database.  Further, any commands you send to the database are simply... not checked at all, and the database just takes the input commands and MODIFIES YOUR DATA DIRECTLY.

That means it was/is possible to simply tell the server "make me level 50 and give me six billion gil" and the server will...happily do it.

you can simply send a javascript request to SE's servers and give yourself billions upon billions of gold.

 You can literally convert any item.  I found a video of someone buying 99 potions from the store, then converting them to 99 Allagan gold pieces and selling them right back.



This has been known about and going on for over a month, since beta phase 4.  People that figured this out obviously exploited the hell out of it to give themselves whatever items and gil they wanted.  They turned around a made bank selling to RMT sites and actual players as well.  Now, most if not all of these players were banned in the recent crackdown, but the damage has been done.  Who knows how much of the economy is basically duped items or gil at this point and since this is still going on, how much worse it'll get before SE decides to do something.

What can actually be done at this point other than a rollback, which would no doubt piss everyone off?  Personally, I'd take that over playing in a world where i don't know what's what anymore.  Either way, SE is in crisis mode.  SE has managed to make the Salvage dupe bans of '09 seem tame in comparison.


Post a Comment

  1. Wow..that's an absolutely huge issue. I've never heard of anything that game breaking and freely exploitable actually making it through.

    ReplyDelete
  2. It makes the Neverwinter exploit, which was very similar, almost seem not as bad. No, it was just as bad!

    ReplyDelete
  3. i was thinking of that one but this seems worse in many ways since it isn't just about a gold exploit it's items, levels and who really knows how far you could take it if you knew the right inputs

    ReplyDelete

Author Name

Contact Form

Name

Email *

Message *

Powered by Blogger.