PDA

View Full Version : HALFLIFE 2 SOURCE CODE: Released


UltimatrixmaN
2003-10-02, 05:53 PM
http://www.halflife2.net/forums/showthread.php?s=&threadid=10692

But since it's not an Illegal Alpha or Beta, I really don't care...

**sigh** back to Doom 3 to kill that IMP for the 7,000th time.

Everay
2003-10-02, 06:21 PM
link to the source code?

MilitantB0B
2003-10-02, 08:39 PM
Wow, that hacker had some skills. Makes me kinda want to take up a black hat... But then I remeber jail time and being some guy named bubba's girlfriend and I find myself content to play video games.

Hamma
2003-10-02, 09:31 PM
It's a hoax

JetRaiden
2003-10-02, 09:33 PM
its not the producer of the project said it himself. then again Im very gullible.

AztecWarrior
2003-10-02, 09:45 PM
OMG HAXXED BY CHINESE! ^__________________^

Setari
2003-10-02, 10:25 PM
Yea that guy got skills it seems and knows what he's doin...Well, if they find they should beat him with a baseball bat and then reserve a jail cell for him with Big Bubba:D

EDIT: *Question solved after rereading Gabe's post..*

EineBeBoP
2003-10-02, 10:27 PM
I have friends who tryed....and succeeded.

its HARD. he was caught twice lol.
but finally got the game 3rd try.

this is differant guy tho. my frnd has no interest in the code only, so oh, well. GL to valve.

JonnyK
2003-10-02, 11:05 PM
Originally posted by Hamma
It's a hoax


hamma lies



Part of the source code for a little-known game called Half-life 2 was leaked recently has made it's way onto the internet this afternoon. Valve has now confirmed that this is indeed the true Half-life 2 source code...

...And it came from Gabe Newell's machine. Valve are now appealing for help and I feel we should give it to them. here is the post made to the Half-life 2 dot net forums:

Ever have one of those weeks? This has just not been the best couple of days for me or for Valve.

Yes, the source code that has been posted is the HL-2 source code.

Here is what we know:

1) Starting around 9/11 of this year, someone other than me was accessing my email account. This has been determined by looking at traffic on our email server versus my travel schedule.

2) Shortly afterwards my machine started acting weird (right-clicking on executables would crash explorer). I was unable to find a virus or trojan on my machine, I reformatted my hard drive, and reinstalled.

3) For the next week, there appears to have been suspicious activity on my webmail account.

4) Around 9/19 someone made a copy of the HL-2 source tree.

5) At some point, keystroke recorders got installed on several machines at Valve. Our speculation is that these were done via a buffer overflow in Outlook's preview pane. This recorder is apparently a customized version of RemoteAnywhere created to infect Valve (at least it hasn't been seen anywhere else, and isn't detected by normal virus scanning tools).

6) Periodically for the last year we've been the subject of a variety of denial of service attacks targetted at our webservers and at Steam. We don't know if these are related or independent.

Well, this sucks.

What I'd appreciate is the assistance of the community in tracking this down. I have a special email address for people to send information to, [email protected]. If you have information about the denial of service attacks or the infiltration of our network, please send the details. There are some pretty obvious places to start with the posts and records in IRC, so if you can point us in the right direction, that would be great.

We at Valve have always thought of ourselves as being part of a community, and I can't imagine a better group of people to help us take care of these problems than this community.

Gabe

OneManArmy
2003-10-02, 11:38 PM
wow, some people really dont have any ounce of life....

Thrik
2003-10-03, 07:42 AM
Yep, it isn't a hoax but the source code is just that.. the source code. There are no models, maps or textures included with the bundle so nobody can actually play it.

However, having the source code available means that hackers now have the very organs of the game to play with in order to make new cheats (VERY bad), can find ways to exploit the engine in future games that may use the HL2 engine, and I've also heard that is technically possible to get a limitless number of cd keys to play the game with by exploring how the game checks them and such.

Of course, Valve will probably have to delay the game for even longer in order to fix up a lot of the problems this will cause. Nice work, hackers. >=/

SilverLord
2003-10-03, 09:01 AM
Jese people need to get lifes and go outside. Grats to the hacker though, the biggest moment of his life I bet. This really sux for us gamers :(

OneManArmy
2003-10-03, 11:22 AM
grats to teh hacker? omfg.. all hackers should be hung and paraded around town... fucking idiots... no better than your run of the mill criminal... go out and get a life.... that doesnt pertain to delaying my presssscious

Squick
2003-10-03, 11:38 AM
I was thinking the same thing SilverLord... Imagine the rush... Most everyone is agreeing that this was a truely talented hacker, not a script kiddie... He spent days preparing, set up the dice, then imagine how hard he had to be sweating while the download of 100 megs of sourecode was being pulled...

You need to be insane to do that now in days though. I am a security consultant, and the firewall that I recommend is the Symantec Enterprise Firewall... I like full logging enabled for all traffic in and out... The firewall itself can be considered unhackable, the damn server has a process called Vulture that kills any non symantec or vital microsoft service the instant it tries to start. And one last layer of security is the firewall goes into lockdown if the logs are tampered with. So if a hacker tries to modify the logs all inbound and outbound traffic stops.

But the moral of the story is a hacker should know that it is an extremely good possibility that every single thing they do on a network is being logged. And it sounds like this hacker took his merry time looking at things, so it would not have been possible for him to just send spoofed packets. Not to mention that the first destination of the source code would be logged aswell.

It would blow my mind if Valve does not have a total logging firewall in place, all of my client, even ones 1/10th the size of Valve respond very positively to knowing that there is absolute traceable liability for everything that happens on their network.

Also I am really curious how that keylogger was able to send the passwords back... A firewall should be blocking all but the very minimum, even for outbound traffic. Well then you might say it could use an existing port like port 80 and send malformed HTTP packets, but modern firewalls are stateful, they look at the packets and would see that it is malformed and not allow it out.

So I definitely do not buy that being hacked is just something that happens, there was certainly some negligence on the part of their security administrator.

Squick

Sputty
2003-10-03, 12:47 PM
Originally posted by JonnyK
hamma lies


I used to love you Hamma
..
Now I don't even know you any more
:tear::tear:

Pilgrim
2003-10-03, 01:25 PM
I agree with Squick

And I also work in the same field as Squick :)

I'm a Network Security Engineer and can say that the only way you get hacked is if you get sloppy.

There is an attitude around developers that security is the last thing they need to worry about. Funny thing is that now they see the price.

They were dependent on the %98 sollution (simple Firewall, maybe proxy, and virus scanners) that works great against Script kiddies, and the unskilled yutzes. Not against anyone who has even a little bitty bit of more skill.

Oh well, yet another article to show to clients to try to sell my services :)

PAX

Hamma
2003-10-03, 02:03 PM
This will delay the release of HL2 6 months imo

EarlyDawn
2003-10-03, 02:53 PM
Between the time it's going to take Valve to do damage control/repair and the sales they've lost (it's more or less an open-source project), it's gonna rape Valve's wallet.

On the plus side, it's been reported that both TF2 and a better-looking CS version, possibly using the Sourse physics are in, which is a big plus. One would only have to conceviably recreate good looking resources (textures, models, ect) and you'd have AMAZING mods.

JetRaiden
2003-10-03, 03:23 PM
wtf I was supposed to get this game in september. last time I checked the release is around 11/22.

UltimatrixmaN
2003-10-03, 05:32 PM
Sux this happened like a week or 2 BEFORE the game would come out....

If it happened a week or 2 after I wouldnt care......well I would but not as much.