Game security review on iOS platform: memory modification of ghost artifacts, defense against in-game purchase and cracking of IAP Free

Source: Internet
Author: User

I wrote an I/O Platform Game security statement in early March this year, which has been around for seven months now. During this period, security issues on the iOS platform have also changed a lot. From the perspective of cheating methods, manual operations (command line operations) with a slight threshold have evolved into the popularization of plug-in tools that only need to click buttons, so that cheating methods can flood a lot. In terms of defense methods, although the development is slow, there are also some effective countermeasures. Games, no matter on which platform, PC, host, arcade, TV or mobile phone? Stand-alone, weak networking, and strong networking? Whether or not a client, web games, or client games are essentially data and commands. It consists of three parts.1. Responsible for logical processing, that is, instructionIn windows, it has exe, dll suffix, good identification (and swf, air, and other suffixes), basically isPE32 executableFormat. On linux/unix systemsELF executable, So format in mac/iOSMach-o executableThe dylib format is dalvik dex on Android. No matter what the format is, you can identify or modify its processing logic by debugging and reverse engineering, the only difference is that different languages and operating platforms bring about different tools and reverse difficulty. Different implementation languages determine whether the resulting assembly code is the source code. For example, java and as can directly obtain the source code. Currently, objective-c (c or Class c) can only obtain assembly code. The running platform is different, and the resulting assembly code is also different.IntelOrArmAt present, mobile phones are all arm.2. Local data (memory + hard disk)When the game runs locally, data is written to the memory and hard disk. This is also the key target of game cheating.Modify the data cheating plug-in written to the hard disk, There are usuallyXxx (game name) archive Modifier,Xxx (game) archival patch/plug-inThis straightforward name. (Archive modification is a comprehensive method of semi-manual cheating. We plan to write a blog for it)By modifying the data cheating plug-in written into the memoryThe name will be much more interesting. There are famous cheat engine in windows and those on mobile phones.GhostIt is obvious that the cheat engine is much more powerful than the Ghost artifact. It supports multiple numeric types (including custom data types) and scan methods, although the Ghost artifact supports a small number of types, it is enough to cope with changes to common game data types, and I believe that as long as mobile games continue to flourish, their functions will be improved in the near future. The memory modifier has a huge impact on game charges and game life. For most players, the game process is a process of upgrading, giving a goal and achieving it, whether it is to earn more points or win more game coins. If these values are not encrypted, it is very easy to use tools to locate and modify them to the specified values. For players, if the goal is easy to achieve and the game's pleasure is reduced, they may seek another game. In addition, most people will not spend any more on what they can get for free. Even if players are really fond of the game, the unfair feeling of those who cheat to benefit will also force the players to leave the game. Think about this scenario. IF 1000 game coins require 100 RMB, will you spend more if you find that you can change the number of game coins to 999999 RMB without spending a dime using the Ghost artifact?To protect the game from being damaged by a tool such as the Ghost artifact, you must start from the principle of the tool, modify the object and defects to deal with it.. The principle of the memory modification tool isBy constantly changing the size of the data to be modified, we can narrow down the address range to locate and modify the actual data storage address.. The player's modification object is inDuring game operation, you can view the changed game value in the memory on the game interface.Such as game currency, number of items, level, HP, attack power, etc. From this we can know that the Ghost artifact can only locate a specific data type (Floating Point Data, custom data, and data that requires server verification cannot be modified.), And can only beExact ValueAnd the general players will only modifyThe interface has the echo value.. Therefore, we can convert the data stored in the memory through an encryption algorithm (changing the game value from the regular type to the custom data type), so that the memory modifier cannot locate the search value, and cannot be modified. For example, for int c = 30000, conventional storage is 0000 0000 0000 0000 0111 0101 0011, which can be performed using specific algorithms.Bit conversion and bit MovementOperate to becomeCustom Storage FormatFor example, if the storage is 0000 0000 0000 0000 0001 1100 0000 0010, this encryption method can prevent normal players from using tools for modification, but it cannot resist the specific search modifier customized by the reverse expert after learning the encryption algorithm logic, however, it has already defended against common player cheating to a great extent. Defense Against plug-ins from professional studios will be a field of reverse and reverse engineering. I believe that only games that reach a certain level will cause special damages to these people. Finally, in order to reduce the damage caused by locating the modified value, it is best to check the logical range of the value when calling the value and determine the exaggerated value as illegal.3. Data transmitted over the networkThe game downloads from the app store need to be connected to the Internet, and the game has purchase behaviors (such as purchasing items and unlocking levels) also need to be connected to the Internet, if a game needs to store data on the developer's server or perform logical processing (such as logon), it also needs to be networked. In general, the networking process involves three parties: app store, developer server (game server), and player device (game client ). Data transmission between the three parties can be captured and modified by the agent tool as long as it passes through the player device. The most common mistake in a game that requires logon verification and data storage on the server is to return the Game Information pulled from the server to the client after the player logs on to the game. For example, the space city and contract killer games from the same company have the same error, that is, when logging on, the current number of coins TapPoints is returned from the server, we can capture the data packets that the server returns to the device and change the number of gold coins to the desired number. This method of installing a proxy tool on a device, hijacking and modifying a communication package has a long history, also known as man-in-the-middle ). The only difference is that different operating platforms have different tools. The more mature the platform tools, the easier the operation, the more convenient the popularization, immature platforms require professional knowledge such as command line operations and data packet analysis. The higher the operation threshold, the safer the game. Of course, security also depends on whether the interests of the target are attractive enough. WhileIAP (in-apple-purchase) in-game purchase (That is, the extra unlock Content downloaded to the device through IAP. The full name is DownLoadable Content, usually DLC) to unlockIt is quite attractive. In this function, the method of destruction is also very exciting.Iap crackerTool, which is very popular nowIap freeTools, as well as non-jailbreaking machines that can also be used to pass the IAP Authentication ServerRussian in-game purchasesMethods are very useful. (Supplement: the essence of in-game purchases is that you need to pay for the game content to be downloaded to your local device, and you can unlock it by modifying the archive content, the well-known online in-game purchase and unlocking websites are also paid to provide such archives to unlock profits. We plan to introduce this method in the next archive modification blog.From iap cracker to iap free, we can see a process of plug-in function upgrade.(1) iap crackerWe analyze what IAP cracker has done from the iap API, I believe that a game with the IAP function must have such similar code development that decides what to present in the inner purchase status change based on the transaction type, there are four types of purchase status transaction values: SKPaymentTransactionStatePurchasingSKPaymentTransactionStatePurchasedSKPaymentTransactionStateFailedSKPaymentTransactionStateRe stored. All messages with successful transactions will enterSKPaymentTransactionStatePurchasedIn this case, andIap cracker simulates a message that returns a successful transaction and enters this case.. If we do not perform the next verification, when we receive the message that the "fake" transaction is successful in our application, we will directly add money, devices, and various things to the user, the entire process of iap cracker operation does not even require online verification. It is interesting to note what kind of vulnerability is used in this software instruction, as long as the game server does not need to verify the processing method again, it will be recruited.
To address this problem, apple recommends that you verify the payment receipt. If the verification fails, you can add the user (device udid) to the blacklist for troubleshooting and sealing, all requests sent from this device to the server will be rejected. (Interestingly, this processing method breeds anotherUdidFakerYou can randomly forge the device's udid .) Bytes




{
"Receip-data": "(receipbytes here )"
}

2. Pass the generated json data to https://buy.itunes.apple.com/verifyreceiptfor verification through the http post method.
3. after the app store server is verified, it returns json data in the following format. Based on the status value, it can be used to determine whether the order is legal. Only 0 is legal. If not 0, it is invalid.
{
"Status": 0,
"Receipt": {(receiphere )}
}

 
The following are legal orders
{"Receept": {"original_purchase_date_pst": "05:54:35 America/Los_Angeles", "purchase_date_ms": "1342097675882", "original_transaction_id": "170000029449420", "Expiration ": "1342097675882", "app_item_id": "450542233", "transaction_id": "170000029449420", "quantity": "1", "bvrs": "1.4", "version_external_identifier ": "9051236", "bid": "com. zeptolab. ctrexperiments "," product_id ":" com. zeptolab. ctrbonus. superpower1 "," purchase_date ":" 2012-07-12 12:54:35 Etc/GMT "," purchase_date_pst ":" 2012-07-12 05:54:35 America/Los_Angeles "," original_purchase_date ":" 2012-07-12 12:54:35 Etc/GMT ", "item_id": "534185042"}, "status": 0}
 


(2) iap free  Iap free is based on the iap cracker (counterfeit the transaction Status of SKPaymentTransactionStatePurchased). In the process of verifying the receipt with the app store server, the counterfeit false receipt function is added.The latest iap free provides the UDID and mac address forgery feature for developers to block numbers based on unique identifiers of devices such as UDID and mac address. (3) Russian in-game purchase method (forged into app store server)Step 1: log out of the logged-on apple ID Step 2: Install the Certificate file on the device 【 Step 2 and Step 3: Install a forged SSL certificate on the iOS device and modify the DNS table to redirect normal requests to the server set up by the attacker so that the server can be forged into an app store server, whether the order is valid or not, the system returns a valid status to crack the iap internal purchase.] Step 4: Go to the game, open the purchase link, select like in the following pop-up box, and enter a non-real apple id to make the purchase successful. Similar to iap free, the final goal is to return the order data for successful purchase, but iap free changes the verification data from the app store server from the failed status to the successful status on the game client. In Russia, in-game purchases are forged into an app store server, allowing it to directly return verification data for successful purchases.The key reason for this kind of in-game purchase cracking can be performed by IAP free and forged app store server even with iap receipt verification is that the receipt verification process is Directly verified by the iOS device and app store server. Again, the data returned from the game client on iOS devices is untrusted and can be tampered. To ensure the security of the verification process Direct verification of game servers and app store servers. Apple for (2) (3) This receipt Verification Vulnerability, also gives the corresponding processing method https://developer.apple.com/library/ios/#releasenotes/StoreKit/IAP_ReceiptValidation/_index.html#//apple_ref/doc/uid/TP40012484 First case: the receipt verification is performed by the developer's own game server and app store.(Not through the game client on iOS devices) will not be affected by the iap free and Russian purchases, and is the best verification method recommended by Apple. The security verification process should be shown in. By looking at this flowchart, we can see the previous iap implementation errors. The reason for iap cracker's effectiveness is from step 1 to step 2, apps on iOS devices directly believe in forged SKPaymentTransactionStatePurchasedStatus. The reason for the effectiveness of iap free and Russian in-house purchase cracking is that the receipt information is directly verified by the app store and client, and the customer believes that the forged purchase successful receipt data. The correct process should be from step 1 to step 12, with the game server and app store Direct communicationVerify the receipt data. If the receipt is valid, a portion of the purchase content will be sent to the client application (Steps 1 to 2 ). Case 2: The receipt verification is performed by the game client directly with the app store.Although Apple recommends that developers use the verification process in the first case, this process increases the waiting time for communications between servers and app store. In the case of unstable wireless networks, it may lead to a middle-end payment process, affecting the user's payment rate. I have observed many iOS applications, many of which are produced by well-known foreign game development companies (for example, music games in Japan can be purchased internally) the customer's verification receipt is still selected, or the receipt is not verified. I wonder if there is any reason for this. Apple also provides the following measures to verify the consistency between the client and app store: 1. check the SSL Certificate used to connect to the app store server and check whether it is an EV Certificate (Extended Validation SSL Certificate) 2. check whether the returned verification information is consistent with the information in the SKPayment object. 3. check whether the signature on the receipt is valid. 4. check whether the transaction ID is unique and provides the verification implementation code. https://developer.apple.com/library/ios/releasenotes/StoreKit/IAP_ReceiptValidation/VerificationController.zip Both of the authentication methods provided by Apple are pre-verification. Only when the verification is passed, some of the purchased content is sent to the client. In the early iap implementation, post-event verification is generally adopted, that is, after the transaction is completed, the receipt is stored on the server, and then reconciled with the app store server again, illegal transactions are blocked. for fear of affecting players' sentiment, gamers are often punished only for a large amount of players, and part of their functions are disabled. However, for games with weak network connections, such punishments do not provide a deterrent. In addition, in the game promotion target user stage, there will be corresponding unblocking operations when there is a seal number. In the unblocking process, the customer service is generally used for manual unblocking. In the case of a flood of silly tools such as iap free, the unblocking processing of a large number of illegal orders will inevitably increase the customer service workload. In general, the development of game security is a process of game plug-in. because of too many reasons, Game Performance, player experience, or labor costs, effective defense always lags behind attack methods. But it is these interesting plug-ins that make gaming more challenging. The next plan is to write the iOS game archive changes (including the internal purchase and unlock by archive replacement). Refer to 1. http://www.himigame.com/iphone-cocos2d/673.html2.iOS Middleware Reverse Engineering Application & mobile terminal remote control technology powered by capabilities 3. https://developer.apple.com/library/ios/#documentation/NetworkingInternet/Conceptual/StoreKitGuide/VerifyingStoreReceipts/VerifyingStoreReceipts.html#//apple_ref/doc/uid/TP40008267-CH104-SW14.https://developer.apple.com/library/ios/#releasenotes/StoreKit/IAP_ReceiptValidation/_index.html#//apple_ref/doc/uid/TP40012484

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.