Jump to content

[HA/ME] Serious possibly abusable bug with per-session progression


Horsting
 Share

Recommended Posts

Reported first here: https://forum.kinkoid.com/index.php?/topic/30999-november-4th-2023-hot-assembly-travelers-tales-of-tits/page/6/#comment-301236
Replicated here: https://forum.kinkoid.com/index.php?/topic/30999-november-4th-2023-hot-assembly-travelers-tales-of-tits/page/6/#comment-301263

  1. Log in with two clients concurrently
  2. Check Xtals on both clients => equal
  3. Gain Xtals on client 1
  4. Reload page on client 2 => Xtals gained on client 1 are not visible on client 2
  5. Gain Xtals on client 2 => Xtals gained on client 1 are still not visible on client 2
  6. Reload page on client 1 => Xtals gained on client 2 are not visible on client 1
  7. Logout and login on client 1 => Xtals gained on client 2 are now there, but those previously gained on client 1 are lost permanently

The only explanation I can think of is a per-session cache of the progression. I could not find this cache on the client, so I hope it is located on the server, otherwise this could be abused to gain Xtals.

This led to some cases where the 800 Xtals from event ranking were lost. Support ist manually restoring it in those cases, with a hint that concurrent sessions are not supported. IMO, this is not good enough for a game I am paying for: This is a browser game with mobile apps, and it is should never be possible to loose resources when not consequently manually logging out every time. If concurrent sessions cannot be guaranteed to neither unintentionally gain or loose resources, then please enforce a logout of all open session for an account on any login.

Also many users might have lost Xtals without even knowing it. Probably there is an automated way to fix everyone's Xtals by summing up all event ranking progressions, in case they were not affected by the same caching issue? If I understand the case linked above correctly, while the Xtals were lost initially, for the ranking they were still counted, and then double-counted after support restored them for the rewards track.

Edited by Horsting
  • Thanks 1
Link to comment
Share on other sites

  • Horsting changed the title to [HA/ME] Serious possibly abusable bug with per-session progression

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
 Share

×
×
  • Create New...