Breaking News

Samsung Launches Onyx Cinema LED Screen for European Market at CineEurope 2025 GAMEMAX Introduces CLAW 360 and CLAW 460 Gaming Cases EnGenius Launches Cloud-Lite Switch Series MSI Redefines Productivity and Versatility with Its New 144Hz Business Monitor Razer announces Kishi V3 Lineup

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Fortnite Vulnerability Put Millions of Players at Risk

Fortnite Vulnerability Put Millions of Players at Risk

Gaming Jan 16,2019 0

Researchers from Check Point Software Technologies discovered security vulnerabilities in the Fortnite’s login process that could have allowed a threat actor to take over the account of any user, view their personal account information, purchase virtual in-game currency and eavesdrop on in-game chatter as well as home conversations.

Created by Epic Games, an American video game developer, Fortnite is the game played by nearly 80 million people worldwide and is responsible for almost half of their $5bn-$8bn estimated company value.

Previous scams took the role of deceiving players into logging into fake websites that promised to generate Fortnite’s ‘V-Buck’ in-game currency, a commodity that can usually only be acquired through the official Fortnite store or by earning them in the game itself. These sites promote players to enter their login credentials, as well as personal information like name, address and credit card details (usually of the player’s parents) and are spread via social media campaigns that claim players can “earn easy cash” and “make quick money”.

Check Point's researchers however, relied on a far more sophisticated and sinister method, that did not require the user to hand over any login details whatsoever. Instead, it took advantage of Epic Games’ use of authentication tokens in conjunction with Single Sign-On (SSO) providers such as Facebook, Google, X-Box and others that are built in to Fortnite’s user login process.

Due to flaws found in Epic Games’ web infrastructure, the researchers were able to identify vulnerabilities with the token authentication process to steal the user’s access token and perform an account takeover.

A flaw was found in Epic Games login page, accounts.epicgames.com. As this domain had not been validated, it was susceptible to a malicious redirect. As a result, Check Point's team redirected traffic to another, though not in use, Epic Games sub-domain.

It was on this sub-domain, also containing security flaws, that the research team was able to identify an XSS attack to load a JavaScript that would make a secondary request to the SSO provider, for example, Facebook or Google+, to resend the authentication token. The SSO provider would correctly resend the token back to the login page. However, this time due to the malicious redirect, the token would be sent back to the manipulated sub-domain where the attacker is able to collect the token via his injected JavaScript code.

For the attack to be successful, all a victim needs to do is click on the malicious phishing link the attacker sends them. To increase the likelihood of a potential victim clicking on this link, for example, it could be sent with an enticement promising free game credits. Once clicked, with no need even for the user to enter any login credentials, their Fortnite authentication token would immediately be captured by the attacker.

With the access token now in the hands of the attacker, he can now log in to the user’s Fortnite account and view any data stored there, including the ability to buy more in-game currency at the user’s expense. He would also have access to all the user’s in-game contacts as well as listen in on and record conversations taking place during game play.

Along with this massive invasion of privacy, the financial risks and potential for fraud is vast. Users could well see huge purchases of in-game currency made on their credit cards with the attacker funneling that virtual currency to be sold for cash in the real world.

Epic Games recently fixed the flaw, the Israeli cyber security company said. The company encourages for users to enable two-factor authentication. By doing so, and when logging into their account from a new device, the user is required to enter a security code that is then sent via email to the account owner.

Tags: FortniteHacking
Previous Post
Iridium Certus Global Broadband Service Goes Live
Next Post
Teac LP-R560K Supports Recording of Vinyl Records and Cassette Tapes on CDs

Related Posts

  • Most popular online games of all time

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

Latest News

Samsung Launches Onyx Cinema LED Screen for European Market at CineEurope 2025
Consumer Electronics

Samsung Launches Onyx Cinema LED Screen for European Market at CineEurope 2025

GAMEMAX Introduces CLAW 360 and CLAW 460 Gaming Cases
Cooling Systems

GAMEMAX Introduces CLAW 360 and CLAW 460 Gaming Cases

EnGenius Launches Cloud-Lite Switch Series
Enterprise & IT

EnGenius Launches Cloud-Lite Switch Series

MSI Redefines Productivity and Versatility with Its New 144Hz Business Monitor
Enterprise & IT

MSI Redefines Productivity and Versatility with Its New 144Hz Business Monitor

Razer announces Kishi V3 Lineup
Smartphones

Razer announces Kishi V3 Lineup

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Noctua NH-D15 G2

Noctua NH-D15 G2

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed