Forums

Network issue

Sort:
ComeHugMyKing

https://www.chess.com/game/live/121830538221

Could someone who works on the network side of the house please take a look at this game? My phone is hacked and they are able to abuse your system.  Look deep enough and I'm certain you'll find something of interest.

Martin_Stahl
ComeHugMyKing wrote:

....

Could someone who works on the network side of the house please take a look at this game? My phone is hacked and they are able to abuse your system. Look deep enough and I'm certain you'll find something of interest.

Your opponents can't impact your connection. The clients never directly communicate so your opponent can't get your connection details.

ComeHugMyKing

https://www.chess.com/game/live/121835376679

Another example

Martin_Stahl
ComeHugMyKing wrote:

You're just getting normal disconnects.

https://support.chess.com/en/articles/8584209-how-do-i-fix-my-disconnect-lag-issues

ComeHugMyKing

1. I had 4 active connections to chesscom while "disconnected."

2. I never said it was my opponent.

3. If that's true, that's the case under typical circumstances. I might have indicated this wasn't one of those.

4. if looking for network vulnerabilites isn't in your job description, this post wasn't for you.

5. If you aren't capable of identifying a zeroday (e.g. can't review network logs), your input is meaningless.

6. That canned response never helped a single person.

Whatever happened was mostly, or even entirely, happening client side. But it happened on your platform using your code. Investigate it as much or as little as you please: that's a matter of how much pride you take in your product.

Martin_Stahl
ComeHugMyKing wrote:

1. I had 4 active connections to chesscom while "disconnected."

2. I never said it was my opponent.

3. If that's true, that's the case under typical circumstances. I might have indicated this wasn't one of those.

4. if looking for network vulnerabilites isn't in your job description, this post wasn't for you.

5. If you aren't capable of identifying a zeroday (e.g. can't review network logs), your input is meaningless.

6. That canned response never helped a single person.

Whatever happened was mostly, or even entirely, happening client side. But it happened on your platform using your code. Investigate it as much or as little as you please: that's a matter of how much pride you take in your product.

You claimed your phone was hacked, that's why I posted what I did.

That said, the live server and other pages on site are hosted differently, so having access to other pages and getting disconnected from the live server can happen.