
Closed
Posted
Paid on delivery
We are developing an online multiplayer strategy game similar to Travian (known as حرب التتار in Arabic). The game is currently under development, and once it is completed, we will hire a security and development expert to perform a comprehensive vulnerability audit and full security hardening process. The goal is to detect, fix, and prevent any type of security flaw that could be exploited by: Players (cheating, exploiting bugs) Internal developers/admins (insider threats) External hackers (cyberattacks) We are posting this early to connect with the right expert in advance. Scope of Work: 1. Player Exploit Prevention Fix duplication glitches for resources, troops, or items. Prevent race condition exploits (multiple rapid commands). Protect game events from time manipulation between client and server. Block modification of HTTP requests or in-game data before reaching the server. Prevent bypassing daily limits or programmed restrictions. Prevent marketplace/trade exploits (price manipulation, infinite trades). Secure map mechanics to block illegal village relocation or interactions with protected zones. Protection against lag-switching exploits that alter battle or trade results. 2. Insider Threat Mitigation Full source code audit to detect backdoors, hidden scripts, or malicious logic. Audit admin panel permissions and prevent privilege abuse. Log and track all admin actions (Admin Command Logging). Prevent unauthorized live file modifications during runtime. Enforce the principle of least privilege for all accounts. 3. External Hacker Protection Close all OWASP Top 10 vulnerabilities: SQL Injection XSS (Cross-Site Scripting) CSRF (Cross-Site Request Forgery) Remote Code Execution (RCE) Insecure Direct Object References (IDOR) Server-Side Request Forgery (SSRF) Protect against DDoS / Botnet attacks. Secure all APIs and third-party integrations. Scan and close unnecessary open ports/services. Harden the server against brute force and credential stuffing attacks. 4. Logic & Design Flaw Fixes Enforce server-side validation for all in-game operations. Use atomic transactions to ensure data consistency. Correct execution order to prevent logical inconsistencies. Real-time monitoring and alert systems for suspicious activity. Verify resource/troop calculation logic to prevent math-related exploits. 5. Bot, VPN & Multi-Account Prevention Implement bot detection systems to block automation scripts. Use device fingerprinting to uniquely identify each player’s device. Block VPN, proxy, and TOR connections to prevent multi-account abuse. Real-time flagging of suspicious login patterns and location changes. Detect and block macros or automated farming scripts. 6. Chat & Messaging Abuse Prevention Block all advertising attempts in public or private chat, including: Text messages containing external links. Images containing promotional or spam content. Repeated spam messages or mass messaging. Implement filters to detect and block suspicious keywords or domains. Allow only safe, whitelisted links if any linking is required. Real-time flagging and moderation of chat activity. 7. Additional Security Measures Session Security: Secure cookies (HttpOnly, Secure, SameSite) and auto session expiration after inactivity. Captcha Integration: Add Captcha for sensitive actions (login, attacks, suspicious trades). Two-Factor Authentication (2FA): For admin and moderator accounts. File Upload Security: Scan and validate all uploaded files to prevent malicious uploads. Data Encryption: Password hashing with bcrypt or Argon2. Encryption of sensitive data in the database. Logging & Forensics: Store all critical logs with timestamps for investigation. Geo-Restrictions (optional): Block or allow access from specific countries if needed. API Rate Limiting: Limit requests per IP/device to prevent abuse or overload. Automatic Ban System: Auto-ban accounts showing abnormal activity patterns. 8. Future-Proof Security Regular security maintenance schedule. Continuous updates with the latest patches. Secure backup & disaster recovery procedures. Load and stress testing to prevent performance-based exploits. Intrusion detection & prevention systems (IDS/IPS). Preferred Tools & Technologies: Security Tools: Burp Suite, OWASP ZAP, Wireshark. Server Protection: ModSecurity, Fail2Ban, WAF solutions. Server Platforms: Linux or Windows Server administration and hardening. Bot & VPN Detection: FingerprintJS, IP2Proxy, custom server-side scripts. Notes: Strict confidentiality is required. Deliverables: A detailed report of all vulnerabilities found, their severity, and the fixes implemented. Preference for candidates with proven experience securing online multiplayer games. Please provide your total price and estimated completion time for the full security process once development is complete.
Project ID: 39691470
99 proposals
Remote project
Active 9 mos ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs