Starmourn Game News

Previous Article | Back to News Summary | Next Article
Announcements News Post #94

Recent Lag.

Written by: Ilyos, the Arbiter
Date: Monday, December 2nd, 2019
Addressed to:


Last night, while investigating lag occurring across all IRE games, we discovered an unmitigated SQL injection vulnerability in the gamefeed processing on the games' websites, which was being actively used by an attacker. In an abundance of caution, we disabled the gamefeed functionality across all games and sinkholed the vulnerable API endpoint. We have now fixed the faulting code and reenabled the gamefeed.

We are still investigating the full impact of the vulnerability, but at this time it does not appear any customer data was accessed. It appears to have been a blind attack that didn't get beyond an attempt to identify access limitations, so no critical information was accessed whatsoever.

Special thanks to Razmael of Aetolia for identifying the initial impact, and Phaestus of Achaea and Eoghan of Imperian for identifying the SQLi and creating a mitigation.


Previous Article | Back to News Summary | Next Article
A digital drawing of a fluffy white cat with a black belly and bowtie juggling an old-fashioned computer mouse with an expression of panic.

New Year, New Roundtable!

It’s been a hectic year in the Starmourn sector, but we’re so happy to have the chance to celebrate another year with you all in our special corner of the internet. Good ol’ twenty-twenty-five saw some pretty big releases including: With all this + bonus fixes like ta-deth crystal recalculations, free gender changes, recurring UPCOMING…
Read More
Piles of colorfully wrapped presents in blue and pink wrapping paper alongside ancient tomes, treasure chests, and more cascade down a snow-laden landscape towards a towering ice castle in the distance.

A tale as old as time… It’s Winterflame Season!

In a fit of questionable holiday cheer, ol’ papa Ironbeard gave his favorite helper Barry a little too much leeway for a special Winterflame project, and now he needs YOUR assistance to keep the celebrations alive. Throughout the month of December, this year’s Winterflame event will let you send anonymous gifts and custom festive messages…
Read More

Maintenance Outage Scheduled

A maintenance window has been scheduled for Tuesday, October 14th beginning at 10 PM Central Time. We are expecting an outage window of up to 8 hours, but every effort will be made to minimize downtime. Please note: your device(s) will not be available during the maintenance period. Thank you in advance for your patience…
Read More