• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 20:04
CEST 02:04
KST 09:04
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Code S RO4 & Finals Preview: herO, GuMiho, Classic, Cure4Code S RO8 Preview: Classic, Reynor, Maru, GuMiho2Code S RO8 Preview: ByuN, Rogue, herO, Cure4[ASL19] Ro4 Preview: Storied Rivals7Code S RO12 Preview: Maru, Trigger, Rogue, NightMare12
Community News
Code S Season 1 - RO8 Group B Results (2025)4[BSL 2v2] ProLeague Season 3 - Friday 21:00 CET6herO & Cure GSL RO8 Interviews: "I also think that all the practice I put in when Protoss wasn’t doing as well is paying off"0Code S Season 1 - herO & Cure advance to RO4 (2025)0Dark to begin military service on May 13th (2025)21
StarCraft 2
General
Code S Season 1 - RO8 Group B Results (2025) 2024/25 Off-Season Roster Moves Code S RO4 & Finals Preview: herO, GuMiho, Classic, Cure Code S RO8 Preview: Classic, Reynor, Maru, GuMiho Code S RO8 Preview: ByuN, Rogue, herO, Cure
Tourneys
[GSL 2025] Code S Season 1 - RO4 and Grand Finals [GSL 2025] Code S:Season 1 - RO8 - Group B SOOP Starcraft Global #20 RSL: Revival, a new crowdfunded tournament series SEL Code A [MMR-capped] (SC: Evo)
Strategy
Simple Questions Simple Answers [G] PvT Cheese: 13 Gate Proxy Robo
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 473 Cold is the Void Mutation # 472 Dead Heat Mutation # 471 Delivery Guaranteed Mutation # 470 Certain Demise
Brood War
General
BW General Discussion ASL 19 Tickets for foreigners BGH auto balance -> http://bghmmr.eu/ Recent recommended BW games Battlenet Game Lobby Simulator
Tourneys
[ASL19] Semifinal B [BSL 2v2] ProLeague Season 3 - Friday 21:00 CET [ASL19] Ro8 Day 4 [Megathread] Daily Proleagues
Strategy
[G] How to get started on ladder as a new Z player Creating a full chart of Zerg builds [G] Mineral Boosting
Other Games
General Games
Beyond All Reason Stormgate/Frost Giant Megathread Grand Theft Auto VI Nintendo Switch Thread What do you want from future RTS games?
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
LiquidLegends to reintegrate into TL.net
Heroes of the Storm
Simple Questions, Simple Answers
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia TL Mafia Community Thread TL Mafia Plays: Diplomacy TL Mafia: Generative Agents Showdown Survivor II: The Amazon
Community
General
UK Politics Mega-thread US Politics Mega-thread Russo-Ukrainian War Thread Elon Musk's lies, propaganda, etc. Ask and answer stupid questions here!
Fan Clubs
Serral Fan Club
Media & Entertainment
[Manga] One Piece Movie Discussion! Anime Discussion Thread [Books] Wool by Hugh Howey
Sports
NHL Playoffs 2024 2024 - 2025 Football Thread NBA General Discussion Formula 1 Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread Cleaning My Mechanical Keyboard How to clean a TTe Thermaltake keyboard?
TL Community
The Automated Ban List TL.net Ten Commandments
Blogs
Why 5v5 Games Keep Us Hooked…
TrAiDoS
Info SLEgma_12
SLEgma_12
SECOND COMMING
XenOsky
WombaT’s Old BW Terran Theme …
WombaT
Heero Yuy & the Tax…
KrillinFromwales
BW PvZ Balance hypothetic…
Vasoline73
ASL S19 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 10175 users

SCBW Bnet hacker: Watch out - Page 2

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 6 7 Next All
igotmyown
Profile Blog Joined April 2009
United States4291 Posts
May 04 2010 07:30 GMT
#21
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?
Deleted User 47542
Profile Blog Joined May 2009
1484 Posts
Last Edited: 2010-05-04 07:35:47
May 04 2010 07:34 GMT
#22
On May 04 2010 16:30 igotmyown wrote:
Show nested quote +
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?

BWHF = brood war hack finder, not a hack.

If you google that exactly you will get it, it's a 3rd party program that analyzes replays for hacks pretty much instantly, and can load up a black list of known hackers, etc. I used it when I used to play around on bnet but those days are long gone :x It catches multi/autogather 100% of the time, but map hack is pretty much undetectable.. [unless a newer version was released in the 1-2 years I've been off bnet]
LunarDestiny
Profile Blog Joined August 2008
United States4177 Posts
May 04 2010 07:35 GMT
#23
BWHF is a replay scanner for hacks. It can not hack and most players use it to analyze their games.

http://code.google.com/p/bwhf/
LunarDestiny
Profile Blog Joined August 2008
United States4177 Posts
May 04 2010 07:39 GMT
#24
On May 04 2010 16:12 omfghi2u2 wrote:
I think the funniest hacks are when you play the UMS game tittled, "Banning game." And when you trap them, they drophack you.

But back on topic, I remember going into a game and someone came in the game and wrote in all caps, "BAN ME? I BAN YOU" and Bnet crashed.

This allah/frost guy is all over bnet.

Ironically, I think Allah made that Banning game and with extra hack speed.
MaRiNe23
Profile Blog Joined December 2006
United States747 Posts
May 04 2010 07:44 GMT
#25
What I've always wondered is..why does he keep the same game names. Like he always makes it ALLAH@USEAST or FROST@USEAST "something@USEAST". If he really wanted to annoy people he would make the game name like "1v1 python play/obs" so that people will join or some other popular UMS. Either he's dumb or he can't adjust the game name for whatever reason and always has to add "@USEAST at the end of his game name" I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.
We have competitive ladder, strong community, progaming in Korea going strong, perfectly balanced game..why do we need sc2? #1 ANTI-SC2 fan
L_Master
Profile Blog Joined April 2009
United States8017 Posts
May 04 2010 07:52 GMT
#26
I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.


Thing is, if you even gloss over them it will make SC crash, you don't even have to try and enter. But yeah, if he gave them random "real" names it would be far more annoying that it is now, where you just have to be careful where you place your cursor.
EffOrt and Soulkey Hwaiting!
EleanorRIgby
Profile Joined March 2008
Canada3923 Posts
May 04 2010 08:00 GMT
#27
On May 04 2010 16:44 MaRiNe23 wrote:
What I've always wondered is..why does he keep the same game names. Like he always makes it ALLAH@USEAST or FROST@USEAST "something@USEAST". If he really wanted to annoy people he would make the game name like "1v1 python play/obs" so that people will join or some other popular UMS. Either he's dumb or he can't adjust the game name for whatever reason and always has to add "@USEAST at the end of his game name" I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.


Clearly he wants to make a name from himself as an e-villian
savior did nothing wrong
anch
Profile Blog Joined June 2006
United States5457 Posts
May 04 2010 08:10 GMT
#28
On May 04 2010 14:15 krndandaman wrote:
Show nested quote +
On May 04 2010 13:33 Amnesia wrote:
Let's get R1CH to stomp his ass


Agreed.
R1CH would make him cry for his mommy.

Show him who's the real wizard around starcraft.

would be scary as hell if R1CH is Frost's alter ego.
dum dum dum.
lgd-haze
Profile Blog Joined January 2009
Sweden547 Posts
May 04 2010 08:32 GMT
#29
Release the Krak.. R1CH!!
Flying Tushin!!
PobTheCad
Profile Blog Joined July 2006
Australia893 Posts
May 04 2010 09:49 GMT
#30
i first noticed those games on west about 1 1/2 - 2 months back
the past few weeks i noticed less of them but it may just be a time of day thing
Once again back is the incredible!
Oddysay
Profile Blog Joined October 2007
Canada597 Posts
May 04 2010 10:14 GMT
#31
blizzard are behind the hacker ! they want you to switch to sc2 !!

seriously that kinda scary people can make hack like that , battle.net security was pretty bad if you think about that .
GTR
Profile Blog Joined September 2004
51399 Posts
May 04 2010 10:16 GMT
#32
[image loading]
Commentator
infinity2k9
Profile Blog Joined January 2009
United Kingdom2397 Posts
May 04 2010 10:23 GMT
#33
On May 04 2010 16:12 omfghi2u2 wrote:
I think the funniest hacks are when you play the UMS game tittled, "Banning game." And when you trap them, they drophack you.

But back on topic, I remember going into a game and someone came in the game and wrote in all caps, "BAN ME? I BAN YOU" and Bnet crashed.

This allah/frost guy is all over bnet.


You know, there is a drophack protector. It works well and is really funny when they try it cause it warns you too or counter-drops them. One guy i had was spamming it loads of times trying to drop me and was getting really mad about it. I just use that along with BWHF and i don't tend to have much trouble with hackers thanks to it (this is on USWest).
Excel Excel
Profile Blog Joined February 2010
142 Posts
May 04 2010 10:37 GMT
#34
On May 04 2010 16:34 superbabosheki wrote:
Show nested quote +
On May 04 2010 16:30 igotmyown wrote:
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?

BWHF = brood war hack finder, not a hack.

If you google that exactly you will get it, it's a 3rd party program that analyzes replays for hacks pretty much instantly, and can load up a black list of known hackers, etc. I used it when I used to play around on bnet but those days are long gone :x It catches multi/autogather 100% of the time, but map hack is pretty much undetectable.. [unless a newer version was released in the 1-2 years I've been off bnet]


The only undetectable hacks (map hack, resource hack) happen to be the most useful; autogather and multicommand do not really help the hacker that much in higher level games, so they can turn off the easily detectable features and still have a massive advantage.
"SCREW OBSERVERS MUST HAVE MOAR ARBITERS!!!11one1" - Famous last words
dhe95
Profile Blog Joined December 2008
United States1213 Posts
May 04 2010 11:01 GMT
#35
From Hot_Bid's R1CH quotes thread:
Sent a copy of this to hacks@blizzard, but if you catch anyone in person, direct them to this thread as this seems serious enough to warrant attention:

---------------------

There appears to be a hack circulating in SC:BW where an oversized game name is passed to bnet upon game creation. Bnet does not perform input sanitization on this value before storing it. Bnet then sends this information back to the client when the client is at the join game screen, at which point the oversized game name is added to the join game list box. When the user clicks the entry, the list box text is copied into an unchecked 128 byte buffer and a stack-based buffer overflow occurs.

On a quick glance, the return address looks possibly controllable, meaning with the right length and combination of characters, this could be exploited to execute arbitrary code on the StarCraft client.

Vulnerable code resides in battle.snp @ base + 0x237D0:

190237D0 |. 8B1D BCA20319 mov ebx,dword ptr ds:[<&USER32.SendMessa>; USER32.SendMessageA
190237D6 |. 6A 00 push 0 ; /lParam = 0
190237D8 |. 6A 00 push 0 ; |wParam = 0
190237DA |. 68 88010000 push 188 ; |Message = LB_GETCURSEL
190237DF |. 56 push esi ; |hWnd
190237E0 |. FFD3 call ebx ; \SendMessageA
190237E2 |. 83F8 FF cmp eax,-1
190237E5 |. 0F84 7D000000 je battle.19023868
190237EB |. 8D95 70FFFFFF lea edx,dword ptr ss:[ebp-90]
190237F1 |. 52 push edx ; /lParam
190237F2 |. 50 push eax ; |wParam
190237F3 |. 68 89010000 push 189 ; |Message = LB_GETTEXT
190237F8 |. 56 push esi ; |hWnd
190237F9 |. FFD3 call ebx ; \SendMessageA

As shown here, LB_GETTEXT is used to pull the string out of the listbox into edx. edx points to a stack buffer of 128 bytes. Since the string in the listbox is controlled by the attacker as no bounds checking is done on either the client or the server, a stack-based buffer overflow occurs.

My suggested immediate fix would be to limit the maximum game name / mapname and other user-controlled parameters that the battle.net server will accept as this would not require a client patch. If the user submits to bnet values of greater length than the BW client would normally allow, they can be flagged as malicious and handled accordingly. An additional suggested client-side update in the next patch would validate the game name and other parameters received from battle.net before working with them, to protect the player from 3rd party servers.

I would appreciate being informed of any updates to this issue, as if no action is taken I will make my own unofficial patch to address this bug. Thanks!


seems like R1CH already found this ages ago.
Nytefish
Profile Blog Joined December 2007
United Kingdom4282 Posts
May 04 2010 11:31 GMT
#36
^Also seems like Blizzard completely ignored him.
No I'm never serious.
TwilightStar
Profile Blog Joined August 2009
United States649 Posts
May 04 2010 12:48 GMT
#37
Holy crap, that's one of my old/good friends from east... wtf is he doing this for xD
(5)Twilight Star.scx --------- AdmiralHoth: There was one week when I didn't shave for a month.
Kentucky
Profile Joined November 2009
United States63 Posts
May 04 2010 13:44 GMT
#38
Who cares?

These people are only looking for attention and that's exactly what you give them by posting this pointless thread.

They're not clever, they're pathetic untalented unemployed retards who downloaded 1 millionth of an ounce of power over an internet game and now they're spending their time trying to annoy people because they're that desperate to get attention from someone even if it's negative attention from a stranger.

They have zero power over you, just avoid them and ignore them. Don't make their little game of annoying people fun for them by showing them how annoyed you are, just ignore it.
gumbum8
Profile Blog Joined December 2008
United States721 Posts
May 04 2010 14:05 GMT
#39
On May 04 2010 22:44 Kentucky wrote:
Who cares?

These people are only looking for attention and that's exactly what you give them by posting this pointless thread.

They're not clever, they're pathetic untalented unemployed retards who downloaded 1 millionth of an ounce of power over an internet game and now they're spending their time trying to annoy people because they're that desperate to get attention from someone even if it's negative attention from a stranger.

They have zero power over you, just avoid them and ignore them. Don't make their little game of annoying people fun for them by showing them how annoyed you are, just ignore it.


Uhm... So if he crashes everyone's computer on East, we should just ignore it and let East become a frost dessert? I'm kinda glad there was this warning, my friend only plays on East... (mac)
but really, has anyone REALLY been far even as decided to use even go want to do look more like?
Xeofreestyler
Profile Blog Joined June 2005
Belgium6768 Posts
May 04 2010 15:58 GMT
#40
I would so love it if rich would e-rape that lil scriptpunk
Graphics
Prev 1 2 3 4 5 6 7 Next All
Please log in or register to reply.
Live Events Refresh
OSC
00:00
2025 Mid Season Playoffs #1
CranKy Ducklings18
Liquipedia
The PiG Daily
23:15
GSL Finals Replay Cast
herO vs GuMiho
Classic vs Cure
LiquipediaDiscussion
PSISTORM Gaming Misc
23:00
FSL s9 plan and showmatches
Freeedom10
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft312
RuFF_SC2 166
JuggernautJason145
StarCraft: Brood War
ZZZero.O 82
Sexy 20
Icarus 6
Dota 2
NeuroSwarm119
LuMiX0
Counter-Strike
Stewie2K895
Foxcn618
flusha400
Super Smash Bros
C9.Mang02803
Mew2King176
Heroes of the Storm
Grubby5097
Khaldor163
Other Games
summit1g8701
shahzam1269
WinterStarcraft132
Trikslyr32
ViBE32
PPMD19
Organizations
Other Games
gamesdonequick845
StarCraft 2
ESL.tv145
Other Games
BasetradeTV112
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 14 non-featured ]
StarCraft 2
• Hupsaiya 67
• musti20045 26
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• Azhi_Dahaki25
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• Ler93
Upcoming Events
Korean StarCraft League
2h 56m
RSL Revival
9h 56m
SOOP Global
14h 56m
Spirit vs SKillous
YoungYakov vs ShowTime
SOOP
17h 26m
HeRoMaRinE vs Astrea
BSL Season 20
17h 56m
UltrA vs Radley
spx vs RaNgeD
Online Event
1d 3h
Clem vs ShoWTimE
herO vs MaxPax
Sparkling Tuna Cup
1d 9h
WardiTV Invitational
1d 10h
Percival vs TriGGeR
ByuN vs Solar
Clem vs Spirit
MaxPax vs Jumy
BSL Season 20
1d 14h
TerrOr vs HBO
Tarson vs Spine
RSL Revival
1d 16h
[ Show More ]
BSL Season 20
1d 17h
MadiNho vs dxtr13
Gypsy vs Dark
Wardi Open
2 days
Monday Night Weeklies
2 days
Replay Cast
3 days
The PondCast
4 days
Replay Cast
4 days
Replay Cast
5 days
Road to EWC
6 days
Liquipedia Results

Completed

Proleague 2025-05-14
2025 GSL S1
Calamity Stars S2

Ongoing

JPL Season 2
ASL Season 19
YSL S1
BSL 2v2 Season 3
BSL Season 20
China & Korea Top Challenge
KCM Race Survival 2025 Season 2
NPSL S3
Heroes 10 EU
PGL Astana 2025
Asian Champions League '25
ECL Season 49: Europe
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025
YaLLa Compass Qatar 2025
PGL Bucharest 2025
BLAST Open Spring 2025
ESL Pro League S21

Upcoming

CSLPRO Last Chance 2025
CSLAN 2025
K-Championship
Esports World Cup 2025
HSC XXVII
Championship of Russia 2025
Bellum Gens Elite Stara Zagora 2025
2025 GSL S2
DreamHack Dallas 2025
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.