• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 04:21
CEST 10:21
KST 17:21
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL20] Ro24 Preview Pt1: Runway132v2 & SC: Evo Complete: Weekend Double Feature3Team Liquid Map Contest #21 - Presented by Monster Energy9uThermal's 2v2 Tour: $15,000 Main Event18Serral wins EWC 202549
Community News
Maestros of The Game—$20k event w/ live finals in Paris18Weekly Cups (Aug 11-17): MaxPax triples again!13Weekly Cups (Aug 4-10): MaxPax wins a triple6SC2's Safe House 2 - October 18 & 195Weekly Cups (Jul 28-Aug 3): herO doubles up6
StarCraft 2
General
What mix of new and old maps do you want in the next 1v1 ladder pool? (SC2) : Geoff 'iNcontroL' Robinson has passed away The GOAT ranking of GOAT rankings RSL Revival patreon money discussion thread Weekly Cups (Aug 11-17): MaxPax triples again!
Tourneys
Maestros of The Game—$20k event w/ live finals in Paris Sparkling Tuna Cup - Weekly Open Tournament Monday Nights Weeklies Master Swan Open (Global Bronze-Master 2) $5,100+ SEL Season 2 Championship (SC: Evo)
Strategy
Custom Maps
External Content
Mutation # 487 Think Fast Mutation # 486 Watch the Skies Mutation # 485 Death from Below Mutation # 484 Magnetic Pull
Brood War
General
Maps with Neutral Command Centers BGH Auto Balance -> http://bghmmr.eu/ Flash Announces (and Retracts) Hiatus From ASL BW General Discussion BW AKA finder tool
Tourneys
[ASL20] Ro24 Group C [Megathread] Daily Proleagues [ASL20] Ro24 Group A [ASL20] Ro24 Group B
Strategy
Simple Questions, Simple Answers Fighting Spirit mining rates [G] Mineral Boosting Muta micro map competition
Other Games
General Games
General RTS Discussion Thread Dawn of War IV Path of Exile Stormgate/Frost Giant Megathread Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine The year 2050 European Politico-economics QA Mega-thread
Fan Clubs
INnoVation Fan Club SKT1 Classic Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece [\m/] Heavy Metal Thread
Sports
2024 - 2026 Football Thread TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
High temperatures on bridge(s) Gtx660 graphics card replacement Installation of Windows 10 suck at "just a moment"
TL Community
"World Leading Blockchain Asset Retrieval" The Automated Ban List TeamLiquid Team Shirt On Sale
Blogs
Evil Gacha Games and the…
ffswowsucks
Breaking the Meta: Non-Stand…
TrAiDoS
INDEPENDIENTE LA CTM
XenOsky
[Girl blog} My fema…
artosisisthebest
Sharpening the Filtration…
frozenclaw
ASL S20 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2952 users

SCBW Bnet hacker: Watch out - Page 2

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 6 7 Next All
igotmyown
Profile Blog Joined April 2009
United States4291 Posts
May 04 2010 07:30 GMT
#21
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?
Deleted User 47542
Profile Blog Joined May 2009
1484 Posts
Last Edited: 2010-05-04 07:35:47
May 04 2010 07:34 GMT
#22
On May 04 2010 16:30 igotmyown wrote:
Show nested quote +
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?

BWHF = brood war hack finder, not a hack.

If you google that exactly you will get it, it's a 3rd party program that analyzes replays for hacks pretty much instantly, and can load up a black list of known hackers, etc. I used it when I used to play around on bnet but those days are long gone :x It catches multi/autogather 100% of the time, but map hack is pretty much undetectable.. [unless a newer version was released in the 1-2 years I've been off bnet]
LunarDestiny
Profile Blog Joined August 2008
United States4177 Posts
May 04 2010 07:35 GMT
#23
BWHF is a replay scanner for hacks. It can not hack and most players use it to analyze their games.

http://code.google.com/p/bwhf/
LunarDestiny
Profile Blog Joined August 2008
United States4177 Posts
May 04 2010 07:39 GMT
#24
On May 04 2010 16:12 omfghi2u2 wrote:
I think the funniest hacks are when you play the UMS game tittled, "Banning game." And when you trap them, they drophack you.

But back on topic, I remember going into a game and someone came in the game and wrote in all caps, "BAN ME? I BAN YOU" and Bnet crashed.

This allah/frost guy is all over bnet.

Ironically, I think Allah made that Banning game and with extra hack speed.
MaRiNe23
Profile Blog Joined December 2006
United States747 Posts
May 04 2010 07:44 GMT
#25
What I've always wondered is..why does he keep the same game names. Like he always makes it ALLAH@USEAST or FROST@USEAST "something@USEAST". If he really wanted to annoy people he would make the game name like "1v1 python play/obs" so that people will join or some other popular UMS. Either he's dumb or he can't adjust the game name for whatever reason and always has to add "@USEAST at the end of his game name" I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.
We have competitive ladder, strong community, progaming in Korea going strong, perfectly balanced game..why do we need sc2? #1 ANTI-SC2 fan
L_Master
Profile Blog Joined April 2009
United States8017 Posts
May 04 2010 07:52 GMT
#26
I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.


Thing is, if you even gloss over them it will make SC crash, you don't even have to try and enter. But yeah, if he gave them random "real" names it would be far more annoying that it is now, where you just have to be careful where you place your cursor.
EffOrt and Soulkey Hwaiting!
EleanorRIgby
Profile Joined March 2008
Canada3923 Posts
May 04 2010 08:00 GMT
#27
On May 04 2010 16:44 MaRiNe23 wrote:
What I've always wondered is..why does he keep the same game names. Like he always makes it ALLAH@USEAST or FROST@USEAST "something@USEAST". If he really wanted to annoy people he would make the game name like "1v1 python play/obs" so that people will join or some other popular UMS. Either he's dumb or he can't adjust the game name for whatever reason and always has to add "@USEAST at the end of his game name" I dunno it was always strange for me that he would keep the same game name so that ppl can just skip over his games.


Clearly he wants to make a name from himself as an e-villian
savior did nothing wrong
anch
Profile Blog Joined June 2006
United States5457 Posts
May 04 2010 08:10 GMT
#28
On May 04 2010 14:15 krndandaman wrote:
Show nested quote +
On May 04 2010 13:33 Amnesia wrote:
Let's get R1CH to stomp his ass


Agreed.
R1CH would make him cry for his mommy.

Show him who's the real wizard around starcraft.

would be scary as hell if R1CH is Frost's alter ego.
dum dum dum.
lgd-haze
Profile Blog Joined January 2009
Sweden547 Posts
May 04 2010 08:32 GMT
#29
Release the Krak.. R1CH!!
Flying Tushin!!
PobTheCad
Profile Blog Joined July 2006
Australia893 Posts
May 04 2010 09:49 GMT
#30
i first noticed those games on west about 1 1/2 - 2 months back
the past few weeks i noticed less of them but it may just be a time of day thing
Once again back is the incredible!
Oddysay
Profile Blog Joined October 2007
Canada597 Posts
May 04 2010 10:14 GMT
#31
blizzard are behind the hacker ! they want you to switch to sc2 !!

seriously that kinda scary people can make hack like that , battle.net security was pretty bad if you think about that .
GTR
Profile Blog Joined September 2004
51465 Posts
May 04 2010 10:16 GMT
#32
[image loading]
Commentator
infinity2k9
Profile Blog Joined January 2009
United Kingdom2397 Posts
May 04 2010 10:23 GMT
#33
On May 04 2010 16:12 omfghi2u2 wrote:
I think the funniest hacks are when you play the UMS game tittled, "Banning game." And when you trap them, they drophack you.

But back on topic, I remember going into a game and someone came in the game and wrote in all caps, "BAN ME? I BAN YOU" and Bnet crashed.

This allah/frost guy is all over bnet.


You know, there is a drophack protector. It works well and is really funny when they try it cause it warns you too or counter-drops them. One guy i had was spamming it loads of times trying to drop me and was getting really mad about it. I just use that along with BWHF and i don't tend to have much trouble with hackers thanks to it (this is on USWest).
Excel Excel
Profile Blog Joined February 2010
142 Posts
May 04 2010 10:37 GMT
#34
On May 04 2010 16:34 superbabosheki wrote:
Show nested quote +
On May 04 2010 16:30 igotmyown wrote:
On May 04 2010 16:23 dRaW wrote:
Where do you find this BWHF? The all @Useast is funny though...


Can TL ban you for asking for hacks?

BWHF = brood war hack finder, not a hack.

If you google that exactly you will get it, it's a 3rd party program that analyzes replays for hacks pretty much instantly, and can load up a black list of known hackers, etc. I used it when I used to play around on bnet but those days are long gone :x It catches multi/autogather 100% of the time, but map hack is pretty much undetectable.. [unless a newer version was released in the 1-2 years I've been off bnet]


The only undetectable hacks (map hack, resource hack) happen to be the most useful; autogather and multicommand do not really help the hacker that much in higher level games, so they can turn off the easily detectable features and still have a massive advantage.
"SCREW OBSERVERS MUST HAVE MOAR ARBITERS!!!11one1" - Famous last words
dhe95
Profile Blog Joined December 2008
United States1213 Posts
May 04 2010 11:01 GMT
#35
From Hot_Bid's R1CH quotes thread:
Sent a copy of this to hacks@blizzard, but if you catch anyone in person, direct them to this thread as this seems serious enough to warrant attention:

---------------------

There appears to be a hack circulating in SC:BW where an oversized game name is passed to bnet upon game creation. Bnet does not perform input sanitization on this value before storing it. Bnet then sends this information back to the client when the client is at the join game screen, at which point the oversized game name is added to the join game list box. When the user clicks the entry, the list box text is copied into an unchecked 128 byte buffer and a stack-based buffer overflow occurs.

On a quick glance, the return address looks possibly controllable, meaning with the right length and combination of characters, this could be exploited to execute arbitrary code on the StarCraft client.

Vulnerable code resides in battle.snp @ base + 0x237D0:

190237D0 |. 8B1D BCA20319 mov ebx,dword ptr ds:[<&USER32.SendMessa>; USER32.SendMessageA
190237D6 |. 6A 00 push 0 ; /lParam = 0
190237D8 |. 6A 00 push 0 ; |wParam = 0
190237DA |. 68 88010000 push 188 ; |Message = LB_GETCURSEL
190237DF |. 56 push esi ; |hWnd
190237E0 |. FFD3 call ebx ; \SendMessageA
190237E2 |. 83F8 FF cmp eax,-1
190237E5 |. 0F84 7D000000 je battle.19023868
190237EB |. 8D95 70FFFFFF lea edx,dword ptr ss:[ebp-90]
190237F1 |. 52 push edx ; /lParam
190237F2 |. 50 push eax ; |wParam
190237F3 |. 68 89010000 push 189 ; |Message = LB_GETTEXT
190237F8 |. 56 push esi ; |hWnd
190237F9 |. FFD3 call ebx ; \SendMessageA

As shown here, LB_GETTEXT is used to pull the string out of the listbox into edx. edx points to a stack buffer of 128 bytes. Since the string in the listbox is controlled by the attacker as no bounds checking is done on either the client or the server, a stack-based buffer overflow occurs.

My suggested immediate fix would be to limit the maximum game name / mapname and other user-controlled parameters that the battle.net server will accept as this would not require a client patch. If the user submits to bnet values of greater length than the BW client would normally allow, they can be flagged as malicious and handled accordingly. An additional suggested client-side update in the next patch would validate the game name and other parameters received from battle.net before working with them, to protect the player from 3rd party servers.

I would appreciate being informed of any updates to this issue, as if no action is taken I will make my own unofficial patch to address this bug. Thanks!


seems like R1CH already found this ages ago.
Nytefish
Profile Blog Joined December 2007
United Kingdom4282 Posts
May 04 2010 11:31 GMT
#36
^Also seems like Blizzard completely ignored him.
No I'm never serious.
TwilightStar
Profile Blog Joined August 2009
United States649 Posts
May 04 2010 12:48 GMT
#37
Holy crap, that's one of my old/good friends from east... wtf is he doing this for xD
(5)Twilight Star.scx --------- AdmiralHoth: There was one week when I didn't shave for a month.
Kentucky
Profile Joined November 2009
United States63 Posts
May 04 2010 13:44 GMT
#38
Who cares?

These people are only looking for attention and that's exactly what you give them by posting this pointless thread.

They're not clever, they're pathetic untalented unemployed retards who downloaded 1 millionth of an ounce of power over an internet game and now they're spending their time trying to annoy people because they're that desperate to get attention from someone even if it's negative attention from a stranger.

They have zero power over you, just avoid them and ignore them. Don't make their little game of annoying people fun for them by showing them how annoyed you are, just ignore it.
gumbum8
Profile Blog Joined December 2008
United States721 Posts
May 04 2010 14:05 GMT
#39
On May 04 2010 22:44 Kentucky wrote:
Who cares?

These people are only looking for attention and that's exactly what you give them by posting this pointless thread.

They're not clever, they're pathetic untalented unemployed retards who downloaded 1 millionth of an ounce of power over an internet game and now they're spending their time trying to annoy people because they're that desperate to get attention from someone even if it's negative attention from a stranger.

They have zero power over you, just avoid them and ignore them. Don't make their little game of annoying people fun for them by showing them how annoyed you are, just ignore it.


Uhm... So if he crashes everyone's computer on East, we should just ignore it and let East become a frost dessert? I'm kinda glad there was this warning, my friend only plays on East... (mac)
but really, has anyone REALLY been far even as decided to use even go want to do look more like?
Xeofreestyler
Profile Blog Joined June 2005
Belgium6771 Posts
May 04 2010 15:58 GMT
#40
I would so love it if rich would e-rape that lil scriptpunk
Graphics
Prev 1 2 3 4 5 6 7 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 39m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
trigger 59
StarCraft: Brood War
Barracks 4857
Sea 3256
TY 333
ggaemo 145
NaDa 33
zelot 29
Bale 7
Dota 2
XcaliburYe439
XaKoH 306
League of Legends
JimRising 613
Dendi282
Other Games
summit1g3368
singsing1518
ceh9493
C9.Mang0322
Happy277
Mew2King30
Trikslyr27
Organizations
Other Games
gamesdonequick555
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 12 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• lizZardDota242
League of Legends
• Jankos867
Upcoming Events
CranKy Ducklings
1h 39m
SC Evo League
3h 39m
WardiTV Summer Champion…
4h 39m
Classic vs Percival
Spirit vs NightMare
CSO Cup
7h 39m
[BSL 2025] Weekly
9h 39m
Sparkling Tuna Cup
1d 1h
SC Evo League
1d 3h
Replay Cast
1d 15h
Afreeca Starleague
2 days
Queen vs HyuN
EffOrt vs Calm
Wardi Open
2 days
[ Show More ]
RotterdaM Event
2 days
Replay Cast
2 days
Afreeca Starleague
3 days
Rush vs TBD
Jaedong vs Mong
Afreeca Starleague
4 days
herO vs TBD
Royal vs Barracks
Replay Cast
4 days
The PondCast
5 days
Replay Cast
5 days
LiuLi Cup
6 days
Cosmonarchy
6 days
OyAji vs Sziky
Sziky vs WolFix
WolFix vs OyAji
BSL Team Wars
6 days
Team Hawk vs Team Dewalt
BSL Team Wars
6 days
Team Hawk vs Team Bonyth
Liquipedia Results

Completed

Jiahua Invitational
uThermal 2v2 Main Event
HCC Europe

Ongoing

Copa Latinoamericana 4
BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Qualifiers
ASL Season 20
CSL Season 18: Qualifier 1
Acropolis #4 - TS1
CSLAN 3
SEL Season 2 Championship
WardiTV Summer 2025
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025

Upcoming

CSL Season 18: Qualifier 2
CSL 2025 AUTUMN (S18)
LASL Season 20
BSL Season 21
BSL 21 Team A
Chzzk MurlocKing SC1 vs SC2 Cup #2
RSL Revival: Season 2
Maestros of the Game
EC S1
Sisters' Call Cup
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
MESA Nomadic Masters Fall
CS Asia Championships 2025
Roobet Cup 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.