• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 04:21
CEST 10:21
KST 17:21
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL20] Ro24 Preview Pt1: Runway132v2 & SC: Evo Complete: Weekend Double Feature3Team Liquid Map Contest #21 - Presented by Monster Energy9uThermal's 2v2 Tour: $15,000 Main Event18Serral wins EWC 202549
Community News
Maestros of The Game—$20k event w/ live finals in Paris18Weekly Cups (Aug 11-17): MaxPax triples again!13Weekly Cups (Aug 4-10): MaxPax wins a triple6SC2's Safe House 2 - October 18 & 195Weekly Cups (Jul 28-Aug 3): herO doubles up6
StarCraft 2
General
What mix of new and old maps do you want in the next 1v1 ladder pool? (SC2) : Geoff 'iNcontroL' Robinson has passed away The GOAT ranking of GOAT rankings RSL Revival patreon money discussion thread Weekly Cups (Aug 11-17): MaxPax triples again!
Tourneys
Maestros of The Game—$20k event w/ live finals in Paris Sparkling Tuna Cup - Weekly Open Tournament Monday Nights Weeklies Master Swan Open (Global Bronze-Master 2) $5,100+ SEL Season 2 Championship (SC: Evo)
Strategy
Custom Maps
External Content
Mutation # 487 Think Fast Mutation # 486 Watch the Skies Mutation # 485 Death from Below Mutation # 484 Magnetic Pull
Brood War
General
Maps with Neutral Command Centers BGH Auto Balance -> http://bghmmr.eu/ Flash Announces (and Retracts) Hiatus From ASL BW General Discussion BW AKA finder tool
Tourneys
[ASL20] Ro24 Group C [Megathread] Daily Proleagues [ASL20] Ro24 Group A [ASL20] Ro24 Group B
Strategy
Simple Questions, Simple Answers Fighting Spirit mining rates [G] Mineral Boosting Muta micro map competition
Other Games
General Games
General RTS Discussion Thread Dawn of War IV Path of Exile Stormgate/Frost Giant Megathread Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine The year 2050 European Politico-economics QA Mega-thread
Fan Clubs
INnoVation Fan Club SKT1 Classic Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece [\m/] Heavy Metal Thread
Sports
2024 - 2026 Football Thread TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
High temperatures on bridge(s) Gtx660 graphics card replacement Installation of Windows 10 suck at "just a moment"
TL Community
"World Leading Blockchain Asset Retrieval" The Automated Ban List TeamLiquid Team Shirt On Sale
Blogs
Evil Gacha Games and the…
ffswowsucks
Breaking the Meta: Non-Stand…
TrAiDoS
INDEPENDIENTE LA CTM
XenOsky
[Girl blog} My fema…
artosisisthebest
Sharpening the Filtration…
frozenclaw
ASL S20 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2968 users

SCBW Bnet hacker: Watch out - Page 4

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 6 7 Next All
tec27
Profile Blog Joined June 2004
United States3701 Posts
Last Edited: 2010-05-04 19:27:39
May 04 2010 19:24 GMT
#61
On May 04 2010 20:01 dhe95 wrote:
From Hot_Bid's R1CH quotes thread:
Show nested quote +
Sent a copy of this to hacks@blizzard, but if you catch anyone in person, direct them to this thread as this seems serious enough to warrant attention:

---------------------

There appears to be a hack circulating in SC:BW where an oversized game name is passed to bnet upon game creation. Bnet does not perform input sanitization on this value before storing it. Bnet then sends this information back to the client when the client is at the join game screen, at which point the oversized game name is added to the join game list box. When the user clicks the entry, the list box text is copied into an unchecked 128 byte buffer and a stack-based buffer overflow occurs.

On a quick glance, the return address looks possibly controllable, meaning with the right length and combination of characters, this could be exploited to execute arbitrary code on the StarCraft client.

Vulnerable code resides in battle.snp @ base + 0x237D0:

190237D0 |. 8B1D BCA20319 mov ebx,dword ptr ds:[<&USER32.SendMessa>; USER32.SendMessageA
190237D6 |. 6A 00 push 0 ; /lParam = 0
190237D8 |. 6A 00 push 0 ; |wParam = 0
190237DA |. 68 88010000 push 188 ; |Message = LB_GETCURSEL
190237DF |. 56 push esi ; |hWnd
190237E0 |. FFD3 call ebx ; \SendMessageA
190237E2 |. 83F8 FF cmp eax,-1
190237E5 |. 0F84 7D000000 je battle.19023868
190237EB |. 8D95 70FFFFFF lea edx,dword ptr ss:[ebp-90]
190237F1 |. 52 push edx ; /lParam
190237F2 |. 50 push eax ; |wParam
190237F3 |. 68 89010000 push 189 ; |Message = LB_GETTEXT
190237F8 |. 56 push esi ; |hWnd
190237F9 |. FFD3 call ebx ; \SendMessageA

As shown here, LB_GETTEXT is used to pull the string out of the listbox into edx. edx points to a stack buffer of 128 bytes. Since the string in the listbox is controlled by the attacker as no bounds checking is done on either the client or the server, a stack-based buffer overflow occurs.

My suggested immediate fix would be to limit the maximum game name / mapname and other user-controlled parameters that the battle.net server will accept as this would not require a client patch. If the user submits to bnet values of greater length than the BW client would normally allow, they can be flagged as malicious and handled accordingly. An additional suggested client-side update in the next patch would validate the game name and other parameters received from battle.net before working with them, to protect the player from 3rd party servers.

I would appreciate being informed of any updates to this issue, as if no action is taken I will make my own unofficial patch to address this bug. Thanks!


seems like R1CH already found this ages ago.

Thats not the same thing. This hack sends a certain amount of specific packets to a target person that results in their client crashing. It does not depend on them viewing the game in the lobby.

On May 05 2010 04:02 Boundz(DarKo) wrote:
Also there is no such thing as anti-drophack unless the person using the drophack is using some exploited drophack with anti-package feature.

There is indeed such a thing as an anti-drophack. Pretty much all drophacks rely on the fact that BW will crash or desync if sent certain malformed packets. Therefore, to develop an anti-drophack, one must simply block/handle those packets and make sure the client doesn't crash.
Can you jam with the console cowboys in cyberspace?
WaZuP
Profile Blog Joined July 2009
Germany487 Posts
May 04 2010 19:35 GMT
#62
On May 04 2010 13:33 Amnesia wrote:
Let's get R1CH to stomp his ass


this :D

luckily i just use iccup and are prevented by such thing by the AH
Kimaker
Profile Blog Joined July 2009
United States2131 Posts
May 04 2010 19:38 GMT
#63
I tried joining one of those games awhile back, and strangely, whenever I start up BW since then, nothing happens, except it reset my resolution to 600x800. I then have to reopen the game, occasionally several times, before the game actually launches.

Does anyone else have this sort of problem?
Entusman #54 (-_-) ||"Gold is for the Mistress-Silver for the Maid-Copper for the craftsman cunning in his trade. "Good!" said the Baron, sitting in his hall, But Iron — Cold Iron — is master of them all|| "Optimism is Cowardice."- Oswald Spengler
Reborn8u
Profile Blog Joined January 2010
United States1761 Posts
Last Edited: 2010-05-04 22:08:07
May 04 2010 21:29 GMT
#64
Sounds like he has a bot to spot you then an irc bot network to flood your ip with bad packets in whats called a DOS or Denial of Service attack. I've seen this before on console games like halo I actually have met people who have done this recently and they confirmed my suspicions. This is actually a felony, it's pretty sad how far people go to cheat lmao. I recommend switching your router or modems ip# afterwards. You may be able to stop this kind of attack by using your nat properly or through a proxy server, it's been around for 20 years.. basically if i have a bot attach it to some torrents, as people d/l them they get infected with this trojan. It doesn't harm the host, what it does is "check in" whenever that computer has an active internet connection to an irc bot. Once you get hundreds or thousands of these bots on computers all over the world you can have them all bombard a target ip# with bad packets or ip packets that have spoofed return addresses. Each bot is only using a tiny fraction of the computers bandwidth theve infected sp they go unnoticed by the infected. The network of the target ip gets eaten up by all the bad packets and if your modem or router get backed up enough they will reset. Basically there is so much crap clogging your connection that the good stuff can't get through fast enough. I'm going to dig up the link to a much better explanation of this, I'll post it as soon as i find it. There have been large attacks used to blackmail websites such as gambling sites, when they get enough bots they can hold a site down for days with these kind of attacks. I believe there was a bot network brought down by the FBI that numbered in the millions, the guilty were caught when they attempted to collect their ransom. This is a bit of a generalization but this should give you the gist of it. This is what it sounds like to me. For the record I HAVE NEVER DONE ANYTHING LIKE THIS, I know about it because almost 15 years ago I was a little nerd and hung out with tons of brilliant nerds and it was pretty common back then because people were so naive when it came to computers. But then I discovered breasts and fell out of the nerd loop. Nowadays so many people have anti virus that it is a bit more difficult to get huge bot networks going.
The reason i suspect this is the culprit is because you said you loose all network service, that's a major tell tail sign of this type of attack. It probably subsides pretty quick because he's simply changing targets.
:)
DreaM)XeRO
Profile Blog Joined December 2008
Korea (South)4667 Posts
May 04 2010 21:35 GMT
#65
omfg. bweast
<3
cw)minsean(ru
OPSavioR
Profile Joined March 2010
Sweden1465 Posts
May 04 2010 21:56 GMT
#66
iccup wont let that happen!
i dunno lol
Reborn8u
Profile Blog Joined January 2010
United States1761 Posts
Last Edited: 2010-05-04 22:45:27
May 04 2010 22:06 GMT
#67
This is a better description Steve Gibson describes DOS attacks
I highly recommend everyone checks out Steve Gibson's security now series, the man is extraordinarily brilliant!
Here is something that will scare the crap out of you courtesy of Steve Gibson.
video of steve gibson after his site was attacked
:)
blahman3344
Profile Blog Joined March 2009
United States2015 Posts
Last Edited: 2010-05-04 22:35:00
May 04 2010 22:25 GMT
#68
man...some guys on bnet are jsut total jerks =_=

im gonna try this and see what happens...

edit: waited about 5 minutes, nothing happened =\
I like haikus and / I can not lie. You other / brothers can't deny
L_Master
Profile Blog Joined April 2009
United States8017 Posts
May 04 2010 22:30 GMT
#69
Hmm, just went there today and didn't see any of the FROST@USEAST>YOU games. Wonder why he stopped?
EffOrt and Soulkey Hwaiting!
igotmyown
Profile Blog Joined April 2009
United States4291 Posts
May 04 2010 22:34 GMT
#70
On May 05 2010 04:22 BalloonFight wrote:
Show nested quote +
On May 05 2010 04:18 GreEny K wrote:
On May 04 2010 12:57 Mindcrime wrote:
On May 04 2010 12:52 Excel Excel wrote:
Creating a new Bnet account will get around this, and so will creating passworded games, but I fear that eventually Frost will begin to prevent ALL people from hosting through some manner.


that would be pretty epic tbh


Obviously it's not permanent if you can just make a new account and get back on, not sure what it is but he didn't hack your computer if that's what you're wondering.


Read the thread. It can be used to execute arbitrary code.


Code injection means arbitrary code using whatever SC/battle.net uses. If you use code injection into php, you get php code. I'm skeptical that you can use SC code to install arbitrary programs onto a computer.


The oh so cool hacker forum mentions something about a dlist, so they're probably adding names onto a continuously running list to either continually attack their bnet account or their internet connection. I'm going to assume the majority of their wannabe shenanigans is done by downloading this battle net packet sender and using their limited coding skills to achieve their narrow results.
Excel Excel
Profile Blog Joined February 2010
142 Posts
Last Edited: 2010-05-04 23:05:13
May 04 2010 23:04 GMT
#71
Code injection means arbitrary code using whatever SC/battle.net uses. If you use code injection into php, you get php code. I'm skeptical that you can use SC code to install arbitrary programs onto a computer.


When shit gets executed from a stack/heap/etc. in overflows, bad things happen. It is literally "arbitrary" code, as in, EVERYTHING. Php and SQL injections are much more limited than overflow exploits.

Also, I thank Reborn8u for being one of the very few people who actually read the thread .
"SCREW OBSERVERS MUST HAVE MOAR ARBITERS!!!11one1" - Famous last words
Kenpachi
Profile Blog Joined August 2009
United States9908 Posts
Last Edited: 2010-05-04 23:15:09
May 04 2010 23:10 GMT
#72
I remember this happening before. the game name was Zynastor's New Drophack!
And, that Frost might not be Frost and some random bnet spoofer. that isnt a new hack. thats been out for about 5 months and it drops everyone in lobby by spamming "____ HAS JOINED THE GAME"
Its like you flooding cept its in the Lobby. wait network connection? well fuck..
not sure why you guys think USEast is funny. Frost@USWest might not be Frost@USEast. I use to call myself Grimmjow@World because i owned all Grimmjows (and still do) except the one on iccup..
Nada's body is South Korea's greatest weapon.
Pokebunny
Profile Blog Joined June 2008
United States10654 Posts
May 04 2010 23:14 GMT
#73
I'm actually interested to see if this guy can take over all of bnet.
Semipro Terran player | Pokebunny#1710 | twitter.com/Pokebunny | twitch.tv/Pokebunny | facebook.com/PokebunnySC
Kenpachi
Profile Blog Joined August 2009
United States9908 Posts
Last Edited: 2010-05-04 23:17:50
May 04 2010 23:15 GMT
#74
On May 05 2010 08:14 Pokebunny wrote:
I'm actually interested to see if this guy can take over all of bnet.

A guy tried and got jailed man not saying any names
just thinking about him makes my heart pump.
Nada's body is South Korea's greatest weapon.
Ian Ian Ian
Profile Blog Joined August 2009
915 Posts
May 04 2010 23:28 GMT
#75
On May 05 2010 08:15 Kenpachi wrote:
Show nested quote +
On May 05 2010 08:14 Pokebunny wrote:
I'm actually interested to see if this guy can take over all of bnet.

A guy tried and got jailed man not saying any names
just thinking about him makes my heart pump.


lol what?

Also, talking about weird games. Today there's a DL ONLY: Crash RPG:Soulburn game being hosted on east. When you enter the game, all the slots are empty and you dl from nobody :o
Chairman Ray
Profile Blog Joined December 2009
United States11903 Posts
May 04 2010 23:35 GMT
#76
Yeah I have had problems with him as well. It crossed my mind that it could be Blizzard just trying to get people switched to SC2, but that's highly unlikely.
Reborn8u
Profile Blog Joined January 2010
United States1761 Posts
Last Edited: 2010-05-04 23:38:18
May 04 2010 23:37 GMT
#77
Is this worth it? This guy could be looking at 10 years in prison if he gets caught? WTF is he thinking? I just laugh at them.... your risking 10 years of your life for what? It's sad when people think they are smart for doing something like this when they in fact are abysmally retarded! The kid in that link was also forced to pay 37k in restitution, how long do you think he'll be getting his paychecks docked after he gets out to pay that? I'm sure he's gonna find a good job after a 10 year prison stay.
If you want to taunt frost try getting on Bnet after setting your computer connection up through an anonymous proxy. If his attack no longer works it is because he can no longer detect your ip. Just your proxied Ip, which will probably be some huge server he can't possibly overload. So you will be free to tell him the penalties of his actions and make him feel very smart I'm sure.
:)
tbrown47
Profile Joined August 2009
United States1235 Posts
May 05 2010 00:01 GMT
#78
Maybe Frost@USEast IS R1CH!

dun dun dunnnnnnnnn

probably not though, LoL
just here
PhailSoBaller
Profile Blog Joined July 2009
United States281 Posts
May 05 2010 00:02 GMT
#79
On May 04 2010 19:16 GTR wrote:
[image loading]


Just gonna go out and say, that card would be fucking broke if it was real. Holy shit the imbalance of that card.
Ballins a habbit i want it i grab it
Marimokkori
Profile Blog Joined October 2009
United States306 Posts
May 05 2010 00:06 GMT
#80
On May 05 2010 08:35 Chairman Ray wrote:
Yeah I have had problems with him as well. It crossed my mind that it could be Blizzard just trying to get people switched to SC2, but that's highly unlikely.


Well some people have said this has been going on for quite a while, so maybe it isn't blizzard trying to get people to sc2, although the thought reminds me of the mass mass mass starcraft / diablo 2 bans blizzard nailed people with for using programs that had been floating around b.net for years. This took place 1-2 weeks before a new WoW expansion was released.

So if it were blizzard trying to open up StarCraft 2 a bit, I think they'd just throw out mass bans again?
A little nonsense now and then is relished by the wisest men
Prev 1 2 3 4 5 6 7 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 39m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
trigger 59
StarCraft: Brood War
Barracks 4857
Sea 3256
TY 333
ggaemo 145
NaDa 33
zelot 29
Bale 7
Dota 2
XcaliburYe439
XaKoH 306
League of Legends
JimRising 613
Dendi282
Other Games
summit1g3368
singsing1518
ceh9493
C9.Mang0322
Happy277
Mew2King30
Trikslyr27
Organizations
Other Games
gamesdonequick555
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 12 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• lizZardDota242
League of Legends
• Jankos867
Upcoming Events
CranKy Ducklings
1h 39m
SC Evo League
3h 39m
WardiTV Summer Champion…
4h 39m
Classic vs Percival
Spirit vs NightMare
CSO Cup
7h 39m
[BSL 2025] Weekly
9h 39m
Sparkling Tuna Cup
1d 1h
SC Evo League
1d 3h
Replay Cast
1d 15h
Afreeca Starleague
2 days
Queen vs HyuN
EffOrt vs Calm
Wardi Open
2 days
[ Show More ]
RotterdaM Event
2 days
Replay Cast
2 days
Afreeca Starleague
3 days
Rush vs TBD
Jaedong vs Mong
Afreeca Starleague
4 days
herO vs TBD
Royal vs Barracks
Replay Cast
4 days
The PondCast
5 days
Replay Cast
5 days
LiuLi Cup
6 days
Cosmonarchy
6 days
OyAji vs Sziky
Sziky vs WolFix
WolFix vs OyAji
BSL Team Wars
6 days
Team Hawk vs Team Dewalt
BSL Team Wars
6 days
Team Hawk vs Team Bonyth
Liquipedia Results

Completed

Jiahua Invitational
uThermal 2v2 Main Event
HCC Europe

Ongoing

Copa Latinoamericana 4
BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Qualifiers
ASL Season 20
CSL Season 18: Qualifier 1
Acropolis #4 - TS1
CSLAN 3
SEL Season 2 Championship
WardiTV Summer 2025
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025

Upcoming

CSL Season 18: Qualifier 2
CSL 2025 AUTUMN (S18)
LASL Season 20
BSL Season 21
BSL 21 Team A
Chzzk MurlocKing SC1 vs SC2 Cup #2
RSL Revival: Season 2
Maestros of the Game
EC S1
Sisters' Call Cup
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
MESA Nomadic Masters Fall
CS Asia Championships 2025
Roobet Cup 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.