Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Players overflow in Serious engine UDP (was Alpha Black Zero, 29 Sep 2004) |
|---|---|
| Date: | Sun, 28 Nov 2004 15:47:08 +0000 |
#######################################################################
Luigi Auriemma
Application: Serious engine
http://www.seriousengine.com
Games: all the games based on this engine and using the UDP
protocol:
- Alpha Black Zero
- Nitro family
- Serious Sam Second Encounter 1.07
Platforms: Windows, Linux and Mac
Bug: crash
Exploitation: remote, versus server
Date: 28 November 2004 (and 29 Sep 2004)
Author: Luigi Auriemma
e-mail: aluigi@altervista.org
web: http://aluigi.altervista.org
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
#######################################################################
===============
1) Introduction
===============
The Serious engine is a well known game engine developed by Croteam
(http://www.croteam.com) and used by some games.
#######################################################################
======
2) Bug
======
The bug affects the games based on the Serious engine using the UDP
protocol (those using TCP are immune).
The problem is that the server doesn't limit the amount of new players,
so it crashs when too much (fake) players try to join.
Is needed only one packet to create a fake player and the bug can be
exploited also versus servers protected by password "without" knowing
the keyword.
#######################################################################
===========
3) The Code
===========
http://aluigi.altervista.org/fakep/ssfakep.zip
#######################################################################
======
4) Fix
======
No fix.
#######################################################################
---
Luigi Auriemma
http://aluigi.altervista.org
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038, Liu Die Yu |
|---|---|
| Next by Date: | [Full-Disclosure] [ GLSA 200411-37 ] Open DC Hub: Remote code execution, Luke Macken |
| Previous by Thread: | [Full-Disclosure] Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038, Liu Die Yu |
| Next by Thread: | [Full-Disclosure] [ GLSA 200411-37 ] Open DC Hub: Remote code execution, Luke Macken |
| Indexes: | [Date] [Thread] [Top] [All Lists] |