Re: TrackMania Demo Denial of Service

From: Luigi Auriemma (aluigi_at_altervista.org)
Date: 02/09/04

  • Next message: Ferruh Mavituna: "Brinkster Multiple Vulnerabilities"
    Date: Mon, 9 Feb 2004 22:06:54 +0000
    To: webmaster@securiteinfo.com, bugtraq@securityfocus.com
    
    

    > TrackMania Demo Denial of Service
    > The original document can be found at
    > http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml

    Also Virtual Skipper 3 is vulnerable so the problem is in the game engine
    developed by Nadeo (http://www.nadeo.com)

    > The multiplayer game use TCP port 2350 to communicate. If you send some
    > garbage to this port, it will shutdown the game server.

    Not exactly garbage data but too long values, in fact the game uses 32bit
    numbers to specify the size of the data that follows so this seems the cause
    of the server crash.
    Another simple test is the modification of the 32bit values in the UDP query
    packets used to define the length of some strings.

    > The multiplayer demo of this game
    > is subject to denial of service.

    Due the type of bug probably also the retail version is vulnerable.
    Who bet?

    BYEZ

    ---
    Luigi Auriemma
    http://aluigi.altervista.org


  • Next message: Ferruh Mavituna: "Brinkster Multiple Vulnerabilities"

    Relevant Pages

    • [FC2] OT - Desert Combat F-16 bug
      ... The game files are the same exact ones from the system when it was ... running FC1 so that can't be the cause. ... operating system files that both versions require. ... perhaps the game server could be tricked into believing that the system ...
      (Fedora)
    • Re: Setting up a public game server on a LAN - Sonicwall
      ... it's best to state your question first, ... [a win2k `game server' on a nat'd lan with a static public ip address using ... a sonicwall soho2 which the op wants to make available for internet and ...
      (comp.security.firewalls)
    • Re: Game Server Help
      ... Does the game, if you want to call it that;), have any type of game server ... > And me and my friend pulled it out the other day and wanted to play ... or a method of connecting computers from different home together ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: [opensuse] Blocking foreigners!
      ... My view is that if you're not playing my game servers you shouldn't be ... it would be a better policy to restrict downloads to those ... That would work however the game server and the web server are in different ...
      (SuSE)