what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Call Of Duty: Black Ops Memory Leak

Call Of Duty: Black Ops Memory Leak
Posted Dec 3, 2010
Authored by Luigi Auriemma | Site aluigi.org

Call of Duty: Black Ops suffers from a remote memory leak vulnerability.

tags | advisory, remote, memory leak
SHA-256 | 23f747fc13e4561d98d08374160cabdd2ae8c84df6b37dd2a2b12bf9451bf8d1

Call Of Duty: Black Ops Memory Leak

Change Mirror Download
#######################################################################

Luigi Auriemma

Application: Call of Duty: Black Ops
https://www.callofduty.com
Versions: unknown, refer to the release date of this advisory
Platforms: unknown (it should be Windows)
Bug: memory leak
Exploitation: remote, versus server
Date: 18 Nov 2010
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Call of Duty Black Ops (cod7) is the new game of the CoD series.
Just like cod6 also this one is distribuited as "client-only", which
means that a normal user cannot host a server.
Only some hosting companies (GameServers) or the same Treyarch can host
dedicated servers.


#######################################################################

======
2) Bug
======


When the server receives an rcon packet (opcode 0x00) it replies with
a packet having a fixed size of 1168 bytes, doesn't matter if its
content is smaller.

The result is that various parts of the server's memory are disclosed
remotely to anyone and through the continuous sending of these invalid
rcon packets is possible to monitor the server and maybe retrieving
important informations like the value of cvars (included rcon), parts
of the logs (included the output of previous rcon packets of the
admin), parts of the server's configuration and the IP addresses of the
other players.


#######################################################################

===========
3) The Code
===========


https://aluigi.org/testz/udpsz.zip
https://aluigi.org/poc/cod7mem.zip

udpsz -C "ffffffff 00 0000000000000000" -D SERVER 3074 -1

or with the filter for easier visualization and monitoring:

udpsz -q -l 1000 -C "ffffffff 00 0000000000000000" -D -L cod7mem.dll SERVER 3074 -1

for example the Treyarch servers are available in a certain range that
covers different C classes like 173.199.77.x, 173.199.78.x, 173.199.79.x
and so on.

it's possible to use "ffffffff 00 6100000000000000" for receiving a
reply string shorter than 50 bytes and so more memory visible but I
don't know if it will appear in the server's logs because it could be
considered a password guessing attack.


#######################################################################

======
4) Fix
======


No fix.


#######################################################################


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close