exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

callOfDuty.txt

callOfDuty.txt
Posted Apr 17, 2005
Authored by Luigi Auriemma | Site aluigi.altervista.org

Call of Duty versions 1.5b and below and Call of Duty: Untied Offensive versions 1.51b and below are susceptible to remote buffer overflows.

tags | advisory, remote, overflow
SHA-256 | bc9681a80144965210de638d00d0fb3b7d12997c80404767fc17eac9bad7d456

callOfDuty.txt

Change Mirror Download

#######################################################################

Luigi Auriemma

Applications: Call of Duty <= 1.5b
Call of Duty: United Offensive <= 1.51b
https://www.callofduty.com
Platforms: Windows only (Linux is safe and Mac has not been tested)
Bug: crash
Exploitation: remote, versus server (in-game)
Date: 02 Apr 2005
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: https://aluigi.altervista.org


#######################################################################


1) Introduction
2) Bug
3) The Code
4) Fix


#######################################################################

===============
1) Introduction
===============


Call of Duty and its expansion pack United Offensive are the famous
military FPS games developed by Infinity Ward
(https://www.infinityward.com) and Gray Matter Studios
(https://www.gmistudios.com).
The games have been released respectively in October 2003 and September
2004.


#######################################################################

======
2) Bug
======


The game server is affected by a problem in the building of the
commands to visualize the clients messages.
If the message is too long and the generated command is longer than
1024 chars the server shows the dialog box of the exception handler
with a warning about a possible buffer-overflow and naturally the match
terminates.
In reality the bug doesn't seem to be a real buffer-overflow but I have
not deeply debugged the problem.

This is an in-game bug so the attacker must have access to the server,
if it's protected by password he must know the keyword and then his
cd-key can be banned since CoD servers use the online authorization.


#######################################################################

===========
3) The Code
===========


- download the following file:
https://aluigi.altervista.org/poc/codmsgboom.cfg
- place it in the base folder of the game: main or uo
- start a client and a server
- join the server
- go into the client console (~ key)
- type: /exec codmsgboom
- the server will crash showing an error


#######################################################################

======
4) Fix
======


No fix.

Developers have not been contacted since already exists another
unpatched bug from over one month (infostring overflow) and is more
easy to exploit than this Windows-only problem where attackers can be
banned and tracked.


#######################################################################


---
Luigi Auriemma
https://aluigi.altervista.org

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close