Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 12:20

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 
Author Message
 Post subject: CoD4 overrun string in call to va() DoS
PostPosted: 11 Feb 2011 08:54 

Joined: 11 Feb 2011 08:39
Posts: 1
Hey,

i just tried the va() DoS exploit exploit in CoD4 in order to test my server on its vulnerability. Since ive got no clue about such things i just did whats written in the advisory.

I moved the cod4va file into my main folder, joined the server and used exec.

Then i received a message which said "unknown cmd aaaaaaaaa..." and nothing happens.
Am i doing something wrong or does this mean my server is secure?

Ive also read something about a way which works without joining the server but actually ive got no idea how this " yyyygetchallenge 0 aaaaaaaaaaaaaaaaaaaaaaa...1025...aaa" stuff works. :/

Thanks,


Top
 Profile  
 
 
 Post subject: Re: CoD4 overrun string in call to va() DoS
PostPosted: 11 Feb 2011 18:33 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
if you server doesn't crash after having executed cod4va.cfg I can say it's not vulnerable or it can't be exploited in that way.
if you have not fixed it with unofficial patches like those written by me and you use punkbuster then this is the reason, because pb filtered the bad packet from the client.

while for the getchallenge thing it works only with internet non-cracked servers.
it should be testable with udpsz (http://aluigi.org/testz.htm#udpsz) using the following command:
udpsz -c "\xff\xff\xff\xffgetchallenge 0 " -b a SERVER PORT 2000


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: