Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 15:01

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 
Author Message
 Post subject: informations about filtered chars and commands in Punkbuster
PostPosted: 26 Jun 2008 10:56 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
After my not so recent advisories about security bugs exploitable in some games through punkbuster Evenbalance has applied the following limitations:
- any byte which is not in the range space-'z' is no longer printable:
"............................... !"#$_&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz....................................................................................................................................."
- the % char is substituited with _
- the various commands which were possible to send with my pbmsgs tool are now filtered or time limited ("pbmsgs -u SERVER PORT hello" works each 5 seconds)

The above 3 limitations have been used to avoid or limit the windows console hell bell bug, possible format string in the games and server freeze through flooding (http://aluigi.org/adv/pbmsgsdos-adv.txt).

But these limitations could lead to the following problems:

- the filtered chars (like % or the accented letters) used in nicknames could have interesting effects, anyway this has not been tested so it's only an hypothesis

- the 5 second limitation in the commands could allow to ignore the real UCON and other packets from the PB master server, tested just in this moment and seems to work perfectly in a similar way to the rcon DoS in the Quake 3 engine caused by the half-second limitation.
in my test in fact I was no longer able to use the pbucon tool


Top
 Profile  
 
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: