Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 D3 account can be hacked via public game, might be explanation to those acc hecked

views
     
I<3LYN
post May 23 2012, 05:17 AM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 03:56 AM)
i replicated the session hijacking theory, and yeap doable without authenticator. but needs some work.
careful guys.
*
really? show us pictures of guys that you hacked... or it didn't happen tongue.gif
I<3LYN
post May 23 2012, 12:29 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 11:54 AM)
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
*
record a video... expose blizzard blaming technique....
now blizzard kept blaming the players.
I<3LYN
post May 23 2012, 12:32 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(farkinid @ May 23 2012, 12:01 PM)
I still don't understand why the game server would pass your session token to other members in the group and vice versa. I haven't done any testing but a wireshark or tcpdump file would interest me very much.
*
i am going to try to replicate the exploit as well. doh.gif
I<3LYN
post May 23 2012, 04:09 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 04:04 PM)
probably due to heavy loads on the server.
Wouldn't be surprised that companies would choose the easy and less secure way out of a problem.
I've not played wow but some guys on my d3 public games told me you can use wow hacks on d3. Unproven as i don't play wow or have any knowledge of it.
If u know any hitb/hackerspace fellows, they may have doxed it as well.

edit: just thought of the whisper and message function, not sure if can directly ping user ip/id from whispering. Any thoughts?
*
with my understanding of the battle.net 1.0 protocol.. nope you cant get any network info by whispering/messaging a player.

not really sure about battle.net 2.0 though.

 

Change to:
| Lo-Fi Version
0.0152sec    0.39    6 queries    GZIP Disabled
Time is now: 2nd December 2025 - 07:29 PM