Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 D3 account can be hacked via public game, might be explanation to those acc hecked

views
     
farkinid
post May 23 2012, 12:01 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(VinluV @ May 23 2012, 11:54 AM)
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
*
I still don't understand why the game server would pass your session token to other members in the group and vice versa. I haven't done any testing but a wireshark or tcpdump file would interest me very much.
farkinid
post May 23 2012, 03:58 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(VinluV @ May 23 2012, 03:43 PM)
here's the setup tho a very very simplified one.

2 pc in the same network. By network I mean me and mate using my router.
No opendns, No dns crypt, No authenticator used, firewall and my IPS turned off.
after trading and dropping items left and right for about half an hour and monitoring packets with tcpdump,
i just copied some token values from my friend to my packets (a certain open source scarab javascript packet interceptor i bet you know was used whistling.gif )

For a few seconds, i got him off his account. Then I got the i got kicked of battle net error.

what i can suspect is that my token and session weren't matching the ones on battlenet so i got kicked off, as the next few packets sent from me was using my original values, instead of the "malformed" packet.

Its doable but based on my setup its quite a below basic one, its still a long way for me.
Will try to pass u a dump with better values if i can get some sort of poc.

edit: wouldn't be surprised if chinese have pwned bnet
*
Hmm interesting.

If you have any interesting dumps, please send them my way. But I still don't understand Bliz's need to allow user machines to communicate with each other. I thought all the heavy lifting was done on the servers and the result was sent to the user machines.

Unless somebody has a way to parse token data and reconstruct login values, then this may not work. Still it does sound possible.

 

Change to:
| Lo-Fi Version
0.0148sec    0.56    6 queries    GZIP Disabled
Time is now: 1st December 2025 - 07:21 PM