Critical EXPLOIT discovered... Anet read plz

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Darko_UK
screens or it couldnt happen
...We already have some earlier in the thread.

Sword Liger

Sword Liger

Lion's Arch Merchant

Join Date: Aug 2006

London

Valendra's Kingdom [VK]

W/E

yeh why not ill come tag along

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Two April Mornings
Bad thing is that OP used the exploit, ANET hates exploiters, even if they come forward to reveal one they found out.
Using it to gain an advantage is one thing, testing it to see if it is repeatable is a whole other thing. Pablo isn't the bad guy here, he is a the good guy.

Quote:
Originally Posted by X Earth X
I've posted a message on Gaile's talk page saying they should look into this ASAP. Let's hope they do.
really wish u hadn't have done that. I am contacting her directly, and making this anymore public is bad.

mr_groovy

mr_groovy

Desert Nomad

Join Date: Jun 2006

Netherlands

No Inherent Effect [NiE]

My question is if this uses a external program, did the op stumble upon it? Or was he in the development of it? And if so why would a person try and make an exe that looks at the packets send to the gw server?
And if he stumbled upon it, it must be roaming the internet, meaning that Anet better hurry up and fix it.

Whirlwind

Whirlwind

Krytan Explorer

Join Date: Aug 2007

Wolven Empire

D/

lol every single person who has posted on the 2nd page is online trolling this right now, probably refreshing the page over and over.

EDIT: Nix that, 2nd and 3rd page as well !

Tyla

Emo Goth Italics

Join Date: Sep 2006

Quote:
Originally Posted by Bryant Again
Yeup. If Rahja is using it too, they're both going to get banned. They should probably be able to get unbanned, though, if they send in a bumload of tickets.

However, I can't say. I've only been banned on ANet "thinking" I was doing something. They actually used the exploit.
Nonetheless, we admire the bravery of the two. /salute
/salute too:P
but either way,rahja and pablo didnt use the exploit to their gain(i mean,if what rahja said was true...)
so imo,let them not be banned!

bamm bamm bamm

bamm bamm bamm

Krytan Explorer

Join Date: Jul 2006

Quote:
Originally Posted by Rahja the Thief
ALright, let me clarify this for people... this exploit allows not just crashing. Pablo could make himself a GM, he could steal EVERY SINGLE GW ACCOUNT ON THE SERVER. The client is poorly coded as I am finding out, and this security hole only gets deeper and deeper the more I am finding. So, I would be afraid. Lucky credit card info is SSL... otherwise, that too would be easy pickings. So, hope that clears up any confusions as to how SERIOUS this is.
What I don't understand is, why is this a client issue and not a server issue? It sounds like you're spoofing something and sending it to the server and it's disconnecting everyone, in which case the server isn't validating it's inputs too well. Surely if it was client-side you would need to know the IP addresses of everyone in a match, and as far as I'm aware, the server is the only one with that info. The client just does what it's told, so you must be getting the server to tell them to disconnect somehow.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Bryant Again
Yeup. If Rahja is using it too, they're both going to get banned. They should probably be able to get unbanned, though, if they send in a bumload of tickets.

However, I can't say. I've only been banned on ANet "thinking" I was doing something. They actually used the exploit.
Nonetheless, we admire the bravery of the two. /salute
Not really, I haven't used it. I know however that it works. I highly doubt banning in this case, considering that would look awfully bad of them. "Hey thanks for finding a massive security hole and not spreading it to others to cause havoc, but your banned anyways" ummm, NO?

Earth

Earth

Always Outnumbered

Join Date: Jul 2006

Quote:
Originally Posted by Rahja the Thief
really wish u hadn't have done that. I am contacting her directly, and making this anymore public is bad.
Ah well, will just remove it then <_<;;;

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Rahja the Thief
Using it to gain an advantage is one thing, testing it to see if it is repeatable is a whole other thing. Pablo isn't the bad guy here, he is a the good guy.
Nonetheless, you're both going to get banned. When the duping thing was brought to ANet's attention, a lot of people who tested it and brought it to their attention, including names such as Fenix and Max Gladius, got their accounts banned.

I think it's because there's like no connection between the ANet staff reading the tickets and the people who're doing the banning. But ya'll know what I mean, aye?

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by mr_groovy
My question is if this uses a external program, did the op stumble upon it? Or was he in the development of it? And if so why would a person try and make an exe that looks at the packets send to the gw server?
And if he stumbled upon it, it must be roaming the internet, meaning that Anet better hurry up and fix it.
he is helping to develop the GWPL server, and as a result, found this massive security hole.

[quote = bamm bamm bamm]What I don't understand is, why is this a client issue and not a server issue? It sounds like you're spoofing something and sending it to the server and it's disconnecting everyone, in which case the server isn't validating it's inputs too well. Surely if it was client-side you would need to know the IP addresses of everyone in a match, and as far as I'm aware, the server is the only one with that info. The client just does what it's told, so you must be getting the server to tell them to disconnect somehow.[/quote]

Ok, you need to stop now... this is what I am talking about. Stop injecting ideas, your only going to encourage more people to look into the issue. Nothing personal, but pls dont post anymore ideas.

Quote:
Originally Posted by Bryant Again
Nonetheless, you're both going to get banned. When the duping thing was brought to ANet's attention, a lot of people who tested it and brought it to their attention, including names such as Fenix and Max Gladius, got their accounts banned.

I think it's because there's like no connection between the ANet staff reading the tickets and the people who're doing the banning. But ya'll know what I mean, aye?
Again, I am going through Gaile, gaile isn't going to ban us, and she isn't going to go mentioning our names to the retards at PlayNC. We are not going to be banned. That is silly.

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Rahja the Thief
Ok, you need to stop now... this is what I am talking about. Stop injecting ideas, your only going to encourage more people to look into the issue. Nothing personal, but pls dont post anymore ideas.
This is a forum.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Bryant Again
This is a forum.
Ugh....this is why I have requested like 9x for this thread to be locked. Further discussion is going to give people more ideas, and someone is going to figure it out, and KABOOM, they are going to go to town and exploit this in every fashion. ... and trust me when I say, those fashions are far worse then just crashing your own team.

bamm bamm bamm

bamm bamm bamm

Krytan Explorer

Join Date: Jul 2006

Quote:
Originally Posted by Rahja the Thief
Ok, you need to stop now... this is what I am talking about. Stop injecting ideas, your only going to encourage more people to look into the issue. Nothing personal, but pls dont post anymore ideas.
I apologize profusely for posting on topic in a thread on a discussion forum.

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Rahja the Thief
Ugh....this is why I have requested like 9x for this thread to be locked. Further discussion is going to give people more ideas, and someone is going to figure it out, and KABOOM, they are going to go to town and exploit this in every fashion. ... and trust me when I say, those fashions are far worse then just crashing your own team.
Bamm bamm bamm's already said it ^

Now this kind of discussion is what'll get it closed. Back to the topic.

Whirlwind

Whirlwind

Krytan Explorer

Join Date: Aug 2007

Wolven Empire

D/

Rahjah you are adding more ideas on your own with each passing post..

Darkobra

Darkobra

Forge Runner

Join Date: Aug 2006

Scotland

Type like an idiot, I'll treat you like an idiot

E/Me

Rahjah, calm down. Each time you snap at a post, you're giving more hints and doing more damage. You even advertised it as FAR more than just a client crasher. You alone have done far more damage and given far more hints than I have EVER seen in this thread with assumptions. Edit the posts in reference to exclude such critical information if you're REALLY after safety over glory.

zwei2stein

zwei2stein

Grotto Attendant

Join Date: Jun 2006

Europe

The German Order [GER]

N/

Quote:
Originally Posted by Rahja the Thief
He is not going to be banned... he figured out the exploit in a harmless manner. He reported it, and he is standing with me right now. He is not going to be banned, it is not like he is going crazy with this. So stop saying that, and stop flaming him and accusing him of this and that.
People who tested, verified and reported duping exploit were banned. For duping one dye to prove it works.

Interesting eh.

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Rahja the Thief
Again, I am going through Gaile, gaile isn't going to ban us, and she isn't going to go mentioning our names to the retards at PlayNC. We are not going to be banned. That is silly.
If you're not banned, then good. But I wouldn't be suprised if you were.

And don't you want her to mention your names at PlayNC so you don't get banned? Otherwise, they'll just use their logs and see "okay these people used it banned".

Of course, this wasn't as widespread as the other exploits, so you may be fine. I'd expect the worst, though.

Reverend Dr

Reverend Dr

Forge Runner

Join Date: Dec 2005

Super Fans Of Gaile [ban]

W/

I'm going to be guessing that this will shut down the GWLP project.

Rampager

Rampager

Krytan Explorer

Join Date: May 2006

Australia

Mo/

very probably

pablo24

Frost Gate Guardian

Join Date: Aug 2007

The people who tested the dupe exploit got unbanned right after. ArenaNet was just running a script to ban anyone with anormal reconnect/trade activity or maybe just banned people who had more than one item with the same GUID. (I think they do have GUIDs for every item to prevent duping)

Quote:
Originally Posted by Reverend Dr
I'm going to be guessing that this will shut down the GWLP project.
Why should it? We are just helping ArenaNet to fix bugs before they get exploited by malicious people.

toon-a-loon

toon-a-loon

Frost Gate Guardian

Join Date: Jun 2005

Belton, Missouri

W/R

What all could you do with this exploit?? I'm interested in that. I don't care about what the program was but I just wanna know all the things you could do with it.

toon-a-loon

toon-a-loon

Frost Gate Guardian

Join Date: Jun 2005

Belton, Missouri

W/R

Quote:
Originally Posted by pablo24
Why should it? We are just helping ArenaNet to fix bugs before they get exploited by malicious people.
Then you better close the download for GWLP for now. I have a few ideas in my head on how to do what your doing. It probably deals with opening GWLP then opening guild wars at the sametime.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Bryant Again
If you're not banned, then good. But I wouldn't be suprised if you were.

And don't you want her to mention your names at PlayNC so you don't get banned? Otherwise, they'll just use their logs and see "okay these people used it banned".

Of course, this wasn't as widespread as the other exploits, so you may be fine. I'd expect the worst, though.
it isnt detectable... so best of luck to them.

Quote:
Originally Posted by toon-a-loon
Then you better close the download for GWLP for now. I have a few ideas in my head on how to do what your doing. It probably deals with opening GWLP then opening guild wars at the sametime.
Frankly... this is silly. THis is like saying TexMod can do dmg. No, GWLP has nothing to do with this, please don't get that great project shutdown.

pablo24

Frost Gate Guardian

Join Date: Aug 2007

Quote:
Originally Posted by toon-a-loon
Then you better close the download for GWLP for now. I have a few ideas in my head on how to do what your doing. It probably deals with opening GWLP then opening guild wars at the sametime.
The GWLP servers aren't even released yet, unless you are on the team you have no way of getting them. Even if you have them, it won't help you exploiting anything.

Leslie

Frost Gate Guardian

Join Date: Nov 2005

England

Slash afk [afk]

A/

This seems serious enough that the servers should really be taken down until it's fixed in my opinion

Bryant Again

Bryant Again

Hall Hero

Join Date: Feb 2006

Quote:
Originally Posted by Rahja the Thief
it isnt detectable... so best of luck to them.
How is it not detectable? Are certain programs able to be coded so they can't be detected? That's what you're saying???

If so, then the botters are going to be pretty damned happy with this info.

But best of luck to you, since ANet has a really good method of banning. If you two *do* get banned, it'll just be temporate. Don't freak out, banned four times here. As long as you're totally innocent, you'll be fine.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Bryant Again
How is it not detectable? Are certain programs able to be coded so they can't be detected? That's what you're saying???

If so, then the botters are going to be pretty damned happy with this info.

But best of luck to you, since ANet has a really good method of banning. If you two *do* get banned, it'll just be temporate. Don't freak out, banned four times here. As long as you're totally innocent, you'll be fine.
a program cannot be detected unless i raises flags on the server. if the server isn't programmed to even look at that data, it can't be seen. Essentially, this exploit revolves around the client code being weak. Without hinting at it anymore, that is about as much detail as I want to go into, or I think we should even go into. I don't even understand EXACTLY how it works, only Pablo does at this point.

toon-a-loon

toon-a-loon

Frost Gate Guardian

Join Date: Jun 2005

Belton, Missouri

W/R

Quote:
Originally Posted by Rahja the Thief
Frankly... this is silly. THis is like saying TexMod can do dmg. No, GWLP has nothing to do with this, please don't get that great project shutdown.
Who is to say that the programs GWLP are using to make it didn't get used to make a little .exe to exploit gw?? Obviously you guys had a idea to see if the .exe you made could do something to gw and it acually was able to do something, but you guys aren't abusing. So thats a good thing. All your intentions was good from the start. Anet always needs a little help on the side, to keep their players safe.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by toon-a-loon
Who is to say that the programs GWLP are using to make it didn't get used to make a little .exe to exploit gw?? Obviously you guys had a idea to see if the .exe you made could do something to gw and it acually was able to do something, but you guys aren't abusing. So thats a good thing. All your intentions was good from the start. Anet always needs a little help on the side, to keep their players safe.
When you dig through code, you are bound to find errors or missing sections. That is all that has happened. The .exe was created (as far as I am aware) to test to see if this "issue" really was true, and if they code was weak (which it obviously has proven to be)

toon-a-loon

toon-a-loon

Frost Gate Guardian

Join Date: Jun 2005

Belton, Missouri

W/R

Quote:
Originally Posted by Rahja the Thief
When you dig through code, you are bound to find errors or missing sections. That is all that has happened. The .exe was created (as far as I am aware) to test to see if this "issue" really was true, and if they code was weak (which it obviously has proven to be)
Yep and its a good thing that is was found by good people.

magi of the light

Frost Gate Guardian

Join Date: Jun 2007

Virginia

NINE

R/E

can someone explain to me what GWLP is please?

Rainman

Rainman

Lion's Arch Merchant

Join Date: Jun 2006

none

P/

meeee!! add me as soone mah jing to friends list but ill be on a pvp char when we test

IF WE ARE STILLTESTING AND SPACES ARE AVAILABLE!

toon-a-loon

toon-a-loon

Frost Gate Guardian

Join Date: Jun 2005

Belton, Missouri

W/R

GWLP = Guild war lan project.

Its like a mod.

Loviatar

Underworld Spelunker

Join Date: Feb 2005

if they actually have found something

if they actually wanted to help

THEY WOULD HAVE PM GAILE AND SUPPORT NOT SPLASHED IT ALL OVER


THIS STINKS

magi of the light

Frost Gate Guardian

Join Date: Jun 2007

Virginia

NINE

R/E

Quote:
Originally Posted by toon-a-loon
GWLP = Guild war lan project.

Its like a mod.
can you be a bit more detailed please?

pablo24

Frost Gate Guardian

Join Date: Aug 2007

Loviatar, calm down. I don't think posting this here will tell people how to reproduce the exploit, it deals with much more complicate things than just opening 2 Guild Wars at once.

As for GWLP, it isn't a "mod". Read this thread for more info http://www.guildwarsguru.com/forum/s...php?t=10205152

Kashrlyyk

Kashrlyyk

Jungle Guide

Join Date: May 2005

Quote:
Originally Posted by Loviatar
if they actually have found something

if they actually wanted to help

THEY WOULD HAVE PM GAILE AND SUPPORT NOT SPLASHED IT ALL OVER


THIS STINKS
They did that! You are a few pages too late for screaming around.

Lord Sojar

Lord Sojar

The Fallen One

Join Date: Dec 2005

Oblivion

Irrelevant

Mo/Me

Quote:
Originally Posted by Loviatar
if they actually have found something

if they actually wanted to help

THEY WOULD HAVE PM GAILE AND SUPPORT NOT SPLASHED IT ALL OVER


THIS STINKS
If you had read, I am trying to directly contact Gaile, although she seems to be away atm.

If you had read, you would have noticed that is exactly what we are doing, and we are trying to keep this semi hush hush. The .exe is locked away and not about to be released.


YOUR RIGHT, THIS DOES STINK.