New Wc3 exploit

Talk about anything you want, but keep it within the rules, please.
User avatar
Bl00D R3av3r
Senior Member
Posts: 165
Joined: January 25th, 2008, 5:20 pm
Title: Lazy

New Wc3 exploit

Post by Bl00D R3av3r »

Recently a very dangerous exploit was discovered within Warcraft III.
Namely, it's possible to execute bytecode through a map using Jass thus allowing practically anything, including distributing malware (viruses, trojans etc).
But, don't take my word for it, try the proof-map found here yourself (it is recommended that you run it in a window).

Source: thehelper
Image
Sig by TheWand
User avatar
X-Isle
Newcomer
Posts: 5
Joined: March 24th, 2007, 3:56 pm

Re: New Wc3 exploit

Post by X-Isle »

thanks for the info... well unless you are almost playing in public places and you use public computers that you dont own... well you might as well wouldnt mind it... This is a good heads up for those computer cafe owners, so that they would be able to prevent any harms this exploit can bring.
User avatar
Bartimaeus
Tyrannical Drama Queen
Posts: 4424
Joined: November 19th, 2007, 5:05 am

Re: New Wc3 exploit

Post by Bartimaeus »

Dekar has confirmed this.
User avatar
Bl00D R3av3r
Senior Member
Posts: 165
Joined: January 25th, 2008, 5:20 pm
Title: Lazy

Re: New Wc3 exploit

Post by Bl00D R3av3r »

for more informations you could try this link
Image
Sig by TheWand
IceMan
Member
Posts: 83
Joined: August 17th, 2008, 5:50 am

Re: New Wc3 exploit

Post by IceMan »

What versions of Warcraft 3 does this exploit apply to? Is it only 1.23? If a private server were to downgrade to a slightly older version would they be safe from this exploit? Lol maybe this could be an excuse to convince whatever private server you play on to downgrade from 1.23. =D
User avatar
Ozzapoo
The Flying Cow!
Posts: 2197
Joined: November 2nd, 2007, 10:34 pm
Location: Melbourne

Re: New Wc3 exploit

Post by Ozzapoo »

All.
Visit Ozzapoo.net, my blog and the home of AutoCP and Cheatpack Detector!
AutoCP3 now available for free!
rnbby
V.I.P.
Posts: 98
Joined: December 4th, 2007, 10:24 am

Re: New Wc3 exploit

Post by rnbby »

anyone interested in making an exploit? hehe

There's already a PoC of it which execs cmd.exe.

Dang! I'm too noob to understand all the code in PoC.
auto-collider for wc3 1.22-- @ http://iliganshack.blogspot.com
User avatar
Hillo
Forum Staff
Posts: 615
Joined: June 9th, 2008, 9:51 am
Location: Finland

Re: New Wc3 exploit

Post by Hillo »

Blizzard wrote:Warcraft III Custom Map Security Warning
We have identified an exploit that could allow malicious software to be spread through Warcraft III maps. We have applied a temporary fix to address this issue when playing on Battle.net, and we are working on a patch to permanently address the issue when playing on a LAN or playing single-player custom maps. In the meantime, we recommend that players avoid downloading maps from unofficial sources or websites they do not trust -- be aware that corrupted maps may share the same name as other popular maps. If you encounter custom maps that no longer function or other issues related to this fix, please post details below.
Image
IceMan
Member
Posts: 83
Joined: August 17th, 2008, 5:50 am

Re: New Wc3 exploit

Post by IceMan »

Perhaps this link can help:

http://forums.boredaussie.com/viewtopic ... 2cc8a01d75

Note I did not make this application.
Below I have copied and pasted directly from the website part of that post:

Fixes:

I have written an application that mimics the actions of the official Blizzard hotfix for this issue. I can't and won't put any guarantees on this working or causing damage. Unlike the blizzard patch, however, you don't have to login for this to work, works for singleplayer and most likely LAN games also, I highly advise its use.

Instructions:
Extract the executable anywhere.
Run this application.
Run Warcraft III.
You should now be safe from maps that contain bad code.
You will need to do this everytime you restart Wc3.

Link: http://files.filefront.com/OverflowFixr ... einfo.html