Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 11:59

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 51 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: haloloop... again
PostPosted: 30 Jun 2008 08:30 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
unfortunately seems that the developers didn't fix completely this vulnerability I reported to them over 3 years ago (wow, the time flies) so was enough to change a number in my old proof-of-concept and the latest 1.07 is vulnerable too:

http://aluigi.org/adv/haloloop2-adv.txt

Naturally also my haloloopfix is affected by the problem since, as stated there, I just used the same function from 1.07.

Differently to the old famous haloboom bug, haloloop has worst effects like the CPU at 100% and the freezing of the server due to an endless loop which makes impossible to autorestart it since there is no termination of the process.

Naturally both Halo and Halo Custom Edition are vulnerables.


Top
 Profile  
 
 
 Post subject:
PostPosted: 30 Jun 2008 22:18 

Joined: 30 Jun 2008 22:14
Posts: 17
O_O wow

the DAY i sign up to the forums to try to find a fix for that... is the DAY you post that message....

*sigh* my hopes for halo PC just flew out the window

----
i would love if somebody would make a patch for this (since i want to host dedis in 1.04)


Top
 Profile  
 
 Post subject:
PostPosted: 01 Jul 2008 00:49 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
my previous patch for fixing haloloop in the 1.04 servers was just the copying of the 1.07 function and worked but naturally if the bug is not fully fixed in 1.07 the same is valid for my patch too.
So at the moment doesn't exist a Halo server (include CE and demo) not vulnerable.


Top
 Profile  
 
 Post subject:
PostPosted: 01 Jul 2008 01:51 

Joined: 30 Jun 2008 22:14
Posts: 17
aluigi wrote:
my previous patch for fixing haloloop in the 1.04 servers was just the copying of the 1.07 function and worked but naturally if the bug is not fully fixed in 1.07 the same is valid for my patch too.
So at the moment doesn't exist a Halo server (include CE and demo) not vulnerable.


so sad... halo being such a fun game, ruined by such pitiful coding...

hopefully gearbox gets some funding to create some sort of patch (1.08)?


Top
 Profile  
 
 Post subject:
PostPosted: 01 Jul 2008 09:10 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
hard to answer, but considering that 1.07 is dated 2005 and as you have seen was only a work-around and not a real patch I highly highly highly doubt that will be released 1.08... or that it will really fix the bug naturally


Top
 Profile  
 
 Post subject:
PostPosted: 01 Jul 2008 20:15 

Joined: 30 Jun 2008 22:14
Posts: 17
random question: main website went down?


Top
 Profile  
 
 Post subject:
PostPosted: 01 Jul 2008 20:46 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
mine? in case of temporary downs or dns problems use the mirror: http://mirror.aluigi.org or directly http://luigi.eliott-ness.com


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 04:57 

Joined: 02 Jul 2008 04:47
Posts: 2
*Deleted by original Author*


Last edited by ~OMG~Ganon on 02 Jul 2008 05:59, edited 2 times in total.

Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 05:12 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
uhmmm probably someone that has still not understood that I'm not Gearbox or Bungie and thinks that his personal problems have a minimal interest on a basic support forum for a personal research website... mah


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 05:15 

Joined: 30 Jun 2008 22:14
Posts: 17
aluigi wrote:
uhmmm probably someone that has still not understood that I'm not Gearbox or Bungie and thinks that his personal problems have a minimal interest on a basic support forum for a personal research website... mah


kids these days *sigh*..... welll guess ima go find another game to get latched on to..

EDIT::::
nvm, i'm back on halo

http://home.scarlet.be/mathy/goemitar/d ... op2fix.rar
its been saved yet again :D


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 05:27 

Joined: 02 Jul 2008 04:47
Posts: 2
*sighs

srry about that, i just get pissed easy, esp about things going bad about my games.

just venting my frustration at who i thought was the main cause.

In reality it's Bungie's fault completely for lying to the dedicated gamers about fixing the loop

If Bungie doesnt get off their lazy asses and REALLY fix it this time, i hope the media ruins them

any chance of Private messaging us an Anti-Loop?


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 06:13 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
I can understand your frustation but not your lack of respect you had versus me and moreover my research; if there is something you don't understand (what is a security bug and/or all the related details) it's only your problem.

The bug has not been created by me, I simply found it 3 years ago and posted the results of my research, so it was already there (I don't want to enter in the pros and cons of full disclosure, I can only say that I have over 6 years and hundreds of game and non-game vulnerabilities in my experience so I know perfectly about what I talk better than anyone else).

About Bungie/Gearbox is also important to not forget Microsoft since this one is the publisher and it has the main decisional power about patches or the dead of games.
Developers and publishers have a contract, and only the publishers (depending by the contract but 99% of times it's this) can authorize the patch, its testing and its release which often can take lot of time without reasons.

3 years ago when I found the so called haloloop and haloboom bugs I exchanged AT LEAST (so this is the minimal amount) 20 mails with my contact there and the conclusion was that after one or two months that the bug was reported and I really annoyed them with my mails about updates I released the advisory before the releasing of the 1.07 patch which luckily happened later (without receiving thanx in the changelog or from the community).

But it's useless to talk about these things since the end-users are the only which can change something, I can do something with my advisories (the classification and pubblication of the bugs as security vulnerabilities is a big step) but naturally it's up to the users contacting the developers and saying "come on, patch it!"
When the publisher sees hundreds of paid consumers angry for the lack of support of their products be sure that something usually changes.


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 06:18 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
~OMG~Ganon wrote:
If Bungie doesnt get off their lazy asses and REALLY fix it this time, i hope the media ruins them

and who you think pays the media?
marketing and advertising is the primary job of the publisher.

Quote:
any chance of Private messaging us an Anti-Loop?

all my research is public on my websites (main and mirror), I don't do private stuff.
try the fix suggested by shankedup, if doesn't work or doesn't fully fix the bug I can't help since I'm not a magician which can fix any bug with the power of the mind


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 14:52 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
~OMG~Ganon wrote:
just venting my frustration at who i thought was the main cause.

Probably I have understood the reason of your anger wrongly directed versus me.

Yesterday night a Halo admin gave me a link to the page of a certain person that I watched only some minutes ago.
That page is the perfect demonstration of a misuse (aka wrong usage) of my work and research, so it's not important if I write "proof-of-concept"/"testing code"/"demonstration code" in big capital letters (and without considering that my website is located in the Research section of dmoz just for this reason: http://www.dmoz.org/Computers/Security/ ... /Research/) since than anyone has his personal interpretation.

The only positive thing is that at least he has credited me, but being credited for something wrongly showed as bad or malicious is not the max of happyness... blah


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 17:47 

Joined: 30 Jun 2008 22:14
Posts: 17
I may not be in the position to request this *or to do anything about it*, however I've done my research and i'm completely stumped..

As the hacker (by the original definition, not that script kiddie shit that paradigms the world), I would like your help to solve this puzzle.

Goemitar's patch was really similar to the previous haloloop patch (however only works for 1.07 dedicated servers).

This hex-code at line 1C2F0A
Code:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

has been changed to:
Code:
0F 84 D6 30 F5 FF 9C 60 83 F8 00 0F 85 FE 00 00
00 83 FA 0A 0F 85 F5 00 00 00 81 FC 1C DC 12 00
0F 85 E9 00 00 00 83 FD 00 0F 85 E0 00 00 00 3E
83 3D F0 4E 76 00 01 74 52 3E C7 05 14 4F 76 00
01 00 00 00 3E C7 05 F0 4E 76 00 01 00 00 00 3E
A3 F4 4E 76 00 3E 89 0D F8 4E 76 00 3E 89 15 FC
4E 76 00 3E 89 1D 00 4F 76 00 3E 89 25 04 4F 76
00 3E 89 2D 08 4F 76 00 3E 89 35 0C 4F 76 00 3E
89 3D 10 4F 76 00 E9 84 00 00 00 3E 39 05 F4 4E
76 00 75 70 3E 39 0D F8 4E 76 00 75 67 3E 39 15
FC 4E 76 00 75 5E 3E 39 1D 00 4F 76 00 75 55 3E
39 25 04 4F 76 00 75 4C 3E 39 2D 08 4F 76 00 75
43 3E 39 35 0C 4F 76 00 75 3A 3E 39 3D 10 4F 76
00 75 31 3E FF 05 14 4F 76 00 3E 81 3D 14 4F 76
00 00 01 00 00 72 28 3E C7 05 F0 4E 76 00 00 00
00 00 3E C7 05 14 4F 76 00 00 00 00 00 61 9D E9
D8 2F F5 FF 3E C7 05 F0 4E 76 00 00 00 00 00 61
9D E9 80 2E F5 FF 00 00 00 00 00 00 00 00 00 00


And the code at line 7211C
Code:
0F 84 46 01 00 00 8D 54 24 18 52 8D 44 24 14 50

has been changed to:
Code:
E9 6B D0 0A 00 90 8D 54 24 18 52 8D 44 24 14 50


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 17:49 

Joined: 30 Jun 2008 22:14
Posts: 17
aluigi wrote:
~OMG~Ganon wrote:
just venting my frustration at who i thought was the main cause.

Probably I have understood the reason of your anger wrongly directed versus me.

Yesterday night a Halo admin gave me a link to the page of a certain person that I watched only some minutes ago.
That page is the perfect demonstration of a misuse (aka wrong usage) of my work and research, so it's not important if I write "proof-of-concept"/"testing code"/"demonstration code" in big capital letters (and without considering that my website is located in the Research section of dmoz just for this reason: http://www.dmoz.org/Computers/Security/ ... /Research/) since than anyone has his personal interpretation.

The only positive thing is that at least he has credited me, but being credited for something wrongly showed as bad or malicious is not the max of happyness... blah



Zagan, i hope it was *lol*

http://freewebs.com/proh1 = epic fail


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 18:01 

Joined: 02 Jul 2008 17:59
Posts: 3
Is it just me or does the patch not work 64bit systems?


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 18:30 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
I have tested the work-around made by Goemitar and doesn't fully fixes the bug, the vulnerability is still there (it's enough to modify an instruction in haloloop2)


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 20:42 

Joined: 27 Jun 2008 10:22
Posts: 8
I quickly made that fix. It wasn't really ready to be released, but because so many people went crazy saying that "halo is now death" I already released it.

Anyway, the new fix also works if you change the instruction. It's that number that needs to be higher than 3 right ;)? About the fix itself, it's a rather simple method to detect if it's in a loop or not. You can't really "proof" this will always work, but it seems to do the trick.

I'll send you a copy of it Luigi, since you're probably better at testing if it actually works or not. Or do you think there's a chance they'll actually release an update? In that case it might actually be better to wait, and let them fix it. The update could make the current aimbot crash (since memory address probably will change etc).


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 21:01 

Joined: 02 Jul 2008 17:59
Posts: 3
omegga: any chance of the patch being released for 1.04 and more importantly 64bit systems (many good dedicated servers are 64bit and the patch strangely does not work there).


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 21:03 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
Hey Goemitar, ok send me the new patch and I will glad to test it and if you have MSN we can make the tests in real-time too.
For the moment the important thing is that your work-around (beta or not is not important) has placed a break to who abuses of my work, this gives time to find the best solution.

About the official update... there are probably more chances that the vulnerability evolves and autopatches itself than waiting for a patch 8-)

I could try to send a mail to my old contact at Microsoft but sincerely I don't know if he still works for them and in any case will be needed at least one or two months for a patch... hoping in a definitive fix naturally


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 21:33 

Joined: 30 Jun 2008 22:14
Posts: 17
aluigi wrote:
Hey Goemitar, ok send me the new patch and I will glad to test it and if you have MSN we can make the tests in real-time too.
For the moment the important thing is that your work-around (beta or not is not important) has placed a break to who abuses of my work, this gives time to find the best solution.

About the official update... there are probably more chances that the vulnerability evolves and autopatches itself than waiting for a patch 8-)

I could try to send a mail to my old contact at Microsoft but sincerely I don't know if he still works for them and in any case will be needed at least one or two months for a patch... hoping in a definitive fix naturally


I have a feeling the end-users have to put in more effort if Microsoft (or whoever) is to create an official patch for Halo. Regardless of the official patch, I would like to initiate a patch for the other *albeit useless* versions of Halo. There are many people who would rather enjoy previous versions (due to competition, hacks and whatever reasons the community has).


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 22:25 

Joined: 02 Jul 2008 22:01
Posts: 3
shankedup wrote:
I have a feeling the end-users have to put in more effort if Microsoft (or whoever) is to create an official patch for Halo.


They don't care about this because Halo is too old and they can't make money by selling it anymore. Simply, we have to patch Halo. xD

Anyway I almost managed to fix this but I am a total n00b at RE and asm.

Here is an idea I used:

vulnerable loop probably looks like that:

Code:
for(;;)
{
if(condition_that_is_not_meet)
   break;
  ....
}


i tried to change it to:

Code:
for(int i=0;i < 200;i++)
{
if(condition_that_is_not_meet)
   break;
  ....
}

It didn't fix the bug itself, but it simply bypass it.
However i had a problem with storing value of 'i', i tried to push it on stack but is was a silly idea. Is there any writable, not used memory location in Halo memory to store that variable?
I used haloceded 1.0.


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 22:33 

Joined: 30 Jun 2008 22:14
Posts: 17
Are you attempting to edit the haloloop Proof source? :S


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 23:10 

Joined: 02 Jul 2008 22:01
Posts: 3
shankedup wrote:
Are you attempting to edit the haloloop Proof source? :S


Good joke.
Im editing function at 0x4cbea0(VA) in haloceded.exe 1.0


Top
 Profile  
 
 Post subject:
PostPosted: 02 Jul 2008 23:24 

Joined: 30 Jun 2008 22:14
Posts: 17
Termy wrote:
shankedup wrote:
Are you attempting to edit the haloloop Proof source? :S


Good joke.
Im editing function at 0x4cbea0(VA) in haloceded.exe 1.0


whatever happened to online sarcasm T_T.... *u obviously stated that before* lol

but anyhow... is there anyway i can contribute luigi?


Top
 Profile  
 
 Post subject:
PostPosted: 03 Jul 2008 11:04 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
for the moment I think not, but naturally when a definitive solution will be found will be required beta testers


Top
 Profile  
 
 Post subject:
PostPosted: 03 Jul 2008 12:36 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
in reality probably there is something you and others can do: avoid disinformation about my research.

It's useless documenting and demonstrating a vulnerability publicly if then all the idiots (admins, attackers and players, ignorant people can be on any side) don't have the knowledge or don't want to understand it.
But idiots don't understand in any case so probably it's useless to talk to such type of people... anyway trying doesn't cost anything


Top
 Profile  
 
 Post subject:
PostPosted: 03 Jul 2008 15:28 

Joined: 03 Jul 2008 15:25
Posts: 1
Quote:
for the moment I think not, but naturally when a definitive solution will be found will be required beta testers

I run a Halo CE Server and would be glad to beta test any fixes.


Top
 Profile  
 
 Post subject:
PostPosted: 03 Jul 2008 16:02 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
EDIT: work-around removed since not ok


Last edited by aluigi on 03 Jul 2008 20:51, edited 1 time in total.

Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 51 posts ]  Go to page 1, 2  Next

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: