Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

ADVISORIES

No More Multiplayer

- Rogue Trooper disclosed with highly critical vulnerabilities

By: Alexandru Dumitru, Security News Editor

Rogue Trooper, a game from Rebellion, based on the Asura engine has been discovered to have two bugs that could cause a buffer-overflow. This flaw has been ranked by Secunia as being Highly critical, receiving a 4 out of 5 on the
threat-o-meter.

This vulnerability affects the 1.0 version, though it is possible to be present in other versions as well. If exploited by hackers, it could allow them to compromise a vulnerable system. This should be taken very seriously and only use Rogue Trooper as a multiplayer server only in a trusted network environment.

There are two problems concerning the Asura Engine Packet. The first one, as seen on Secunia's website, the vulnerability in the PRISM Guard Shield is caused due to a boundary error in the processing of network packets by the included Asura engine when PRISM Guard Shield runs as a server. This can be exploited to cause a stack-based buffer overflow via a specially crafted packet with a type of "0xF007" sent to the vulnerable server (default port 3658/udp).

As I've seen on Luigi Auriemma's site (the guy that discovered the flaws) a buffer-overflow vulnerability is located in the function which handles the 0xf007 packet used for the challenge B query. In this function, the data passed by the client is copied (without checks on its length) to a stack buffer of 256 bytes used for sending the data back to the client, something similar to a ping.

These explanations might be somewhat hard to digest but anyway, there are two things that you need to keep in mind: one thing is that the game is flawed and the second is that to avoid being attacked by malicious users, you need to play Rogue Trooper only on a secure network.

MORE RELATED ARTICLES: Proof of Concept Code Published for Critical IE Vulnerability AOL Vulnerability! Flash Vulnerability Solved 4 Months after Being Spotted OpenOffice Highly Critical Vulnerability Hot Pictures of Paris Hilton Nude Served Through XP Vulnerability
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


23rd August 2007, 14:13 GMT | Copyright (c) 2007 Softpedia | Contact:
Read by 420 user(s) | Rating: | 7 vote(s) so far | Cast your vote:
No More Multiplayer - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT No More Multiplayer

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive