games  anime  |  toys
This is a Dtoid readers's blog. For staff blogs click here. Confused? read this Create you own!  |   Members: Login now





[MYTHBUSTER] Modern Warfare 2 : Sending Trojans via IWNet?
Boomsling | 5:02 AM on 11.18.2009 10 comments




There are some forums posts on IW and Steam about a group call KoT (german for faeces?) going around griefing in MW2 multiplayer. Due to the internet's open door policy on ass-holes this comes as no real surprise. There is always a new group of nobs trying to be the next myg0t. However what is alarming is the claims that they are able to compromise the host and send trojans via the IWnet 2p2 network.

Donvanbadboy has this to say on IW forums:

''It's possible if you host a game for a hacker client, and it's possible if you don't host a game, but are connected to a hacker hosting the game. If the game's net code is not 100% secure then it could be possible to craft special packets of data to cause buffer over-runs (stack smashing). This injects hackers code into your computer, which executes it, and hey presto you have a remote code execution hack. If the code's written well it's possible to make it secure, but stack-smashing bugs are so often overlooked.''

I dont know him or who he is so he could be way off the mark here....

Anyone here in the know about p2p and 'stack smashing' and care to comment?

Is this really possible?

I know diddley squat about programming but if they can start injecting their packets into my back door I'm not gonna be a happy bunny.

UPDATE:

Sort of confirmed by this webby as a false positive (thanks to Jon B for the heads-up)

Status:



Attached photos:

Photo

  related blogs:
 

Is this post awesome? Vote it up!

2

Those who have fapped:  Lodd  

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

10 comments | showing # 1 to 10

prev next

Jon B's Destructoid Blog
Completely possible. I find this utterly hilarious since IWnet is supposedly so amazing, but it can happen on dedis too if the dedicated server was infected.
Lodd's Destructoid Blog
It's very plausible at the very least. If it's possible to merge code with Jpegs (an old trick to hide files) I don't see why they couldnt merge code with the game files.

The fact that the forum topic on

http://www.infinityward.com/forum/viewtopic.php?f=24&t=181646

is now unreachable, does not speak in the defense of Infinity Ward either. They need to come out with a statement or a patch soon.

Besides, as far as I understand it, IWnet is p2p based. Historically, p2p networks have always had an abundance of viruses being shared.

Still want to play even though you might be at risk? Check around which antivirus programs work. Avira seems to detect it from what I read on the IWnet forums. I think some other scanners as well, but I can't remember which ones.
Boomsling's Destructoid Blog
tJust checked and the thread is still alive and kicking on IW's forums.

Click on the red IW in my blog post for the link.
Zantetsuken's Destructoid Blog
Yeah, its possible. Wasn't IWnet supposed to be safer and more secure than dedicated servers?

The fact that the topic was deleted twice and the forums are now down shows that IW has cocked up and they know it.
Lodd's Destructoid Blog
@ boomsling.

I stand corrected. The thread is blinking in and out of existence, probably because their forums cannot handle the load.

Without getting overly emotional about it, I can understand the human error in this thing. I mean, would you have thought about this? It's pretty deviously clever and simple if you ask me.

We just need a statement from IW as soon as possible.
Lodd's Destructoid Blog
update: the steam thread is now closed.

I think we should start exploring the possibility of refunds should this issue not be addressed soon.
Lodd's Destructoid Blog
new steam thread here http://forums.steampowered.com/forums/showthread.php?t=1031092

The old one was closed by mods to keep things in one topic.

Btw, im new to destructoid. Any way to edit my posts or delete them so I dont have to spam a new post everytime I have an update? Thanks.
Boomsling's Destructoid Blog
@lodd

not that I know of
Jon B's Destructoid Blog
Confirmed as a false positive. Avira is the only scanner that picks it up.

I'd be cautious though. I wouldn't put it past people to actually use a similar method to actually spread viruses.
Lodd's Destructoid Blog
My avira just ran its full scan, and is 99% done. Nothing yet.

I imagine the whole thing sounds rather silly now. But at least it laid bare some serious security issues that I did not know about earlier. I still think IW should address the issue. Because if they don't, you can bet that hackers are going to try this now.


prev next


Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

Comments policy

Destructoid is an open discussion community. You don't need to "audition" to post a comment - just speak your mind. We respect differing opinions on the site, so have at it. Be smart, funny, insightful, clueless, or cute -- but back it up with substance. Keep your cool, keep it fun. We only ask that you act respectfully and above all: don't be a troll and ruin it for everyone else. Don't bring down gamers or we'll, you know, gently shoot you in the face and stuff you into a flaming mailbox. Each comment is your opportuntity to make this community awesomer. Is that even a word?

Avoiding the banhammer only requires common sense: spamming, trolling, racism, NSFW stuff, and other forms of sucking will not be tolerated. If anyone is griefing please report abuse. Be good. Don't suck!

 about me

Boomsling is a 35 year old zombie and happily married with no kids...yet, which why he is happy (he still doesnt want to share his toys or PC). He lives in the UK and is a virtual 'War Tourist' or FPS slave.




 xbox 360 gamertag
 friends' updates
Brad Nicholson's Profile Brad Nicholson
Metro 2033 Title Update a prep for DLC


 
 
  get involved

register or login
post a blog
post a forum
enter a contest
contribute a news tip
suggest a feature
be a guest editor
support

new member's guide
login assistance
tech support
report abuse
email our editors
read our dev blog
nuclear crisis?
keep in touch

RSS feed
Twitter
Facebook
Myspace
Flickr
Game nights
Meetup+play online
seriously

about Destructoid
advertising
terms of use
privacy policy
jobs at MM
buy our crap
our network

Tomopop
Japanator
Despingation?




Destructoid is an independently-run publication forged by our love of video games and the gaming community's need of accountable enthusiast press
living the dream since March 16, 2006