How the Unlocks were Hacked... A very good Guess

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SUPERD

    #1

    How the Unlocks were Hacked... A very good Guess

    When BF was released, there was a link to a testing app on the WikiPedia page for BF2 Developers. http://bf2.fun-o-matic.org/index.php/BF2Stats

    It looked like this:



    This 'frame' had lots of DEBUG stuff still inside it. Also, the code was easily obtained by just using "save page".

    Then, when the stats went off, it was found that to turn the stats back on in a browser, you first had to fetch the stats "as if you were the BF2 Game"

    Like this in ColdFusion (notice the GameSpyHTTP ) :



    Once ppl figured out WHAT TO SEND and HOW TO SEND IT AS IF THEY WERE THE GAME it was only a matter of time for someone to write a loop program to do a bulk OpenURL Execute.

    PS. I DID'NT DO IT *****S
  • Fall0ut

    #2
    I don't know

    Comment

    • SB NBT

      #3
      A ha!

      YOU did it,... you have the screenshot and knowledge, plus you are Mr. 1 Post.

      But nice work, I'm forwarding this to EA :p :p

      Comment

      • SaladFork

        #4
        Don't bother. The test framework is extremely old news. And anyone who's made a signature or signature service knows about modifying the HTTP headers so it works like the BF2 client. Hell, I even said it out loud and TOLD you how to do it in my tutorial! (link my sig).

        This post is nothing more than bringing up old information, but with screenshots of something we've all seen.

        And doing a bulk OpenURL would do nothing but lag the stat server up for the rest of us, and is something that you shouldn't do unless you're a script kiddie out to ruin the fun of others.

        And yes, the only commands that worked were read-only ones. updateplayerstats.aspx, resetprofile.aspx, and the rest would NOT work at all, thus disproving your theory.

        I don't mean to sound rude, but you've basically taken some basic and commonly known info and adding pictures to it.

        If you look at the fact that many servers were taken down recently, and maybe run a Packet Sniffer once or twice, you might figure out the truth.

        Oh, and as an inside source of the EA said:
        Originally posted by GamerNode
        This is all Facts from an inside source! Some might be wordering why they have their weapons unlocked, its because EA Games has left a backdoor to BF2. What this means is a port left open for hackers to find. A hacker did find it and anyone with identity 400000 to 450000 has all weapons unlocked. Also by leaving this "doorway open", it has come to the conclusion that anyone who owns bf2 has a doorway open and any server company as well; this is a global issue.This is not just affecting ranked servers but unranked aswell. EA Claims it will be fixed by morning, but they are unsure. Expect alot more problems to pile up amound the already large list.
        Because of this insanely dangerous vulnerability issue, servers had to be taken offline so that this could be fixed immediately.

        Thanks again to GamerNode for this info.

        Don't believe me or GamerNode, or anyone else? Run a packet sniffer yourself next time you're playing.

        ~Salad

        Comment

        • SUPERD

          #5
          Eh, .... it was just a GUESS (see title of post).

          Just thought I would say HI !

          SD

          Comment

          • imported_element

            #6
            What's funny though, is the passwords are sent to the authentication servers unencrypted. Wouldn't want to log on to BF2 at a LAN party, that's for sure.

            Comment

            Working...