DNS error allows to hack millions of PCs on all Blizzard games
On January 22, Google researcher Tavis Ormandy discovered a Rebinding DNS error that allowed anyone to pretend to be a server to update and distribute malicious code when Update Agent thought it was a game update.
Specifically, according to the bug report, the Blizzard Update Agent contains a JSON RPC server that other applications send commands to interact with the Agent. According to Ormandy, he can use the browser and bring JavaScript code to users, attack the server and "force" the Agent's update server to the infected server.
The Blizzard Update Agent is silently patched
After Ormandy revealed this error on Twitter and said that Blizzard patched it without saying anything.
The Blizzard Update Agent update (version 5996) takes the name of the application when sending the command to the JSON RPC server, computes a 32-bit hash string FNV-1a and compares it to the list of unauthorized applications.
The vulnerability fake Blizzard game updates
While Ormandy offered to use the whitelist, Blizzard came up with a blacklisted solution, which he considered "perfect and maintained" so the way Blizzard applied was too simple.
Maybe many other applications get the same error
Ormandy created a PoC page to simulate a DNS Rebinding attack using the Blizzard Update Agent.http://lock.cmpxchg8b.com/yah4od7N.html. There are also other sites to attack on other applications and to find other applications with similar errors. https://lock.cmpxchg8b.com/rebinder.html
Ormandy had earlier found this error in Transmission BitTorrent.
See more:
- Quickly register to play Age of Empires 4K upgrade version of the graphic
- Quickly download 6 games that are free for a short time
- How to install the Rules Of Survival game on PC
You should read it
- Legendary Warcraft game will have a mobile version in 2022
- Diablo IV was officially announced, top notch graphics, impressive trailers
- The series of pictures showing the world filled with wonders, the imagination of people is far from catching up
- StarCraft II becomes a free game
- The best deck building tips in Hearthstone
- How to Download World of Warcraft for Free
- How to play Ultra Cold mode - Cold Front Survival PUBG Mobile
- The man lived only by hacking online games for 20 years
May be interested
- Now even YouTube ads use CPU viewers to dig virtual moneyads bring profits to attackers while users naively watch videos on youtube.
- Campaign to distribute spyware aimed at macOS in Vietnamsecurity experts discovered a campaign to distribute spyware with compelling content emails and attach a malicious text file to the mac of a number of vietnamese organizations and businesses.
- There are vulnerabilities that allow hackers to bypass the fingerprint security mechanism of Lenovo computersthe fingerprint manager pro program of microsoft windows 7, 8 and 8.1 allows users to store data, log in personal accounts on websites, log in to a lenovo computer via fingerprint there are many vulnerabilities that may allow hackers to access user sensitive data.
- The Ministry of Public Security warned users to warn of bank account theft when withdrawing money at ATMsaccording to the ministry of public security, the operation of criminals using high technology is increasingly sophisticated. they can use high-tech devices located at many public atms to steal bank account information to hijack cardholders' assets or use fake bank cards to withdraw money at atms. .
- Hacker was jailed for 2 years for DDoS attacks against Skype and Googlea 21-year-old was jailed for two years after being accused of conducting ddos attacks on high-tech companies such as skype and google.
- Adobe Flash Player has a serious zero-day vulnerabilityrecently, another zero-day vulnerability was discovered by south korea's cert in adobe flash player to allow remote code execution (rce), remote code execution behavior on different platforms.