Battlefield 3 Official Ranked game servers now available!

i3D.net Game Forums   i3D.net Support (email & live chat)
Amsterdam +31 (0)10 8900070
USA 1-800-482-6910 (toll free)
Frankfurt +49 69 257378709

Go Back   i3D.net Game Forums > i3D.net Technical > Technical newsletters > Unreal Tournament 3 newsletter
Downloads
300 GB of games and patches
Downloads

Reply
 
Thread Tools Search this Thread Display Modes
Old 5-12-2008, 13:46   #1 (permalink)
Jeff Morris
Guest
 
Posts: n/a
Downloads:
Uploads:

Default Re: [ut3servers] Server termination

Updated exe for another exploit. Feel free to share this EXE with
any server operators you know. Please let me know about any mirrors you
Read more on: : i3D.net Game Forums /unreal-tournament-3-newsletter/40796-re-ut3servers-server-termination.html
setup.

Thanks!

Hi everyone. In response to a few UT3 hacks released, we have an updated
EXE for dedicated server operators that shuts these exploits down.

If you're running a Windows dedicated server, please download and apply
this exe: http://www.epicgames.com/download/ut3.exe.

This exe requires the v1.3 patch. This file is for dedicated servers only
and doesn't introduce any new features over v1.3 other than the hack
fixes.

Please PM me if you have any questions. Thanks!


Jeff


-----Original Message-----
From: UT3 Servers [mailto:UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM] On Behalf Of Jeff
Morris
Read more on: : i3D.net Game Forums http://forum.i3d.net/showthread.php?t=40796
Sent: Monday, September 15, 2008 12:20 PM
To: UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM
Subject: Re: [ut3servers] Server termination
Importance: High

v1.3 Windows exe that addresses this issue can be found here:
http://www.epicgames.com/download/ut3.exe.

Please let me know if this doesn't help the issue. Linux v1.3 DS
is in closed beta, so we should be able to roll this into that release.

Thanks.

Jeff


-----Original Message-----
From: UT3 Servers [mailto:UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM] On Behalf Of Jeff
Morris
Sent: Monday, September 15, 2008 10:29 AM
To: UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM
Subject: Re: [ut3servers] Server termination

Hi guys. We should have a beta exe that addresses this issue for
ut3 servers available today. If you guys give it a clean bill of health,
we'll make it publically available.

Thanks!

Jeff

-----Original Message-----
From: UT3 Servers [mailto:UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM] On Behalf Of
[PHX]Big_Deal
Sent: Saturday, September 13, 2008 10:04 AM
To: UT3SERVERS (AT) LIST (DOT) EPICGAMES.COM
Subject: [ut3servers] Server termination

Hi
Today my server shut down allready 3 times with this error

Critical: appError called:
Critical: Ran out of virtual memory. To prevent this condition, you must
free up more space on your primary hard disk.
Critical: Windows GetLastError: Falscher Parameter. (87)
Log: === Critical error: ===
Ran out of virtual memory. To prevent this condition, you must free up
more space on your primary hard disk.

RaiseException() Address = 0x7c812aeb (filename not found)
CxxThrowException() Address = 0x78158e89 (filename not found)
Address = 0xba0102 (filename not found)
Address = 0xe8781b4c (filename not found)

I know it comes from from this bug:
The problem is located in the function which reads the strings from the
packet where is located a 32 bit number (was an index number in the
previous Unreal engine 1 and 2) which specifies the size in bytes of the
subsequent string to read.

This function removes the sign of the number if it's negative and then
tries to allocate an amount of memory double than this value because
the new buffer is used for containing the unicode version of the string.
Before copying the data is performed an additional check on the sign of
the value for avoiding integer overflows (for example using the value
0x80000000).

If an attacker uses a 32 bit number major than how much allocable on
the system (like 0x7fffffff) the engine terminates immediately showing
a log message like the following:

Critical: Ran out of virtual memory. To prevent this condition, you
must free up more space on your primary hard disk."

Turning Point: Fall of Liberty is another game which uses the Unreal
engine 3 but, differently to the others tested by me, the function
which allocates the memory doesn't shut down the entire game for
reporting the error but simply returns a NULL value (like a classical
malloc) which is correctly handled and so the game is not vulnerable.

The attack can be performed versus the server using one simple UDP
packet with the possibility of spoofing it.

We need a urgent fix!

--
[PHX]Big_Deal
Leader and Admin

PHOENIX UT3 SERVER : ut3://195.245.9.170:6666
PHOENIX UT2004 VCTF AND TAM SERVER : ut2004://195.245.9.170:7777
PHOENIX HOMEPAGE: http://www.phoenix-4ever.de

---------------------
TO LEAVE THE LIST
---------------------
Write to LISTSERV (AT) LIST (DOT) EPICGAMES.COM and, in the text of your message
(not the subject line), write: SIGNOFF UT3SERVERS

---------------------
TO LEAVE THE LIST
---------------------
Write to LISTSERV (AT) LIST (DOT) EPICGAMES.COM and, in the text of your message
(not the subject line), write: SIGNOFF UT3SERVERS

---------------------
TO LEAVE THE LIST
---------------------
Write to LISTSERV (AT) LIST (DOT) EPICGAMES.COM and, in the text of your message
(not the subject line), write: SIGNOFF UT3SERVERS

---------------------
TO LEAVE THE LIST
---------------------
Write to LISTSERV (AT) LIST (DOT) EPICGAMES.COM and, in the text of your message
(not the subject line), write: SIGNOFF UT3SERVERS
  Reply With Quote
Sponsored Links
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are On



New To Site? Need Help?

All times are GMT +2. The time now is 02:19.


©2011 INTERACTIVE 3D BV - Alle rechten voorbehouden
no new posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264