Oct 23, 2009, 01:37 AM | ||
JJ2 level RCE exploit?
Hey again,
I was looking for smt on YT, and I found this: http://www.youtube.com/watch?v=LQ32itAikCE Quote:
Regards, Xx
__________________
lolZing on the floor |
Oct 23, 2009, 12:01 PM | |
A truely malicious version of this would install a bot/rootkit on the victim's computer instead of just spawning a shell.
|
Oct 23, 2009, 02:26 PM | |
Limited rights will stop this, using Vista or Windows 7 with UAC will stop any major harm done as the application (jj2) would be run with little user rights. XP users however running with admin rights would be screwed.
|
Oct 23, 2009, 03:19 PM | |
This exploit isn't something you need to worry too much, the only people who have any idea how to do this (and you could probably count them on one hand) aren't going to abuse it or let the information out. Newspaz is right in that this sort of thing has been known about for some time.
The fact remains that jj2 has some major security holes though, and it's something that would be good to fix. The stuff shown in this video isn't even the worst that's possible. |
Oct 23, 2009, 05:07 PM | |
not like anyone would actually join a server hosting battle1 XD.
Even though alot in theory can be done, I dont see at as a huge threat. Nowadays most people either join friends servers or the major dedicated ones, so falling for this isnt very likely. Also I agree with Evilmike, people who have this and actually know how to use it areny very likely to abuse, and if they do, well its not the end of the world. Theres a limited amount someone can do from command prompt and even if your computer gets screwed, thats what backups are for. |
Oct 23, 2009, 05:27 PM | ||
Quote:
If you can hijack someone's computer like in that video, uploading a trojan or virus is trivial. If your computer gets compromised in this way, the person on the other end can do whatever they want to. There really is no limit, and if they are smart about it, you won't even notice that they hacked you. The best protection is what nimrod mentioned: don't run your computer in admin mode. |
Oct 24, 2009, 09:52 AM | |
Depends on how it's configured. If there's no signature for whatever shellcode or rootkit is being used, and the firewall is configured to generally let stuff through, then it may never warn about this.
I have seen computers with current anti-virus definitions and a reasonably secure firewall get owned by trojans. |
Oct 24, 2009, 10:07 AM | ||
who'd do that?maybe he was accessing his other computer.
what about this. Quote:
but seriously,who'd do that? |
Oct 24, 2009, 03:49 PM | |
lol you got owned
__________________
Yes, I am, in fact, ALWAYS the one to blame for everything. And none of your are full of yourself. Good job. Do you like Stijn? Take my poll! ![]() ![]() Windows is not a virus. A virus is small and efficient... Note to Stijn: how am i even getting away with this |
![]() |
«
Previous Thread
|
Next Thread
»
Thread Tools | |
|
|
All times are GMT -8. The time now is 07:50 AM.
Jazz2Online © 1999-INFINITY (Site Credits). Jazz Jackrabbit, Jazz Jackrabbit 2, Jazz Jackrabbit Advance and all related trademarks and media are ™ and © Epic Games. Lori Jackrabbit is © Dean Dodrill. J2O development powered by Loops of Fury and Chemical Beats. Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Original site design by Ovi Demetrian. DrJones is the puppet master. Eat your lima beans, Johnny.