injecting a packet with long enough text to overflow a buffer?
injecting a packet with long enough text to overflow a buffer?
you can't search an area you haven't been to with that character. but ya, I understand what you meanOriginally Posted by Mifaco
NopeOriginally Posted by dendryte
![]()
I crash my client if I try to copy + paste too much into the chat buffer. But I think that has more to do with the IME (or whatever the client uses when you're typing stuff) rather than when it tries to render the text.Originally Posted by dendryte
It's probably something really simple like sending the bytecodes for Alt + F4 into a packet. The key being that you have to know the packet structure and bypass the client completely.
If I were to wager a guess, he's using the chatlog to inject a character that the client sees is missing, or one that it cannot recognize. If you go by the theory that if you delete the Darter file and don't put something in its place, the client will search for the file, become unable to find it, and the client then crashes.
I remember back in my old Counterstrike days I had a little program that would inject a computer-controlled character into strictly PvP servers. Since no AI for dummy characters is programmed into these servers, it times out and crashes the server trying to find it. I'm not really a good FPS player so if people pissed me off too much I would use the program to crash the server.
I can surmise that Taj is using a similar method, and to prevent him from disconnecting himself, he inserts the character into a windower macro, blacklists himself, then hits it in /say or /shout range of other people. The actual character he could be trying to insert into the text (though I am sure there are many) I am not familiar with. And yes, SE could fix it easily.
How close am I?
Not very. I'm hesitant to divulge how it works because then nubs like iiFuzz or whatever that fag's name is is going to build it in to FFXIApp.Originally Posted by Jeryhn
Then don't. >_>Originally Posted by Taj
Exactly what went through my mind- LSes zoning right outside DA when Nidd pops and just having someone dc the zoneOriginally Posted by Mifaco
Darn. Was worth a shot though.
I just hope people realize that if he does give out what he is doing, it will be fixed very fast.Originally Posted by Septimus
I would also guess that they'd include a detection method if anyone tried duplicating it, if they can't already.Originally Posted by Scythiroth
Seeing how we know Taj likes to flaunt his ability to hack FFXI, I'm pretty sure he wouldn't care if his 30th character got banned.
Would be anything similar to a SQL injection?
No.Originally Posted by Eanae
![]()
I don't see how SQL Injection is even related. I'm sure if SQL Injection was possible, you'd be able to do an awful lot more damage than just crash their clients ' OR DROP DATABASEOriginally Posted by Eanae
I'm guessing you edit the packets in such a way that the rest of the people in a zone can't find said information in the packets=mass POL failure? If not this then I definately know my other way is right.
I bet Taj getting PM bombed now with people asking how this is done. lol
Hey was just putting a shot out thereOriginally Posted by Faranim
![]()
Using Python? >,>
Isn't python a compiler/SDK? >_>aOriginally Posted by Vobent
Python is an interpreter, and I'm using C++Originally Posted by Vobent