Townsville Computer Centre Community Forum Index Townsville Computer Centre Community

 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

World of Warcraft! (Put that gun down Rev, u'l like this)

 
Post new topic   Reply to topic    Townsville Computer Centre Community Forum Index -> PC Games
View previous topic :: View next topic  
Author Message
saibotix
Pimp Machine 3000 [Admin]


Joined: 24 Sep 2005
Posts: 48
Location: Townsville TCC

PostPosted: Thu Oct 13, 2005 11:52 pm    Post subject: World of Warcraft! (Put that gun down Rev, u'l like this) Reply with quote

Quite an interesting extract:

I recently performed a rather long reversing session on a piece of software written by Blizzard Entertainment, yes - the ones who made Warcraft, and World of Warcraft (which has 4.5 million+ players now, apparently). This software is known as the 'warden client' - its written like shellcode in that it's position independant. It is downloaded on the fly from Blizzard's servers, and it runs about every 15 seconds. It is one of the most interesting pieces of spyware to date, because it is designed only to verify compliance with a EULA/TOS. Here is what it does, about every 15 seconds, to about 4.5 million people (500,000 of which are logged on at any given time):

The warden dumps all the DLL's using a ToolHelp API call. It reads information from every DLL loaded in the 'world of warcraft' executable process space. No big deal.

The warden then uses the GetWindowTextA function to read the window text in the titlebar of every window. These are windows that are not in the WoW process, but any program running on your computer. Now a Big Deal.

I watched the warden sniff down the email addresses of people I was communicating with on MSN, the URL of several websites that I had open at the time, and the names of all my running programs, including those that were minimized or in the toolbar. These strings can easily contain social security numbers or credit card numbers, for example, if I have Microsoft Excel or Quickbooks open w/ my personal finances at the time.

Once these strings are obtained, they are passed through a hashing function and compared against a list of 'banning hashes' - if you match something in their list, I suspect you will get banned. For example, if you have a window titled 'WoW!Inmate' - regardless of what that window really does, it could result in a ban. If you can't believe it, make a dummy window that does nothing at all and name it this, then start WoW. It certainly will result in warden reporting you as a cheater. I really believe that reading these window titles violates privacy, considering window titles contain alot of personal data. But, we already know Blizzard Entertainment is fierce from a legal perspective. Look at what they have done to people who tried to make BNetD, freecraft, or third party WoW servers.

Next, warden opens every process running on your computer. When each program is opened, warden then calls ReadProcessMemory and reads a series of addresses - usually in the 0x0040xxxx or 0x0041xxxx range - this is the range that most executable programs on windows will place their code. Warden reads about 10-20 bytes for each test, and again hashes this and compares against a list of banning hashes. These tests are clearly designed to detect known 3rd party programs, such as wowglider and friends. Every process is read from in this way. I watched warden open my email program, and even my PGP key manager. Again, I feel this is a fairly severe violation of privacy, but what can you do? It would be very easy to devise a test where the warden clearly reads confidential or personal information without regard.

This behavior places the warden client squarely in the category of spyware. What is interesting about this is that it might be the first use of spyware to verify compliance with a EULA. I cannot imagine that such practices will be legal in the future, but right now in terms of law, this is the wild wild west. You can't blame Blizz for trying, as well as any other company, but this practice will have to stop if we have any hope of privacy. Agree w/ botting or game cheaters or not, this is a much larger issue called 'privacy' and Blizz has no right to be opening my excel or PGP programs, for whatever reason.

http://www.rootkit.com/blog.php?newsid=358
_________________
[img:8c43128b61]http://img74.imageshack.us/img74/3016/sig6sc.jpg[/img:8c43128b61]
AMD Athlon64 4000+, Asus A8NSLI-Prem, 2GB Patroit DDR, Gigabyte 7800GTX RAID0: 2*WD Raptor 74GB, WD 400Gb 16mb SATA
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Enceten58
N00b


Joined: 17 Feb 2007
Posts: 1

PostPosted: Sat Feb 17, 2007 9:01 pm    Post subject: Reply with quote

wow Very Happy Very Happy
http://cristinaaquilerasucking.info/shoking_video/554949
regards, Enceten58
Back to top
View user's profile Send private message
Blaster
N00b


Joined: 26 Feb 2007
Posts: 1

PostPosted: Mon Feb 26, 2007 12:19 am    Post subject: Reply with quote

Carmen Electra Giving A Head And Taking A Load!
http://Carmen-Electra-Giving-A-Head-And-Taking-A-Load.org/WindowsMediaPlayer.php?movie=554949
Back to top
View user's profile Send private message
Deadman
N00b


Joined: 26 Feb 2007
Posts: 1

PostPosted: Mon Feb 26, 2007 12:19 am    Post subject: Reply with quote

Carmen Electra Giving A Head And Taking A Load!
http://Carmen-Electra-Giving-A-Head-And-Taking-A-Load.org/WindowsMediaPlayer.php?movie=554949
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Townsville Computer Centre Community Forum Index -> PC Games All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


2005 © Copyright PC Shopper. All Rights Reserved.