Logo

CS.RIN.RU - Steam Underground Community

IRC: #cs.rin.ru at irc.rizon.net
It is currently Friday, 17 Apr 2015, 22:29

English | Русский




Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 70 posts ] 
Author Message

Post Post subject:    
Posted: Monday, 24 Jan 2005, 06:48   
Cracker Legend
Joined: Friday, 03 Dec 2004, 03:39
Posts: 362
GarGaMel wrote:
Can't we create servers that block the authentication server but it still shows up in the steam server list.
I think that many servers don't want to go cracked because that they will lose many players. It can't be hard to setup iptables to block the right ports?


Thats the same effect as using a cracked server.
You can either block the traffic to the authentication server, or use a cracked server (which blocks it code-wise).

Both should allow all types of clients to join. (I didn't test that though).


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 06:52   
Beginner Без звания
Joined: Wednesday, 19 Jan 2005, 20:46
Posts: 18
Touche` hCupa.

I'm glad you finally posted this information though, hopefully it will thwart n00bs with magical fixes. :)


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 06:53   
Forum ghost Местное привидение
Joined: Sunday, 12 Dec 2004, 01:12
Posts: 334
Location: carpe noctem
Nice this will clear up the whole mess about the ticket I honestly hope.

_________________
Image


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 06:54   
Beginner Без звания
Joined: Wednesday, 19 Jan 2005, 20:46
Posts: 18
Obscurax wrote:
Nice this will clear up the whole mess about the ticket I honestly hope.


Indeed.


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:00   
Super flooder Почетный графоман
User avatar
Joined: Saturday, 01 Jan 2005, 04:05
Posts: 898
hCUPa wrote:
Thats the same effect as using a cracked server.
You can either block the traffic to the authentication server, or use a cracked server (which blocks it code-wise).

Both should allow all types of clients to join. (I didn't test that though).


But is the cracked server showing up in the steam server list?

_________________
“Итс дангероус то бе ригхт вхен тхе говернмент ис вронг!” - Волтаире


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:03   
Cracker Legend
Joined: Friday, 03 Dec 2004, 03:39
Posts: 362
GarGaMel wrote:
hCUPa wrote:
Thats the same effect as using a cracked server.
You can either block the traffic to the authentication server, or use a cracked server (which blocks it code-wise).

Both should allow all types of clients to join. (I didn't test that though).


But is the cracked server showing up in the steam server list?


That depends if the master server ip/port is different from the authentication one. I think it is though.


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:23   
Advanced forumer Завсегдатай
Joined: Saturday, 22 Jan 2005, 09:09
Posts: 96
Location: Under the Steam Mainframe, arming a C4.
hCUPa wrote:
Chopz:

It could indeed be an idea to corrupt tickets manually and see if that works, but I'd assume a new steam update would block that.

The other idea I had is the same as yours, automating the password entry when connecting to a server, effectively flooding the authentication server in order to get through.

And lastly, as valve controls all the server and authentication code, and we cannot touch that remotely its obviously a battle you can never win. Its just that valve messed up their Steam protocol design that this all could happen in the first place. (It never did on other games).


You spoke of a time-out exploit by having mIRC interfere with the client and the blob. I'd like to point out that since this is in fact a problem on the client side, there is nothing that can be done on the server side.

Also, "you must have a registered game on your list" ... so do you understand the client protocol? I'm asking here, fishing, but really, does the client have to specify who's list? Redirecting the server to check another list would be a nice sneaky hack. Of course, still fixable, so...

And ... are the lists dictated by the client or server?
... in the registration process, who gives the final packet, client or server?

And yet another question. If a packet is lost during the registration process (as you duly point out that it uses UDP), how is it resent, by client or server detection? Spoofing a packet loss to make the server grant authentication is another vunerability as well.

As a last and final hope, remember the SDKs for Half-Life. Worst comes to worst, make a mod that uses a non-Steam online service. Worst comes to worst.


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:24   
Eyebrows of manliness.
User avatar
Joined: Saturday, 01 Jan 2005, 14:21
Posts: 3718
Location: 日本
www.steamlessproject.nl

_________________
Image


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:26   
Advanced forumer Завсегдатай
Joined: Saturday, 22 Jan 2005, 09:09
Posts: 96
Location: Under the Steam Mainframe, arming a C4.
hCUPa wrote:
GarGaMel wrote:
Can't we create servers that block the authentication server but it still shows up in the steam server list.
I think that many servers don't want to go cracked because that they will lose many players. It can't be hard to setup iptables to block the right ports?


Thats the same effect as using a cracked server.
You can either block the traffic to the authentication server, or use a cracked server (which blocks it code-wise).

Both should allow all types of clients to join. (I didn't test that though).


This is called a "Master Server", same idea being used as the ones that id had to index Quake servers. Since I believe that authentication takes place on the same port, this may not be doable.


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:29   
Advanced forumer Завсегдатай
Joined: Saturday, 22 Jan 2005, 09:09
Posts: 96
Location: Under the Steam Mainframe, arming a C4.
ColdFusioN² wrote:
www.steamlessproject.nl


Very VERY nice, I recommend going here and getting the mod...time to have fun again!!


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:39   
Forum ghost Местное привидение
Joined: Sunday, 19 Dec 2004, 07:26
Posts: 327
Location: Canada
man I'm about to cry right now :cry: when all of these cool programs started to come out like six, steam-down, steamluncher........I thought we owned valve for good and that there is nothing they could do. but instead they releast a fucking update that probably took them 1 day to come up with and literally destroid every thing :x :x :cry: :cry: :cry: :cry: :cry:


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:42   
User Редкий гость
Joined: Thursday, 20 Jan 2005, 00:44
Posts: 48
@ hCUPa,

Would you or anyone you know be so kind as to give me 3 accounts via steam (free ones not registered with a key)?

I have got my friends up and running using SiX-STEAM lol but he wants his account now, it's been in the spider webs for a few months and like my theory I was right, old accounts that are free work online with STEAM servers...

If you or anyone would be so kind to help me out (I will help you out also 8) ) my email address is cro_23q@hotmail.com

This works flawlessly and I swear to God this is not BS.

Regards
Chopz.

_________________
I am 66% addicted to Counterstrike (28/43 Yes'). What about you?
I am 75% addicted to Porn (was watching porn whilst filling this in). What about you?


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 07:50   
Beginner Без звания
Joined: Wednesday, 19 Jan 2005, 20:46
Posts: 14
Location: Somewhere down the Ebro
Is there any method to check when ur blob is going to expire?

_________________
Si tu problema tiene solucion... ¿ por que te afliges ? Si no tiene solucion... ¿ por que te afliges ?


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 08:03   
Beginner Без звания
Joined: Tuesday, 31 Aug 2004, 02:31
Posts: 5
AlfaTango wrote:
Is there any method to check when ur blob is going to expire?


when u join a server and u dont have any games registered the server modifies blob file and forward the current time 5 hours later so that's why is expired -.- so let's say u access at 4pm the blob file would actually said that u accessed 9pm making a conflict i think making it not be valid ticket -.-... so i dont think there's a method to check the blob file...


Top
 Profile  

Post Post subject:    
Posted: Monday, 24 Jan 2005, 08:41   
Beginner Без звания
Joined: Wednesday, 19 Jan 2005, 20:46
Posts: 14
Location: Somewhere down the Ebro
Ok I see.

It was just to check how long im gonna be able to play cos my six is not yet affected by that ticket error.

_________________
Si tu problema tiene solucion... ¿ por que te afliges ? Si no tiene solucion... ¿ por que te afliges ?


Top
 Profile  
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 70 posts ]  Go to page Previous  1, 2, 3, 4, 5  Next


Who is online

Users browsing this forum: No registered users and 4 guests


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum




Powered by phpBB® Forum Software © phpBB Group