Staredit Network > Forums > General StarCraft > Topic: Frost@USEast > You 2.0
Frost@USEast > You 2.0
Aug 29 2010, 3:52 pm
By: TiKels
Pages: < 1 « 3 4 5 6 710 >
 

Sep 29 2010, 5:29 am LoTu)S Post #81



Quote from Zhuinden
I'm certain they need to know your account name. If you can conceal your account name, you win.
Or change your account. Probably the best way to deal with this is to ALWAYS spoof. That way if you were encounter one of the "key stealers" for the FIRST time, it would be impossible for them to figure out the true name. If you meet them then spoof, it doesn't work at all, since your name will still be recognized and the spoof is useless. For example: If A spoofed as B, and C did /whois A, it would still show up.

Better yet, it's more effective to act more civilized and not hack like those power-hungry noobs who simply inject dll. and call themselves pro hackers. In all sincerity, though this act of pseudo warden act is wrong, a slight upside would be ridding one less basement dweller from battle.net.




None.

Sep 29 2010, 6:47 am Frost Post #82



Quote from LoTu)S
Quote from Zhuinden
I'm certain they need to know your account name. If you can conceal your account name, you win.
Or change your account. Probably the best way to deal with this is to ALWAYS spoof. That way if you were encounter one of the "key stealers" for the FIRST time, it would be impossible for them to figure out the true name. If you meet them then spoof, it doesn't work at all, since your name will still be recognized and the spoof is useless. For example: If A spoofed as B, and C did /whois A, it would still show up.

Better yet, it's more effective to act more civilized and not hack like those power-hungry noobs who simply inject dll. and call themselves pro hackers. In all sincerity, though this act of pseudo warden act is wrong, a slight upside would be ridding one less basement dweller from battle.net.

For the last time: Spoofing will not help you. There's a bot that runs 24/7 collecting information about users (including evidence of the hacks that person is using), and the information collected by the bot can help to identify users for bannage from the channel. The only way to protect yourself is to not use hacks like SPECIFICALLY Oblivion.



None.

Sep 29 2010, 4:24 pm Zhuinden Post #83



PingGnome?



None.

Sep 29 2010, 5:37 pm Frost Post #84



Quote from Zhuinden
PingGnome?
I have a custom bot made by me. It logs some things that ping gnome doesn't, namely what hacks you use.

Post has been edited 1 time(s), last time on Sep 29 2010, 6:16 pm by Frost.



None.

Sep 29 2010, 11:13 pm TiKels Post #85



That's not utterly terrifying.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Sep 30 2010, 7:11 pm Heinermann Post #86

SDE, BWAPI owner, hacker.

Quote from Frost
For the last time: Spoofing will not help you. There's a bot that runs 24/7 collecting information about users (including evidence of the hacks that person is using), and the information collected by the bot can help to identify users for bannage from the channel. The only way to protect yourself is to not use hacks like SPECIFICALLY Oblivion.
Ok, enough with the lame threats. They've been bothering me for quite a while now.

Using a digital install (just getting the digital key isn't enough, you'll have to re-install using the digital download) will completely prevent an attempt. Getting a new account and IP address is fine as long as you don't reveal who you are at all, however it does not prevent anything. Additionally, such information can't be retrieved from channels, only games.




Sep 30 2010, 9:57 pm LoTu)S Post #87



Quote from Monstrous
Some basic protection, considering the exploit just went public.

Wait wut :wut: You serious?
Did one of the 6 release it?

Does digital install COMPLETELY shut down any attempt? Like it's impossible?




None.

Sep 30 2010, 10:10 pm OlimarandLouie Post #88



Quote from Monstrous
Some basic protection, considering the exploit just went public.
I'm not going onto bnet anymore until I am assured that I can protect myself from teh haxorz.



None.

Sep 30 2010, 11:46 pm Monstrous Post #89



Basically the actual "key-stealing hack" wasn't released, just the details of how to perform it. It works in which whenever you join a game your Starcraft client send a few packets. One of said packets, (0x40) the same one that makes other players /astat you, actually contains your cd-key hash (+0x0E if I recall correctly.) All the hackers have to do is brute it and you'll have their key in a couple minutes or so.

It's a serious blunder on Blizzards part. I assume they originally had put it in so when hosts ban people it would ban their cd-key from the game (and not name), but they dropped it and just forgot to remove the part that sends your cd-key hash. Just a guess though, I'm not 100% sure. *Edit: It's validation for spawns.

Anywho, the protection I posted is simple in that it just changes your hash to 0. It will ABSOLUTELY prevent anyone from stealing your cd-key. Though a mod removed it because it's still technically considered a hack. I guess exceptions can't be made. :<_<:

Post has been edited 2 time(s), last time on Oct 1 2010, 12:12 am by Monstrous.



None.

Oct 1 2010, 10:19 pm Heinermann Post #90

SDE, BWAPI owner, hacker.

Exceptions can be made. Staredit.net already supports several hacks including ChaosLauncher and Firegraft.

Quote from LoTu)S

Does digital install COMPLETELY shut down any attempt? Like it's impossible?
Not impossible but extremely unlikely. The length of the key is increased dramatically. Even if someone does manage to write a digital brute force, the time needed to actually do it would be exponentially greater(I estimated at least 9 years on my 2.4 Ghz dual core, this doesn't include the far more intensive code required to handle such a key) as well as return hundreds, maybe thousands of "possible matches".

Starcraft keys themselves were insecure. Even if the 9-year time for generating digital keys were skipped, they would still need to test thousands of keys(and get IPBanned from battle.net thousands of times, each ban lasting a week or longer) before finding the one that works.


In short, digital keys are far more secure and are recommended.




Oct 2 2010, 3:13 am Gladius_Tito Post #91



Frost, I understand you're doing this with good intentions, but you have to understand that people are afraid not that you'll specificially hack them, but that people who discover your methods will.

If a person uses cdkey stealing for good, what stops others from using it for bad?



None.

Oct 2 2010, 3:38 am Apos Post #92

I order you to forgive yourself!

This way of taking the keys is not new (AFAIK), they may have found it out not long ago, but I'm pretty sure it's always been doable. Battle.net was always insecure.

Correct me if I'm wrong.

Post has been edited 1 time(s), last time on Oct 2 2010, 4:44 am by Apos. Reason: I messed up 2 words together...




Oct 2 2010, 3:42 am Lakai Post #93



Quote from Gladius_Tito
If a person uses cdkey stealing for good

....

it isnt for good.



None.

Oct 2 2010, 4:32 am Heinermann Post #94

SDE, BWAPI owner, hacker.

It was a scare tactic afaik.




Nov 24 2010, 3:28 pm Jesusfreak Post #95



How do I get the digital download? Do I need to buy the game again?



None.

Nov 24 2010, 5:12 pm NudeRaider Post #96

We can't explain the universe, just describe it; and we don't know whether our theories are true, we just know they're not wrong. >Harald Lesch

Go to battle.net, make an account, register your old sc1 key, download digital version.




Nov 24 2010, 6:39 pm Dem0n Post #97

ᕕ( ᐛ )ᕗ

It doesn't matter anymore. I'm pretty sure Frost is gone. I haven't seen one of his games for a couple of weeks now.




Nov 24 2010, 8:45 pm Jesusfreak Post #98



Ok... it turns out I don't have my CD key with me (I'm at "home" for thanksgiving), so I'll have to wait for a few days I guess...



None.

Nov 26 2010, 1:07 am TiKels Post #99



Frost is in jail, blizzard apparently either said "Pay 500k fine or jail lulz". Of course, no verification, that is just what I heard.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Nov 26 2010, 1:10 am The Starport Post #100



Sauce plz.



None.

Options
Pages: < 1 « 3 4 5 6 710 >
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[07:46 am]
RIVE -- :wob:
[2024-4-22. : 6:48 pm]
Ultraviolet -- :wob:
[2024-4-21. : 1:32 pm]
Oh_Man -- I will
[2024-4-20. : 11:29 pm]
Zoan -- Oh_Man
Oh_Man shouted: yeah i'm tryin to go through all the greatest hits and get the runs up on youtube so my senile ass can appreciate them more readily
You should do my Delirus map too; it's a little cocky to say but I still think it's actually just a good game lol
[2024-4-20. : 8:20 pm]
Ultraviolet -- Goons were functioning like stalkers, I think a valk was made into a banshee, all sorts of cool shit
[2024-4-20. : 8:20 pm]
Ultraviolet -- Oh wait, no I saw something else. It was more melee style, and guys were doing warpgate shit and morphing lings into banelings (Infested terran graphics)
[2024-4-20. : 8:18 pm]
Ultraviolet -- Oh_Man
Oh_Man shouted: lol SC2 in SC1: https://youtu.be/pChWu_eRQZI
oh ya I saw that when Armo posted it on Discord, pretty crazy
[2024-4-20. : 8:09 pm]
Vrael -- thats less than half of what I thought I'd need, better figure out how to open SCMDraft on windows 11
[2024-4-20. : 8:09 pm]
Vrael -- woo baby talk about a time crunch
[2024-4-20. : 8:08 pm]
Vrael -- Oh_Man
Oh_Man shouted: yeah i'm tryin to go through all the greatest hits and get the runs up on youtube so my senile ass can appreciate them more readily
so that gives me approximately 27 more years to finish tenebrous before you get to it?
Please log in to shout.


Members Online: Ultraviolet