appsec & stuff
appsec & stuff
Home avatar

A space where I talk about Application Security & other stuff

Opinions are my own

This House is Haunted: a decade old RCE in the AION client

TL;DR
I found a RCE in the AION client starting from 3.0 (not confirmed the latest version vulnerable) using the built-in housing system. Private servers are still vulnerable.
Important Note
In the initial version of this post I wrote that the housing system was removed in 5.0 but some players made me notice that this is wrong indeed the housing system is still there in the retail version of AION (still maintained) but not present in the classic version of the game. This is interesting because apparently we have a bigger playground to investigate, maybe in a follow-up.

When I was younger, MMOs were everywhere. World of Warcraft had already taken over the world with millions of players, Lineage II and Runescape had their own massive communities, and when AION launched in 2009 by NCSoft (a South Korean Company) it quickly became one of the most populated MMOs, with around 6 million players in Asia and 1 million in Europe.

Debloating the Onyx Boox Go 10.3

I was looking for an eink tablet to r ead books and take notes while I’m away from home.

After adventuring in the eInk rabbit hole I decided to go for the Onyx Boox Go 10.3: a Black and White eInk Android Tablet with 300ppi that’s also good for taking notes, weighting only 365g!

I was a bit concerned about this report from Mozilla so I decided to take a look at the device.

Getting "Zero Click" Remote Code Execution in Mycroft AI vocal assistant

During my journey contributing to open source I was working with my friend Matteo De Carlo on an AUR Package of a really interesting project called Mycroft AI. It’s an AI-powered vocal assistant started with a crowdfunding campaign in 2015 and a more recent one that allowed Mycroft to produce their Mark-I and Mark-II devices. It’s also running on Linux Desktop/Server, Raspberry PI and will be available soon™ on Jaguar F-Type and Land Rover