appsec & stuff
appsec & stuff
Home avatar

A space where I talk about Application Security & other stuff

Opinions are my own

This House is Haunted: a decade old RCE in the AION client

TL;DR
I found a RCE in the AION client starting from 3.0 (not confirmed the latest version vulnerable) using the built-in housing system. Private servers are still vulnerable.
Important Note
In the initial version of this post I wrote that the housing system was removed in 5.0 but some players made me notice that this is wrong indeed the housing system is still there in the retail version of AION (still maintained) but not present in the classic version of the game. This is interesting because apparently we have a bigger playground to investigate, maybe in a follow-up.

When I was younger, MMOs were everywhere. World of Warcraft had already taken over the world with millions of players, Lineage II and Runescape had their own massive communities, and when AION launched in 2009 by NCSoft (a South Korean Company) it quickly became one of the most populated MMOs, with around 6 million players in Asia and 1 million in Europe.

Debloating the Onyx Boox Go 10.3

I was looking for an eink tablet to r ead books and take notes while I’m away from home.

After adventuring in the eInk rabbit hole I decided to go for the Onyx Boox Go 10.3: a Black and White eInk Android Tablet with 300ppi that’s also good for taking notes, weighting only 365g!

I was a bit concerned about this report from Mozilla so I decided to take a look at the device.