ID Software Quake 3 "smurf attack" Denial of Service vulnerability
BID:3060
Info
ID Software Quake 3 "smurf attack" Denial of Service vulnerability
| Bugtraq ID: | 3060 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2001 12:00AM |
| Updated: | Jul 17 2001 12:00AM |
| Credit: | Reported to bugtraq by "Jamal Motsa" <[email protected]>. Based on qflood.c by Andy Gavin (_k3nny@EFnet, k@ETG) Additional information contributed by Tom Vogt <[email protected]>. |
| Vulnerable: |
Sierra Entertainment Half-Life 1.1.1 .0 Sierra Entertainment Half-Life 1.1 .0.7 id Software Solaris Quake II 3.14 id Software Solaris Quake II 3.13 id Software QuakeWorld 2.1 id Software QuakeWorld 2.0 id Software Quake II Server 3.21 id Software Quake II Server 3.20 id Software Quake II 3.14 id Software Quake II 3.13 id Software Quake 3 Arena Server 1.29 g id Software Quake 3 Arena Server 1.29 f id Software Quake 3 Arena 1.31 id Software Quake 3 Arena 1.16 n id Software Quake 3 Arena 1.1.7 id Software Quake 3 Arena 1.1.7 id Software Quake 1.9 id Software Linux QuakeWorld 2.2 id Software Linux QuakeWorld 2.1 id Software Linux Quake II 3.15 id Software Linux Quake II 3.14 a id Software Linux Quake II 3.13 Epic Games Unreal Tournament Server 436.0 |
| Not Vulnerable: | |
Discussion
ID Software Quake 3 "smurf attack" Denial of Service vulnerability
Quake 3 network play features contain a remotely exploitable denial of service vulnerability.
A hostile client program can be used by to generate a large number of forged client queries on behalf of a target user. The server's responses flood the target user, consuming the target system's network bandwidth and CPU cycles.
It has been reported that other games suffer from similar issues. Additional amplification attacks may be possible through the usage of commands which return detailed information about the game status or server information. In some cases, packets larger than 500 bytes may be sent in response to a 50 byte spoofed UDP packet.
Quake 3 network play features contain a remotely exploitable denial of service vulnerability.
A hostile client program can be used by to generate a large number of forged client queries on behalf of a target user. The server's responses flood the target user, consuming the target system's network bandwidth and CPU cycles.
It has been reported that other games suffer from similar issues. Additional amplification attacks may be possible through the usage of commands which return detailed information about the game status or server information. In some cases, packets larger than 500 bytes may be sent in response to a 50 byte spoofed UDP packet.
Exploit / POC
ID Software Quake 3 "smurf attack" Denial of Service vulnerability
An exploit for Quake3 has been provided by Jamal Motsa:
An exploit for Quake3 has been provided by Jamal Motsa:
References
ID Software Quake 3 "smurf attack" Denial of Service vulnerability
References:
References:
- Application-Level Reflection Attacks (Tom Vogt
)