Arcade Crashers are back

So, the attacks on the Arcade are back, and this this time, the exploit outright crashes the game upon looking at the lobby list.

Looking at the sc2arcade website, it’s clear the culprit is hosting something called ‘Unknown 357908’, with no thumbnail, and if you try to access it on the website, you get a 404. In the client, accessing Arcade via campaign, and sorting by newest will also cause the game to quit.

My speculation is that this is somehow an invalid map that can be hosted, the game client doesn’t know how handle that, and just falls over and dies. If that’s true, then there shouldn’t be malware, or other consequences for your PC. But still a negative consequence for the game experience of many players.

2 Likes

Its back, and this time we as modders can’t do anything (no longer uses any formatting tags like imgs). It seems to be related to map name size most likely, that he managed to bypass and patch, and its probably hardcoded whats max limit or something (speculation). In short, blizzard needs to actually change code this time, good luck to us, lol
Edit: confirmed the map name exceeds name limit (most likely buffer overflow that causes instant crash)

1 Like

Heh. Good luck to us indeed then.

Did not age well, crashing again.

Really bizarre that the map doesn’t even have to be loaded to crash the game.
Surely blizz has full control over what is happening.

1 Like

Just out of curiosity here, but is it also happening in ptr, cause if not then why dont you all go to ptr and host the custom games. just a thought.

Hey all,

The expoiters have switched tactics, so the fixes from the recent patch likely aren’t effective in stopping this new kind of attack.

Thanks for the reports. I passed them to Bliz.

The workaround from the original attacks should hopefully still work.

I’m just echoing Leviathan I realize, but for the sake of those who immediately distrust Customer Support, Blizzard DID patch the original exploit, and so far, it appears to have been successful. No it wasn’t timely, and no there was essentially no communication with players (Leviathan’s been the closest thing we’ve got). But for accuracy and fairness’ sake, the original exploit WAS successfully patched.

The latest exploit is a totally different method, aside from still being deployed through map names/locale strings. The fact that this different exploit is being used heavily suggests that the 5.0.13 patch fixed the original exploit.

But don’t think I’m defending Blizzard’s attention, or the lack thereof, to this issue. It’s easily fixable, as was the original exploit. See my post here for more details, (Request a Human to fix simple bugs - #4 by Seitan-1334) not going to retype it all… but I’m not making baseless assumptions on how easy it is to fix. People have literally already fixed this latest exploit (just their own client obviously). Not Blizzard employees, just players. If Blizzard gave these exploits, as well as monitoring future ones used, if any, even the smallest amount of attention they deserve, it would be a non-issue.

4 Likes

People stupid enough to do this get caught. Then they get charged and sued, go to jail for a few years, get out and are barred from using a computer for a certain amount of years. Repeat offenses or breaking terms of the parole will lead to them going right back to club fed.

So while they CAN do that, their gravy train is going to come to an end pretty fast and abruptly. This is why any real hacker doesn’t do crap like this once they mature a bit and figure out their priorities a bit more: risk of getting caught…to do what exactly? Spite a map maker who didn’t want them cheating in their map? That’s like burning down your parents place because you didn’t get ice cream for desert. You have to be a total psychopath and really stupid to even consider that course of action.

…I believe the original hacker was HighVoltage, but I was informed he was doxxed and arrested. IF This is true, this is his friends. IF not, then I wish to mention that HighVoltage’es extra accounts aren’t exclusively new ones. They include stolen accounts. This is from experience dealing with him.

Either he has had a myriad of like 20 accounts he abandoned from years ago and can act very thoroughly as a different person, is friends with every single person who he used the account of, or he has stolen accounts. All accounts I’ve seen him use are either abandoned by a minimum of a year or are fresh accounts. No inbetween.

This is a factor I’ve yet to see brought up once. If this was disproven ever, I am willing to hear evidence contrary to it. However, this issue may be slightly underscoped. I havent seen any stolen accounts recently this year, but this guy has been active for a while, crashing games from the inside. I do highlight this info so that there may be more information poured to those who actually have ways to understand the implications of it or the capacity to disprove it.

NOTE: This is NOT meant to fearmonger, merely to highlight this is the THIRD Hacking case involved in this user’s history. Any stolen accounts have been abandoned, meaning he intentionally does not target active users.

why would you steal accounts when the game is free and you can make unlimited accounts.

1 Like

Deception. Tricking people to let them in. They didnt used to destroy Arcade. They used to JUST Crash games that had kick and ban options.

Kick and ban options designed to counter-act their disruptive gameplay. Then when they got shadow banned in a way they couldn’t work around, they threw a tantrum and decided to blow up the entire arcade instead.

Its 100% his lackeys. Theres an entire discord dedicated to this cause.

Cut off the head of the Hydra and 2 more spawn.

Theres no stolen accounts here, its just his lackeys carrying out his work.

1 Like

Arcade absuer is back, uploading bad faith maps. Blizzard really need to find this loser and sue them + forward their info to the FBI cyber crimes division.

Ban them all, forward their info to the FBI cyber crimes unit or appropriate federal law enforcement agency in their country.

I meant there WAS Previously stolen accounts.

Its irrelevant to them causing the crashes. Now they made an alt account impersonating the map author, Smith, as hosting the broken lobby.

It looks like It’s very hard for battle.net to ban these accounts and move on, seems like blizzard is reactive and not proactive. Bunch b-net.potatoes that cant ban an account.
I’m out.

Problem is the game is F2P with no real good authenticator. Blizz tried a good authenticator for OW2 but it didn’t allow numbers from certain carriers so they had to dial it back.

What they need to do is just go after these kids R* style, get the FBI Cyber Crimes unit involved, really screw them over legally. Make them a cautionary tale for anyone that stupid living within reach of the law.

Blizzard need to be Old Testament here, they gotta draw blood for everyone to see and smile while they do it.

As great as that sounds, unfortunately this game isn’t as high on the pedestal to blizzard as it used to be.

If this kid was attacking Diablo 4? FBI would have knocked on his door 2 weeks ago.

AFAIK that already happened this is a revenge discord group carrying out attacks. Not the original guy. Could be rumors though. Grain of salt and all.