Settings

Theme

This House is Haunted: a decade-old RCE in the AION client

appsec.space

2 points by _zeta 10 months ago · 1 comment

Reader

_zetaOP 10 months ago

Exploring how AION’s old housing system, introduced over 10 years ago, left the client vulnerable to remote code execution through Lua scripting. Even though official servers removed the feature years ago, it’s still alive (and exploitable) in legacy versions. Write-up: https://appsec.space/posts/aion-housing-exploit/

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection