I think it comes down to devs being inconsistent with the opcodes.
The AgentServer filters all incoming packets based on some rules:
First it filters all framework opcodes (0x2000->0x2FFF, 0x6000->0x6FFF, 0xA000, 0xAFFF) with the some exceptions:
Code:
0x600D (massive)
0x6103 (auth)
0x6110
0x6314 (cas_request)
0x6316 (cas_answer)
0x2110
0x2113 (xtrap)
0x2001 (identity)
0x2002 (keep alive)
Second it removes all acknowledges (0x8000, 0x9000, 0xA000, 0xB000) and any opcode > 0x07FF in their respective group.
0x9000 is only allowed in _OnMsgReceivedBeforeHandshake().
So the remaining allowed opcode ranges are:
Code:
0x1000 -> 0x17FF: NetEngineNoDir
0x5000 -> 0x57FF: NetEngineReq
0x3000 -> 0x37FF: GameNoDir
0x7000 -> 0x77FF: GameReq
The exploit happens to be within this range, good luck :P