HLDS Exploit

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • joe

    #16
    Edited by [user="3037"] @ [time="1042290894"]

    the news post is incorrect:
    game servers running the popular server administration tool Adminmod are vulnerable to attacks through an exploit found recently. There is a slight possibility that someone with the knowledge of this exploit can gain remote access to the server
    should be:

    players connecting to HL or HL mod game servers are vulnerable to attacks through an exploit found recently. There is a slight possibility that a anyone who has an rcon password to a server can gain remote access to the players connecting to the server.



    rcon_password "" disables rcon, thus making your server and players connecting to your server completely protected from the exploits.



    server admins are recommended to disable rcon completely until admin_MM.dll, metamod.dll, clanmod_MM.dll, mp.dll and all the other game dlls that can execute code on the player's pcs are checked or patched.


    the exploit requires rcon, and rcon passwords are transmitted via cleartext so it's hypothetically possible that they can be sniffed.



    http://www.seas.rochester.edu:8080/CNG/...ty/node8.html

    Comment

    • ProdigyPuNk

      #17
      Didn't even mention the one packet HLTV DoS ? Didn't link to the advisories ? lame....

      Comment

      • MikeJ

        #18
        Wait so if i delete metamod i don't have to worry about this? No way I can disable rcon on my private server, i have to use it for round restarts and such during scrims. I don't have any of that admin mod bullshit though, just metamod.

        Comment

        • [KBS]@LiX

          #19
          just take amx mod on http://amxmod.net



          got the same function as adminmod stats and more



          ( sorry for my english im french )

          Comment

          • MikeJ

            #20
            Thanks for missing the point

            Comment

            • joe

              #21
              mikej - use admin_rcon :)



              and anything that can execute code is a risk, especially AMX mod which is worked on by 1 person instead of 6 :)

              Comment

              • Gaill.arD

                #22
                stunn0r wrote..

                Andeh you could also stop playing with 11 year olds you know?

                go to proper servers then
                You know a server without 11 year olds!?!?!?! Tell me!

                Comment

                • joe

                  #23
                  by the way here's the text from the bugtraq posting



                  Overview

                  ========

                  Due to a format string in the Half-Life *client*, it is

                  possible for an attacker who has rcon access to a game-

                  server that runs Adminmod, to exploit the machine of

                  a player that is connected to the game server.



                  No, even better, you can exploit ALL clients that play

                  on the server AT ONCE!



                  Note, the attacker needs to know the rcon-password.

                  However, it is easy to sniff since it is being transmitted

                  in plaintext.



                  Affected Versions

                  =================

                  Since there is always the latest version of Half-Life

                  and Counter-Strike required to play online, there is no

                  need to check for other affected versions; the current one

                  is vulnerable.



                  On the server-side, this bug can be exploited using

                  any Adminmod version.



                  Details

                  =======



                  This seems to be a format string bug in the Half-Life-Client,

                  Adminmod has little to do with it. I found it by accident as I

                  blackboxed the admin_ssay and admin_psay commands.

                  Comment

                  • nix

                    #24
                    Edited by [user="8111"] @ [time="1042303390"]

                    GG to let everyone know the rcon issue with HLDS

                    now 75% of the kids reading this will try.....



                    btw: just newbie admins forgets to set rcon_password "" to none

                    Comment

                    • Simplex

                      #25
                      Thanks joe for letting me know it was on BUGTRAQ. I found it. Maybe that wasn't the best idea. Maybe my post is going to get deleted as well...



                      Practically, what this means is that any joe (not that joe) who rents a server from a server farm (who is then given rcon access) can take control of the server computer where there are probably a few more servers running and have his filthy way with them (like a french whore*). Or he can just screw stuff up enough so the server computer would need to be reformatted.



                      -OR-



                      The little guy like me hosts a server on my personal computer and lets a little guy I kinda know (plays CS real well) have admin privileges on my server when I'm out gets his computer trashed because this guy I thought I knew wanted to be an ass.**



                      * My apologies to all the stupid communist bastards*** I offended.

                      ** Story completely fictional.

                      *** My apologies to all the communist bastards**** I've offended.

                      **** My apologies to all the fatherless people out there.

                      Comment

                      • sniv

                        #26
                        Gaill.arD wrote..

                        You know a server without 11 year olds!?!?!?! Tell me!
                        I know one. It our clan server. It's all the time empty, except when three or four of us come on it. And the youngest of us is 15.

                        Comment

                        • ProdigyPuNk

                          #27
                          Edited by [user="1457"] @ [time="1042307505"]

                          joe wrote..

                          by the way here's the text from the bugtraq posting



                          Overview

                          ========

                          Due to a format string in the Half-Life *client*, it is

                          possible for an attacker who has rcon access to a game-

                          server that runs Adminmod, to exploit the machine of

                          a player that is connected to the game server.



                          No, even better, you can exploit ALL clients that play

                          on the server AT ONCE!



                          Note, the attacker needs to know the rcon-password.

                          However, it is easy to sniff since it is being transmitted

                          in plaintext.



                          Affected Versions

                          =================

                          Since there is always the latest version of Half-Life

                          and Counter-Strike required to play online, there is no

                          need to check for other affected versions; the current one

                          is vulnerable.



                          On the server-side, this bug can be exploited using

                          any Adminmod version.



                          Details

                          =======



                          This seems to be a format string bug in the Half-Life-Client,

                          Adminmod has little to do with it. I found it by accident as I

                          blackboxed the admin_ssay and admin_psay commands.
                          Good for someone to post it, anyone who wants it can find it, might as well put it out there for the good ppl. It's called freedom of information



                          Please do not link to the exploit.

                          Comment

                          • Darkhorse

                            #28
                            » rcon_password ""
                            i suggest getting rid of the » csn code bit else you'll get a lot of frustrated nubz wondering why someones still hax0ring all their pr0n

                            Comment

                            • DrMagus

                              #29
                              ProdigyPuNk wrote..

                              Good for someone to post it, anyone who wants it can find it, might as well put it out there for the good ppl. It's called freedom of information



                              Please do not link to the exploit.
                              Personally, what he did was fine. What I DIDN'T want was someone to post the bugtraq link that had the actual exploit code.



                              Oh, and freedom of information doesn't apply here. Sorry.

                              Comment

                              • Ritchey007

                                #30
                                Mr Natural wrote..

                                ..........erm....is it just me or does this not seem like a practical joke. setting your rcon_password to "" means anyone can access it.



                                /me won't be doing it. hax away if u like
                                no that's not a joke at all...

                                Comment

                                Working...