HLDS Exploit

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • CSN NewsBot

    #1

    HLDS Exploit

    There has been talk on the HLDS (Half-Life Dedicated Server) mailing lists that game servers running the popular server administration tool Adminmod are vulnerable to attacks through an exploit found recently. There is a slight possibility that someone with the knowledge of this exploit can gain remote access to the server. The current suggestion to fix the exploit is to disable the rcon password. Just change the line to look like the following:



    » rcon_password ""



    There are other reports that server side addons such as ClanMod and StatsMe are also vulnerable to the exploit. Please don't ask how use this exploit, because neither I nor anyone else will tell you. Please also refrain from posting any link with the exploit in the comments.



    I have spoken to people who work closely with these programs and they assure me all necessary steps are being taken to resolve these issues. AdminMod currently is working on a beta dll to fix this issue, but has yet to release it for public use.



    Thanks to everyone who submitted this, and thanks to Ritchey007 for helping out on this post (most of this was his you know).
  • CSN NewsBot

    #2
    HLDS Exploit

    If you haven't been attune to the HLDS mailing list, you've missed out on a lovely little bug. Sv_allowdownload is great for allowing custom maps, wads, and sounds to transfer to the client upon connection. Too bad you can download everything else in the cstrike directory including configs, passwords, and maps(which will crash the server). VALVe knows about the problem and is working on a fix.
    I have verified this problem.



    For now put:

    sv_allowdownload 0



    In your server.cfg file to disallow downloading of content from the server. If you have custom maps this will stop people being able to get them.



    We are working on a fix now, it should be out in a couple of days.
    I bet the exploit is gone by the end of the week. Until then, add/change sv_allowdownload 0 in the server.cfg.

    Comment

    • Ritchey007

      #3
      We make a great team DrMagus

      Comment

      • DrMagus

        #4
        Ritchey007 wrote..

        We make a great team DrMagus
        /me high fives Ritchey007

        Comment

        • CabalSoljea

          #5
          woot!



          gd one!!!

          Comment

          • FReNZY_KiLL@

            #6
            :o hmm

            /me wonders how it is done :P

            Comment

            • Brutus

              #7
              Wouldn't setting allow_client_exec 0 make it so they couldn't exec commands on a clients machine?

              Comment

              • kris

                #8
                Remember folks - this exploit only works if you have rcon access to the server. And if you did have rcon access, you could enable allow_client_exec anyway :)

                Comment

                • philmcneal

                  #9
                  Hope they fix it soon

                  /me hacks rizzuh's HLDS

                  Comment

                  • mouth

                    #10
                    This news item was worth it just to see those 2 jackasses patting themselves on the back for managing to get a single relevant newpost up.

                    Comment

                    • Andeh

                      #11
                      bah Adminmod gives those 11 year old admins too much power for thier own good. you shouldn't get kicked for getting three kills in a row. The sooner adminmod discontinues, the better......

                      Comment

                      • stunn0r

                        #12
                        Andeh you could also stop playing with 11 year olds you know?

                        go to proper servers then

                        Comment

                        • mouth

                          #13
                          Last time i checked, you didn't need AdminMod to be a cunt who kicks people for shady reasons. Of all the garbage problems that can be attributed to AdminMod, that isn't one of them.

                          Comment

                          • Mr Natural

                            #14
                            ..........erm....is it just me or does this not seem like a practical joke. setting your rcon_password to "" means anyone can access it.



                            /me won't be doing it. hax away if u like

                            Comment

                            • RavenousBugblatterBe

                              #15
                              FYI, There are two variants of this vulerability - one allows an attack on the server, one allows an attack on the clients. Both allow the attacker to run arbitrary code on the target machine. I've seen sample exploits for both Adminmod & Clanmod, but other metamod plugins may be vulnerable as the actual problem was in an HLSDK function. Disabling rcon is the best workaround until all metamod plugins have been checked.

                              Comment

                              Working...