Edited by [user="3037"] @ [time="1042290894"]
the news post is incorrect:
game servers running the popular server administration tool Adminmod are vulnerable to attacks through an exploit found recently. There is a slight possibility that someone with the knowledge of this exploit can gain remote access to the servershould be:
players connecting to HL or HL mod game servers are vulnerable to attacks through an exploit found recently. There is a slight possibility that a anyone who has an rcon password to a server can gain remote access to the players connecting to the server.
rcon_password "" disables rcon, thus making your server and players connecting to your server completely protected from the exploits.
server admins are recommended to disable rcon completely until admin_MM.dll, metamod.dll, clanmod_MM.dll, mp.dll and all the other game dlls that can execute code on the player's pcs are checked or patched.
the exploit requires rcon, and rcon passwords are transmitted via cleartext so it's hypothetically possible that they can be sniffed.
http://www.seas.rochester.edu:8080/CNG/...ty/node8.html
Comment