HLDS Exploit

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • mouth

    #46
    DrMagus wrote..

    If Bugtraq wants to post it, it's their right and OBLIGATION to post it to let people know. We just have to let you know that it's out there.
    You also have to let us know that what your saying isn't bullshit by linking to a source, sport. If you're going to act like a bundle of nerves about being a newsposter, you might as well do it right.

    Comment

    • d.a.| raw

      #47
      Many exploits exist in adminmod. My fav in the log exploit. You can gain adminmod passwords, rcon passes anything mearly from looking closely at a file.



      Thats all i will say, people who know about it can have the priviledge of smiling.

      Comment

      • BoNeLeSS

        #48
        do'h
        We are working on a fix now, it should be out in a couple of days.
        Yeah... true...

        Comment

        • raging dragon

          #49
          lol crash a server... hmmm

          Comment

          • Steakeater

            #50
            Also in that e-mail from Valve's Alfred Reynolds:
            It would have been nice if the author of this report had contacted us (at all..) so he didn't expose everyone to this problem.
            Security through obscurity doesn't work. I think it's great that someone posted all the details to this exploit so that admins can protect themselves before Valve produces a fix. And we all know that full disclosure of such an exploit is about the only thing that gets companies motivated to fix their software.

            Comment

            • naem

              #51
              Steakeater wrote..

              Security through obscurity doesn't work. I think it's great that someone posted all the details to this exploit so that admins can protect themselves before Valve produces a fix. And we all know that full disclosure of such an exploit is about the only thing that gets companies motivated to fix their software.
              Generally, respectable people will notify the vendor at least a couple weeks before they publicly disclose the exploit.

              Comment

              • Steakeater

                #52
                naem wrote..

                Generally, respectable people will notify the vendor at least a couple weeks before they publicly disclose the exploit.
                I agree that it's polite to notify the vendor, but I recall that on the last major HLDS exploit (where you could overflow a buffer and freeze and/or crash a server) they were notified and didn't produce a patch until someone did a full disclosure (wasn't it like 4-6 months later?) which included that "crashserver.exe." Only then did Valve make an effort to produce a patch.



                The individual who found this exploit probably didn't tell Valve first simply because exposing the details gets a patch out quicker.

                Comment

                • Buddah

                  #53
                  naem wrote..

                  Generally, respectable people will notify the vendor at least a couple weeks before they publicly disclose the exploit.
                  You mean there are respectable people play CS. Where? :P

                  Comment

                  • Mikemike 2.0

                    #54
                    lol posted at 3:55 am west coast time lol

                    Comment

                    • stooopid

                      #55
                      Man, I remember the days of OGC they didn't have to write a script to grab people's passwords. There was a builtin sniff that just ran and told you everything. So many angry admins...



                      -stooop

                      Comment

                      Working...