HLDS Exploits II

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • cheetarah654

    #16
    -Gpig wrote..

    I'm not going to play CS till this blows over.
    dont i see a gpig on irc with -scrim after his name right now? :P



    anyways, id ont understand why people are obsessed with finding ways to exploit things. so childish

    Comment

    • Exo

      #17
      It's unclear what exactly this is. Is this admins doing the exploiting, or clients? I was under the impression some random whacko could hack me, not admins. I'm not going to change the rcon password when I'm the only one who has it.

      Comment

      • bkrose120

        #18
        cheetarah654 wrote..

        dont i see a gpig on irc with -scrim after his name right now? :P



        anyways, id ont understand why people are obsessed with finding ways to exploit things. so childish
        'his' name? But I thought by saying HOT ASIAN GUYS gpig would be a girl... otherwise 'he' is gay!

        Comment

        • ProdigyPuNk

          #19
          cHic0! wrote..

          Wouldn't it have been much better if the guy's who found these bugs just e-mailed all the detailed stuff to valve and told everyone else to uninstall adminmod and such? Now a whole bunch of people know how to use these exploits.
          The "details" are already out, along with demonstration code...

          Comment

          • bkrose120

            #20
            Exo wrote..

            It's unclear what exactly this is. Is this admins doing the exploiting, or clients? I was under the impression some random whacko could hack me, not admins. I'm not going to change the rcon password when I'm the only one who has it.
            What their saying is that when admins type in their rcon password a CLIENT can see the text file or log or something w/ your name and password and then use it to login i think. But they also seem to be saying the client can do more than use admin commands, but can fuck up your server (and ANYONE'S COMPUTER WHO'S PLAYING ON THE SERVER) as well.

            Comment

            • ProdigyPuNk

              #21
              cheetarah654 wrote..

              dont i see a gpig on irc with -scrim after his name right now? :P



              anyways, id ont understand why people are obsessed with finding ways to exploit things. so childish
              If people didn't find exploits, software would be much, much less secure. Your opinion is one of the stupidest things I've heard in a while ;P

              Comment

              • Disk2

                #22
                Exo wrote..

                It's unclear what exactly this is. Is this admins doing the exploiting, or clients? I was under the impression some random whacko could hack me, not admins. I'm not going to change the rcon password when I'm the only one who has it.
                The thing is, it could be either. If someone knows (or sniffs, guesses, or steals it some other way) they can use the exploits to gain control of the server, the clients (all of them), or both. Perhaps the scariest thing is that any admin can start up a server on his PC, have someone connect, exploit the bugs in Half-Life's code, and take control of the unsuspecting player.



                The nature of the attacks is this:



                Attack #1: the person with rcon can send excessively long, malformed data to the server, which will cause the server to allow the person with rcon to have root (super-user) access on the server computer.



                Attack #2: the person with rcon can send excessively long, malformed data to the server, which will send it to the clients, which will allow the rcon user to execute commands on the clients' machines.



                We're not just talking Half-Life commands. We're talking "deltree /Y c:\".



                Outside attacks are not what worry me -- asshole admins with rcon passwords scare me. As for what you said, ProdigyPuNk, you're right. Without people exposing these really n00bish bugs in Half-Life's code VALVe would never fix it and it would get even worse as time went on. Releasing the information like this will, if nothing else, embarrass VALVe enough to do something.

                Comment

                • cHic0!

                  #23
                  Edited by [user="29272"] @ [time="1042348953"]

                  ProdigyPuNk wrote..

                  The "details" are already out, along with demonstration code...
                  I know, I meant instead of posting that code on bugtraq or whatever, they should have just informed valve and kept quiet.
                  Disk2 wrote..

                  Releasing the information like this will, if nothing else, embarrass VALVe enough to do something.
                  But it also further endangers HL servers and clients by showing hundreds of people how to use the exploit.



                  This is somewhat like figuring out how to get past VAC, make a "demonstration cheat" and posting it for all the world to see. Sure, VAC will be updated to fix it, but there will probably be rampant cheating on CS servers for a few days. Only instead of cheating, peoples computers get screwed.



                  That was a bad metaphor, and I really don't know what I'm talking about, so I'll shutup now.

                  Comment

                  • Delta|Cpt.Terran

                    #24
                    i am confused, what is so bad about this bug. i don't understand. someone please clear this up for my simple mind...D:>

                    Comment

                    • Spartibus

                      #25
                      If your game locks up, turn off your computer quickly.
                      okay honestly, that scared me shitless. i cant believe i have to worry about getting hacked while playing cs

                      Comment

                      • `loki

                        #26
                        lol, that's pretty freaky.

                        Comment

                        • icer-

                          #27
                          terran wrote..

                          i am confused, what is so bad about this bug. i don't understand. someone please clear this up for my simple mind...D:>
                          this bug will allow admins (if they're going to be stupid enough) to control your computer. by controling your computer, they can do anything you can on your computer. this could include reformatting your computer. :O

                          Comment

                          • Pharlap

                            #28
                            Disk2 wrote..

                            We're not just talking Half-Life commands. We're talking "deltree /Y c:\".
                            hardly anyone has MS-DOS on their computers nowadays...so deltree is a bad example isnt it....

                            Comment

                            • Disk2

                              #29
                              terran wrote..

                              i am confused, what is so bad about this bug. i don't understand. someone please clear this up for my simple mind...D:>
                              As I said in my previous reply, what's bad about this bug is that people can execute commands on your computer. They can delete files, change files, etc. using these exploits.

                              Comment

                              • dRage

                                #30
                                Tech N9ne wrote..

                                okay honestly, that scared me shitless. i cant believe i have to worry about getting hacked while playing cs

                                Comment

                                Working...