HLDS Exploit Released

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • CSN NewsBot

    #1

    HLDS Exploit Released

    Security Focus has released a security exploit for HLDS. What this means is someone who knows what they're doing can crash an HL server.



    Fixes have been created and are available for download, however they are unofficial and we at CS-Nation recommend you wait for an official VALVe release unless this bug is a concern to you. You can find links on the Security Focus page about the issue.
  • -:Nighthawk:-

    #2
    Edited by [user="26841"] @ [time="1059511340"]

    Great, let's post "how to crash a server" now.



    Unless I'm totally confused, it seems like a rather dumb thing to link to until server admins have had sufficient time to fix the problem. Don't get me wrong -- I understand the motivation of this guy, that is, prompting VALVe to actually fix the problem instead of waiting around.



    However, this approach of forcing the issue is rather stupid and selfish. Obviously this hadn't been a huge problem before, but by voicing it loudly, it could easily turn into one. Sure, you'd have to be relatively intelligent to use these instructions to actually go around crashing servers. But it's not like a cheating group with intelligent programmers can't take this info and put it all in one nice and easy util for their dumbass lackeys to wreak havok with.
    Practically I avoid that the data sent by the client will be managed by the vulnerable functions if it is longer than 256 bytes.
    Beware that the patch is NOT official, and pretty much just does a hackjob of working around the potential problem. I'm not saying it's not valid, but it's definitely not VALVe's doing, and I'd be pretty pissed if I start seeing servers go down as a result of this guy pushing his agenda.

    Comment

    • FAF

      #3
      Hate to be a party pooper, but surely it can't be all that safe to install a 3rd party patch over a HL server. Not saying that the patch is hax or 'owt, but i'd rather wait for the h'official Valve line on this :)

      Comment

      • naem

        #4
        Valve was notified of this vulnerability on April 14 2003, and replied

        that they were working to patch these bugs.



        Since that last point of contact, Valve and it's representatives have

        been contacted on multiple occasions for a status update on the patch,

        without any replies.
        I'd rather risk running a third-party patch until the official patch is released. The risk of getting your server crashed (it won't restart by itself) outweighs the risk of a 3rd party patch, IMO.



        You know Valve has been sitting on their ass on this for months and is scrambling to get a patch out right now.

        Comment

        • orphy

          #5

          Comment

          • MikeJ

            #6
            it will restart if you use screen ;o

            Comment

            • phrzn

              #7
              Edited by [user="32660"] @ [time="1059511254"]

              cu hlds ;_;



              This bug is not like "RUN THIS EXE AND HIT ENTER TO BE LEET HAXOR AND CRASH TEH SERVUR~~" so I don't think putting it here will do any harm, btw.

              Comment

              • abysmal

                #8
                id leave it. fact of it is servers have been running fine for years without this (well i dont know when the bug was introduced), but im quite happy waiting for the official release to put on my server.

                Comment

                • rsg_6100

                  #9
                  its easy to crash a server its called a DDoS attack, and unfortunatly there is no patch for that.

                  Comment

                  • naem

                    #10
                    Phr0z3n wrote..

                    This bug is not like "RUN THIS EXE AND HIT ENTER TO BE LEET HAXOR AND CRASH TEH SERVUR~~"
                    Actually, it is.

                    Comment

                    • Spedmaster

                      #11
                      To start off, I'm glad that this bug was caught, and I don't mind the publicity of its existence being announced.



                      This has not been a major problem from what I've experienced. You see, the number of preteens who would spend the time and energy to download an .exe whose soul purpose is to crash a Half-Life server for their own personal amusement is significantly less than the number of preteens who are happy enough to wank to pornographic .jpgs .



                      I dunno, maybe other people have had this happen to them. I'm all ears.

                      Comment

                      • Helkite

                        #12
                        Nighthawk... who are you speaking about, Dassbaba or the Security Focus people?

                        Comment

                        • Kuros

                          #13
                          "crash an HL server", not "crash a HL server".

                          Or does it depend on if you actually say the word out instead of just the abbreviation? It's like saying ahm instead of A-W-P I guess.

                          Comment

                          • Steve_81

                            #14
                            You only use "an" if the word after it starts with a vowel.

                            Comment

                            • FAF

                              #15
                              Nope, ALL words beginning with "H" are supposed to have "an" as the indefinite article; ie "an" hotel, "an" historical fact, "an" half life server....



                              /me waits for an english major to prove me wrong ...

                              Comment

                              Working...