HLDS Exploit Released

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • stunn0r

    #46
    tbh i think he should have made the exploiter so that you'd have to mess with the source and compile it to get it to work. this way every gimp like me can download it and go 'have fun' crashing hl-servers fun isnt it!



    but i must say that this might be the only way to get this bug fixed fast..

    Comment

    • Thinge

      #47
      I reccomend using the unoffical patches, the Linux one was stated earlier by a kind guy. The unofficial patches DO work but you might still want to use Valve's patch as it will be a lot neater.

      The topic name "HLDS Exploit Released" couldn't be more truer, you really have released this HLDS Exploit.

      "What this means is someone who knows what they're doing can crash an HL server."

      In this case you mean someone who can download a program and run it.

      The funny thing is though, you made this bug a concern to us because you link to a page with a program that can crash an unpatched server, very clever.

      At least dassbaba has his claim to fame now.

      Comment

      • Joey2cool

        #48
        it will be only a while before someone puts a worse payload into the exploit, making it easy for your computer to also be hacked instead of the server just crashing.

        Comment

        • -:Nighthawk:-

          #49
          -:Nighthawk:- wrote...

          Unless I'm totally confused, it seems like a rather dumb thing to link to until server admins have had sufficient time to fix the problem.
          -:Nighthawk:- wrote...

          Releasing exact information on how to crash servers will result in servers going down, and a lot of people getting screwed over in Security Focus' little agenda to get a stupid buffer overflow check added. The ends, in my opinion, don't justify the means in this case.
          From the first comment, I predicted exactly what the result of this would be. Call me a prophet.



          Either that, or just not completely fucking blind.

          Comment

          • -:Nighthawk:-

            #50
            Pharlap, if I hadn't switched from being an admin to doing SotD reviews only, I'd ban you right now. You're a jerk, you have no right to crash servers that don't belong to you. If you don't like the admins, play somewhere else.



            People like you screw over the CS community at large. Get off your little "woo, I'm a hacker" trip, stop acting as if you're justified, and get the hell out of here. We're not liking your immature crap.

            Comment

            • Joey2cool

              #51
              -:Nighthawk:- wrote..

              Unless I'm totally confused, it seems like a rather dumb thing to link to until server admins have had sufficient time to fix the problem. Don't get me wrong -- I understand the motivation of this guy, that is, prompting VALVe to actually fix the problem instead of waiting around.
              there are 2 ways to release an exploit: the same day, or contacting the software manufacturer first. To be respectable you do the latter, and PivX did that. Valve had 3 1/2 months to fix the problem, which is a LOT of time. This exploit should have been released a month after they first tried to contact valve because they haven't had any response from valve at all. If valve is smart they will release an official patch today.

              Comment

              • ja]2ev

                #52
                After all the time, energy, and money that goes into running and paying for servers (I've had for over the past year) there is NO EXCUSE for maliciously crashing them. If it wasn't for brats like you I would still be running a server.



                Just because someone slapped you or kicked you because you were annoying the hell out of them does not give you any right to vandalize their property.



                If a convenience store clerk gives you little attitude when you go to buy your beef jerky do you throw a brick through their window???

                Comment

                • trb

                  #53
                  This guy was very good to give Valve three months notice before posting an analysis of the vulnerability to Bugtraq. Many groups consider a couple of weeks to be plenty of time (as I do, honestly, for major security holes), and the true jerks don't even notify the vendor first.



                  Notice the advertisement for security consulting at the bottom of the message. Most security researchers hope the time they spend poking through hundreds of thousands of lines of assembly code looking for one tiny slip-up will pay off in consulting work or a job with a security firm. This field is notoriously hard to break into, and posting something like this to Bugtraq is often considered the best, if not only way to do so.



                  Independent security researchers are essential to making our software more secure, and they perform a valuable service that most people (including the vendors, for the most part) aren't willing to. As such, allowing them to write about what they've found after a reasonable period of time is only fair.



                  If you want to whine to anyone about this, whine to Valve. Especially since it's pretty obvious that this guy would have postponed releasing the details of the vulnerability if Valve would have just said, "Hey, we're still working on this. Give us a couple more weeks." Notice he said he has tried contacting them multiple times, with no response. This is irresponsible on their part.



                  As far as CS-Nation linking to the Bugtraq post: Well, Bugtraq is pretty much the largest security mailing list in the world. Its readership far outnumbers CSN's. Most people who fancy themselves hackers, malicious or not, are already subscribed to this list and have already read about this. It's like getting mad at CSN for linking to an article on cnn.com.

                  Comment

                  • ja]2ev

                    #54

                    Comment

                    • Pharlap

                      #55

                      Comment

                      • Joey2cool

                        #56
                        trb wrote..

                        This field is notoriously hard to break into, and posting something like this to Bugtraq is often considered the best, if not only way to do so.
                        yes. and whoever posts the exploits first gets the jobs and notoriety so they HAVE to post it before someone else does.

                        Comment

                        • markman_10

                          #57
                          Whats the name of the Program that is crashing the server??

                          Comment

                          • kureosity

                            #58
                            Joey2cool wrote..

                            Valve had 3 1/2 months to fix the problem, which is a LOT of time. This exploit should have been released a month after they first tried to contact valve because they haven't had any response from valve at all. If valve is smart they will release an official patch today.
                            What bothers me about the approach taken by this "researcher" and others like him is the arrogance they display in presuming to know better than the software manufacturer how and when to fix the defect(s) in question. I believe they are driven by the desire to generate publicity in the hope that it will lead to work for themselves and/or their company. Personally, I would never consider hiring an individual or company that subscribes to this irresponsible philosophy.

                            Comment

                            • Poddster

                              #59
                              hmm, large exploit released, Halflife 2 delayed

                              any wonder?

                              Comment

                              • T|2i|34L

                                #60
                                Poddster wrote..

                                hmm, large exploit released, Halflife 2 delayed

                                any wonder?
                                Yea - really. Although there has been speculation that they are implementing a new CD key system, it was referenced in earlier posts on this thread.

                                Comment

                                Working...