HLDS Exploit Fix

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • naem

    #16
    [PKM]GenocideS1 wrote..

    Hl-Guard 1.50 Sucks Im anti-cheat but jeez... Valve isnt blocking models so why should Hl-Guard be. Please post no news about it. Modeling is hard work. How ANYONE could see using Insomniax swatpack or high quality weapons models as cheating is beyond me.
    Heh. HLG Blocks stuff like the fusion pack now, it's pretty lame.



    I'm gonna be pissed if people turn on model checking for scrims.

    Comment

    • shurcool

      #17
      see? they knew about the exploit for more than a month (or whatever), but didn't really worry about it since it wasn't a top priority. but w/ the exploit released, it took them only a couple of days. so who cares if some servers were down for a few days? if u had a life and went somewhere, u might've not even noticed. geegee. go... whoever found this exploit.

      Comment

      • Steakeater

        #18
        shurcool wrote..

        but w/ the exploit released, it took them only a couple of days. so who cares if some servers were down for a few days? if u had a life and went somewhere, u might've not even noticed. geegee. go... whoever found this exploit.
        I agree with you wholeheartedly. Releasing the exploit to the public really got Valve on the ball on this one.



        I also noticed that people using the exploit knocked out a number of CS servers over the past few days and those servers are not yet back up. I guess a lot of admins don't really maintain (or care about) their servers enough to apply the patch or just haven't noticed their servers went down.

        Comment

        • shurcool

          #19
          Steakeater wrote..

          I agree with you wholeheartedly. Releasing the exploit to the public really got Valve on the ball on this one.
          thanks, i love when ppl agree with me, as opposed to just ignore my posts. :P
          I also noticed that people using the exploit knocked out a number of CS servers over the past few days and those servers are not yet back up. I guess a lot of admins don't really maintain (or care about) their servers enough to apply the patch or just haven't noticed their servers went down.
          that's true. it does take a while until all the servers get updated, but at least now it's not the exploiter's fault, but lazy admin's. damn those bastards. to hell. yeah. ;\

          Comment

          • -:Nighthawk:-

            #20
            Steakeater wrote..

            Releasing the exploit in detail forced Valve to produce a fix - they did it in only 4 days. Thanks Valve!
            shurcool wrote..

            see? they knew about the exploit for more than a month (or whatever), but didn't really worry about it since it wasn't a top priority. but w/ the exploit released, it took them only a couple of days. so who cares if some servers were down for a few days? if u had a life and went somewhere, u might've not even noticed. geegee. go... whoever found this exploit.
            I think you're both totally missing the bigger issue, honestly. Sure, VALVe hadn't released the update yet, but chances are it was already fixed in the beta they were working on. All this did was force them to release a new version that didn't receive the amount of testing it should have gone through before release, thus everyone's servers are now not quite as good as they should be.



            We've got people running bots that are now screwed over by the new update, simply because VALVe likely didn't have the time to check out various bots yet. So yeah, it's not like all this "full disclosure" crap was a good thing. No, instead it forced out an incomplete update and caused a lot of headaches for server admins and players alike for several days.



            Full disclosure is a very stupid thing to do, and was totally irresponsible as it was done in this case. I'm glad VALVe patched it up, but they would have anyway, so it's not like we gained anything. It's disappointing that the dumbasses at Security Focus couldn't have the patience to allow VALVe to take care of the problem silently and effectively when the time was right.

            Comment

            • naem

              #21
              Three months isn't enough time to fix an exploit, NightHawk?



              How much experience do you have in the security scene? Do you even know who Security Focus is?

              Comment

              • Joey2cool

                #22
                naem wrote..

                Three months isn't enough time to fix an exploit, NightHawk?



                How much experience do you have in the security scene? Do you even know who Security Focus is?
                ok heres a brief summary of how the security scene works :



                If someone finds a bug they can release the exploit the same day(blackhats) or they can notify the company(whitehats). Usually the standard wait time for responses is about a month for any response. If the company doesn't respond at all, even whitehats release the code. PivX notified Valve 3.5 months ago and there were no responses.



                If the company does respond they will fix the bug in a day to a couple weeks. If they need more time to find the bug the company notifies the people who found the bug to hold off on full disclosure.



                In the security industry, you must be the first to do full disclosure to claim you found the bug. Both blackhats and whitehats compete for this for clout and possibly consulting contracts. Without this system though, there would be nobody but hackers and software companies themselves looking for these bugs. The half-life exploit that was found cannot be found by any ordinary computer user. You need skills in programming and networking to understand how the bug works.



                I think they gave valve a lot more time then they should have to release a patch. If you think about it, before this patch was made ALL SERVERS could have been hacked. No, not crashed... HACKED! Complete control. It makes you wonder each time a buffer overflow is found, is it really safe to be running software from that company on your computer? Is it the people who found the bug the bad guy or the software company for not patching the bug promptly or for even releasing a product with this sort of problem?

                Comment

                • hitnrun

                  #23
                  ahhh, make sure you have the latest wip, that seems to do the trick.
                  hitnrun wrote..

                  Well, my realbot (linux) core dumps on this ver.

                  Comment

                  Working...