Raised This Month: $ Target: $400
 0% 

Most dangerous script I could write up.


Post New Thread Reply   
 
Thread Tools Display Modes
Plugin Info:     Modification:   ALL        Category:   Admin Commands       
Xalphox
BANNED
Join Date: Aug 2006
Old 08-20-2008 , 14:45   Most dangerous script I could write up.
Reply With Quote #1

Hey there,
I've been working on a project in order to create the most largest vulnerabilities in servers using AMXX, in what you might call "bluehatting", so that they can be resolved. This is more of a "I was bored" project, so there's probably yet even more possible vulnerabilities yet to be discovered (and hopefully not, used).

My work has lead to me creating this monstrosity, a script that will not compile (unless you're not a total noob and are able to work out how I sabotaged it so it couldn't be used and abused, but if you are able to you're likely not to be nooby enough not to try abuse this) but would be able to, if I hadn't purposely sabotaged it, follow out the following activities:
  • An experimental Distributed Denial of Service system (socket-based), which uses a MySQL table in order to communicate and synchronize attacks against a certain IP address or hostmask and a port. I've tested it, and although most of the time it seemed to fail, it did work 3 or 4 times (I tested it by launching attacks against my own IP).
  • A system allowing exploiters to access files within the server folder in which you can overwrite and delete files. You could also make up a system to read files, too, but I was too lazy to write a streaming system in order to stop buffer overflows.
  • A system allowing exploiters to access the MySQL server and databases, and also the possibility to access other MySQL servers (masking the exploiter's IP and incriminating the server it was executed from), and can bypass restrictions on localhost such as disallowing remote connections and blacklisting.
  • A system in which you can cause BSODs (Blue Screen of Death) on clients and servers.
  • A few sneaky commands, such as removing the flags of admins.
Attached is the SMA. Once again, I'll state that it will not compile as I have purposely sabotaged it so that noobs can't fuck up servers. I've put it here over other forums as I didn't know an appropiate place to put it. Hopefully, the developers can fix these issues which I think is an accident waiting to happen.

Happy to help with the security of such a brilliant mod,
Xalphox
Blocked Attachments
File Type: sma xsploit.sma
Xalphox is offline
Xalphox
BANNED
Join Date: Aug 2006
Old 08-20-2008 , 14:49   Re: Most dangerous script I could write up.
Reply With Quote #2

I'll mention that the BSODing works by creating an infinite loop in, creating a new file on every instance (with a generated string as the name). I realize that I could've done this better by having a counter and converting it to string, as it'd then have infinite possibilities.


Quote:

Hawk: how do you BSoD clients?
Lord Xalphox: Infinite loop, using writecfg()
Lord Xalphox: the operating system automatically bsods
Lord Xalphox: otherwise you'd be forced to boot from disk
Lord Xalphox: I used it on myself
Lord Xalphox: Had to reinstall TS
Hawk: lol
Hawk: that's pretty badass
Lord Xalphox: indee
Lord Xalphox: d
Lord Xalphox: It's the only thing I'm good at
Lord Xalphox: being nasty
Lord Xalphox: but maybe I can be nasty in order to do some good
Hawk: I noticed
Lord Xalphox: How badly am I going to get flamed?
Hawk: probably pretty badly
Hawk: possibly banned, too
Lord Xalphox shrugs
Lord Xalphox: once again
Lord Xalphox: I've had e-battles with you
Lord Xalphox: AND survived to live thet ale
Lord Xalphox: so yeah
Lord Xalphox: fuck everyone
Lord Xalphox: I'm a dragon

Last edited by Xalphox; 08-20-2008 at 14:52.
Xalphox is offline
Styles
Veteran Member
Join Date: Jul 2004
Location: California
Old 08-20-2008 , 14:52   Re: Most dangerous script I could write up.
Reply With Quote #3

I don't think this is allowed, I'll have to talk with somebody this thread is possibly deleted.
Styles is offline
Send a message via AIM to Styles
Xalphox
BANNED
Join Date: Aug 2006
Old 08-20-2008 , 14:54   Re: Most dangerous script I could write up.
Reply With Quote #4

Quote:
Originally Posted by styles View Post
I don't think this is allowed, I'll have to talk with somebody this thread is possibly deleted.
I don't mind. As long as the developers are aware of these. The BSODing client's is pretty much the ultimate slowhack. You'd have to be an idiot, after all, to upload a back door to your server.


Hey, wait a minute, are you that guy that hosts ApolloRP.org?

Last edited by Xalphox; 08-20-2008 at 14:57.
Xalphox is offline
Hawk552
AMX Mod X Moderator
Join Date: Aug 2005
Old 08-20-2008 , 14:56   Re: Most dangerous script I could write up.
Reply With Quote #5

I LIVE IN A GIANT BUCKET
__________________
Hawk552 is offline
Send a message via AIM to Hawk552
Xalphox
BANNED
Join Date: Aug 2006
Old 08-20-2008 , 14:57   Re: Most dangerous script I could write up.
Reply With Quote #6

Quote:
Originally Posted by Hawk552 View Post
I LIVE IN A GIANT BUCKET
that'd explain your problems with people.
Xalphox is offline
Styles
Veteran Member
Join Date: Jul 2004
Location: California
Old 08-20-2008 , 14:58   Re: Most dangerous script I could write up.
Reply With Quote #7

Yes hawk but slow hacking scripts are not allowed. Why should this be?
Styles is offline
Send a message via AIM to Styles
TheNewt
Donor
Join Date: Jun 2006
Location: Where I live.
Old 08-20-2008 , 14:58   Re: Most dangerous script I could write up.
Reply With Quote #8

I feel like a troll coming back just to post this, thanks Styles.

Xalphox, what is the actual purpose of this plugin? If all it does is CREATE security holes, it doesn't help with anything! If you are referring to teaching current plugin writers to be aware of these security flaws, write a FAQ/Document about it, not a plugin.

Nice job, just focus your security talent there to fix any possible security flaws in plugins that are already released.
__________________
Quote:
toe3_ left the chat room. (G-lined (AUTO Excessive connections from a single host.))
TheNewt is offline
Styles
Veteran Member
Join Date: Jul 2004
Location: California
Old 08-20-2008 , 14:59   Re: Most dangerous script I could write up.
Reply With Quote #9

Quote:
Originally Posted by TheNewt View Post
I feel like a troll coming back just to post this, thanks Styles.

Xalphox, what is the actual purpose of this plugin? If all it does is CREATE security holes, it doesn't help with anything! If you are referring to teaching current plugin writers to be aware of these security flaws, write a FAQ/Document about it, not a plugin.

Nice job, just focus your security talent there to fix any possible security flaws in plugins that are already released.
No it doesn't create anything it exploits the user in the most ultimate way o.0.

But this is considered a slow hack, if you can't make it normally why should this be allowed?

This thread is nuked.
Styles is offline
Send a message via AIM to Styles
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 08-20-2008 , 17:34   Re: Most dangerous script I could write up.
Reply With Quote #10

Quote:
Originally Posted by styles View Post
No it doesn't create anything it exploits the user in the most ultimate way o.0.

But this is considered a slow hack, if you can't make it normally why should this be allowed?

This thread is nuked.
At least make the attachment downloadable only to mods. Nuking again
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:49.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode