AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   Extensions (https://forums.alliedmods.net/forumdisplay.php?f=134)
-   -   SM RCon (updated 2012-09-09) (https://forums.alliedmods.net/showthread.php?t=168403)

GoD-Tony 03-16-2012 04:02

Re: SM RCon (updated 2012-03-10)
 
Quote:

Originally Posted by psychonic (Post 1666230)
The engine apparently lets banned users use rcon :/

Quote:

Source Engine Changes (TF2, DoD:S, HL2DM)
- Fixed IP bans not applying to RCON access
Well that didn't take long. :)

Visual77 03-16-2012 04:26

Re: SM RCon (updated 2012-03-10)
 
and like every other time, they don't fix these security holes for L4D/2.
why is that? is it because l4d 1 and 2 already has everything that TF2 has or is it just valve being lazy and ignorant like usual?

psychonic 03-16-2012 08:18

Re: SM RCon (updated 2012-03-10)
 
Quote:

Originally Posted by GoD-Tony (Post 1669785)
Well that didn't take long. :)

The same fix will also be in the next Nuclear Dawn update as well.

This will leave L4D2 and CS:S as the only games this supports that requires this just for that fix (though the other functionality is still useful for plugins ofc). CS:S will also get the fix next time they sync in the engine changes.

Quote:

Originally Posted by Visual77 (Post 1669791)
and like every other time, they don't fix these security holes for L4D/2.
why is that? is it because l4d 1 and 2 already has everything that TF2 has or is it just valve being lazy and ignorant like usual?

I can add L4D1 support for this later today if its wanted.

Visual77 03-16-2012 09:28

Re: SM RCon (updated 2012-03-10)
 
that's up to you. i don't play it anymore.

Powerlord 03-16-2012 13:45

Re: SM RCon (updated 2012-03-10)
 
Quote:

Originally Posted by Visual77 (Post 1669791)
and like every other time, they don't fix these security holes for L4D/2.
why is that? is it because l4d 1 and 2 already has everything that TF2 has or is it just valve being lazy and ignorant like usual?

Doesn't Valve still update L4D2 every (other?) Friday? Unfortunately, since they don't post about those changes to the server lists, you have to check the Steam News to know what changed.

Visual77 03-16-2012 13:53

Re: SM RCon (updated 2012-03-10)
 
more like every third week now and no, they don't seem to patch srcds vurnabilites on l4d2. the only thing valve has been doing lately is updating their mutations and it sucks big time.
they did fix some bugs for certain maps last month but that's it. tf2/cs:s has been having a lot of server vurnability related patches and why they haven't been pushed into l4d1/2 is something I don't understand.

tonight's update, if there will be one, will most likely be another mutation update and nothing else. if there is no update tonight, then it's been a month since the last decent update which was in february.

edit: the update contained some map bug fixing and a mutation change like usual. and like usual, they didn't patch any server vurnabilites like the rcon one that was just discovred. very dissapointed again.

jake84 04-16-2012 12:06

Re: SM RCon (updated 2012-03-10)
 
with this extension loaded, im not able to get server logs through HLSW with rcon.
l4d2 game. as soon as I unload it, i can get live server logs from HLSW again.

Edit: will you fix it? i consider this extension useless with the metioned bug. otherwise it can be a really handy one.

jake84 04-27-2012 10:02

Re: SM RCon (updated 2012-03-10)
 
no comment about not being able to get logs through HLSW?

one more question. if i'd put rcon_password "" in my server.cfg and then define a rcon password inside public Action:SMRCon_OnAuth, which I got to work
with HLSW (except for the logging issue I just metioned), would this still block attackers from attacking my servers tcp rcon port?

psychonic 04-28-2012 14:05

Re: SM RCon (updated 2012-03-10)
 
Quote:

Originally Posted by jake84 (Post 1697405)
no comment about not being able to get logs through HLSW?

No comment as I haven't had time yet to verify it and/or look into it further.

Quote:

Originally Posted by jake84 (Post 1697405)
one more question. if i'd put rcon_password "" in my server.cfg and then define a rcon password inside public Action:SMRCon_OnAuth, which I got to work
with HLSW (except for the logging issue I just metioned), would this still block attackers from attacking my servers tcp rcon port?

If the rcon socket listens when no rcon_password is set (which I don't believe to be the case), then yes, rejecting the password in the OnAuth forward would have the same effect as the server rejecting it for not matching the rcon_password. (respecting the max retries cvars, etc.)

psychonic 04-28-2012 15:25

Re: SM RCon (updated 2012-03-10)
 
Quote:

Originally Posted by jake84 (Post 1690491)
with this extension loaded, im not able to get server logs through HLSW with rcon.
l4d2 game. as soon as I unload it, i can get live server logs from HLSW again.

I've identified the issue causing remote logging to not function in most cases with version 1.2.0. I'll have a fixed 1.2.1 posted in a bit.


All times are GMT -4. The time now is 20:03.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.