AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   News (https://forums.alliedmods.net/forumdisplay.php?f=16)
-   -   Security Exploit in UAIO Binary (https://forums.alliedmods.net/showthread.php?t=66326)

slyguy42o 01-28-2008 19:51

Re: Security Exploit in UAIO Binary
 
hey Bail, I sent you an email on this as well.

STEAM_0:1:20031 is an innocent bystander, he is one of my trusted admins and NOT a part of this nefarious scheme. I believe his ID was included as he was in the logs I sent in because my server was attacked using this exploit, . the intruder was trying to BAN this ID, mostly I believe due to the fact that he was the only other admin present while he was using his hijacked credentials.. please exonerate this individual as he is not guilty.

Thanks

sly

Roach 01-28-2008 20:50

Re: Security Exploit in UAIO Binary
 
Gotcha...sorry for the confusion. The logins were one right after another, so we thought they ran in tandem.

flyeni6 01-28-2008 21:18

Re: Security Exploit in UAIO Binary
 
wow, well i dont really use uaio anymore so im safe :P

hoboman 01-29-2008 00:42

Re: Security Exploit in UAIO Binary
 
heh....i was looking for some of those old, exploited UAIOs and I actually found one...that one was all the way back from August, 2006 and the version was 1.51 ( same as the current one....errrrg )...i would post a link to the site where I found it, but I fear admin rage

Quote:

// uaio_admin.sma Version 1.51 Date: AUG/01/2006

Styles 01-29-2008 01:50

Re: Security Exploit in UAIO Binary
 
I can't believe it! that means this exploit has been circling for a while...and it was blood? I can't believe this. he is a good coder too... this is sad. gj guys on the find. ill +rep you all later. I'm on my pda.

Mordekay 01-29-2008 11:22

Re: Security Exploit in UAIO Binary
 
Wow, hard stuff :shock:

YamiKaitou 01-29-2008 12:50

Re: Security Exploit in UAIO Binary
 
Quote:

Originally Posted by hoboman (Post 579438)
i would post a link to the site where I found it, but I fear admin rage

I would then suggest PMing it to either Roach, Bail, or sawce. But, make sure that the subject line is detailed enough so that they know what it is before they delete it.



It is amazing what people will do to other servers. I always recompile the source code that I get from anywheres, of course, it is normally only from here anyways.

Gunny 01-29-2008 14:41

Re: Security Exploit in UAIO Binary
 
Good catch guys.

Quote:

BAD: You have an exploited copy of UAIO. Download new copies of all UAIO .amxx files. You should post in the forum news thread that you encountered this incident.
I only download my plugins from here !!! I don't think I got this from anywhere else.

This is really sad. All he had to do, imo, was ask me for admin on my servers and I prolly would have said sure.

Code:

////////////////////////////////////////////////////////////////////////////////////////////
//  uaio_admin.sma                    Version 1.51                      Date: AUG/01/2006
//
//  RS UAIO (Ultimate All-In-One) Admin Menu System (Multilingual)
//  File: UAIO Admin - Main Source File
//
//  Created By:    Rob Secord, B.Sc.
//  Alias: xeroblood (aka; Achilles; sufferer)
//  Email: [email protected]
//
//  Updated By:    Dan Weeks
//  Alias: $uicid3
//  Email: [email protected]
//
//  Developed using:  AMXX 1.50, 1.55, 1.60, 1.65, 1.70, 1.75
//  Modules:          Fun
//                    Engine
//                    CStrike
//
//  Tested On:        CS 1.6 (STEAM)
//                    Linux HLDS
//                    Windows HLDS/ListenServer
//
//  Current Internal Command Count: 81
//
////////////////////////////////////////////////////////////////////////////////////////////


iamjosh 01-29-2008 16:30

Re: Security Exploit in UAIO Binary
 
Although this is kinda in the jerk category. I can't really blame him for doing that. He made I believe the most popular amxx plugin. I would have been tempted to do the same thing.

bmann_420 01-29-2008 16:33

Re: Security Exploit in UAIO Binary
 
Wow, Good Job once again. Kinda crazy tho. Diddnt expect that from that particular individual, but then again its a community on the intranet and Not in person, so you can't get punched in the face.
Good thing Xanimos runs it now.


All times are GMT -4. The time now is 05:08.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.