AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   News (https://forums.alliedmods.net/forumdisplay.php?f=16)
-   -   Security Exploit in UAIO Binary (https://forums.alliedmods.net/showthread.php?t=66326)

DSi 01-30-2008 17:03

Re: Security Exploit in UAIO Binary
 
BAD: You have an exploited copy of UAIO. Download new copies of all UAIO .amxx files. You should post in the forum news thread that you encountered this incident.

I got this message :( I posted here because it told me to :wink:

>)SL(< | Wicked 01-30-2008 19:10

Re: Security Exploit in UAIO Binary
 
Hey DSi!!! Its Robert.

Well, I can't really believe someone would do this! Good job guys for finding this! Its also a good thing I took UAIO off my server.

Dric Laar 01-31-2008 23:05

Re: Security Exploit in UAIO Binary
 
Well this actually explains ALOT.
I got my server hacked before...had UAIO on it too...I didn't keep it though...

But seriously....THANKS ALOT lol :mrgreen:

kuttaja 02-01-2008 04:53

Re: Security Exploit in UAIO Binary
 
What about his other plugins?

Xanimos 02-01-2008 13:50

Re: Security Exploit in UAIO Binary
 
Quote:

Originally Posted by kuttaja (Post 580429)
What about his other plugins?

His other plugins are clean. The only reason he was able to do it in UAIO was by pre-compiling the plugin with the exploit. And since none of his other plugins are pre-compiled, meaning only the .sma is uploaded, they are perfectly fine.

This report isn't meant to bash UAIO, it in its self is a good plugin and has no exploit. Just that the creator went a little far when he scripted a secret back door.

Jheshka 02-01-2008 19:18

Re: Security Exploit in UAIO Binary
 
Wow, didn't see this coming...

chris 02-01-2008 22:09

Re: Security Exploit in UAIO Binary
 
Oh I see, he put a differnent AMXX file than the sma's AMXX file. :gyar:

Firecracker 02-02-2008 13:56

Re: Security Exploit in UAIO Binary
 
What steps should we take besides replacing our UAIO. I will say I had someone appear to change maps on my server and I know I am the only admin. When I looked at my logs there was nothing about the map change till time ran out and all of a sudden something besides the only map on my rotation was there.

BAILOPAN 02-02-2008 13:59

Re: Security Exploit in UAIO Binary
 
Make sure your users.ini (or SQL tables, if applicable) only contains entries you know about.

vittu 02-02-2008 14:30

Re: Security Exploit in UAIO Binary
 
Also, if there is no amxmodx log about the map change it sounds like they had your rcon password. Could check hl logs to see if anyone else was on rcon at the time or just change your rcon password to be safe either way.


All times are GMT -4. The time now is 18:58.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.