AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   Plugins (https://forums.alliedmods.net/forumdisplay.php?f=108)
-   -   [CSGO] Server Lagger Exploit Security Patch [5/28/2021] (https://forums.alliedmods.net/showthread.php?t=332721)

backwards 05-28-2021 18:08

[CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
3 Attachment(s)
Another denial of service exploit has been released to the public.
This one is being referred to as the "ping raiser" , "high ping" or "ping increaser" exploit.
I'm unsure if it affects all source engine games or just csgo at the moment.

Installation:
Just put the attached `LagExploitFix_5_28_2021.txt` file inside your `csgo\addons\gamedata\` folder and install the `smx` in the `plugins` folder.
Load the plugin manually with `sm_rcon sm plugins load ServerLagExploitFix_5_28_2021` or restart your server for it to auto load.


Warning:

This plugin is written differently then most. It's just raw assembly instruction replacement. This means it can easily break and lead to crashing after server updates.
If you are using this plugin and your server starts crashing, start your debugging efforts by removing this plugin.

NOTE:
Three more server lagger exploits were released today along side this one. This is the most prevalent one though. I'll release more patches if they start to become an issue.

NOTE 2:
This plugin is mostly untested, let me know if you run into any issues while running it.


Updated on 10/22/2022:
A CSGO update broke this plugin and lead to server crashes.
Vauff#2804 from the sourcemod discord has updated it (Not Fully Tested)

Updated on 02/04/2023:
A CSGO update broke this plugin on linux.
Vauff#2804 from the sourcemod discord has updated it (Not Fully Tested)

Download the `ExploitFix_5_28_2021_updated_on_02_04_23_by_ vauff.zip` attachment for the newest verison.

asdfxD 05-29-2021 00:35

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
thx.

possible to log steamid of player who try to lag the server?

freak.exe_uLow 05-29-2021 06:01

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
thanks backwards :3

yuv41 05-29-2021 16:21

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
Thanks backwards :3
----
Apparently this exploit was effective only on Valve servers, and was patched.
So no worries to communities.

backwards 05-29-2021 18:58

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
Quote:

Originally Posted by yuv41 (Post 2748219)
Thanks backwards :3
----
Apparently this exploit was effective only on Valve servers, and was patched.
So no worries to communities.

This is misinformation as the exploit still works. I happen to of built a proof of concept which I actively tested while developing this patch. I can assure you it's not only affecting valve servers and still is unpatched. Multiple exploits were released yesterday, the one that only affected MM servers and was patched is not related to this patch fix.

Quote:

Originally Posted by asdfxD (Post 2748141)
thx.

possible to log steamid of player who try to lag the server?

It's possible to log the steamid for sure, it's just not easy to do it with only sourcemod and no extra extensions.

Fragkiller 05-29-2021 19:20

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
Is CS:S also affected? There was a video around from some days ago where someone was joining CS:S servers and crashed them.

freak.exe_uLow 05-29-2021 21:07

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
Quote:

Originally Posted by yuv41 (Post 2748219)
Thanks backwards :3
----
Apparently this exploit was effective only on Valve servers, and was patched.
So no worries to communities.

think first, then write.....(check the video)
https://forums.alliedmods.net/showthread.php?t=332705

backwards 05-29-2021 21:20

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
Quote:

Originally Posted by Fragkiller (Post 2748234)
Is CS:S also affected? There was a video around from some days ago where someone was joining CS:S servers and crashed them.

I believe it is affected but I haven't tested. This patch only works for csgo though. If it becomes an issue in other games just message me and i'll find time to write a fix.

foxsay 05-30-2021 11:12

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
What we would do without you :) you are our server guard

FroGeX 05-31-2021 07:01

Re: [CSGO] Server Lagger Exploit Security Patch [5/28/2021]
 
please not mix old and new syntax :_D


All times are GMT -4. The time now is 19:01.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.