Monthly Target: $400 Donations: $53
 13% 

[NOTICE] 'status' abuse


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
GoD-Tony
Veteran Member
Join Date: Jul 2005
Old 03-23-2012 , 05:45   [NOTICE] 'status' abuse
Reply With Quote #1

In today's update (0.7.7.5) I've added a command for displaying the server's player status (smac_status). It's meant to be a simple alternative to the existing 'status' command.

It's possible for an attacker to temporarily disable the status command on your server, and combined with a unicode-mess for a name can make it very annoying for admins to kick them. If you find this happening on your server, you can do one of the following:
  • Use smac_status in console
  • Use the existing status command from the server console
  • Use rcon or sm_rcon (1.4+) with the existing status command
Then grab their UserID and easily kick/ban them.

It's becoming increasingly more common for this to be abused. Now you're prepared!
__________________

Last edited by GoD-Tony; 03-23-2012 at 07:41.
GoD-Tony is offline
TnTSCS
SourceMod Donor
Join Date: Oct 2010
Location: Undisclosed...
Old 03-23-2012 , 10:48   Re: [NOTICE] 'status' abuse
Reply With Quote #2

Thank you for this command
__________________
View my Plugins | Donate
TnTSCS is offline
GoD-Tony
Veteran Member
Join Date: Jul 2005
Old 04-27-2012 , 14:28   Re: [NOTICE] 'status' abuse
Reply With Quote #3

Today's engine update:
Code:
Source Engine Changes (TF2, DoD:S, HL2:DM)
- Fixed a problem that allowed malicious clients to disable the "ping" and "status" commands for other connected clients
The SMAC command will stay since it still applies to other games.
__________________

Last edited by GoD-Tony; 04-27-2012 at 14:29.
GoD-Tony is offline
MundoAlterno
Junior Member
Join Date: Sep 2011
Old 05-05-2012 , 07:25   Re: [NOTICE] 'status' abuse
Reply With Quote #4

I and been the victim of this attack here are the logs

Code:
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status 
Fri Mar 23 19:45:06 2012: Console<0><Console><Console> executes: status
__________________
MundoAlterno is offline
Send a message via MSN to MundoAlterno Send a message via Skype™ to MundoAlterno
MundoAlterno
Junior Member
Join Date: Sep 2011
Old 06-01-2012 , 20:23   Re: [NOTICE] 'status' abuse
Reply With Quote #5

as of today still attacks through this platform bug tf2


HTML Code:
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status 
Fri Jun  1 20:32:40 2012: Console<0><Console><Console> executes: status
__________________
MundoAlterno is offline
Send a message via MSN to MundoAlterno Send a message via Skype™ to MundoAlterno
adrianman
Senior Member
Join Date: Sep 2010
Old 06-02-2012 , 13:01   Re: [NOTICE] 'status' abuse
Reply With Quote #6

why don't you just block it?
__________________
The best thing in life's for free
adrianman is offline
checkster
Veteran Member
Join Date: Apr 2007
Location: Norway
Old 06-12-2012 , 09:43   Re: [NOTICE] 'status' abuse
Reply With Quote #7

Whould you mind making this command public instead "smac_status" ? As it is useful for all, I know I can go in and edit myself, but then I have to do it each time the plugin updates, and that sounds like a lot of work
checkster is offline
GoD-Tony
Veteran Member
Join Date: Jul 2005
Old 06-12-2012 , 09:47   Re: [NOTICE] 'status' abuse
Reply With Quote #8

Quote:
Originally Posted by checkster View Post
Whould you mind making this command public instead "smac_status" ? As it is useful for all, I know I can go in and edit myself, but then I have to do it each time the plugin updates, and that sounds like a lot of work
http://wiki.alliedmods.net/Overridin..._Configuration

View the example for sm_chat.
__________________
GoD-Tony is offline
checkster
Veteran Member
Join Date: Apr 2007
Location: Norway
Old 06-12-2012 , 12:50   Re: [NOTICE] 'status' abuse
Reply With Quote #9

Quote:
Originally Posted by GoD-Tony View Post
You clearly did not read my part about doing the work

But in all seriousness, not all admins are aware of how to edit/config they're server's, hence I made that suggestion.
I do get your point tho, and I will do it that way on my server.
checkster is offline
TnTSCS
SourceMod Donor
Join Date: Oct 2010
Location: Undisclosed...
Old 06-12-2012 , 14:07   Re: [NOTICE] 'status' abuse
Reply With Quote #10

here... there's not much to "fixing" it the way you want:

Code:
Overrides
{
	"smac_status"	""	//Allow anyone to use "smac_status"
}
__________________
View my Plugins | Donate

Last edited by TnTSCS; 06-12-2012 at 14:07.
TnTSCS is offline
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 13:49.


Powered by vBulletin®
Copyright ©2000 - 2015, vBulletin Solutions, Inc.
Theme made by Freecode