Raised This Month: $ Target: $400
 0% 

File upload exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 08-21-2009 , 19:28   Re: File upload exploit fix
Reply With Quote #31

No love for CS:S. Damn you Valve!
thetwistedpanda is offline
DaFox
Senior Member
Join Date: Mar 2005
Old 08-21-2009 , 20:16   Re: File upload exploit fix
Reply With Quote #32

Quote:
Originally Posted by thetwistedpanda View Post
No love for CS:S. Damn you Valve!
Or Episode 1 mods.. This is horrible that they are not supporting it even in light of major exploits like this.
__________________
Quote:
Originally Posted by Peoples Army
your from Finland? what country is that in?
DaFox is offline
Kigen
BANNED
Join Date: Feb 2008
Old 08-22-2009 , 17:41   Re: File upload exploit fix
Reply With Quote #33

Well, a more complex temporary work around that I'm doing is using Windows file permissions to lock down the files and places that srcds shouldn't be altering.

Of course the only people who can do this are people who have complete control of their box. (i.e., dedicated hosting)
Kigen is offline
NouveauJoueur
SourceMod Donor
Join Date: May 2009
Old 08-23-2009 , 08:52   Re: File upload exploit fix
Reply With Quote #34

Under linux you can use chmod to protect sensitive files, but some folder need to be able to receive new files, or write already existing files (logs, sqlite, ...) And if you need to change write rights each time you want to add something in server.cfg, admins_simple.cfg, it'll take longer too.
__________________
NouveauJoueur is offline
violentcrimes
Senior Member
Join Date: Nov 2006
Old 08-25-2009 , 15:46   Re: File upload exploit fix
Reply With Quote #35

Anyway to make it to where it will allow sourcebans to write? Maybe add a config for allowed IPs?
__________________

Last edited by violentcrimes; 08-25-2009 at 16:38.
violentcrimes is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 08-25-2009 , 22:19   Re: File upload exploit fix
Reply With Quote #36

http://store.steampowered.com/news/

PHP Code:
Updates to Counter-StrikeSource have been releasedThe updates will be applied automatically when your Steam client is restartedThe specific changes include:

Engine

Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system
Fixed a server crash caused by a client packet claiming to be an HLTV client when HLTV is disabled on the server
Fixed a server crash caused by spoofing a client disconnect message
Fixed a server crash caused by sending malformed reliable subchannel data

Counter
-StrikeSource
Novint Falcon support is now enabled by 
default 
thetwistedpanda is offline
violentcrimes
Senior Member
Join Date: Nov 2006
Old 08-25-2009 , 23:28   Re: File upload exploit fix
Reply With Quote #37

Still not orangebox mod. Also update broke css for linux.
__________________
violentcrimes is offline
DaFox
Senior Member
Join Date: Mar 2005
Old 08-26-2009 , 07:43   Re: File upload exploit fix
Reply With Quote #38

Quote:
Originally Posted by violentcrimes View Post
Still not orangebox mod. Also update broke css for linux.
They updated the engine, it /should/ be fixed for OB mods.
__________________
Quote:
Originally Posted by Peoples Army
your from Finland? what country is that in?
DaFox is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-26-2009 , 09:02   Re: File upload exploit fix
Reply With Quote #39

Quote:
Originally Posted by DaFox View Post
They updated the engine, it /should/ be fixed for OB mods.
They updated the orangebox engine that tf2/dods use. They did not update the old orangebox engine.
psychonic is offline
violentcrimes
Senior Member
Join Date: Nov 2006
Old 08-26-2009 , 13:35   Re: File upload exploit fix
Reply With Quote #40

About 3 weeks ago they separated orangebox and TF2 & DODS.
__________________
violentcrimes is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 01:56.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode