Raised This Month: $12 Target: $400
 3% 

[IMPORTANT] A new HLDS engine exploit !!!


Post New Thread Reply   
 
Thread Tools Display Modes
guven5
Senior Member
Join Date: Jul 2010
Location: counter strike 1.6 downl
Old 08-09-2012 , 17:47   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #61

Server cvar "max_queries_sec" = "***PROTECTED***"
Server cvar "max_queries_window" = "***PROTECTED***"


you cvar commands may be can reduce replay but what is that "PROTECTED"


also how to disable "FF FF FF FF" with iptables

Quote:
Originally Posted by asherkin View Post
If your server is updated and you aren't using dproto, the issue is already solved.
i have steam servers... also upto date, but still probem... smaller yes but somethings also depend attack parameters....
__________________

Last edited by guven5; 08-09-2012 at 17:52.
guven5 is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 08-09-2012 , 17:49   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #62

Update your server and you will not have to worry about this exploit.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
FiFiX
Senior Member
Join Date: May 2008
Location: Poland
Old 08-09-2012 , 18:47   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #63

Stable or beta?
FiFiX is offline
Send a message via Skype™ to FiFiX
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 08-09-2012 , 18:52  
Reply With Quote #64

Quote:
Originally Posted by FiFiX View Post
Stable or beta?
Stable, but it was an optional update.

Also, for people that still don't understand this, you can't do anything as the target of an attack - the fixes are for people who's servers are being used to source them.
__________________
asherkin is offline
Zephyrus
Cool Pig B)
Join Date: Jun 2010
Location: Hungary
Old 08-09-2012 , 18:58   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #65

limiting number of max queries isnt a good protection either as the attacker can simply delist your server by exceeding that number
__________________
Taking private C++/PHP/SourcePawn requests, PM me.
Zephyrus is offline
FiFiX
Senior Member
Join Date: May 2008
Location: Poland
Old 08-10-2012 , 01:18   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #66

Quote:
Originally Posted by asherkin View Post
Stable, but it was an optional update.

Also, for people that still don't understand this, you can't do anything as the target of an attack - the fixes are for people who's servers are being used to source them.
And how to do that 'optional' update? Just -autoupdate?

Also, how can I now, which version of stable and which of beta is the newest? And is there any changelog for hlds?(linux)
FiFiX is offline
Send a message via Skype™ to FiFiX
Powerlord
AlliedModders Donor
Join Date: Jun 2008
Location: Seduce Me!
Old 08-10-2012 , 15:31   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #67

Quote:
Originally Posted by FiFiX View Post
And how to do that 'optional' update? Just -autoupdate?
Manually run hldsupdatetool (or ./steam on Linux) with the usual arguments (-command update -game cstrike -dir whatever)

Note: I used cstrike as an example, but cstrike likely needs the -hlbeta argument...

Quote:
Originally Posted by FiFiX View Post
Also, how can I now, which version of stable and which of beta is the newest? And is there any changelog for hlds?(linux)
cstrike is the only game with an hlbeta currently going on. For all other games, use stable... it's newer.
__________________
Not currently working on SourceMod plugin development.

Last edited by Powerlord; 08-10-2012 at 15:33.
Powerlord is offline
FiFiX
Senior Member
Join Date: May 2008
Location: Poland
Old 08-11-2012 , 01:10   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #68

Quote:
Originally Posted by Powerlord View Post
cstrike is the only game with an hlbeta currently going on. For all other games, use stable... it's newer.
Is it going to change someday?
Thats better for me to use beta or stable for cstrike?
FiFiX is offline
Send a message via Skype™ to FiFiX
mabaclu
Senior Member
Join Date: Jun 2010
Location: Portugal
Old 08-11-2012 , 15:49   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #69

Use beta, otherwise people may crash your server.
__________________
mabaclu is offline
farenheitcx
New Member
Join Date: Aug 2012
Old 08-11-2012 , 22:29   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #70

I check with

Code:
./steam -command update -game cstrike -dir . -beta hlbeta
But nothing happend, the message i received is "HLDS installation up to date"
Now I have the version "5758" for hlds server. Is that the latest version with the fix for this kind of attack?.
farenheitcx is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:22.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode