Raised This Month: $ Target: $400
 0% 

Security Exploit in UAIO Binary


Post New Thread Closed Thread   
 
Thread Tools Display Modes
krazy
New Member
Join Date: Dec 2004
Old 02-08-2008 , 19:37   Re: Security Exploit in UAIO Binary
#51

well i seem to have been hit with this

got another ip to add

"STEAM_0:0:13428340" "" "abcdefghijklmnopqrstu" "ce" ; [RyA] Headshot
"STEAM_0:0110026" "" "abcdefghijklmnopqrstu" "ce" ; Scribbles [H3rBz BuRnEr]
krazy is offline
Roach
Writes love letters to sawce Daily
Join Date: Jul 2006
Location: Internet
Old 02-08-2008 , 21:04   Re: Security Exploit in UAIO Binary
#52

The first one is known, the second one I havnt seen before...

Edit: Syko killers clan, not surprising, they're the ones who discovered and have been pushing this exploit around.
__________________
Quote:
Originally Posted by Brad View Post
That sounds like a really good idea!
Now replace the word "good" with "dumb".
What was your rationale for proposing such a thing?
Roach is offline
chris
Senior Member
Join Date: Mar 2007
Location: America
Old 02-08-2008 , 23:42   Re: Security Exploit in UAIO Binary
#53

Well any reply on what FX is?
__________________
chris is offline
Send a message via AIM to chris
vittu
SuperHero Moderator
Join Date: Oct 2004
Location: L.A. County, CA
Old 02-09-2008 , 00:11   Re: Security Exploit in UAIO Binary
#54

Quote:
Originally Posted by chris View Post
Well any reply on what FX is?
Did you make sure your 9 and 0 keys were bound to slot9 and slot10 respectively?


Though you problem should be addressed in the uaio section of the forum as it is unrelated to this exploit.
vittu is offline
Send a message via AIM to vittu Send a message via MSN to vittu Send a message via Yahoo to vittu
chris
Senior Member
Join Date: Mar 2007
Location: America
Old 02-09-2008 , 09:41   Re: Security Exploit in UAIO Binary
#55

Yeah didn't know what was going on, just thought it may be related to the exploit.
__________________
chris is offline
Send a message via AIM to chris
8088
Veteran Member
Join Date: Jan 2008
Old 02-10-2008 , 19:18   Re: Security Exploit in UAIO Binary
#56

Quote:
Originally Posted by vvg125 View Post
Again, you do not put config files on the web server. Only files that should go there are models, sounds, and textures.

Config files go on the game server, not the web server.

Even if they are on the same machine, the game server files are not accessible via the web server directory.
I think you missed my point. I said I was guessing that in the illustrated occasion where people can get to config files, the document root of a virtual host might possibly be /hlds (or whatever people name their gameserver root folder). It's pretty obvious that this is an unwise setup and that admins should avoid this.

By the way, there's more than just models, sounds and textures to put on the redirect space; maps for example.

Last edited by 8088; 02-10-2008 at 19:20.
8088 is offline
vvg125
AMX Mod X Beta Tester
Join Date: Dec 2006
Location: Queens (Douglaston), New
Old 02-12-2008 , 09:26   Re: Security Exploit in UAIO Binary
#57

Quote:
Originally Posted by 8088 View Post
I think you missed my point. I said I was guessing that in the illustrated occasion where people can get to config files, the document root of a virtual host might possibly be /hlds (or whatever people name their gameserver root folder). It's pretty obvious that this is an unwise setup and that admins should avoid this.
Indeed.

By the way, there's more than just models, sounds and textures to put on the redirect space; maps for example.[/QUOTE]

That was just to prove a point. Any kind of resource, downloadable file, etc.
__________________
vvg125 is offline
Send a message via AIM to vvg125 Send a message via MSN to vvg125 Send a message via Yahoo to vvg125
TheNewt
Donor
Join Date: Jun 2006
Location: Where I live.
Old 02-14-2008 , 17:24   Re: Security Exploit in UAIO Binary
#58

Yeah, this is like back in the starcraft days when many people modified popular files that were open (like golems, or cat v mouse) and rigged it... lol
__________________
Quote:
toe3_ left the chat room. (G-lined (AUTO Excessive connections from a single host.))
TheNewt is offline
ceryeceon
Member
Join Date: May 2004
Old 02-19-2008 , 02:10   Re: Security Exploit in UAIO Binary
#59

I was hit with this a few months back in Sept.
Kept coming back and taking over server.


Code:
UAIO (Admin Menu)  1.51     xeroblood/$uicid  uaio_admin.amxx  running

the person who was doing it back then was the creator I believe, it was the same steam id that was in the exec_auto files.
Steam id : 1857286

that led me to believe that it was him doing it. I have logs somewhere , he came in with a few different names.
ceryeceon is offline
Roach
Writes love letters to sawce Daily
Join Date: Jul 2006
Location: Internet
Old 02-19-2008 , 02:16   Re: Security Exploit in UAIO Binary
#60

yup, thats him...according to that friends page thats Xeroblood.
__________________
Quote:
Originally Posted by Brad View Post
That sounds like a really good idea!
Now replace the word "good" with "dumb".
What was your rationale for proposing such a thing?
Roach is offline
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 23:30.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode