Raised This Month: $51 Target: $400
 12% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


Post New Thread Reply   
 
Thread Tools Display Modes
Xaphan
SourceMod Donor
Join Date: Jun 2008
Old 04-14-2011 , 03:57   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #461

Guess we can remove this plug-in now...
Some guy just uploaded files and renamed a map.. now the map is a folder.
Had to delete the folder and replace the map.
Code:
L 04/13/2011 - 23:09:09: [D-FENS] "<><STEAM_0:1:26233280><IP>" uploaded file "maps/cs_office.bsp\hacked.txt".
__________________

Last edited by Xaphan; 04-14-2011 at 16:40.
Xaphan is offline
altex
Veteran Member
Join Date: May 2009
Location: Russia
Old 04-14-2011 , 04:17   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #462

Try this plugin http://forums.alliedmods.net/showthread.php?t=142249
__________________
altex is offline
KyleS
SourceMod Plugin Approver
Join Date: Jul 2009
Location: Segmentation Fault.
Old 04-14-2011 , 13:00   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #463

Quote:
Originally Posted by Xaphan View Post
Guess we can remove this plug-in now...
Some guy just uploaded files and renamed a map.. now the map is a folder.
Had to delete the folder and replace the map.
Code:
L 04/13/2011 - 23:09:09: [D-FENS] "<><STEAM_0:1:XXX><IP>" uploaded file "maps/cs_office.bsp\hacked.txt".
What's his SteamID?
KyleS is offline
Xaphan
SourceMod Donor
Join Date: Jun 2008
Old 04-14-2011 , 16:42   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #464

Updated thread with his steam id, I didn't wanna break any rules.
__________________
Xaphan is offline
energySPB
New Member
Join Date: Apr 2011
Old 04-19-2011 , 09:38   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #465

I install plugin, but I can't understand - it works or not? How I can check it?
energySPB is offline
energySPB
New Member
Join Date: Apr 2011
Old 04-19-2011 , 10:15   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #466

dosp_status - unknown command

I write "meta list" and saw D-Fens. it's mean that plugin is working?
energySPB is offline
dataviruset
AlliedModders Donor
Join Date: Feb 2009
Location: Hong Kong
Old 04-19-2011 , 10:17   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #467

Oh, sorry. Seems like I'm used to DoSprotect.
Yes, if you see D-FENS in meta list, hopefully you should be fine.
dataviruset is offline
SirCole
Member
Join Date: Nov 2006
Old 04-20-2011 , 00:51   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #468

Quote:
Originally Posted by Xaphan View Post
Guess we can remove this plug-in now...
Some guy just uploaded files and renamed a map.. now the map is a folder.
Had to delete the folder and replace the map.
Code:
L 04/13/2011 - 23:09:09: [D-FENS] "<><STEAM_0:1:26233280><IP>" uploaded file "maps/cs_office.bsp\hacked.txt".
Quote:
Originally Posted by energySPB View Post
dosp_status - unknown command

I write "meta list" and saw D-Fens. it's mean that plugin is working?
as you can see the poster above was showing output from D-FENS which saw the upload happen but didn't block it..

So IMO no
SirCole is offline
krayser
Junior Member
Join Date: Jan 2009
Location: IL
Old 04-20-2011 , 10:31   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #469

Metamod:Source version 1.8.6
SourceMod Version: 1.3.7
Linux

plugin doesn't work
krayser is offline
dataviruset
AlliedModders Donor
Join Date: Feb 2009
Location: Hong Kong
Old 04-20-2011 , 11:07   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #470

Quote:
Originally Posted by krayser View Post
Metamod:Source version 1.8.6
SourceMod Version: 1.3.7
Linux

plugin doesn't work
It hasn't been working for a while on Linux.
I suggest you use the ServerSecure extension for SourceMod instead.
dataviruset is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:55.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode