Raised This Month: $32 Target: $400
 8% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


Post New Thread Reply   
 
Thread Tools Display Modes
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 11-18-2009 , 00:09   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #11

Quote:
Originally Posted by Solor View Post
Question - I see that several user's are being blocked from downloading this .dat file.

Is this crashing their clients out when it does this or what?

What's the importance of this file, to restrict it?

Seeing the pure number of user's requesting this file, it must be something that is automated, and not the user doing it.
What file?
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Solor
Member
Join Date: Jan 2009
Old 11-18-2009 , 01:07   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #12

In my logs I see stuff like this

Code:
L 11/17/2009 - 21:29:40: [D-FENS] "<3mix<1107><STEAM_0:1:13039208><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "A Fancy Little Cupcake<1095><STEAM_0:0:24151259><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Execration<1102><STEAM_0:1:10646949><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Suminagashi<1054><STEAM_0:1:8831378><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Aesop<1089><STEAM_0:1:9219688><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "polius<1098><STEAM_0:1:21965317><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "phoenix<1081><STEAM_0:1:24773473><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "๖ۣۜRobby ๖ۣۜFennec<1030><STEAM_0:0:21528178><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Alfre6 (Silver)<1104><STEAM_0:0:13790285><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "DiKo7omy<1084><STEAM_0:1:18130367><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "derekmrickey<1087><STEAM_0:0:26553921><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Everest^<1077><STEAM_0:0:23334313><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "hlampert<1043><STEAM_0:1:22634762><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Station<1056><STEAM_0:0:16776035><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "luke7<1090><STEAM_0:0:17612760><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "TOTAL_POWER<1110><STEAM_0:1:21107244><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "SetSail4Fail<1060><STEAM_0:0:18996712><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Lesrac - SexualDiplodocus<1067><STEAM_0:1:19304932><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "osteshorts<1108><STEAM_0:0:18398709><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "InSaNe<1068><STEAM_0:0:24957322><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Darksurge<1091><STEAM_0:0:26211839><>" requested file "downloads/6175980a.dat".
L 11/17/2009 - 21:29:40: [D-FENS] "Spidey426<1052><STEAM_0:0:27283105><>" requested file "downloads/6175980a.dat".
Because it's not just one user (usually), I suspect it's something automated. Possibly this file is spray's and such that user's have uploaded to the server that other clients are trying to get?
Solor is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 11-18-2009 , 02:07   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #13

getting this in log file:

Code:
L 11/16/2009 - 23:37:12: [META] Failed to load plugin addons/D-FENS/bin/D-FENS_OB: Plugin API 14 is newer than internal version (11)
__________________
Fearts is offline
DontWannaName
Veteran Member
Join Date: Jun 2007
Location: VALVe Land, WA
Old 11-18-2009 , 02:43   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #14

Quote:
Originally Posted by Fearts View Post
getting this in log file:

Code:
L 11/16/2009 - 23:37:12: [META] Failed to load plugin addons/D-FENS/bin/D-FENS_OB: Plugin API 14 is newer than internal version (11)
You are getting that error because you must use Metamod 1.8.

Does rcon locker also fix this same issue?
__________________

DontWannaName is offline
jockersoft
Member
Join Date: Aug 2008
Old 11-18-2009 , 04:20   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #15

Quote:
Originally Posted by Solor View Post
Question - I see that several user's are being blocked from downloading this .dat file.

Is this crashing their clients out when it does this or what?

What's the importance of this file, to restrict it?

Seeing the pure number of user's requesting this file, it must be something that is automated, and not the user doing it.
those .dat files in the downloads directory are players sprays.
Since they do not contain .ini, .cfg, .log anywhere in the files path they are not being blocked, but just logged.
jockersoft is offline
voogru
Inspector Javert
Join Date: Oct 2004
Old 11-18-2009 , 05:49   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #16

The reason why I log every transaction is in case it's not blocked there will still be a log event.


Downloads of the .dat files and other game content are still allowed and do not get blocked.
voogru is offline
NoS
Senior Member
Join Date: Nov 2006
Old 11-18-2009 , 13:13   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #17

Anything for CS:S in Windows 2003?
NoS is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 11-18-2009 , 16:39   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #18

Quote:
Originally Posted by DontWannaName View Post
You are getting that error because you must use Metamod 1.8.
I am using this MetaModL

http://www.sourcemm.net/mmsdrop/1.8/

mmsource-1.8.0-hg682

isnt that the right version?
__________________
Fearts is offline
DontWannaName
Veteran Member
Join Date: Jun 2007
Location: VALVe Land, WA
Old 11-18-2009 , 17:17   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #19

You must not have loaded it right, verify with meta version in console.
__________________

DontWannaName is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 11-18-2009 , 19:17   Re: D-FENS - Emergency patch against downloading server files.
Reply With Quote #20

I did It is running:

] rcon meta version
autokick is disabled for -[FF]- Fire ̷̨●̷̨°
Metamod:Source version 1.8.0-dev
Build ID: 682:f125dd3ed7d0-dev
Loaded As: GameDLL (gameinfo.txt)
Compiled on: Nov 17 2009
Plugin interface version: 11:7
SourceHook version: 4:4
http://www.metamodsource.net/
L 11/17/2009 - 19:07:48: rcon from "98.235.103.185:55885": command "meta version"
__________________
Fearts is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 10:36.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode