Raised This Month: $51 Target: $400
 12% 

[IMPORTANT] A new HLDS engine exploit !!!


Post New Thread Reply   
 
Thread Tools Display Modes
lickshot
Junior Member
Join Date: Jul 2012
Old 07-24-2012 , 04:21   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #31

Just to say that stopping the international chanell from the ISP didn't help. The attack with 1400 length packets stopped but now another started with different lengths (6 and 7) but this time it hits server ports and comes from 27005. What is strange is that the packets are still coming from outside my country (or at least the logs say so). So you are right . I think that the attack with 1400 length is some kind of exploit that uses real cs servers, because they can't do it now when I don't have international traffic, but the attack with 6-7 lengths is some kind of spoofed ip adresses because the IPs are again foreign. Any ideas ?!
lickshot is offline
lickshot
Junior Member
Join Date: Jul 2012
Old 08-01-2012 , 06:12   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #32

Hey guys Valve has made a test fix for this flood which is included in the yesterday's HLDS platform update. Big thanks to Alfred Reynolds.

He said that it will take some time for everyone to update their platforms. So please update your platforms!

Spread the news to your local communities!

Last edited by lickshot; 08-01-2012 at 08:05.
lickshot is offline
S0m3Th1nG_AwFul
Member
Join Date: Sep 2011
Location: is not known.
Old 08-01-2012 , 06:48   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #33

Quote:
Originally Posted by lickshot View Post
Alse the update fixes another exploit which allows downloading of server files.
That was fixed in previous update.
S0m3Th1nG_AwFul is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 08-01-2012 , 09:16   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #34

Quote:
Originally Posted by lickshot View Post
Hey guys Valve has made a test fix for this flood which is included in the yesterday's HLDS platform update. Big thanks to Alfred Reynolds.
You are assuming that the "attack" you originally mentioned in this thread is indeed the malformed A2S attack, you didn't seem too willing to accept this earlier. Also, it wasn't a test fix. If it was, it would have been pushed to hlbeta first.

Quote:
He said that it will take some time for everyone to update their platforms.
No he didn't
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
lickshot
Junior Member
Join Date: Jul 2012
Old 08-01-2012 , 09:43   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #35

Quote:
Originally Posted by YamiKaitou View Post
You are assuming that the "attack" you originally mentioned in this thread is indeed the malformed A2S attack, you didn't seem too willing to accept this earlier. Also, it wasn't a test fix. If it was, it would have been pushed to hlbeta first.


No he didn't
Quote:
Originally Posted by Alfred Reynolds
Thanks for the details, based on your tcpdump logs I have a theory about what the issue may be, we will be releasing an update for Half-Life 1 dedicated servers tomorrow that will apply a potential fix. It requires servers to update for it to apply, so it will take some time for the change to move through the user base.
lickshot is offline
Powerlord
AlliedModders Donor
Join Date: Jun 2008
Location: Seduce Me!
Old 08-02-2012 , 15:53   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #36

I really wish Valve would mark server-only updates as required. This would solve the issue of servers not being updated in two ways:

  1. -autoupdate would work on them (sorry, I'm just assuming Goldsrc has -autoupdate like Source does... for Linux anyway)
  2. Clients would bitch at server owners to update. ;)
__________________
Not currently working on SourceMod plugin development.
Powerlord is offline
guven5
Senior Member
Join Date: Jul 2010
Location: counter strike 1.6 downl
Old 08-03-2012 , 05:13   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #37

i am not sure update solve flood attack, i did update but all looks like same
__________________

Last edited by guven5; 08-03-2012 at 05:17.
guven5 is offline
xPaw
Retired AMX Mod X Moderator
Join Date: Jul 2008
Old 08-03-2012 , 05:24   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #38

Quote:
Originally Posted by Powerlord View Post
I really wish Valve would mark server-only updates as required. This would solve the issue of servers not being updated in two ways:

  1. -autoupdate would work on them (sorry, I'm just assuming Goldsrc has -autoupdate like Source does... for Linux anyway)
  2. Clients would bitch at server owners to update. ;)
Alfred was planning to updating CS client… Let's just hope they will change protocol number to break all old servers
__________________
xPaw is offline
hyphen
Senior Member
Join Date: Aug 2011
Old 08-03-2012 , 05:47   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #39

Quote:
Alfred was planning to updating CS client… Let's just hope they will change protocol number to break all old servers
That will be cool. Once done most of servers cant run dproto I guess.
hyphen is offline
S0m3Th1nG_AwFul
Member
Join Date: Sep 2011
Location: is not known.
Old 08-03-2012 , 06:44   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #40

It will happen only if this 'new' protocol will strongly differ from old ones (NOT like 48 from 47). Otherwise we have a possibility, that someone will invent, to example, TProto (Triple Protocol)
S0m3Th1nG_AwFul is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 08:02.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode