Raised This Month: $51 Target: $400
 12% 

Rcon locker / exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-03-2009 , 21:45   Re: Rcon locker / exploit fix
Reply With Quote #41

Updated to fix a recently discovered exploit that seems to effect anything based on the source engine. Also added "meta" to the list of forbidden commands inside ent_fire
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
retsam
Veteran Member
Join Date: Aug 2008
Location: so-cal
Old 08-03-2009 , 21:52   Re: Rcon locker / exploit fix
Reply With Quote #42

Interesting... Thx for heads up. So essentially it doesnt crash the server, but makes it so people cant join?
retsam is offline
adamnp
Member
Join Date: Jul 2008
Location: Connecticut
Old 08-03-2009 , 21:53   Re: Rcon locker / exploit fix
Reply With Quote #43

thanks dev!

-Adam
__________________
Ritmo Technology Group, LLC
Adam Piatek - Chief Technology Officer / Partner
- Cheap Ventrilo Servers - NooBGalore Gaming Community - Cheap Web Hosting - Free file hosting - Free Tech Support -

adamnp is offline
Send a message via AIM to adamnp Send a message via Skype™ to adamnp
Kenny Loggins
SourceMod Donor
Join Date: Jun 2008
Location: Rochester, MN
Old 08-04-2009 , 22:09   Re: Rcon locker / exploit fix
Reply With Quote #44

Shit, I need to update i'm getting hit hard right after this info went out on the HLDS mailing list.
__________________

Server Admin / Leader
ClanAO.com
Kenny Loggins is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-05-2009 , 10:31   Re: Rcon locker / exploit fix
Reply With Quote #45

Just updated, it seems that SourceMod's usual way of detecting commands is not fired for commands that are executed while loading. I've switched to an alternate method, and this should prevent the exploit now.

Just to be clear: 0.2.6 will not prevent the early cmd exploit.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
INFINITI
Junior Member
Join Date: May 2008
Location: Russia
Old 08-05-2009 , 11:56   Re: Rcon locker / exploit fix
Reply With Quote #46

0.2.7v errors(
0.2.6 it was ok
Quote:
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
Writing cfg/banned_ip.cfg.
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()
L 08/05/2009 - 19:53:54: [SM] Native "IsClientInGame" reported: Client index 0 i
s invalid
L 08/05/2009 - 19:53:54: [SM] Displaying call stack trace for plugin "rcon_lock.
smx":
L 08/05/2009 - 19:53:54: [SM] [0] Line 222, /home/groups/alliedmodders/forums
/files/7/2/43224.attach::HalfConnected()

Last edited by INFINITI; 08-05-2009 at 11:59.
INFINITI is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-05-2009 , 13:31   Re: Rcon locker / exploit fix
Reply With Quote #47

Updated again to fix that. That error would not hurt any of the protection though.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
siosios
SourceMod Donor
Join Date: Jan 2008
Old 08-05-2009 , 19:59   Re: Rcon locker / exploit fix
Reply With Quote #48

thanks dev
__________________
siosios is offline
ratty
SourceMod Donor
Join Date: Jan 2006
Old 08-06-2009 , 02:19   Re: Rcon locker / exploit fix
Reply With Quote #49

This is awesome, does it log when people try that half connected exploit? I'd really like to ban these guys.
__________________
Visit the NOM NOM NOM community
http://www.nom-nom-nom.us
ratty is offline
Kenny Loggins
SourceMod Donor
Join Date: Jun 2008
Location: Rochester, MN
Old 08-06-2009 , 04:07   Re: Rcon locker / exploit fix
Reply With Quote #50

Hmm ya that would be a nice option maybe allow it to integrate with SourceBans? I don’t need people like that playing on my servers…
__________________

Server Admin / Leader
ClanAO.com
Kenny Loggins is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:00.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode