Raised This Month: $ Target: $400
 0% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


  
 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
Author Message
voogru
Inspector Javert
Join Date: Oct 2004
Old 11-17-2009 , 10:09   D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #1

TL;DR
This plug-in will prevent a malicious user from uploading or downloading sensitive files from your server.

-
This plug-in patches a security vulnerability that allows an attacker to download sensitive files, or upload files that change the behavior of your server.

The servers console by default actually will echo out when a player tries to upload or download a file, but this can't be seen 99% of the time.

If a client tries to upload or download an illegal file, 3 things will happen:

1. It will output to the log file "Player Name<userid><steamid><ip> requested/uploaded illegal file "filename"".
2. Their client will be maliciously crashed in an effort to slow them down. (they won't be kicked but will time out naturally)
3. The file operation will obviously, be denied.

Update: Source code made available, the client crash defense mechanic has been removed as well, file operations are just logged and bad operations get blocked.

Installation: Simply place the files in your addons directory, modify the VDF file depending on what engine you are using. Files with mm18 in the file name require MM 1.8, files with mm17 in the file name require MM 1.7.

Update by Viper: I attached D-Fens for EP1 (CSS) and Orange box engines to the post ;)

linux binaries
Attached Files
File Type: zip d-fens.zip (106.2 KB, 6015 views)
File Type: zip D-FENS mm1.8.zip (68.6 KB, 5198 views)

Last edited by voogru; 05-22-2010 at 07:00. Reason: Uploaded to the forums
voogru is offline
 



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 19:46.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode