Raised This Month: $32 Target: $400
 8% 

File upload exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-20-2009 , 23:15   Re: File upload exploit fix
Reply With Quote #21

Updated to fix the delete file issue. No windows builds ATM I'm afraid, as I don't have the ability to do so.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-21-2009 , 06:57   Re: File upload exploit fix
Reply With Quote #22

Quote:
Originally Posted by devicenull View Post
Updated to fix the delete file issue. No windows builds ATM I'm afraid, as I don't have the ability to do so.
Have to run out the door at the moment, but I'll post the windows build in about an hour if no one beats me to it.
psychonic is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-21-2009 , 08:08   Re: File upload exploit fix
Reply With Quote #23

Quote:
Originally Posted by psychonic View Post
Have to run out the door at the moment, but I'll post the windows build in about an hour if no one beats me to it.
Nevermind, looks like they're already in the zip
psychonic is offline
jockersoft
Member
Join Date: Aug 2008
Old 08-21-2009 , 09:47   Re: File upload exploit fix
Reply With Quote #24

Quote:
Originally Posted by psychonic View Post
Nevermind, looks like they're already in the zip
comparing the dates, the .dlls are the old version
jockersoft is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-21-2009 , 11:18   Re: File upload exploit fix
Reply With Quote #25

Quote:
Originally Posted by jockersoft View Post
comparing the dates, the .dlls are the old version
Alright, well then just in case:
Attached Files
File Type: dll exploit_l4d_mm.dll (79.0 KB, 217 views)
File Type: dll exploit_ob_mm.dll (79.0 KB, 273 views)
File Type: dll exploit_orig_mm.dll (84.0 KB, 248 views)
psychonic is offline
shustas
SourceMod Donor
Join Date: May 2007
Location: London
Old 08-21-2009 , 11:32   Re: File upload exploit fix
Reply With Quote #26

R u kiddin me? Peeps can overwrite gamedata and server.cfg files now?
__________________
shustas is offline
NoS
Senior Member
Join Date: Nov 2006
Old 08-21-2009 , 13:14   Re: File upload exploit fix
Reply With Quote #27

Is there a possible fix for SourceBans so that if new admins are added it won't automatically write the admins.cfg file to exploits.
NoS is offline
Flyflo
Senior Member
Join Date: Jun 2008
Location: Grenoble, France
Old 08-21-2009 , 17:34   Re: File upload exploit fix
Reply With Quote #28

Hum, it seems valve just released a fix for this bug (http://store.steampowered.com/news/2759/).
Flyflo is offline
violentcrimes
Senior Member
Join Date: Nov 2006
Old 08-21-2009 , 18:02   Re: File upload exploit fix
Reply With Quote #29

Not fixed for Mods or CSS yet.
__________________
violentcrimes is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-21-2009 , 18:49   Re: File upload exploit fix
Reply With Quote #30

Quote:
Originally Posted by violentcrimes View Post
Not fixed for Mods or CSS yet.
This was an engine wide fix. As long as the mod uses the orangebox engine, it will be fixed.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:57.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode