Raised This Month: $51 Target: $400
 12% 

[IMPORTANT] A new HLDS engine exploit !!!


Post New Thread Reply   
 
Thread Tools Display Modes
last_hope
Senior Member
Join Date: Dec 2011
Old 08-03-2012 , 15:19   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #41

Quote:
Originally Posted by guven5 View Post
i am not sure update solve flood attack, i did update but all looks like same
Of course! Because all servers must be updated!!!
You updated your server, so, bad guyz can't use your server, but they still can use thousands other...
last_hope is offline
Send a message via ICQ to last_hope
lickshot
Junior Member
Join Date: Jul 2012
Old 08-04-2012 , 08:02   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #42

Bad news guys - some server admins noticed that their outgoing upload was much higher than normal with 0 players in their servers. This doesn't affect the lag or ping of the players in the servers. Today I also noticed a rise in the outgoing upload on all of my servers so I made a traffic dump of a server with 0 players. My server was receiving packets from random IPs and was answering to them with the same info (1400 length) packets which we receive when being flooded. I am with the latest 5758 build on all of my servers.
lickshot is offline
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 08-04-2012 , 08:06   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #43

Quote:
Originally Posted by Zephyrus View Post
if this is the case, its not an exploit, its a simple reflected DDOS attack and has nothing to do with valve and hlds
Amplification vectors for DRDoS attacks are exploits. Which this is.
__________________
asherkin is offline
joropito
AlliedModders Donor
Join Date: Mar 2009
Location: pfnAddToFullPack
Old 08-04-2012 , 10:35   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #44

The latest update doesn't fix the bug.

I was able to block this using iptables.

For those who can prove they have STEAM SERVERS and they are running under linux, I will share this information.

I will not post here in public because this information let you reproduce the exploit.

EDIT:

I was testing with a non up to date server. After updating I found it's fixed.
__________________

Divide et vinces
approved plugins | steam account

I don't accept PM for support. Just ask on forums.
If you're looking for private work, PM me.

Last edited by joropito; 08-04-2012 at 13:45.
joropito is offline
Send a message via MSN to joropito
lickshot
Junior Member
Join Date: Jul 2012
Old 08-04-2012 , 13:19   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #45

Quote:
Originally Posted by joropito View Post
The latest update doesn't fix the bug.

I was able to block this using iptables.

For those who can prove they have STEAM SERVERS and they are running under linux, I will share this information.

I will not post here in public because this information let you reproduce the exploit.
You have a pm.
lickshot is offline
mabaclu
Senior Member
Join Date: Jun 2010
Location: Portugal
Old 08-04-2012 , 14:16   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #46

joropito said it is fixed in the new update
@lickshot thanks for reporting it in the mailing lists and ignoring people that say "it's just a ddos"
__________________
mabaclu is offline
guven5
Senior Member
Join Date: Jul 2010
Location: counter strike 1.6 downl
Old 08-04-2012 , 14:34   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #47

attack from Quad ip in same time, also 2 different packet lenght... length 9 and length 5 (for me)
attack algorythm always changing, it never try banned ip again

God mercy us
__________________
guven5 is offline
joropito
AlliedModders Donor
Join Date: Mar 2009
Location: pfnAddToFullPack
Old 08-04-2012 , 15:04   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #48

Users having the same behaviour after updating engine are using dproto.

Disable dproto an you will be safe.
__________________

Divide et vinces
approved plugins | steam account

I don't accept PM for support. Just ask on forums.
If you're looking for private work, PM me.
joropito is offline
Send a message via MSN to joropito
lickshot
Junior Member
Join Date: Jul 2012
Old 08-04-2012 , 15:24   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #49

Quote:
Originally Posted by joropito View Post
Users having the same behaviour after updating engine are using dproto.

Disable dproto an you will be safe.
No dproto, 4mbps outgoing from the port without any players in the server?
lickshot is offline
joropito
AlliedModders Donor
Join Date: Mar 2009
Location: pfnAddToFullPack
Old 08-04-2012 , 15:40   Re: [IMPORTANT] A new HLDS engine exploit !!!
Reply With Quote #50

Quote:
Originally Posted by lickshot View Post
No dproto, 4mbps outgoing from the port without any players in the server?
Show the output of

rcon meta list
rcon version
__________________

Divide et vinces
approved plugins | steam account

I don't accept PM for support. Just ask on forums.
If you're looking for private work, PM me.
joropito is offline
Send a message via MSN to joropito
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:01.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode