Raised This Month: $32 Target: $400
 8% 

Security Exploit in UAIO Binary


Post New Thread Closed Thread   
 
Thread Tools Display Modes
Rolnaaba
Veteran Member
Join Date: May 2006
Old 03-04-2008 , 09:25   Re: Security Exploit in UAIO Binary
#71

Thats disgusting that someone would actually abuse AMXX in such a way, thanks for the catch sawce.
__________________
DO NOT PM me about avp mod.
Rolnaaba is offline
Old 04-17-2008, 00:33
Q-bA11
This message has been deleted by Greentryst. Reason: useless post
Old 04-17-2008, 09:34
hazard1337
This message has been deleted by Greentryst. Reason: reply to deleted post
rudle
BANNED
Join Date: Mar 2008
Location: About to be sent to bant
Old 04-17-2008 , 09:43   Re: Security Exploit in UAIO Binary
#72

What a loser he is then if he thinks he is a pro hacker and sause found him out
rudle is offline
hazard1337
Senior Member
Join Date: Sep 2006
Old 04-17-2008 , 10:09   Re: Security Exploit in UAIO Binary
#73

This has nothing to do with hacking anything, he simply released a binary format of the plugin that he had coded to have a backdoor command, anyone could do that if they really wanted to, most don't cause they aren't d*ckholes.
__________________
[IMG]http://img139.**************/img139/1530/2sejaewg1.gif[/IMG]
If you +/- my K, leave your name.
I do not take requests VIA PM
Click on this before requesting/suggesting
This is your best friend
hazard1337 is offline
Send a message via Skype™ to hazard1337
Old 04-17-2008, 10:17
rudle
This message has been deleted by Greentryst. Reason: what? no. shut up
Roach
Writes love letters to sawce Daily
Join Date: Jul 2006
Location: Internet
Old 04-17-2008 , 10:25   Re: Security Exploit in UAIO Binary
#74

Quote:
Originally Posted by Q-bA11 View Post
Hmm interesting.
If you are going to report post saying that your steamid is listed for admins to blacklist you, its generally helpful to say a) which steamid it is and b) why we should take it off

That being said, with the bumping of the post and just the comment of Humm, Interesting, I think ill be leaving the aforementioned steamid's on this thread.

The burden of proof is on you to prove your non-involvement.
__________________
Quote:
Originally Posted by Brad View Post
That sounds like a really good idea!
Now replace the word "good" with "dumb".
What was your rationale for proposing such a thing?
Roach is offline
madman122
New Member
Join Date: Dec 2007
Old 07-10-2008 , 08:54   Re: Security Exploit in UAIO Binary
#75

i know this is a bit late in posting but i think that steam id needs reporting to steam directly then they can slap a vac and vac 2 ban on there sorry A**es
madman122 is offline
Xanimos
Veteran Member
Join Date: Apr 2005
Location: Florida
Old 07-10-2008 , 09:35   Re: Security Exploit in UAIO Binary
#76

Quote:
Originally Posted by madman122 View Post
i know this is a bit late in posting but i think that steam id needs reporting to steam directly then they can slap a vac and vac 2 ban on there sorry A**es
That's pointless. Steam only VAC bans for cheating/using hacks. This is neither here nor there on this matter. Compromising custom software installed on the servers with more custom software that needs to be installed has nothing to do with hacks and cheating that Steam is concerned with.
Xanimos is offline
Send a message via AIM to Xanimos Send a message via MSN to Xanimos
madman122
New Member
Join Date: Dec 2007
Old 07-10-2008 , 10:50   Re: Security Exploit in UAIO Binary
#77

Quote:
Originally Posted by Xanimos View Post
That's pointless. Steam only VAC bans for cheating/using hacks. This is neither here nor there on this matter. Compromising custom software installed on the servers with more custom software that needs to be installed has nothing to do with hacks and cheating that Steam is concerned with.
ye but wasent that version of the plugin basicly a hack
madman122 is offline
Xanimos
Veteran Member
Join Date: Apr 2005
Location: Florida
Old 07-10-2008 , 11:02   Re: Security Exploit in UAIO Binary
#78

Quote:
Originally Posted by madman122 View Post
ye but wasent that version of the plugin basicly a hack
No, not even close. It just added backdoor to AMXX.
Xanimos is offline
Send a message via AIM to Xanimos Send a message via MSN to Xanimos
xeroblood-clone
BANNED
Join Date: Jul 2008
Old 07-17-2008 , 14:30   Re: Security Exploit in UAIO Binary
#79

Hi All. Just wanted to come in here and say that I am xeroblood, and I apologize for my actions with AMXX. I have great respect for the AMXX community and the developers, so it is with great regret that I am no longer welcomed here, though it is understandable.

For the record, UAIO was the only plugin I added the backdoor too, and I have never released the key to the back door to ANYONE (keep in mind that it is impossible to figure out the key or stumble upon it accidentally). Also, I will not tell anyone how I did it, so do not msg me asking (this account will prolly get banned too, and the email I used is a spam collector, so I won't read that inbox), but I'm sure half of you developers could figure out how it was done anyway.

My STEAM ID was 1857286, but no longer as I have purchased a new copy of CS. Whoop-dee-doo though, as I don't target UAIO servers anymore. It was fun (for me) while it lasted, but no longer.

Also, the RCON password is easily obtainable once you have admin access, there is no further exploit needed to retrieve that (as some people seem to think). But again, I will not elaborate if you do not already know.

So Blame me, flame me, hate me or love me, in the end, you DL'd and installed the plugin on your server at your own risk.
I never did harm anyone's server permanantly (I just took admin for the fun of it). UAIO has had this exploit from the very beginning (sometimes I forgot to recompile with it, so a few clean copies slipped through along the way). I never did tell Suicide about the exploit (sry Suicide if I got you in trouble as well), though I cannot be certain if I sent him a copy of the code (SMA) with the exploit still in it when he took it over. If the code was somehow still in the SMA he cannot be held responsible, as I doubt anyone would read every line of code in the plugin before compiling it and posting it (in case you don't know, it's HUGE). So I do believe the exploit has been abandoned since he took it over, or if not, he was simply unaware of it.

In the end, anyone can write a plugin with a backdoor in it, I was just the first (and so far the only one caught). That's not to say it isn't possible anymore though.

Also, congrat's to sawce for finding it, I really didn't think that would ever happen! haha! But he did, so that's gotta be worth some serious props!

Anyway, I'm off, so enjoy the exploit-free UAIO!

Again, I apologize to the AMXX community and developers, I regret my actions mainly because it was childish and deceitful. We all learn from our mistakes! If you're still really mad, then go shoot someone in CS!

Take care all, and happy gaming!
xeroblood-clone is offline
Greentryst
WHAT MORE DO THEY WANT?!
Join Date: Mar 2004
Location: ? MAYBE SYRUP+TREES?
Old 07-18-2008 , 03:06   Re: Security Exploit in UAIO Binary
#80

Quote:
Originally Posted by xeroblood-clone View Post
I'm so sorry for what I did. But FUCK, that was fun!
Greentryst is offline
Send a message via ICQ to Greentryst Send a message via AIM to Greentryst Send a message via MSN to Greentryst Send a message via Yahoo to Greentryst Send a message via Skype™ to Greentryst
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 21:35.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode