Raised This Month: $32 Target: $400
 8% 

Security Notice - SteamID Bug


Post New Thread Closed Thread   
 
Thread Tools Display Modes
Author Message
BAILOPAN
Join Date: Jan 2004
Old 01-19-2006 , 19:38   Security Notice - SteamID Bug
#1

Since many people have been complaining on hlds_linux and IRC about this, I thought I'd make a public announcement to the AMX Mod X community.

Currently, there are various bugs in the Half-Life 1 engine server concerning player steamids. There are widespread reports of players getting each other's steamids, players not authenticating (STEAM_ID_PENDING), and related bugs.

This is not a bug with AMX Mod X, but with Valve's software. However, it can drastically affect administration tools -- if a connecting player is accidentally assigned a Steam ID which happens to be an admin on your server, they will get admin access unknowingly. This is not a rare coincidence. It can happen if an administrator joins, disconnects, and then another player joins into the same slot.

If this is happening on your server, I highly recommend that you either implement passwords for your admins or use name/password based authentication. This will make it so players who accidentally get an admin steamid by the HL engine will be kicked, rather than granted administrative rights.

You can read more about this method of AMX Mod X authentication here:
http://wiki.tcwonline.org/index.php/...28AMX_Mod_X%29

If you are not experiencing this problem on your server, you can disregard this message.
__________________
egg
BAILOPAN is offline
Caesar
BANNED
Join Date: Nov 2004
Old 01-21-2006 , 23:37  
#2

Interesting this happend on my server a few days ago, I thought someone had got into my account (it had a 15 number password) so i changed my password to 3 random words and 26 numbers or something (thank the lord for photgraphic memory)

lol
Caesar is offline
SweatyBanana
BANNED
Join Date: Sep 2005
Location: LOL
Old 01-26-2006 , 10:59  
#3

Someone was on mine and had STEAM_ID_PENDING the whole time.
SweatyBanana is offline
Send a message via AIM to SweatyBanana Send a message via Yahoo to SweatyBanana
BAILOPAN
Join Date: Jan 2004
Old 01-31-2006 , 01:48  
#4

update on this issue, alfred reynolds posted this to hlds_linux:
Quote:
Originally Posted by Alfred Reynolds
We have a beta release available for both the Source and HL1 engine.
This beta fixes the steam id swapping problem amongst other small fixes.
You can apply the beta by running the hldsupdatetool and adding "-beta
swapbeta" to the command line.

A couple of users in an initial test reported a server hang and
associated assert (pipes.cpp line 29, if you see this please send me
your OS configuration and hardware.

- Alfred
__________________
egg
BAILOPAN is offline
pendragon
Senior Member
Join Date: Mar 2004
Location: In a bubble
Old 01-31-2006 , 15:19  
#5

I'm assuming this only applies to Linux boxes then?
__________________
pendragon is offline
Send a message via ICQ to pendragon
teame06
i have a hat
Join Date: Feb 2005
Location: Hat City
Old 01-31-2006 , 15:23  
#6

No It for both
__________________
No private support via Instant Message
GunGame:SM Released
teame06 is offline
Send a message via AIM to teame06
diamond-optic
Veteran Member
Join Date: May 2005
Location: Upstate New York
Old 01-31-2006 , 19:13  
#7

so anyone try it out yet?

before i i bother putting in a support ticket to my host to have them add it to the cmd line...
__________________
diamond-optic is offline
Send a message via AIM to diamond-optic
Skyrider
AMX Mod X Beta Tester
Join Date: May 2005
Location: Netherlands
Old 02-07-2006 , 05:37  
#8

I'm not going to try something out which is only beta. Besides, i never have the STEAMID problem anymore. Even though i had it once, which really freaked me out, but after that never again.
__________________
Skyrider is offline
Send a message via AIM to Skyrider Send a message via MSN to Skyrider Send a message via Yahoo to Skyrider
Petey B
Member
Join Date: Feb 2005
Old 02-07-2006 , 16:42  
#9

im not sure if this works on amxx but i have STEAM_ID_PENDING in my users.ini with a password so it will kick them if they get the password wrong (which is allways)
Petey B is offline
Send a message via MSN to Petey B
Curryking
Veteran Member
Join Date: Jun 2004
Location: 51.22°N / 6.77°E
Old 02-15-2006 , 08:31  
#10

Quote:
Originally Posted by BAILOPAN
update on this issue, alfred reynolds posted this to hlds_linux:
Quote:
Originally Posted by Alfred Reynolds
We have a beta release available for both the Source and HL1 engine.
This beta fixes the steam id swapping problem amongst other small fixes.
You can apply the beta by running the hldsupdatetool and adding "-beta
swapbeta" to the command line.

A couple of users in an initial test reported a server hang and
associated assert (pipes.cpp line 29, if you see this please send me
your OS configuration and hardware.

- Alfred
This night I've tried out this "beta". Update from Linux Server Engine 29 -> 33. Bad idea! With this version no SteamID was identificated, everyone had STEAM_ID_PENDING and VAC2 was disabled automaticly.
Result: Cheaters were attract by a non secure Server and Admins weren't able to react 'cause they weren't admins anymore (idendification by STEAM_ID). So downgrade back to engine 29 and back to the old STEAM_ID-Error.

Viva la steam!

Curry
__________________
Full speed - no brakes!
Curryking is offline
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:50.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode