Raised This Month: $51 Target: $400
 12% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


Post New Thread Reply   
 
Thread Tools Display Modes
Dustin
Member
Join Date: Sep 2005
Location: Finland
Old 10-01-2010 , 21:07   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #411

Having random crashes too with TF2 and CS Source server. All they have in common is D-FENS.
Dustin is offline
KyleS
SourceMod Plugin Approver
Join Date: Jul 2009
Location: Segmentation Fault.
Old 10-01-2010 , 21:18   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #412

You guys are not alone, another plugin that messes with file transfers is crashing as well. Hopefully the fix is the same, and it comes sooner rather then later as we're all susceptible to this attack at the moment.

http://forums.alliedmods.net/showthr...99#post1312699 - My post in regards to ServerSecure2.
KyleS is offline
matrixmark
Senior Member
Join Date: Jun 2010
Old 10-02-2010 , 05:56   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #413

Indeed people are even uploading/downloading sprays on purpose now as a griefing tactic because they know its crashing some if not all servers running [D-FENS]

I'm talking about the linux version for LFD I'm not sure if windows users will also be effected?

Mark
matrixmark is offline
altex
Veteran Member
Join Date: May 2009
Location: Russia
Old 10-02-2010 , 06:55   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #414

I use dfens on windows servers without crashes at all.
__________________
altex is offline
dataviruset
AlliedModders Donor
Join Date: Feb 2009
Location: Hong Kong
Old 10-02-2010 , 09:50   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #415

It's obvious, D-FENS for Linux crashes on file uploads/downloads which doesn't exist in the game_dir/downloads/ folder.
dataviruset is offline
matrixmark
Senior Member
Join Date: Jun 2010
Old 10-02-2010 , 13:02   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #416

Quote:
Originally Posted by dataviruset View Post
It's obvious, D-FENS for Linux crashes on file uploads/downloads which doesn't exist in the game_dir/downloads/ folder.
Exactly what is happening you explained it better lol
matrixmark is offline
dataviruset
AlliedModders Donor
Join Date: Feb 2009
Location: Hong Kong
Old 10-02-2010 , 13:16   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #417

Maybe D-FENS isn't needed anymore, a friend of mine told me that he couldn't load SM/ManiAdminTakeover, I know that doesn't speak for other kinds of exploits with upload/downloading, but... yeah.
dataviruset is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 10-02-2010 , 14:24   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #418

I was under the impression that this was patched a few months ago, but there was a workaround that kept this plugin worth keeping around.
__________________
thetwistedpanda is offline
Dustin
Member
Join Date: Sep 2005
Location: Finland
Old 10-02-2010 , 16:43   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #419

This is somewhat "patched" by valve but not all the methods. This would be still usefull, if someone would just fix the linux version.
Dustin is offline
LordMarqus
Senior Member
Join Date: Sep 2009
Location: Poland
Old 10-04-2010 , 14:25   Re: D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)
Reply With Quote #420

Quote:
Originally Posted by dataviruset View Post
It's obvious, D-FENS for Linux crashes on file uploads/downloads which doesn't exist in the game_dir/downloads/ folder.
Server crashes on this:
Code:
File 'downloads/0d070c67.dat' requested from server 192.168.0.104:27015
Code:
Program terminated with signal 11, Segmentation fault.
#0  0x005bd082 in __SourceHook_FHCls_INetChannelHandlerFileReceived0::Func(char const*, unsigned int) ()
   from /home/lordmarqus/MAP-Dev/srcds_1/orangebox/cstrike/addons/dfens/bin/dfens_mm_i486.so
#0  0x005bd082 in __SourceHook_FHCls_INetChannelHandlerFileReceived0::Func(char const*, unsigned int) ()
   from /home/lordmarqus/MAP-Dev/srcds_1/orangebox/cstrike/addons/dfens/bin/dfens_mm_i486.so
File is uploaded correctly, server fails when players download this file. I tested it with only me as a player and after crash it works without problems. So, something is not right just after file is uploaded I guess.
__________________
My public plugins: [CS:S/CS:GO] Last Man Standing
LordMarqus is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 20:45.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode