Raised This Month: $51 Target: $400
 12% 

Old-new client-side DoS exploit [CS v1.6]


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Seikk.
Junior Member
Join Date: Feb 2016
Old 02-21-2016 , 03:06   Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #1

Hi all!
I apologize in advance for their knowledge of the English language.

Since Alfred sees no need to fix it, then said:

Many remember the vulnerability with labels when required to write a couple of labels and all the players have read the message, crash (> 192 characters at the inlet). Functioning, it is actually using AMXX, but the bug is in the game client.

So, the bug can be reproduced without the help AMXX (no, I do not mean "rcon say" chat-channel) - in HLTV spectators chat-channel. That's right, you can check:
1. Connect HLTV server with CVar chatmode '1' (So far, the only protection to the value '0');
2. Write in the chat "#CStrike_GIGN_Label #CStrike_GIGN_Label" (as an example, a lot of options);
3. Done! Any major broadcast, with dozens of spectators and commentator cut short!

Bug urgent need to correct! Or maybe not? In any case, Alfred silent second week...
Each will make conclusions for themselves.

Thanks.
Seikk. is offline
simanovich
AlliedModders Donor
Join Date: Jun 2012
Location: Israel
Old 02-24-2016 , 00:40   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #2

This was fixed almost 3 years ago.
__________________
simanovich is offline
Seikk.
Junior Member
Join Date: Feb 2016
Old 02-24-2016 , 01:49   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #3

Quote:
Originally Posted by simanovich View Post
This was fixed almost 3 years ago.
True? I use the Steam beta client and beta hltv server downloaded from SteamCMD (6153 build, v1.1.2.7).
Seikk. is offline
simanovich
AlliedModders Donor
Join Date: Jun 2012
Location: Israel
Old 02-24-2016 , 06:44   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #4

Quote:
Originally Posted by Seikk. View Post
True? I use the Steam beta client and beta hltv server downloaded from SteamCMD (6153 build, v1.1.2.7).
The last time I checked, which is about 1 year ago, it doesn't do anything a just show me "#CStrike_GIGN_Label" in the chat. Used updated client & server with beta, no metamod or amxmodx
__________________
simanovich is offline
Seikk.
Junior Member
Join Date: Feb 2016
Old 02-24-2016 , 10:04   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #5

Quote:
Originally Posted by simanovich View Post
The last time I checked, which is about 1 year ago, it doesn't do anything a just show me "#CStrike_GIGN_Label" in the chat. Used updated client & server with beta, no metamod or amxmodx
Without metamod/amxmodx bug works in server 'say' cmd (or client 'rcon say' cmd) chat-channels on game server and client 'say' cmd on hltv server. Try it.
Seikk. is offline
safetymoose
Senior Member
Join Date: Feb 2015
Old 02-24-2016 , 15:41   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #6

https://forums.alliedmods.net/showpo...7&postcount=28
safetymoose is offline
Seikk.
Junior Member
Join Date: Feb 2016
Old 02-24-2016 , 16:05   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #7

Quote:
Originally Posted by safetymoose View Post
And how you offer to install the mm-plugin on HLTV server? Btw, long since a new 2.4 version was released.
Seikk. is offline
addons_zz
Veteran Member
Join Date: Aug 2015
Location: Dreams, zz
Old 02-25-2016 , 02:44   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #8

A server hosted by the site hltv.org? You cannot install plugins? Lets they deal with it.
__________________
Plugin: Sublime Text - ITE , Galileo
Multi-Mod: Manager / Plugin / Server

Support me on Patreon, Ko-fi, Liberapay or Open Collective
addons_zz is offline
Seikk.
Junior Member
Join Date: Feb 2016
Old 02-25-2016 , 13:48   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #9

Quote:
Originally Posted by addons_zz View Post
A server hosted by the site hltv.org?
Quote:
Originally Posted by Seikk.
beta hltv server downloaded from SteamCMD (6153 build, v1.1.2.7)
Perhaps you misunderstood me. Why we are talking about hosting? HLTV, in my context, is a SOFTWARE, not a HARDWARE. Re-read the first post I write bad English.

Yea, bug with labels in chat works on HLTV server between spectators. How to deal with it, if on HLTV is impossible to install MetaMod? The only protection - chat close (CVar chatmode '0').
Seikk. is offline
addons_zz
Veteran Member
Join Date: Aug 2015
Location: Dreams, zz
Old 02-25-2016 , 15:57   Re: Old-new client-side DoS exploit [CS v1.6]
Reply With Quote #10

HLDS is the server, HLTV is a client which connect to HLDS server and "HLTV Server" means a HLDS server hosted by hltv.org

Beyond it I do not what does you mean by "HLTV Server".
__________________
Plugin: Sublime Text - ITE , Galileo
Multi-Mod: Manager / Plugin / Server

Support me on Patreon, Ko-fi, Liberapay or Open Collective
addons_zz is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 17:17.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode