Raised This Month: $32 Target: $400
 8% 

CSGO server lagger exploit might have migrated to Team Fortress 2


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Oshizu
Veteran Member
Join Date: Nov 2012
Location: Warsaw
Old 05-03-2018 , 15:33   CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #1

Hiya,

I just wanted to give you guys heads-up that recently discovered exploit in CSGO might be abused in TF2 aswell at the moment.

The VoiceData one:
https://forums.alliedmods.net/showthread.php?t=280545

My community probably have just been attacked by it
Basically a specific player, their profile here: https://steamcommunity.com/profiles/76561198368497255/
As soon as he finished joining, voice netchannel was flooded, server choking.
Also there was this message spammed in server's console:
Code:
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
Netchannel: failed reading message clc_VoiceData from 100.16.124.112:27005.
As soon as staff muted this player the issue was gone. And once they were unmuted the issue was back. sv_voiceenable set to 0 seemed to do the trick aswell.

I plan making lazy fix because I can't be bothered to write sm extension atm:

Simplest but not really optimal solution is setting sv_voiceenable to 0
Second one would be hooking console print and setting sv_voiceenable to 0 for x amount of minutes when " failed reading message clc_VoiceData" spam reaches specific threshold
Third one would be hooking console print and banning player & their ip if their clc_VoiceData spam reaches specific threshold.
Fourth one would either need to be sm extension or metamod plugin but I don't have ambuild setup atm so nah.

As for why I think it's attack rather than engine/client bug. It's first time this kind of stuff happened. Second one of this player's who lagged the server past nicknames was "failed reading message svc_Voice", too much coincidence eh?

I've attached aswell two pics in my post, first showing their profile, second net_graph while server was flooded

Im kinda busy these days so I don't know whether I'il be able to write exploit fix myself, so I wanted to let you guys know just in case
- Cheers
Attached Images
File Type: jpg voicedata.jpg (76.0 KB, 416 views)
File Type: jpg voicedata2.jpg (90.9 KB, 551 views)

Last edited by Oshizu; 05-03-2018 at 15:48.
Oshizu is offline
VPPGamingNetwork
Veteran Member
Join Date: Sep 2012
Location: Japan
Old 05-03-2018 , 16:27   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #2

will the csgo fix plugin block this on tf2?
__________________

We provide MOTD Ads
Net 1 payments
Visit us
VPPGamingNetwork is offline
Dr.Mohammad
Senior Member
Join Date: Jan 2016
Location: CSGO Servers
Old 05-04-2018 , 02:29   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #3

new bug, server time out for this log:
https://forums.alliedmods.net/showpo...&postcount=123

please fix.
i before installed VoiceDataFix.smx plugin.
Dr.Mohammad is offline
jillchang917
Member
Join Date: Dec 2017
Old 06-12-2018 , 07:05   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #4

Which csgofix are you guys referring to? I'm getting this issue on my tf2servers as well and getting crashes on map change.
jillchang917 is offline
Naydef
Senior Member
Join Date: Dec 2015
Location: Doom Town, Nevada
Old 06-12-2018 , 10:39   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #5

I don't know if anyone noticed, but the steam profile of the player has link to the code used for lagging. Might be useful for preventing exploit
__________________
My plugins:
*None for now*


Steam:
naydef

Last edited by Naydef; 06-12-2018 at 10:43.
Naydef is offline
ambn
Veteran Member
Join Date: Feb 2015
Location: Fun servers
Old 06-12-2018 , 11:04   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #6

well, by using regular expressions i was able to catch the ip of the attacker ( actually the ip which appears on the server's console with the following message in the first post more than 5 times which is customizable by your selves) and ban them though the conosle by banid 0 userid.

actually i didn't tested it with banid command but it worked for me on my servers.

give it a try.

REQUIRES PTaH
Attached Files
File Type: sp Get Plugin or Get Source (af.sp - 316 views - 1.9 KB)
File Type: smx af.smx (5.6 KB, 302 views)
__________________

Last edited by ambn; 06-12-2018 at 11:08.
ambn is offline
kaeming
Senior Member
Join Date: Nov 2015
Old 06-12-2018 , 12:34   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #7

just manually ban them, you have no other solution as of now.
__________________
Add me up HERE if you have inquiries regarding server related stuff!
CS:GO Multimod & Jailbreak Servers > I am selling my entire ready to play server, add me up on steam to discuss.
kaeming is offline
StealtHack
Member
Join Date: Jun 2013
Location: The Netherlands
Old 07-04-2018 , 16:54   Re: CSGO server lagger exploit might have migrated to Team Fortress 2
Reply With Quote #8

Today I start getting them and people timed out after the spam. Valve please fix.

Code:
Msg from 97.123.20.220:27005: clc_VoiceData msg rejected (130 bytes)
Msg from 97.123.20.220:27005: clc_VoiceData msg rejected (130 bytes)
Msg from 97.123.20.220:27005: clc_VoiceData msg rejected (130 bytes)
Msg from 97.123.20.220:27005: clc_VoiceData msg rejected (130 bytes)
I'll give @ambn fix a try.
StealtHack is offline
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 00:28.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode