Raised This Month: $51 Target: $400
 12% 

File upload exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
voogru
Inspector Javert
Join Date: Oct 2004
Old 08-20-2009 , 00:18   Re: File upload exploit fix
Reply With Quote #11

Yeah I had a crash too, had to remove the code sadly.

I run srcds as another user that has no write permissions to anything except logs and downloads anyway so don't really think I'm too vulnerable.
voogru is offline
Lethal-
Member
Join Date: Jun 2009
Old 08-20-2009 , 06:37   Re: File upload exploit fix
Reply With Quote #12

Quote:
[EXP] Exploitable FS_OPen() call!, file=addons\sourcemod\configs\admin_groups.cf g redirecting to exploits/1250764546.txt
is it supposed to do that?
Lethal- is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-20-2009 , 06:51   Re: File upload exploit fix
Reply With Quote #13

Quote:
Originally Posted by Lethal- View Post
is it supposed to do that?
I know it's tough to read a whole 1.2 page topic, but if you had...

"Blocks sourcemod from creating files." appears twice
psychonic is offline
psychonic

BAFFLED
Join Date: May 2008
Old 08-20-2009 , 07:55   Re: File upload exploit fix
Reply With Quote #14

Quote:
Originally Posted by DontWannaName View Post
Crash as a result of this?
@devicenull

Callstack:
http://psychonic.ampaste.net/f37d5f2b4
psychonic is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-20-2009 , 12:36   Re: File upload exploit fix
Reply With Quote #15

updated to attempt to fix this crash issue
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
BrutalGoerge
AlliedModders Donor
Join Date: Jul 2007
Old 08-20-2009 , 14:00   Re: File upload exploit fix
Reply With Quote #16

how easy is it for a client to take advantage of this exploit?

I just barely started to hear talk of this. thanks for the fix btw
__________________
My Pluggies If you like, consider to me.

Last edited by BrutalGoerge; 08-20-2009 at 14:05.
BrutalGoerge is offline
Hipster
SourceMod Donor
Join Date: Jun 2009
Location: Florida
Old 08-20-2009 , 15:30   Re: File upload exploit fix
Reply With Quote #17

Quote:
Originally Posted by BrutalGoerge View Post
how easy is it for a client to take advantage of this exploit?

I just barely started to hear talk of this. thanks for the fix btw
It's an external program that needs to be recompiled or hex edited for an attacker to upload a file, so you're probably safe from pissed off 13-year-olds.

Editing the source code is pretty straight-forward, though, so I think you'd be vulnerable to anyone who knows how to open and compile a C program.
Hipster is offline
ilovelamp
Junior Member
Join Date: Aug 2009
Old 08-20-2009 , 20:44   Re: File upload exploit fix
Reply With Quote #18

There is apparently a workaround, as I have this loaded on to both Windows AND Linux boxes and I have someone still overwriting my gameinfo.txt and server.cfg files.

Metamod is loading these as I've been checking in the meta list.
ilovelamp is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 08-20-2009 , 21:54   Re: File upload exploit fix
Reply With Quote #19

Quote:
Originally Posted by ilovelamp View Post
There is apparently a workaround, as I have this loaded on to both Windows AND Linux boxes and I have someone still overwriting my gameinfo.txt and server.cfg files.

Metamod is loading these as I've been checking in the meta list.
I know. I'm working with someone else to confirm I have a fix for that too before I release it.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
ilovelamp
Junior Member
Join Date: Aug 2009
Old 08-20-2009 , 22:33   Re: File upload exploit fix
Reply With Quote #20

Quote:
Originally Posted by devicenull View Post
I know. I'm working with someone else to confirm I have a fix for that too before I release it.
I know. <3

We were just testing it on my jailbreak server, after all.

Thank you for putting all this work into the fix.
ilovelamp is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 19:22.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode