Raised This Month: $32 Target: $400
 8% 

Urgent: New security bug?


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
blaacky
Senior Member
Join Date: Oct 2012
Old 04-19-2014 , 06:14   Urgent: New security bug?
Reply With Quote #1

Where can I report this privately? It's about as bad as it can get.

EDIT: Apparently this bug hit hard on many servers, especially in Garry's Mod. It lets players see into the server.cfg file and retrieve the rcon password. I'm told setting sv_allowdownload to 0 will fix it.

Last edited by blaacky; 04-19-2014 at 08:46.
blaacky is offline
hamilton5
Veteran Member
Join Date: Oct 2012
Location: USA
Old 04-19-2014 , 07:03   Re: Urgent: New security bug?
Reply With Quote #2

oh the humanity don't play teh wavzzzz windowzzz
hamilton5 is offline
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 04-19-2014 , 08:34   Re: Urgent: New security bug?
Reply With Quote #3

The best way is to file a bug. Bugs in the AM Security component are visible only to members of the core team.
__________________
asherkin is online now
psychonic

BAFFLED
Join Date: May 2008
Old 04-19-2014 , 12:57   Re: Urgent: New security bug?
Reply With Quote #4

It should be noted that this is not a bug in SourceMod, but rather a bug in the Source Engine.
psychonic is offline
Powerlord
AlliedModders Donor
Join Date: Jun 2008
Location: Seduce Me!
Old 04-19-2014 , 13:27   Re: Urgent: New security bug?
Reply With Quote #5

There was already a conversation going about this bug on the hlds mailing list.
__________________
Not currently working on SourceMod plugin development.
Powerlord is offline
nikooo777
AlliedModders Donor
Join Date: Apr 2010
Location: Lugano, Switzerland
Old 04-19-2014 , 13:38   Re: Urgent: New security bug?
Reply With Quote #6

I was also hit!
But it happened on counter strike source.
Is there any connections with it?
__________________

Last edited by nikooo777; 04-19-2014 at 13:45.
nikooo777 is offline
AeroAcrobat
AlliedModders Donor
Join Date: Apr 2011
Location: lives in a circus
Old 04-19-2014 , 14:34   Re: Urgent: New security bug?
Reply With Quote #7

http://facepunch.com/showthread.php?...1#post44589068

Anything to take care of or looking for files?
Should we set [TF2] sv_allowupload 0;sv_allowdownload 0 ?

I'm a bit worried because of the lack of info :/
__________________
AeroAcrobat is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 04-19-2014 , 15:41   Re: Urgent: New security bug?
Reply With Quote #8

Would be nice if someone fixed this: https://forums.alliedmods.net/showthread.php?t=142249
__________________
Fearts is offline
AeroAcrobat
AlliedModders Donor
Join Date: Apr 2011
Location: lives in a circus
Old 04-19-2014 , 15:48   Re: Urgent: New security bug?
Reply With Quote #9

Quote:
Originally Posted by Fearts View Post
Would be nice if someone fixed this: https://forums.alliedmods.net/showthread.php?t=142249
What about: https://forums.alliedmods.net/showth...6541&page=2#16
__________________
AeroAcrobat is offline
blaacky
Senior Member
Join Date: Oct 2012
Old 04-19-2014 , 16:03   Re: Urgent: New security bug?
Reply With Quote #10

It happened in Counter-Strike:Source for me as well. Forgot to mention that.

Last edited by blaacky; 04-19-2014 at 18:02.
blaacky is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 19:05.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode