Raised This Month: $51 Target: $400
 12% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


Post New Thread Reply   
 
Thread Tools Display Modes
empmdk
Junior Member
Join Date: Mar 2010
Old 03-07-2010 , 10:52   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #231

Quote:
Originally Posted by Allstar View Post
You need to have the vdf point towards the file.

So edit your vdf like this:

Code:
"Metamod Plugin"
{
    "alias"        "D-FENS"
    "file"        "addons/D-FENS/bin/dfens_mm_i486_og.so"
}
Ah,Thanks. Working now
empmdk is offline
Cooltad
Veteran Member
Join Date: Apr 2008
Old 03-07-2010 , 11:13   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #232

Don't use a vdf. Save yourself a headache and just modify the ini.
__________________
Please, give me some rep if you found what I posted useful. :]
Cooltad is offline
zerosin
Member
Join Date: Sep 2005
Location: San Francisco
Old 03-08-2010 , 21:16   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #233

Quote:
Originally Posted by bobdole View Post
better yet set your rcon in the launch properties?

if you cant do that create a config with an original name and edit the valve.rc to run that new config with the server.cfg on startup

if they can read your server.cfg (i dont know how i whould think to be able to read it whould mean you whould need to download it) they will know u are calling another config and if they can read the server.cfg chances are they can read any
Hi Bob,
Just wondering, if I were to use it in launch properties, how would it look like in commandline? So, obviously in rcon_password "" would be nothing, right? And would RconLock be still used concurrently?.

BTW, everyone, I just got hacked a few days ago, by someone up in Seattle, have tracked him and his cronies. Had every other security tool, except this one.

Thanks everyone for your hardwork to keep our communities up & fun. If I ever do come across any of these script kiddies, I will bash them in instead of calling the Feds. Already did that to a few kids before, reporting it is just a slap on the wrist, they need a "wake the f*%k up" b!tch slap. Sorry, I'm just a little pissed when I just got out of surgery and have to deal with a bunch of hacked servers... I'm so over these kids nowadays..

Peace,
zero

Last edited by zerosin; 03-08-2010 at 21:19.
zerosin is offline
FrozenHaxor
Senior Member
Join Date: Jun 2009
Location: Poland
Old 03-09-2010 , 23:24   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #234

Throw in your command line +rcon_password <pass>

I suggest you running D-FENS, DAF and KAC.

Also check in your DM plugins folder if there is nothing weird inside (malicious plugin), for example called sourceadmin.smx or hax.smx

Cheers.
FrozenHaxor is offline
bobdole
SourceMod Donor
Join Date: May 2008
Location: Houston,Texas
Old 03-10-2010 , 05:34   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #235

if you keep your rcon_lock updated then it will deleate all the know bad plugin names automaticly on map start, you also get all of the bug fixes that any other plguin offers (i know myself dont run KAC nor want to run it)
bobdole is offline
zerosin
Member
Join Date: Sep 2005
Location: San Francisco
Old 03-10-2010 , 19:18   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #236

Thanks guys,

@ FrozenHaxor
So in server.cfg do I take out the rcon_password "" like this? Or just take it out of server.cfg completely?

@bobdole
I have rcon_lock running ATM, with the latest build, can I use it concurrently with having +rcon_password <12345> in the command instead of server.cfg?

Personal question, why don't you run KAC? I understand the beta version has bugs in it still, but why not use KAC?

Other than that, thanks everyone for putting their effort in helping out to stamp these script kiddies back in their hole.

Really... I just want to play the game, and my community to enjoy playing on our servers.

Cheers
zero
zerosin is offline
bobdole
SourceMod Donor
Join Date: May 2008
Location: Houston,Texas
Old 03-10-2010 , 20:53   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #237

yes just remove the command from server.cfg completely.

and yes rcon_lock will still function, rcon lock simply gets the rcon by seeing what it is set to from the cvar rcon_password. what your doing is simply defining your cvar in a place where outside eyes can't see it.

and i chose not to run KAC for the pure reason that his beta version does not support a non-sockets version (i could easaly modify it to not need sockets but why take the time) and i also dont like to hear that the reason is because he dosnt want to support two different builds when he can simply have a cvar that can turn off or on the network features (or even detect if sockets is installed on the server and disable newtork events then) its not but a few extra lines of code but for some reason still refuses to do it.
bobdole is offline
Kigen
BANNED
Join Date: Feb 2008
Old 03-15-2010 , 04:54   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #238

Its mainly due to laziness. Most people would not install Sockets due to laziness rather than because of any valid issues. By not installing Sockets you limit the functionality of KAC. The next major version of KAC (1.3) will rely heavily on its ability to communicate to a master server to fight cheaters. Right now if I have a CVar that needs to be added or a command that crashes a server blocked I have to update the entire plugin, in KAC 1.3 this will be significantly changed so that it is just added in the server in real time without the need to reload the plugin.

If what I am doing now doesn't get people to get Sockets then it will be mayhem when I release KAC 1.3.

So my question to you is what is your issue with installing Sockets?

And before anyone says I owe anyone anything please do remember that KAC is provided free to everyone and I get no benefit from providing it to anyone. Plus I am alone as far as development on the project is concerned and KAC is a complex project.
Kigen is offline
lhffan
Senior Member
Join Date: Jul 2008
Old 03-18-2010 , 12:52   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #239

Quote:
Originally Posted by cmptrgk View Post
You need two different users. One user owns the server files and can add modules and edit configuration. The other user is the user the server runs as, and can read all of the files in the server installation, but can only write to the logs, sprays and data directories. If you have a hosted server, they would need to support this kind of configuration.

You definitely should NOT be running your server as root, or administrator in windows.
What exact dirs is:
sprays
data directorys
lhffan is offline
SmackDaddy
Veteran Member
Join Date: Oct 2009
Old 03-19-2010 , 13:42   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #240

What is the difference between using DFENS and the DDOS blocker for metamod?
SmackDaddy is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:59.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode