Raised This Month: $51 Target: $400
 12% 

D-FENS - Patch for upload/download server file exploit. (Updated 05-10-2010)


Post New Thread Reply   
 
Thread Tools Display Modes
voogru
Inspector Javert
Join Date: Oct 2004
Old 12-06-2009 , 20:38   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #71

Quote:
Originally Posted by WebNoob View Post
So...with a TF2 install, and Metamod 1.7.1, the .vdf should look like this?

How can I verify it is loaded? Where does the log output info?
meta list.
voogru is offline
Ninjadude101
Junior Member
Join Date: Dec 2009
Old 12-06-2009 , 20:58   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #72

Hey voogru, do you know when the update will be done?

The path to add is /cache, thanks.
Ninjadude101 is offline
voogru
Inspector Javert
Join Date: Oct 2004
Old 12-06-2009 , 23:14   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #73

Quote:
Originally Posted by Ninjadude101 View Post
Hey voogru, do you know when the update will be done?

The path to add is /cache, thanks.
I saw your post the first time I'll try to get something in by the next day or so.
voogru is offline
Ninjadude101
Junior Member
Join Date: Dec 2009
Old 12-06-2009 , 23:52   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #74

Apologies for my being impatient. I understand you have other important things to do.

It's just my customers are also asking me a lot.

Thanks.
Ninjadude101 is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 12-07-2009 , 17:52   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #75

Quote:
Originally Posted by lake393 View Post
Got a question:

I'm using a firewall to block TCP, and only allow a whitelisted set of IP addresses.

This means my server no longer gets ranked by GameTracker.


--http://forums.gametracker.com/faq.ph...manage_servers

Does anybody happen to have a work-around for this... such as a list of their IPs to whitelist?

Thanks
I can tell you with 100% certainty that gametracker does not use TCP for scanning Source based servers. Also, this is horribly off topic for this thread, so post on the gametracker forums if you need more information.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Kevin_b_er
SourceMod Donor
Join Date: Feb 2009
Old 12-07-2009 , 22:37   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #76

Well this was supposedly patched tonight in TF2 and DoD:S, maybe. (Somehow I doubt valve got all the possibilities, plus what about vdf and dll files?!)

Nothing seems to have changed for CSS or L4D series.
Kevin_b_er is offline
raydan
Senior Member
Join Date: Aug 2006
Old 12-07-2009 , 22:51   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #77

Quote:
Originally Posted by Kevin_b_er View Post
Well this was supposedly patched tonight in TF2 and DoD:S, maybe. (Somehow I doubt valve got all the possibilities, plus what about vdf and dll files?!)

Nothing seems to have changed for CSS or L4D series.
because valve doesn't want patch all security hole (like vdf, dll), they must keep them private, so that valve can hack you server any time (like ms windows)
raydan is offline
DontWannaName
Veteran Member
Join Date: Jun 2007
Location: VALVe Land, WA
Old 12-07-2009 , 22:59   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #78

Ya, I dont trust Valve so Im not removing this yet, perhaps someone who knows the exploit can make sure it was fixed.
__________________

DontWannaName is offline
MadMakz
SourceMod Donor
Join Date: Oct 2008
Old 12-08-2009 , 09:34   Re: D-FENS - Emergency patch against downloading server files. (Updated 11-29-2009)
Reply With Quote #79

Quote:
Originally Posted by egor1908 View Post
...

i cant get it to run on my L4D-1 server.
Quote:
meta load addons/D-FENS/bin/dfens_mm_i486_l4d.so

Failed to load plugin addons/D-FENS/bin/dfens_mm_i486_l4d.so (/usr/local/games/~/l4d/left4dead/addons/D-FENS/bin/dfens_mm_i486_l4d.so: undefined symbol: _Unwind_Resume).
same here
__________________
MadMakz is offline
nomy
Senior Member
Join Date: Dec 2009
Location: United Kingdom
Old 12-08-2009 , 14:59   Re: D-FENS - Patch for upload/download server file exploit. (Updated 11-29-2009)
Reply With Quote #80

valve.rc can still get uploaded.
nomy is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 15:18.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode