Raised This Month: $ Target: $400
 0% 

Exploit being used to spam servers.


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Horsedick
AlliedModders Donor
Join Date: Sep 2011
Old 12-29-2014 , 09:15   Exploit being used to spam servers.
Reply With Quote #1

I posted about this in the other thread about /ff but here it is.

http://steamcommunity.com/groups/FriendlyFireAwareness

This group of thieves here, took me a few minutes to narrow down who was doing it as it was rather annoying.

Needless to say all of them were banned that I could find involved, and to even make me more annoyed is they stole out map to use on their worthless server. A map that took me and the main designer nearly 3months to make.

Take a look at the group page there and it will show you what they were using to spam servers.
Horsedick is offline
Mitchell
~lick~
Join Date: Mar 2010
Old 12-29-2014 , 09:42   Re: Exploit being used to spam servers.
Reply With Quote #2

1, this has been around for years.
2, why do you have the wait command enabled? (i know a few scripts clients use it.) there are a some plugins to prevent the use of commands within a set amount of time.
3, Why didn't the mapper add some kind of protection to his map to prevent that. (i always do something with a plugin so the plugin will remove blocks from the spawn, etc. Most people who steal map can't figure out how to get past these simple blocks. (trigger_hurts over the spawn, and trigger_teleports that don't work are the easiest.)
Mitchell is offline
ddhoward
Veteran Member
Join Date: May 2012
Location: California
Old 12-29-2014 , 10:07   Re: Exploit being used to spam servers.
Reply With Quote #3

Quote:
Originally Posted by Mitchell View Post
2, why do you have the wait command enabled?
I have privately distributed several scripts which rely on looping aliases. For example, "tradeloop" is a script that loops through a customizable list of messages and sends one through the chat every minute or so, which is really useful on trade servers. Another, "statusloop", automatically calls the "status" command every 2 minutes, thus preserving this information in my conlog. (statusloop is really irrelevant to me now, though, since I was given FTP access to the server I normally play on)

Joining a server with wait disabled while a looping alias is running will cause the client to crash.
__________________
ddhoward is offline
Mitchell
~lick~
Join Date: Mar 2010
Old 12-29-2014 , 10:14   Re: Exploit being used to spam servers.
Reply With Quote #4

Quote:
Originally Posted by ddhoward View Post
I have privately distributed several scripts which rely on looping aliases. For example, "tradeloop" is a script that loops through a customizable list of messages and sends one through the chat every minute or so, which is really useful on trade servers. Another, "statusloop", automatically calls the "status" command every 2 minutes, thus preserving this information in my conlog. (statusloop is really irrelevant to me now, though, since I was given FTP access to the server I normally play on)

Joining a server with wait disabled while a looping alias is running will cause the client to crash.
Sorry, i knew that already, i was pointing out the fact he could've disabled it while he was looking for a fix or something for the instance he was being attacked.
Mitchell is offline
Horsedick
AlliedModders Donor
Join Date: Sep 2011
Old 12-29-2014 , 10:28   Re: Exploit being used to spam servers.
Reply With Quote #5

Quote:
Originally Posted by Mitchell View Post
Sorry, i knew that already, i was pointing out the fact he could've disabled it while he was looking for a fix or something for the instance he was being attacked.
I'm open for a perm fix..as for the map yes I'm working on revisions now and will include a kill edict to prevent it from running without a plugin running. Only issue with doing this (that I'll have to suck up) is if SM is broken a while I'll just have to keep the server down till updated.


Edit: Ohh and I did turn off basetriggers to stop the flooding but I was having difficulty tracking down who was doing it at first so I was letting it spam while I looked at logs or anything to point to the client. Not easy to do with a 7year old wanting something, wife needing something and whatever else going on thru several servers at once ya know ;)

Last edited by Horsedick; 12-29-2014 at 10:29.
Horsedick is offline
Mitchell
~lick~
Join Date: Mar 2010
Old 12-29-2014 , 10:55   Re: Exploit being used to spam servers.
Reply With Quote #6

Quote:
Originally Posted by Horsedick View Post
I'm open for a perm fix..as for the map yes I'm working on revisions now and will include a kill edict to prevent it from running without a plugin running. Only issue with doing this (that I'll have to suck up) is if SM is broken a while I'll just have to keep the server down till updated.


Edit: Ohh and I did turn off basetriggers to stop the flooding but I was having difficulty tracking down who was doing it at first so I was letting it spam while I looked at logs or anything to point to the client. Not easy to do with a 7year old wanting something, wife needing something and whatever else going on thru several servers at once ya know ;)
Usually stripper doesn't stop working when SM does.
Mitchell is offline
Horsedick
AlliedModders Donor
Join Date: Sep 2011
Old 12-29-2014 , 11:14   Re: Exploit being used to spam servers.
Reply With Quote #7

Quote:
Originally Posted by Mitchell View Post
Usually stripper doesn't stop working when SM does.
Are you saying adding a kill edict to prevent it running without a plugin enabled won't work as stripper will just circumvent this?
Horsedick is offline
Mitchell
~lick~
Join Date: Mar 2010
Old 12-29-2014 , 11:20   Re: Exploit being used to spam servers.
Reply With Quote #8

Quote:
Originally Posted by Horsedick View Post
Are you saying adding a kill edict to prevent it running without a plugin enabled won't work as stripper will just circumvent this?
If you are writing a plugin to remove a certain entity, you could just use stripper: source or w/e instead of writing a new plugin. You were implying that you would have issues if SM needed updated and the map wouldn't work as needed. Using stripper would go around this since it isn't part of SM.. I could've misunderstood you though.

Last edited by Mitchell; 12-29-2014 at 11:20.
Mitchell is offline
Horsedick
AlliedModders Donor
Join Date: Sep 2011
Old 12-29-2014 , 11:23   Re: Exploit being used to spam servers.
Reply With Quote #9

Quote:
Originally Posted by Mitchell View Post
If you are writing a plugin to remove a certain entity, you could just use stripper: source or w/e instead of writing a new plugin. You were implying that you would have issues if SM needed updated and the map wouldn't work as needed. Using stripper would go around this since it isn't part of SM.. I could've misunderstood you though.
No I'm going to add an entity in that unless a plugin is present the map will cause the server to crash. I'm working with another designer to do this. The current map I have which was as of last night being used on another server at least has my group name stamped on a few open locations and there are two large features that will not even show up and/or work without two custom plugins I'm running so I at least keep that advantage. Still though, I don't like how a client can just rip a BSP from their files and upload it to run on a server... Valve needs to do something to protect property.
Prob talking out my butt with that comment but ohh well.
Horsedick is offline
Horsedick
AlliedModders Donor
Join Date: Sep 2011
Old 12-29-2014 , 11:29   Re: Exploit being used to spam servers.
Reply With Quote #10

Either way - still need to find a more perm solution to the spam vs unloading basetriggers.
Horsedick is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:15.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode