Forum archive — a preserved copy of the VentMob forums (2008–2011), rebuilt from Wayback Machine captures. Skin: 2009 | 2011 · Back to the memorial

Thread: Downtime

Only part of this thread survives: 75 posts were captured (some pages are missing). Posts are shown in the order they were written.
  1. #10037066
    Applejack Lead Developer
    Join Date
    Dec 2008
    Posts
    1,555

    Re: Downtime

    I wouldn't download them, whoever exploited to get them could well have packed extra presents in there with them.

    There aren't any. It's just lua files and you can't do much with those. Read every line if you'd like, you will find nothing that wasn't already on those servers.
    Someone's tracking referrer urls. :o
    I code your babies.


  2. #10037067
    Donator
    Join Date
    Dec 2008
    Posts
    711

    Re: Downtime

    Seems so.

  3. #10037102
    Super Donator
    Join Date
    Jul 2009
    Posts
    33

    Re: Downtime

    Here's what I don't understand:

    1. The exploit doesn't prevent servers for gmod from existing, and many big name RP servers are still up, so why did VM pull theirs?

    2. Even so, I barely see any servers even remotely affected by this, and it seems to have only been noticed as other games have been patched and gmod hasn't.

    So what the fuck is up with all of this bullshit? It seems like fucking swine flu! (IE: something that seems serious, but has been going on forever and ever and NOW everyone is making a big stink about it)

    Furthermore, It looks as though VM has pulled their servers for the exclusive purpose of saying FU to Garry(http://www.facepunch.com/showthread.php?t=798387) (which in truth is really stupid as Garry knows the problem exists and has admitted that, as someone who really doesn't know the source engine's code, he can't do anything for now until valve helps him)

    In closing, Please reinstate the servers, this is bullshit. If you're so paranoid about people fucking with the server, maybe you should recruit some admins that are at least 17? (not to imply that your admins are kids, I'm just saying it helps to have admins with more maturity, yanno?)


    TL;DR
    BAWWWWWWW I WANT THE SERVER BACK!!!!!11!!!111one

    In short, the exploit allows people to upload any file to anywhere on the machine.

    From a GMod perspective - You could put a lua script to make everyone who connects download the entire contents of the gamemode folder.

    Non-GMod perspective - You could upload a malicious executable into the computers startup folder, potentially allowing someone to seize control of the server.

    The exploit also allows you to delete files from the target machine, so someone could quite happily destroy the operating system and render the machine useless for a time.

  4. #10037108
    V.I.P
    Join Date
    Dec 2008
    Posts
    333

    Re: Downtime

    Gentlemen.

    [-]September 10, 2009 - Source 2007 Engine Update Released

    Updates to the Source 2007 Engine have been released. The updates will be applied automatically when your Steam client is restarted. The specific changes include:

    Source 2007 Engine


    Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system

    Fixed a server crash caused by a client packet claiming to be an HLTV client when HLTV is disabled on the server

    Fixed a server crash caused by spoofing a client disconnect message

    Fixed a server crash caused by sending malformed reliable subchannel data


    I believe the serious exploit is now fixed.

  5. #10037109
    Super Administrator
    Join Date
    Nov 2008
    Posts
    2,573

    Re: Downtime

    Gentlemen.

    [-]September 10, 2009 - Source 2007 Engine Update Released

    Updates to the Source 2007 Engine have been released. The updates will be applied automatically when your Steam client is restarted. The specific changes include:

    Source 2007 Engine


    Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system

    Fixed a server crash caused by a client packet claiming to be an HLTV client when HLTV is disabled on the server

    Fixed a server crash caused by spoofing a client disconnect message

    Fixed a server crash caused by sending malformed reliable subchannel data


    I believe the serious exploit is now fixed.


    We are aware, waiting for Lexi or Drewley to respond on steam. We will keep you informed!

    Follow me on Twitter! www.twitter.com/letomg0

  1. #?
    Lost to time
    Missing posts

    More posts existed here

    The Wayback Machine never archived them.
    What you see above is everything that survived of this thread. The rest of the conversation is gone.

Users Browsing this Thread: 2 (0 members and 2 guests)