Re: [hlds] New srcds exploit

2009-02-02 Thread AzuiSleet
These exploits have been around for a very long time, it's just nobody really abused them like they have been now. The obvious commands are physics_select and friends. The reason they crash a server is because the player is NULL during connect. As for the console spam, that's a side effect of

Re: [hlds] Achievement Farmer Honeypot

2009-02-25 Thread AzuiSleet
I'd use this plugin if it banned people randomly. On Wed, Feb 25, 2009 at 5:10 PM, Blood Letter bw_bloodlet...@hotmail.comwrote: I'm not pushing my beliefs or tactics on anyone Really? Achievement Farmers: Be Warned! Server admins are fighting back! You can help STOP achievement farming!

Re: [hlds] blocking the server's PLAYERNAME has joined the game message

2009-03-18 Thread AzuiSleet
Maybe someone could make a plugin that bans users for connecting AND removes the message, I bet they were only trying to farm achievements anyway. No point in letting them spoil the gameplay with a connect message. On Wed, Mar 18, 2009 at 2:42 PM, SakeFox sake...@kingdomsend.com wrote: don't

Re: [hlds] Team Fortress 2 Update Released

2009-04-20 Thread AzuiSleet
4/20 special feature, delete your stuff. I was high when I coded it. On Mon, Apr 20, 2009 at 6:33 PM, Jason Ruymen jas...@valvesoftware.comwrote: A required update for Team Fortress 2 is now available. Please run hldsupdatetool to receive. The specific changes include: Game Changes: -

Re: [hlds] Team Fortress 2 Update Released

2009-04-20 Thread AzuiSleet
It may be that they're turning it into an RPG, where you pick up a rocket launcher + 3, and you can decide to delete it in your backpack. On Mon, Apr 20, 2009 at 6:41 PM, Jeff Sugar jeffsu...@gmail.com wrote: - Added the ability for players to permanently delete items from their inventory

Re: [hlds] Stealing Accounts

2009-04-25 Thread AzuiSleet
Let this thread die. Sent from my Personal Computer. On Sat, Apr 25, 2009 at 5:09 PM, Saul Rennison saul.renni...@gmail.comwrote: Didn't you just post jailbait? End of topic-- let it die please. Sent from my iPhone On 25 Apr 2009, at 23:47, Karl Weckstrom k...@weckstrom.com wrote:

[hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can fix this instead of us having to fix every exploit they ignore? ___ To unsubscribe, edit your list

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
PM, AzuiSleet azuisl...@gmail.com wrote: It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can fix this instead of us having to fix every exploit they ignore

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
It doesn't freeze, the bell character \7 freezes when it's printed. On Sun, May 3, 2009 at 5:17 PM, Yaakov Smith m4ngr...@gmail.com wrote: But what does it actually do? (apart from freezing servers) ___ To unsubscribe, edit your list preferences, or

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
~_~. @AzuiSleet what do you mean? It freezes when it prints \x07, yes. AKA lags. Sent from my iPhone On 4 May 2009, at 00:23, 1nsane 1nsane...@gmail.com wrote: Sends messages. A quick search got this: A2C_PRINT from 68.142.72.250:27011 : No challenge for your address. A2C_PRINT from

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
just make a new line. Sent from my iPhone On 4 May 2009, at 00:32, AzuiSleet azuisl...@gmail.com wrote: Or if you want to be really clever and cover up the message you can do \xFF\xFF\xFF\xFFl\rhello \n On Sun, May 3, 2009 at 5:29 PM, Saul Rennison

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
now... is it not? On Sun, May 3, 2009 at 7:37 PM, Cc2iscooL cc2isc...@gmail.com wrote: You guys do a good job of exposing your servers :) with this info the kiddies will get worse most likely since half the script kiddies watch this list for new commands to run. On 5/3/09, AzuiSleet

Re: [hlds] Referenced Memory

2009-05-04 Thread AzuiSleet
You should check the mdmp. On Mon, May 4, 2009 at 10:40 PM, Mike Stiehm mikesti...@gmail.com wrote: Hay your the power admin LOL How many people see this error? Kenny Loggins ClanAO.com On May 4, 2009, at 11:23 PM, Surplus Power Admin admin.surpluspo...@gmail.com wrote: Lately,

Re: [hlds] Vac Ban for Idle program @ Source Op?

2009-06-01 Thread AzuiSleet
Maybe someone could make a sourcemod plugin that bans people for standing still. They could have been idling. On Mon, Jun 1, 2009 at 1:56 PM, Cc2iscooL cc2isc...@gmail.com wrote: Lollypop? On 6/1/09, msleeper mslee...@cyberwurx.com wrote: What are you talking about? I'm refering to the VAC

Re: [hlds] Error On Steam Client

2009-08-26 Thread AzuiSleet
On the topic of odd steam bugs, I always get random context menus stuck in the upper left of my screen. On Wed, Aug 26, 2009 at 6:34 AM, Jeff Sugar jeffsu...@gmail.com wrote: What does this have to do with servers On Wed, Aug 26, 2009 at 5:29 AM, AJ King pcmaster...@hotmail.com wrote: I

Re: [hlds] [TF2] Valve using their special weapons

2009-09-08 Thread AzuiSleet
You're all forgetting the easy solution, unlock the items interface and let anyone make items. On Tue, Sep 8, 2009 at 5:57 PM, Alec Sanger eclyp...@hotmail.com wrote: wat Thank you, Alec Sanger P: 248.941.3813 F: 313.286.8945 Date: Tue, 8 Sep 2009 19:50:16 -0400 From:

[hlds] Source Engine Upload/Download POC

2009-11-29 Thread AzuiSleet
It seems the upload/download exploits aren't dead yet, and Valve didn't do a good job at patching them. A blacklist didn't work too well. Here is a serverplugin POC to upload and download files. It's fairly trivial to use: download_file cfg/server.cfg upload_file addons/serverplugin_sample.dll

Re: [hlds] Source Engine Upload/Download POC

2009-11-29 Thread AzuiSleet
Yes well you can ignore those fools. They like to vandalize my pastebin. On Sun, Nov 29, 2009 at 3:55 AM, cnu bsh...@broadpark.no wrote: On Sunday 29 November 2009 10:26:50 AzuiSleet wrote: Source: http://azu.pastebin.com/m1cd1ab0b You got some other interesting pastes here :p http

Re: [hlds] watch out lua script cheat available in CSS, may be all source game soon

2010-02-08 Thread AzuiSleet
Looking at those scripts, they aren't much different than what plagued GMod a while. It's mostly a bunch of scripts that run a console command a bunch (physics_budget) and some that run commands during the connect phase. In TF2 it was fixed and there are plenty of plugins to block console commands

Re: [hlds] Plugin Loading on clients, enough is enough.

2010-04-02 Thread AzuiSleet
So consider Valve does disable clientside plugins, what will change? Absolutely nothing. All the cheaters will continue to use their cheats that don't rely on clientside plugins. Everyone else will use a network proxy, which can replication all the malicious exploits you're worried about. With a

Re: [hlds] CSS: Long disconnect messages crashing servers?

2010-04-26 Thread AzuiSleet
This particular exploit is a buffer overflow in the event message where the client can specify a disconnect message, and the server will serialize an event containing that message. There is an issue with the function that serializes the game event that causes a buffer overflow in the net message,

Re: [hlds] Garrysmod Servers and Invalid STEAM UserID Ticket

2010-06-19 Thread AzuiSleet
I took a quick look at that particular message, Invalid STEAM UserID Ticket, and it appears in the new engine it's ignored, but the general context is that there is an issue with Valve's ticket servers (although I can't think of why because the old auth protocol uses two ticket servers). If you're