Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread px@ipt
Здравствуйте, Alfred. Вы писали 3 липня 2012 р., 1:39:45: If I use -beta hlbeta, then 0:17 Updating 'Linux Server Engine' from version 69 to version 67 :))) So I wonder, what's the idea to force to make decision of having either latest hl engine binary, or latest cs engine? Because you

Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread Alfred Reynolds
Try the update again, you should be getting v69 for the Linux server engine depot. - Alfred -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of px@ipt Sent: Tuesday, July 03, 2012 12:59 AM To: Half-Life

Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread Alfred Reynolds
All servers were potentially vulnerable. - Alfred -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Invalid Protocol Sent: Monday, July 02, 2012 5:34 PM To: 'Half-Life dedicated Linux server mailing list'

[hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread c0m4r
There is an exploit in q3 engine named q3dirtrav, which allows players to download any of server files, including server configuration (server.cfg).Today I found evidence of possible existence of the same exploit in HLDS.As a company we host hundreds of servers. We received many reports from

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread Sazpaimon
This was already fixed in an update, apparently. On 7/3/2012 2:54 PM, c0m4r wrote: There is an exploit in q3 engine named q3dirtrav, which allows players to download any of server files, including server configuration (server.cfg).Today I found evidence of possible existence of the same

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread Ken Bateman
For quite a while we have been careful to specify our tf2 rcon passwords on the command line, not a config file, because we suspected the existence of an exploit like this. It's possible that the vulnerability might be in tcadmin. -Ken On Jul 3, 2012 2:54 PM, c0m4r c0...@tlen.pl wrote: There

Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread Thiago Abreu
Without -hlbeta the server stay vulnerable to cl_setautobuy 2012/7/3 Alfred Reynolds alf...@valvesoftware.com Try the update again, you should be getting v69 for the Linux server engine depot. - Alfred -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread Collin Howard
I use no tcadmin or any control panel for that matter. It is not a control panel vulnerability, it is an exploit for HLDS. I had the exact same issue. However, Alfred said that the latest update fixed this exploit. I have updated my servers and have yet to see a similar problem come up. Will

Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread px@ipt
Здравствуйте, Alfred. Вы писали 3 липня 2012 р., 19:44:16: Just checked, now works as should, seems either was temporary glitch or server on 194.som.eth.ing was not properly updated... Try the update again, you should be getting v69 for the Linux server engine depot. - Alfred

Re: [hlds_linux] CS 1.6 New Exploit?

2012-07-03 Thread Collin Howard
did you use the -beta hlbeta command? From: px@ipt p...@i.kiev.ua To: Half-Life dedicated Linux server mailing list hlds_linux@list.valvesoftware.com Sent: Tuesday, July 3, 2012 2:53:21 PM Subject: Re: [hlds_linux] CS 1.6 New Exploit? Здравствуйте, Alfred.

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread doc
Is this an ok practice? I never thought about having my rcon password in my file - I guess it would be more secure if you just start it up with the rcon password in the string? Doesn't it show up when you run top/htop though? On Tue, Jul 3, 2012 at 12:05 PM, Ken Bateman novadeni...@gmail.com

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread Jesse Molina
Yes, it does. I pointed this out to the author awhile ago privately. Just for clarity, to make sure nobody else thinks it's a good idea, IT IS NOT A GOOD IDEA. =) This is the same reason that programs like sudo and ssh make it very difficult for you to pass passwords on the command line.

Re: [hlds_linux] HLDS q3dirtrav-like exploit

2012-07-03 Thread Ken Bateman
Having the password on the command line would indeed be a concern for us if we didn't have our box to ourselves. -Ken On Jul 3, 2012 7:44 PM, Jesse Molina je...@opendreams.net wrote: Yes, it does. I pointed this out to the author awhile ago privately. Just for clarity, to make sure nobody

[hlds_linux] TF2 Voting

2012-07-03 Thread Joshua Conley
Our server seems to have issues with TF2's Map Voting system. We have a list of maps in our mapcycle maplist files that are identical and the following CVARs set: sv_allow_votes 1 sv_vote_allow_spectators 0 sv_vote_failure_timer 300 sv_vote_issue_nextlevel_allowed 1

Re: [hlds_linux] TF2 Voting

2012-07-03 Thread Ross Bemrose
Even if you're not using any of its voting plugins, SourceMod still overrides the server's nextmap with its own... you'll notice in your server console that when a map starts, SourceMod will select the next map. It will change to that map when the current map ends unless a plugin overrides

Re: [hlds_linux] TF2 Voting

2012-07-03 Thread Joshua Conley
Is there anyway at all to override this behavior aside from just deleting SourceBad entirely? On Tue, Jul 3, 2012 at 9:08 PM, Ross Bemrose rbemr...@gmail.com wrote: Even if you're not using any of its voting plugins, SourceMod still overrides the server's nextmap with its own... you'll notice

Re: [hlds_linux] TF2 Voting

2012-07-03 Thread Jeff Sugar
If I recall correctly, removing the nextmap.smx plugin will do so. Not completely sure, though On Jul 3, 2012 6:26 PM, Joshua Conley joshuacon...@gmail.com wrote: Is there anyway at all to override this behavior aside from just deleting SourceBad entirely? On Tue, Jul 3, 2012 at 9:08 PM, Ross

Re: [hlds_linux] TF2 Voting

2012-07-03 Thread Joshua Conley
Yeah, I removed that plugin long ago. The only sourcemod plugin we have running right now that is related to votes is funvotes basevotes.smx. We do not use any other voting or map based plugins at all (really had no need for such a thing). On Tue, Jul 3, 2012 at 9:36 PM, Jeff Sugar