Still when I download /maps/de_survivor.bsp the server will crash...
And I think (didn't tested it) that you still might be able to use
/../../adminmod/config/users.ini in the exploit to still get the
users.ini.
For the server.cfg I think you need the non-steam client to download it
(again not tested) since steam has a server.cfg in the cache (?)

Jesper

----- Original Message -----
From: "Emanuel Harangus" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: Re: [hlds_linux] [Full-Disclosure] Half Life dedicated server
information leak and DoS
Date: Thu, 20 Nov 2003 12:51:55 +0200

That's in fact a brilliant idea :)

----- Original Message -----
From: "Florian Zschocke" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, November 20, 2003 12:27 PM
Subject: Re: [hlds_linux] [Full-Disclosure] Half Life dedicated server
information leak and DoS


> Emanuel Harangus wrote:
> > I could dl addons/adminmod/config/users.ini ..
addons/metamod/plugins.ini
> > The server.cfg seems to fail as exists in hdd.
> > I disabled allowdownload and allowupload untill further news about
fixing
> > the exploit.
>
> As for Admin Mod: you can move the Admin Mod config files like
> users.ini to a directory above the game directory so that a download
> will not work anymore. You just have to specify the path in the
> adminmod.cfg file accordingly. Example:
>
> addons/adminmod/config/adminmod.cfg:
> users_file ../../adminmod/config/users.ini
>
> And the tree:
>
> -- somedir
>    |-- hlds
>    |  |-- cstrike
>    |  \-- valve
>    |
>    \-- adminmod
>       \-- config
>          \-- users.ini
>
> (I hope you use a fixed width font to read your email or you may not
> see the tree drawing correctly.)
>
> Florian.


_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux

Reply via email to