Still when I download /maps/de_survivor.bsp the server will crash... And I think (didn't tested it) that you still might be able to use /../../adminmod/config/users.ini in the exploit to still get the users.ini. For the server.cfg I think you need the non-steam client to download it (again not tested) since steam has a server.cfg in the cache (?)
Jesper ----- Original Message ----- From: "Emanuel Harangus" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Subject: Re: [hlds_linux] [Full-Disclosure] Half Life dedicated server information leak and DoS Date: Thu, 20 Nov 2003 12:51:55 +0200 That's in fact a brilliant idea :) ----- Original Message ----- From: "Florian Zschocke" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, November 20, 2003 12:27 PM Subject: Re: [hlds_linux] [Full-Disclosure] Half Life dedicated server information leak and DoS > Emanuel Harangus wrote: > > I could dl addons/adminmod/config/users.ini .. addons/metamod/plugins.ini > > The server.cfg seems to fail as exists in hdd. > > I disabled allowdownload and allowupload untill further news about fixing > > the exploit. > > As for Admin Mod: you can move the Admin Mod config files like > users.ini to a directory above the game directory so that a download > will not work anymore. You just have to specify the path in the > adminmod.cfg file accordingly. Example: > > addons/adminmod/config/adminmod.cfg: > users_file ../../adminmod/config/users.ini > > And the tree: > > -- somedir > |-- hlds > | |-- cstrike > | \-- valve > | > \-- adminmod > \-- config > \-- users.ini > > (I hope you use a fixed width font to read your email or you may not > see the tree drawing correctly.) > > Florian. _______________________________________________ To unsubscribe, edit your list preferences, or view the list archives, please visit: http://list.valvesoftware.com/mailman/listinfo/hlds_linux

