Staying out of cstrike directory renders startup scripts secure so I've
put my users.ini file outside cstrike (users_file "../users.ini") and I've
tried to retrieve it. I've also changed my server.cfg to something like
jfrfhruehfrhfr.cfg
    Anyway I have faith that Alfred will fix asap it as I've noticed the new
blood that flows in Valve's veins.
________________________________
Emanuel 'Rygars' Harangus
Technical Manager,
Professional Gamers League Romania


----- Original Message -----
From: "Florian Zschocke" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, November 20, 2003 2:13 PM
Subject: Re: [hlds_linux] [Full-Disclosure] Half Life dedicated server
information leak and DoS


> [FAW]Terran wrote:
>
> > I didn't follow the entire thread. But if I can download the
adminmod.cfg
> > all i have to do is to take a look into it and i will know the location
of
> > the users.ini file...
>
> The advisory says that you can only download files from below the
> game directory (e.g. cstrike) or the valve directory. From that I
> am assuming that a relative path leading out of those would not
> work. This is something that had been fixed by Valve in  a
> different context some time ago. But I haven't tested this myself
> yet, so I can't say for sure if you can download files from above
> those directory with the method described.
>
> Florian.
>
>
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives,
please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux


_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux

Reply via email to