I dug into a user report of this, they were running a plugin that lets people 
from stolen versions of the game play on servers (dproto), that software has 
(at least one) bug that means you can be attacked. So yeah, be careful the 3rd 
party software you use on a server, and if its job is to let people steal the 
game....

- Alfred

-----Original Message-----
From: [email protected] 
[mailto:[email protected]] On Behalf Of Alfred Reynolds
Sent: Monday, August 06, 2012 9:41 AM
To: Half-Life dedicated Linux server mailing list
Subject: Re: [hlds_linux] New 1.6 Exploit very dangerous!

Right, they both require a challenge.

-----Original Message-----
From: [email protected] 
[mailto:[email protected]] On Behalf Of Saul Rennison
Sent: Saturday, August 04, 2012 11:03 AM
To: Half-Life dedicated Linux server mailing list
Subject: Re: [hlds_linux] New 1.6 Exploit very dangerous!

Don't A2S_RULES and A2S_PLAYERS require a challenge? That completely breaks
spoofed IP attacks.


Kind regards,
*Saul Rennison*


On 4 August 2012 18:41, Oskar Levin <[email protected]> wrote:

> I'm not sure this is fixed. It's still possible to get the convars of the
> server, right? Then it must still be possible to craft a UDP packet with a
> spoofed sender and that way make the server send a reply to the spoofed IP
> address?
>
> Best regards
> Oskar Levin
> [email protected]
>
> -----Ursprungligt meddelande-----
> Från: [email protected]
> [mailto:[email protected]] För John
> Skickat: den 4 augusti 2012 19:05
> Till: [email protected]
> Ämne: Re: [hlds_linux] New 1.6 Exploit very dangerous!
>
> On 8/3/2012 7:50 PM, LocalStrike | Live your game! wrote:
> > i read this from a forum and at this time we have the same situation
> here!
> > please we need a fix asap!
>
> Valve fixed this attack in the most recent Goldsrc engine release (July
> 31):
>
> "... This update fixes a potential vulnerability in the challenge/response
> protocol uses for out of band queries (in particular A2S_RULES and
> A2S_PLAYERS responses)... "
>
> Since it's not a required release, many server operators are not running it
> yet.
>
> In terms of what you can do to block the reflected attack on your end
> without waiting for others to update, you could use string-based rules that
> look for common cvars that will show in most output, or you could have a
> script that generates a list of IPs to block from tcpdump output and pushes
> that list into an "ipset" set, to be blocked with a single iptables rule.
>
> -John
>
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds_linux
>
>
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds_linux
>
_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds_linux

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds_linux

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/hlds_linux

Reply via email to