Re: [hlds] Its the law!

2009-11-18 Thread Steven Crothers
Not to re-open this, but if you run your own machine, you can IPTable the
TCP gameport to certain IP's to limit RCON.

On Tue, Nov 17, 2009 at 1:12 PM, Ronny Schedel i...@ronny-schedel.dewrote:

 Strange, because TF2 isn't even 7 years old.


 - Original Message -
 From: Charles Mabbott cmabb...@verizon.net
 To: 'Half-Life dedicated Win32 server mailing list'
 hlds@list.valvesoftware.com
 Sent: Tuesday, November 17, 2009 7:05 PM
 Subject: Re: [hlds] Its the law!


 Short answer, yes it does.


 -Original Message-
 From: hlds-boun...@list.valvesoftware.com
 [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of Ronny Schedel
 Sent: Tuesday, November 17, 2009 12:17 PM
 To: Half-Life dedicated Win32 server mailing list
 Subject: Re: [hlds] Its the law!

 But does is it work today with a fully patched server?

 Google it and theres almost the same exploit from 7 years ago?

 Ronny Schedel wrote:
  But didn't they fix this file download bug some months ago?
 
 
  - Original Message -
  From: Spencer 'voogru' MacDonald voo...@voogru.com
  To: 'Half-Life dedicated Win32 server mailing list'
  hlds@list.valvesoftware.com
  Sent: Tuesday, November 17, 2009 4:14 PM
  Subject: Re: [hlds] Its the law!
 
 
  Here is a possible patch for the new found exploit. It hasn't been fully
  tested yet though since I am only speculating on how this exploit is
 being
  performed.
 
  This plug-in will output a log event every time someone requests a file
  from
  the server, whether it be a spray logo file or your server.cfg.
 
  http://forums.alliedmods.net/showthread.php?p=992047
 
  -Original Message-
  From: hlds-boun...@list.valvesoftware.com
  [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of Ronny Schedel
  Sent: Tuesday, November 17, 2009 2:06 AM
  To: Half-Life dedicated Win32 server mailing list
  Subject: Re: [hlds] Its the law!
 
  Under which conditions?
 
 
  - Original Message -
  From: 1nsane 1nsane...@gmail.com
  To: Half-Life dedicated Win32 server mailing list
  hlds@list.valvesoftware.com
  Sent: Tuesday, November 17, 2009 12:31 AM
  Subject: Re: [hlds] Its the law!
 
 
  Under certain conditions It is possible to download files from the
 server.
  Server.cfg being a good one.
 
  Also the reverse is true.
 
  On Mon, Nov 16, 2009 at 5:37 PM, JäKë T can_kic...@hotmail.com wrote:
 
 
  It's just cracking rcon password, then they set it to private and change
  the name.
  So just having rcon locker and a nice password fixes it.
 
 
 
  From: i...@ronny-schedel.de
  To: hlds@list.valvesoftware.com
  Date: Mon, 16 Nov 2009 23:32:24 +0100
  Subject: Re: [hlds] Its the law!
 
  The big question is: how is it done? Let's hope there is backdoor in
 the
  fake player app and not a bug in the server code.
 
 
  http://img692.imageshack.us/img692/4728/71956486.jpg
  I lay money on Lotusclan getting there comeuppance!
 
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
 
  please visit:
 
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
  _
  Windows Live: Make it easier for your friends to see what you're up to
 on
  Facebook.
  http://go.microsoft.com/?linkid=9691816
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 

 ___
 To unsubscribe, edit your list preferences, or view the list archives,
 please visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds


 ___
 To unsubscribe, edit your list preferences, or view the list archives,
 please visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds


 ___
 To unsubscribe, edit your list preferences, or view the list archives,

[hlds] The Session is No Longer Available

2009-11-18 Thread Blood Letter

Anyone getting this?

Windows.

--command line--
srcds.exe -console -game left4dead2 -maxplayers 8 -ip 192.168.1.11 -port 27015 
-nohltv +sv_lan 0 +map c1m1_hotel

--server.cfg--
hostname Love Me Sexy
rcon_password 
password
sv_steamgroup 12345
sv_steamgroup_exclusive 1
sv_search_key searchkey

Forwarding pots 27000-27015 to 192.168.1.11 .

??
  
_
Windows 7: I wanted simpler, now it's simpler. I'm a rock star.
http://www.microsoft.com/Windows/windows-7/default.aspx?h=myidea?ocid=PID24727::T:WLMTAGL:ON:WL:en-US:WWL_WIN_myidea:112009
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds


Re: [hlds] The Session is No Longer Available

2009-11-18 Thread Shane Arnold
Yes, on a Linux server. Are you running it behind a NAT firewall? We 
were told that using mm_dedicated_force_servers public|private would 
fix this, but it doesn't. Test this for me, if you start with +sv_lan 1 
does it then work flawlessly?

Blood Letter wrote:
 Anyone getting this?

 Windows.

 --command line--
 srcds.exe -console -game left4dead2 -maxplayers 8 -ip 192.168.1.11 -port 
 27015 -nohltv +sv_lan 0 +map c1m1_hotel

 --server.cfg--
 hostname Love Me Sexy
 rcon_password 
 password
 sv_steamgroup 12345
 sv_steamgroup_exclusive 1
 sv_search_key searchkey

 Forwarding pots 27000-27015 to 192.168.1.11 .

 ??
 
 _
 Windows 7: I wanted simpler, now it's simpler. I'm a rock star.
 http://www.microsoft.com/Windows/windows-7/default.aspx?h=myidea?ocid=PID24727::T:WLMTAGL:ON:WL:en-US:WWL_WIN_myidea:112009
 ___
 To unsubscribe, edit your list preferences, or view the list archives, please 
 visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds
   

___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds


Re: [hlds] The Session is No Longer Available

2009-11-18 Thread Blood Letter

Zero problems when running with sv_lan 1.

 Date: Thu, 19 Nov 2009 13:05:37 +0800
 From: clontar...@iinet.net.au
 To: hlds@list.valvesoftware.com
 Subject: Re: [hlds] The Session is No Longer Available
 
 Yes, on a Linux server. Are you running it behind a NAT firewall? We 
 were told that using mm_dedicated_force_servers public|private would 
 fix this, but it doesn't. Test this for me, if you start with +sv_lan 1 
 does it then work flawlessly?
 
 Blood Letter wrote:
  Anyone getting this?
 
  Windows.
 
  --command line--
  srcds.exe -console -game left4dead2 -maxplayers 8 -ip 192.168.1.11 -port 
  27015 -nohltv +sv_lan 0 +map c1m1_hotel
 
  --server.cfg--
  hostname Love Me Sexy
  rcon_password 
  password
  sv_steamgroup 12345
  sv_steamgroup_exclusive 1
  sv_search_key searchkey
 
  Forwarding pots 27000-27015 to 192.168.1.11 .
 
  ??

  _
  Windows 7: I wanted simpler, now it's simpler. I'm a rock star.
  http://www.microsoft.com/Windows/windows-7/default.aspx?h=myidea?ocid=PID24727::T:WLMTAGL:ON:WL:en-US:WWL_WIN_myidea:112009
  ___
  To unsubscribe, edit your list preferences, or view the list archives, 
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds

 
 ___
 To unsubscribe, edit your list preferences, or view the list archives, please 
 visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds
  
_
Bing brings you maps, menus, and reviews organized in one place.
http://www.bing.com/search?q=restaurantsform=MFESRPpubl=WLHMTAGcrea=TEXT_MFESRP_Local_MapsMenu_Resturants_1x1
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds


Re: [hlds] Its the law!

2009-11-18 Thread Ronny Schedel

How does it prevent the remote file download of the server.cfg?

 Not to re-open this, but if you run your own machine, you can IPTable the
 TCP gameport to certain IP's to limit RCON.

 On Tue, Nov 17, 2009 at 1:12 PM, Ronny Schedel 
 i...@ronny-schedel.dewrote:

 Strange, because TF2 isn't even 7 years old.


 - Original Message -
 From: Charles Mabbott cmabb...@verizon.net
 To: 'Half-Life dedicated Win32 server mailing list'
 hlds@list.valvesoftware.com
 Sent: Tuesday, November 17, 2009 7:05 PM
 Subject: Re: [hlds] Its the law!


 Short answer, yes it does.


 -Original Message-
 From: hlds-boun...@list.valvesoftware.com
 [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of Ronny Schedel
 Sent: Tuesday, November 17, 2009 12:17 PM
 To: Half-Life dedicated Win32 server mailing list
 Subject: Re: [hlds] Its the law!

 But does is it work today with a fully patched server?

 Google it and theres almost the same exploit from 7 years ago?

 Ronny Schedel wrote:
  But didn't they fix this file download bug some months ago?
 
 
  - Original Message -
  From: Spencer 'voogru' MacDonald voo...@voogru.com
  To: 'Half-Life dedicated Win32 server mailing list'
  hlds@list.valvesoftware.com
  Sent: Tuesday, November 17, 2009 4:14 PM
  Subject: Re: [hlds] Its the law!
 
 
  Here is a possible patch for the new found exploit. It hasn't been 
  fully
  tested yet though since I am only speculating on how this exploit is
 being
  performed.
 
  This plug-in will output a log event every time someone requests a file
  from
  the server, whether it be a spray logo file or your server.cfg.
 
  http://forums.alliedmods.net/showthread.php?p=992047
 
  -Original Message-
  From: hlds-boun...@list.valvesoftware.com
  [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of Ronny Schedel
  Sent: Tuesday, November 17, 2009 2:06 AM
  To: Half-Life dedicated Win32 server mailing list
  Subject: Re: [hlds] Its the law!
 
  Under which conditions?
 
 
  - Original Message -
  From: 1nsane 1nsane...@gmail.com
  To: Half-Life dedicated Win32 server mailing list
  hlds@list.valvesoftware.com
  Sent: Tuesday, November 17, 2009 12:31 AM
  Subject: Re: [hlds] Its the law!
 
 
  Under certain conditions It is possible to download files from the
 server.
  Server.cfg being a good one.
 
  Also the reverse is true.
 
  On Mon, Nov 16, 2009 at 5:37 PM, JäKë T can_kic...@hotmail.com wrote:
 
 
  It's just cracking rcon password, then they set it to private and 
  change
  the name.
  So just having rcon locker and a nice password fixes it.
 
 
 
  From: i...@ronny-schedel.de
  To: hlds@list.valvesoftware.com
  Date: Mon, 16 Nov 2009 23:32:24 +0100
  Subject: Re: [hlds] Its the law!
 
  The big question is: how is it done? Let's hope there is backdoor in
 the
  fake player app and not a bug in the server code.
 
 
  http://img692.imageshack.us/img692/4728/71956486.jpg
  I lay money on Lotusclan getting there comeuppance!
 
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list 
  archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list 
  archives,
 
  please visit:
 
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
  _
  Windows Live: Make it easier for your friends to see what you're up to
 on
  Facebook.
  http://go.microsoft.com/?linkid=9691816
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 
  ___
  To unsubscribe, edit your list preferences, or view the list archives,
  please visit:
  http://list.valvesoftware.com/mailman/listinfo/hlds
 
 

 ___
 To unsubscribe, edit your list preferences, or view the list archives,
 please visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds


 ___
 To unsubscribe, edit your list preferences, or view the list archives,
 please visit:
 http://list.valvesoftware.com/mailman/listinfo/hlds