Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-04 Thread Saul Rennison
You reported that weeks ago. Who gives a shit if we're posting it in the wild? There's a fix already and Valve just need to hurry the fuck up and patch it. Sent from my iPhone On 4 May 2009, at 02:17, Unknown | zD. unknow...@gmail.com wrote: Can you guys just stop saying / posting the

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-04 Thread dave foster
Security by obscurity is never a good idea. Thanks for posting, and thanks to Tony for the quick fix :) On Mon, May 4, 2009 at 04:54, Saul Rennison saul.renni...@gmail.com wrote: You reported that weeks ago. Who gives a shit if we're posting it in the wild? There's a fix already and Valve just

[hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can fix this instead of us having to fix every exploit they ignore? ___ To unsubscribe, edit your list

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread 1nsane
Oh fun. On Sun, May 3, 2009 at 2:55 PM, AzuiSleet azuisl...@gmail.com wrote: It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can fix this instead of us having to fix every exploit they ignore?

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Yaakov Smith
: [hlds] Script kiddies abusing A2C_PRINT Oh fun. On Sun, May 3, 2009 at 2:55 PM, AzuiSleet azuisl...@gmail.com wrote: It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can fix this instead of us having

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread 1nsane
mailing list Subject: Re: [hlds] Script kiddies abusing A2C_PRINT Oh fun. On Sun, May 3, 2009 at 2:55 PM, AzuiSleet azuisl...@gmail.com wrote: It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve can

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Sebastian Staudt
list Subject: Re: [hlds] Script kiddies abusing A2C_PRINT Oh fun. On Sun, May 3, 2009 at 2:55 PM, AzuiSleet azuisl...@gmail.com wrote: It seems people discovered the old A2C_PRINT UDP message and are spamming servers. http://screencast.com/t/JRYs3LglN Is there any chance Valve

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
- From: hlds-boun...@list.valvesoftware.com [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of 1nsane Sent: Monday, 4 May 2009 6:46 AM To: Half-Life dedicated Win32 server mailing list Subject: Re: [hlds] Script kiddies abusing A2C_PRINT Oh fun. On Sun, May 3, 2009 at 2:55

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Yaakov Smith
But what does it actually do? (apart from freezing servers) ___ To unsubscribe, edit your list preferences, or view the list archives, please visit: http://list.valvesoftware.com/mailman/listinfo/hlds

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
[mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of 1nsane Sent: Monday, 4 May 2009 6:46 AM To: Half-Life dedicated Win32 server mailing list Subject: Re: [hlds] Script kiddies abusing A2C_PRINT Oh fun. On Sun, May 3, 2009 at 2:55 PM, AzuiSleet azuisl...@gmail.com wrote: It seems

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
It doesn't freeze servers it merely prints a message in the server console. Although it can make them lag and beep using \x07. Sent from my iPhone On 4 May 2009, at 00:17, Yaakov Smith m4ngr...@gmail.com wrote: But what does it actually do? (apart from freezing servers)

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread 1nsane
Sends messages. A quick search got this: A2C_PRINT from 68.142.72.250:27011 : No challenge for your address. A2C_PRINT from 72.165.61.189:27011 : No challenge for your address. Adding master at 72.165.61.189:27011 A2C_PRINT from 72.165.61.189:27011 : Bad challenge. Just a few examples of legit

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
It doesn't freeze, the bell character \7 freezes when it's printed. On Sun, May 3, 2009 at 5:17 PM, Yaakov Smith m4ngr...@gmail.com wrote: But what does it actually do? (apart from freezing servers) ___ To unsubscribe, edit your list preferences, or

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
All you do is send: FF FF FF FF 6C your message here Note the above is in hex ~_~. @AzuiSleet what do you mean? It freezes when it prints \x07, yes. AKA lags. Sent from my iPhone On 4 May 2009, at 00:23, 1nsane 1nsane...@gmail.com wrote: Sends messages. A quick search got this: A2C_PRINT

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
Or if you want to be really clever and cover up the message you can do \xFF\xFF\xFF\xFFl\rhello \n On Sun, May 3, 2009 at 5:29 PM, Saul Rennison saul.renni...@gmail.comwrote: All you do is send: FF FF FF FF 6C your message here Note the above is in hex

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
Huh? You mean by using \b to cover up the A2C_PRINT from x.x.x.x:y : prefix? Using \r would just make a new line. Sent from my iPhone On 4 May 2009, at 00:32, AzuiSleet azuisl...@gmail.com wrote: Or if you want to be really clever and cover up the message you can do

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Yaakov Smith
So what would happen on the server if I sent Hello Everyone!? Would it appear in the console? ingame chat? ___ To unsubscribe, edit your list preferences, or view the list archives, please visit: http://list.valvesoftware.com/mailman/listinfo/hlds

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Cc2iscooL
You guys do a good job of exposing your servers :) with this info the kiddies will get worse most likely since half the script kiddies watch this list for new commands to run. On 5/3/09, AzuiSleet azuisl...@gmail.com wrote: Or if you want to be really clever and cover up the message you can do

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
I don't know what \b is, but \r is return, it puts the cursor at the start of the line. \n puts the cursor on a new line. On Sun, May 3, 2009 at 5:36 PM, Saul Rennison saul.renni...@gmail.comwrote: Huh? You mean by using \b to cover up the A2C_PRINT from x.x.x.x:y : prefix? Using \r would

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread 1nsane
It is a very good idea to post exploits on HLDS. Only Azui does not run any servers. So that's kinda mute now... is it not? On Sun, May 3, 2009 at 7:37 PM, Cc2iscooL cc2isc...@gmail.com wrote: You guys do a good job of exposing your servers :) with this info the kiddies will get worse most

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
Good. Will make it a higher priority for Valve to gtfo their asses and fix some exploits for once. Sent from my iPhone On 4 May 2009, at 00:37, Cc2iscooL cc2isc...@gmail.com wrote: You guys do a good job of exposing your servers :) with this info the kiddies will get worse most likely since

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
It will appear in the server console only. Sent from my iPhone On 4 May 2009, at 00:36, Yaakov Smith m4ngr...@gmail.com wrote: So what would happen on the server if I sent Hello Everyone!? Would it appear in the console? ingame chat? ___ To

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Saul Rennison
\b is backspace. Sorry never knew about \r! Thanks :D Sent from my iPhone On 4 May 2009, at 00:40, AzuiSleet azuisl...@gmail.com wrote: I don't know what \b is, but \r is return, it puts the cursor at the start of the line. \n puts the cursor on a new line. On Sun, May 3, 2009 at 5:36

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread 1nsane
Never heard of it. deja vu. On Sun, May 3, 2009 at 7:51 PM, AzuiSleet azuisl...@gmail.com wrote: I run a very popular Garry's Mod server, you may have heard of it, NoxiousNet. Go ahead, try and DDoS me, I'm invincible. On Sun, May 3, 2009 at 5:41 PM, 1nsane 1nsane...@gmail.com wrote: It

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread AzuiSleet
I run a very popular Garry's Mod server, you may have heard of it, NoxiousNet. Go ahead, try and DDoS me, I'm invincible. On Sun, May 3, 2009 at 5:41 PM, 1nsane 1nsane...@gmail.com wrote: It is a very good idea to post exploits on HLDS. Only Azui does not run any servers. So that's kinda mute

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Chad Austin
famous last words AzuiSleet wrote: I run a very popular Garry's Mod server, you may have heard of it, NoxiousNet. Go ahead, try and DDoS me, I'm invincible. On Sun, May 3, 2009 at 5:41 PM, 1nsane 1nsane...@gmail.com wrote: It is a very good idea to post exploits on HLDS. Only Azui does

Re: [hlds] Script kiddies abusing A2C_PRINT

2009-05-03 Thread Dr Stinglock
: hlds-boun...@list.valvesoftware.com [mailto:hlds-boun...@list.valvesoftware.com] On Behalf Of Unknown | zD. Sent: Monday, 4 May 2009 9:18 AM To: hlds@list.valvesoftware.com Subject: Re: [hlds] Script kiddies abusing A2C_PRINT Can you guys just stop saying / posting the exploit / command / packet