Re: [hlds] Source Engine remote slowhacking exploit - how can I dump a .dem file?

2012-04-13 Thread Bruno Garcia
First, the demo file won't record any crucial information... plus, these exploits aren't valve commands being messed up, it could be protocols being buggy; for example sending the connection packet of 300 different clients... And secondly, this reminds me of the disconnect message exploit, that

Re: [hlds] Source Engine remote slowhacking exploit - how can I dump a .dem file?

2012-04-13 Thread Harry Strongburg
On Fri, Apr 13, 2012 at 09:16:40PM -0300, Bruno Garcia wrote: First, the demo file won't record any crucial information... What makes you think this? The client being unusable happens if you play back the demo, so whatever (at least the clientside breakage) is, it's recorded there. plus,

[hlds] Source Engine remote slowhacking exploit - how can I dump a .dem file?

2012-04-12 Thread Harry Strongburg
Hi, just thought I'd tell you guys that there's a remote slowhacking exploit in the wild. Any user, who doesn't need any permissions at all on the server, and happens without ANY server modifications installed, can make all the client's on the server unresponsive. The exploit will even run