Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 12:17

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 22 posts ] 
Author Message
 Post subject: Crash HLDS with HLShield?
PostPosted: 08 Sep 2007 19:02 

Joined: 08 Sep 2007 18:55
Posts: 22
Hi all, hi Aluigi :) I want to crash secured server with HLShield (hlshield webpage -> http://hobby.sarichioi.com/index.php?topic=8.0 ). When I want crash, i give error [code] Error: the server has sent an unexpected reply
ost looser, we hate stupid people!
This server is protected by HLShield. [/code] :( How I can crash this server?


Top
 Profile  
 
 
 Post subject:
PostPosted: 08 Sep 2007 20:06 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
in my opinion there are no ways using the bugs fixed by that patch, which is normal and right (otherwise why the patch exists? ih ih ih)
I'm not aware of other bugs


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:07 

Joined: 08 Sep 2007 18:55
Posts: 22
Maybe bug on patch?


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:10 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
do you mean a bug caused by the patch or not totally fixed?
uhmmm too difficult, then this hlshied seems enough updated


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:12 

Joined: 08 Sep 2007 18:55
Posts: 22
Hmm, no more bugs in hlds (without csdos)? I like old nonsteam binaries, no updated steam.


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:18 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
New bugs are ever possible but at the moment I'm not aware of new vulnerabilities or possible types of attacks.

A thing which I have ever found funny is the possibility of sending messages from outside the game (I think you know about what I refer) moreover because is possible to spoof them but they are just annoying stuff.


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:25 

Joined: 08 Sep 2007 18:55
Posts: 22
[quote]is possible to spoof them but they are just annoying stuff.[/quote]
I know... :(
[quote]I have ever found funny is the possibility of sending messages from outside the game[/quote]Can you write more about this?[/quote]


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 20:43 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
Very simple, the following is an example packet:

????????lhello friends

where the first 4 bytes are 0xff, followed by the 'l' (0x6c) and then the text you wan to send to the server's console.
this works on version 4.1.1.1 but I don't know if works on older versions too.
old versions worked in console, so if the 0x07 chars are not filtered could work the freezing of the windows dedicated server through the hell bell bug


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 22:00 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
I was testing some random commands in my half-life version (just because I'm annoyed) and there is a strange effect which I hope someone can try to replicate:

cmd dlfile pak0.pak

then the server freezes completely with cpu at 100%
Someone with more experience than me in Half-life can test it?


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 22:05 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
correction, this problem is already known (found on Google) but it's strange if it still exists


Top
 Profile  
 
 Post subject:
PostPosted: 08 Sep 2007 22:11 

Joined: 08 Sep 2007 18:55
Posts: 22
Sorry for lame, but where i must type it?

EDIT: On russian page I look up for this... when I write this in console nothing do. :/ I tested on counter strike 1.6 nonsteam

EDIT2: This bug is fixed in 2003 year...


Top
 Profile  
 
 Post subject: Re: Crash HLDS with HLShield?
PostPosted: 09 Sep 2007 18:39 

Joined: 09 Sep 2007 18:38
Posts: 15
[quote="seba"]Hi all, hi Aluigi :) I want to crash secured server with HLShield (hlshield webpage -> http://hobby.sarichioi.com/index.php?topic=8.0 ). When I want crash, i give error [code] Error: the server has sent an unexpected reply
ost looser, we hate stupid people!
This server is protected by HLShield. [/code] :( How I can crash this server? [/quote]

why do you want crash hlds server,are you lol ?


Top
 Profile  
 
 Post subject:
PostPosted: 10 Sep 2007 20:24 

Joined: 08 Sep 2007 18:55
Posts: 22
Why? Because admin crashed my serwer...


Top
 Profile  
 
 Post subject:
PostPosted: 20 Sep 2007 01:41 

Joined: 15 Aug 2007 01:21
Posts: 3
http://hobby.sarichioi.com

Notice: Undefined variable: sourcedir in /var/www/sarichioi.com/hobby/index.php on line 49

Warning: require_once(/QueryString.php) [function.require-once]: failed to open stream: No such file or directory in /var/www/sarichioi.com/hobby/index.php on line 49

Fatal error: require_once() [function.require]: Failed opening required '/QueryString.php' (include_path='.:/usr/share/php5:/usr/share/php') in /var/www/sarichioi.com/hobby/index.php on line 49
:wink:


Top
 Profile  
 
 Post subject:
PostPosted: 10 Oct 2007 09:28 

Joined: 10 Oct 2007 09:27
Posts: 3
[quote="aluigi"]I was testing some random commands in my half-life version (just because I'm annoyed) and there is a strange effect which I hope someone can try to replicate:

cmd dlfile pak0.pak

then the server freezes completely with cpu at 100%
Someone with more experience than me in Half-life can test it?[/quote]
what did you say, where do we type this...I would like to try


Top
 Profile  
 
 Post subject:
PostPosted: 10 Oct 2007 09:53 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
in the Half-life console naturally, the one which you can open with the tilde (~) key.


Top
 Profile  
 
 Post subject:
PostPosted: 10 Oct 2007 10:27 

Joined: 10 Oct 2007 09:27
Posts: 3
oh, that...I thought it could be ran in all servers, you must have rcon access to do this :(


Top
 Profile  
 
 Post subject:
PostPosted: 10 Oct 2007 10:31 

Joined: 10 Oct 2007 09:27
Posts: 3
I guess this is solved, I typed it on my server and nothing happened :)


Top
 Profile  
 
 Post subject:
PostPosted: 16 Oct 2007 18:14 

Joined: 15 Oct 2007 12:13
Posts: 3
ok dats obvious.. the file is the main file of counterstrike.. so if u del it it offcourse effects the server!


Top
 Profile  
 
 Post subject:
PostPosted: 17 Mar 2008 02:42 

Joined: 17 Mar 2008 02:16
Posts: 2
That cmd dlfile bug still exist on HLDS x.1.1.1/e and let the server freeze with %100 cpu usage, i tried that boffix thing but it was not working and refuses nearly all connections


Top
 Profile  
 
 Post subject:
PostPosted: 17 May 2008 23:31 

Joined: 24 Apr 2008 20:46
Posts: 11
khmer wrote:
http://hobby.sarichioi.com

Notice: Undefined variable: sourcedir in /var/www/sarichioi.com/hobby/index.php on line 49

Warning: require_once(/QueryString.php) [function.require-once]: failed to open stream: No such file or directory in /var/www/sarichioi.com/hobby/index.php on line 49

Fatal error: require_once() [function.require]: Failed opening required '/QueryString.php' (include_path='.:/usr/share/php5:/usr/share/php') in /var/www/sarichioi.com/hobby/index.php on line 49
:wink:

what are you tryin'?


Top
 Profile  
 
 Post subject:
PostPosted: 21 May 2008 14:25 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
in attachment there is an example file to use with netcat or in loop with udpsz to test the hell bell bug versus the HL dedicated server running on the windows console (so some old versions):

nc SERVER 27015 -v -v -u < hl07.txt


Attachments:
hl07.txt [518 Bytes]
Downloaded 557 times
Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 22 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: