Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 12:00

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 3 posts ] 
Author Message
 Post subject: overwriting the cvars of a server??!
PostPosted: 09 Oct 2007 18:04 

Joined: 09 Oct 2007 17:49
Posts: 19
In fact, I don't understand the bug B which is described here...

http://aluigi.altervista.org/adv/q3cfilevar-adv.txt

For that, I need to change this c-files, but i couldn't find them... wether in the *.pk3s of quake3 or in the ones of Jedi Academy... so I thougt they're in the .dlls but anyway I'm not sure about that... I heard about programs called disassembler but they didn't helped me too...

So, could you tell me which programs you used to change this files, and where you find that files, too? I just need a better description for using that bug... would be kind of you.

plz help x)

malo


Top
 Profile  
 
 
 Post subject:
PostPosted: 09 Oct 2007 19:11 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
The two bugs described in that advisory are client side, which means that a server (attacker) can overwrites the cvars and the files of the clients (victims).
The proof-of-concept showed there must be applied to the game source code (not the sdk) so only Quake 3 can actually tested with that specific PoC because it's open source.


Top
 Profile  
 
 Post subject:
PostPosted: 09 Oct 2007 19:16 

Joined: 09 Oct 2007 17:49
Posts: 19
omg.

now i understand u.u

thx for your fast reply


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 3 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: