Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 12:15

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 11 posts ] 
Author Message
 Post subject: Crash steam server via nonsteam client ?
PostPosted: 04 Nov 2008 13:33 

Joined: 08 Sep 2007 18:55
Posts: 22
Hi all (and Luigi ;) ). Yesterday I saw text "new bug - steam servers can be crashed by nonsteam client". Anyone can explain me?


Top
 Profile  
 
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 04 Nov 2008 13:55 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
where have you read it?
anyway I don't have a steam server for testing and in reality I don't test actively Half-life from years


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 04 Nov 2008 14:14 

Joined: 08 Sep 2007 18:55
Posts: 22
Quote:
where have you read it?
In polish forum, but i really cant ask author.

Code:
jest fajny bug do crashowania serwero steamowych
przez klienta non-steamowego.....
zg??oszone do valve, na dniach powinien by?? fix ;)


in english
Code:
one nice bug exist to crash steam servers
via nonsteam client
reported to valve, fix will be relased


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 04 Nov 2008 14:29 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
probably it exists and it's very good that valve will fix it but the words there make it impossible for the following reasons:
"via nonsteam client" means that this is an in-game vulnerability which means that (for example) HL 4.1.1.0 can join a steam HL server which is not possible because it's kicked immediately, so if you can't join the server you can't test the bug and that's why I say it's not possible (not possible with that description and default clients).

in short I mean that the description is wrong.


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 05 Nov 2008 09:22 

Joined: 24 Sep 2007 02:12
Posts: 1114
Location: http://sethioz.co.uk
i think its a bug that crashes the steam server upon a join attempt or something like that.
or some command you send into server thru console.
Think its referred to an external crash, using the nonsteam client.
but it does sound a lil bit suspecious.


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 02 Feb 2009 06:36 

Joined: 02 Feb 2009 06:29
Posts: 13
its still not fixed, what it is. is a rcon overflow exploit


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 02 Feb 2009 13:54 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
uhmmm the old HL x.1.1.1e has been never vulnerable to rcon overflows, all the rcon packets in fact with a size major of (plus or less) 512 bytes are just dropped and there are no overflow in the password or in the command or in the number of arguments.

I don't have Steam HL and so I can't verify what you say but in any case why Valve should have introduced a similar critical vulnerability?
I mean, why touching that part of the code?
it would be not the first time of a similar thing (watch IW with call of duty and the va() overflow) but looks strange


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 03 Feb 2009 03:14 

Joined: 02 Feb 2009 06:29
Posts: 13
HL2 Engine based games are vulnerable to these attacks


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 10 Feb 2009 18:53 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
just for curiosity I was watching the documentation made by Valve about the rcon protocol in the Source engine:

http://developer.valvesoftware.com/wiki ... N_Protocol

if that protocol is the same used in HL2 it's logical that it's bugged or simply just more prone to vulnerabilities.


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 12 Feb 2009 04:23 

Joined: 24 Sep 2007 02:12
Posts: 1114
Location: http://sethioz.co.uk
Luigi didnt you test this few days ago and found no bugs ?!


Top
 Profile  
 
 Post subject: Re: Crash steam server via nonsteam client ?
PostPosted: 13 Feb 2009 01:35 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
yeah, versus the latest version of the server anyway was only a basic test, nothing more


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 11 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: