FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
HL Security Leak/ For Servers only

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    The Ville.org Half-Life Gaming Community Forum Index -> General Ramblings
View previous topic :: View next topic  
Author Message
SpeCies
Registered User


Joined: 05 Sep 2001
Location: North Carolina Guild: <TVB>
Posts: 1948

PostPosted: Sun Sep 23, 2001 1:15 pm    Post subject: Reply with quote

Cut and Pasted this from Planethalflife..

HL 1.1.0.8 Security Leak
9/22/2001 20:24 PST | Community | by redef |
Thanks to Tommyjoe for alerting us of a little security alert on SecurityFocus. According to this alert, it is possible for servers (not clients) to exploit the “connect” command in HL, potentially causing harm to a user’s PC. Realistically this isn’t a serious problem, but it could become an issue. Here’s a little clip that details it nicely:
By running the command ["connect"] with around 128 characters it is possible to overflow the buffer and execute arbitrary code. While this problem is on the client side it is still a serious issue, since servers have a function named "g_engfuncs.pfnClientCommand" which allows the server to force clients to execute whatever console command they want. This means that this overflow can be exploited remotely by means of this function.

_________________
http://www.nosmacktards.com
Back to top
View user's profile Send private message
Robert E. Lee
Registered User


Joined: 18 Jul 2001

Posts: 2904

PostPosted: Sun Sep 23, 2001 3:27 pm    Post subject: Reply with quote

Thanks, but I don't think any of our admins would stoop to this level. I don't it will be a problem for anyone, but thanks for posting it anyway.

_________________
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    The Ville.org Half-Life Gaming Community Forum Index -> General Ramblings All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group