Jump to content

Garrysmod Exploits


tehrichie

Recommended Posts

Guest louise

Forums / internet is public, so really in posting what you have done may make it worse.

I would simple contact valve with your findings and let them deal with it

Link to comment
Share on other sites

From the looks of it, it's just the file upload bug - which allows players to upload files to any place on the server. This was fixed in all other Valve source games, but Garry hasn't fixed it yet.

 

If TCA ran the games under a more restrictive user account (e.g creating a seperate Windows account for each user and giving them privileges over just their folder) this wouldn't be so much of a problem, since then only the user's own directory could be damaged rather than the server as a whole.

Link to comment
Share on other sites

If TCA ran the games under a more restrictive user account (e.g creating a seperate Windows account for each user and giving them privileges over just their folder) this wouldn't be so much of a problem, since then only the user's own directory could be damaged rather than the server as a whole.

 

Yea, probably the thing I think is most missing from TCA and most hope exists in V2. As its tiring having to manually create each user and adjust the service created and folder permisions to tighten security.

Link to comment
Share on other sites

From the looks of it, it's just the file upload bug - which allows players to upload files to any place on the server. This was fixed in all other Valve source games, but Garry hasn't fixed it yet.

 

If TCA ran the games under a more restrictive user account (e.g creating a seperate Windows account for each user and giving them privileges over just their folder) this wouldn't be so much of a problem, since then only the user's own directory could be damaged rather than the server as a whole.

 

The ability to run the game under a different account is possible in the current version. However it is a manual process to change the service settings.

 

V2 will have the process automated.

Link to comment
Share on other sites

The ability to run the game under a different account is possible in the current version. However it is a manual process to change the service settings.

 

V2 will have the process automated.

 

Uhoh there goes ECF dropping more tidbits about the cool new features of V2. But whohoo for it being automated in V2!!!

Link to comment
Share on other sites

Uhoh there goes ECF dropping more tidbits about the cool new features of V2. But whohoo for it being automated in V2!!!

 

so true. you just gotta watch every post from ECF :p 1 in every 100 posts we will get a secret... hopefully in 2011 we will have v2 :p

Link to comment
Share on other sites

The ability to run the game under a different account is possible in the current version. However it is a manual process to change the service settings.

 

V2 will have the process automated.

 

Oh excellent! This is the feature i've really wanted to see! Looking forward to it.

Link to comment
Share on other sites

  • 3 weeks later...

Hi the upload bug it to do with orangebox games and L4D

 

By default the Source engine allows to download and upload files.

While the download operation is denied if there is a slash or a ".."

or an unsupported extension in the requested file (to avoid directory

traversal bugs although \file is allowed) in the upload operation there

are just no checks.

 

The result is that an attacker can upload files in arbitrary locations

in the hard disks of the server like

"C:\Documents and Settings\All Users\Start Menu\Programs\Startup\bad.exe"

or "\file.txt" or "../file.txt" and so on.

 

The existent files cannot be replaced (will be showed the console

message "Download file 'FILENAME' already exists!") but is possible to

put place malicious programs in the Startup folder for being executed

at the next logon/reboot of the system.

 

Note that these "file uploading" vulnerabilities can be exploited even

with uploads and downloads disabled, indeed using "sv_allowupload 0"

does NOT solve the situation.

 

There is a fix for this issue released by a community and it does work.

 

If you would like more details you can contact me outside these forums

 

i could go on with arbitray file deletion with valve exploits, but cannot be arsed to type anymore

Link to comment
Share on other sites

  • 2 weeks later...

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Terms of Use