Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-08 Thread Saul Rennison
A, thanks for clearing that up :)

Thanks,
- Saul.


2009/12/8 Didrole 

> Because of the ".   " trick used to bypass the extension filter (windows
> only).
>
> 2009/12/8 Saul Rennison 
>
> > How come I could download server CFGs before this update then?
> >
> > On Tuesday, December 8, 2009, Didrole  wrote:
> > > Already blacklisted since ages.
> > >
> > > 2009/12/8 Saul Rennison 
> > >
> > >> What about VDF, DLL, EXE, CFG, and more?
> > >>
> > >> On Tuesday, December 8, 2009, Maximilian L.  wrote:
> > >> > Quote myself from IRC:
> > >> > [ "Added checks to prevent transferring .smx, .gcf, and .sys
> files
> > >> > between client/server" <- does that mean i can still remotely
> download
> > >> > my .ini including my  SQL logins?]
> > >> >
> > >> > I think .ini's are more importand to secure than .smx?!!
> > >> >
> > >> > --
> > >> > Mailing List Conversations - mail...@ml86.de - Please don´t spam :)
> > >> >
> > >> >
> > >> > ___
> > >> > To unsubscribe, edit your list preferences, or view the list
> archives,
> > >> please visit:
> > >> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > >> >
> > >>
> > >> --
> > >>
> > >> Thanks,
> > >>  - Saul.
> > >>
> > >> ___
> > >> To unsubscribe, edit your list preferences, or view the list archives,
> > >> please visit:
> > >> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > >>
> > > ___
> > > To unsubscribe, edit your list preferences, or view the list archives,
> > please visit:
> > > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > >
> >
> > --
> >
> > Thanks,
> >  - Saul.
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> > please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-08 Thread Didrole
Because of the ".   " trick used to bypass the extension filter (windows
only).

2009/12/8 Saul Rennison 

> How come I could download server CFGs before this update then?
>
> On Tuesday, December 8, 2009, Didrole  wrote:
> > Already blacklisted since ages.
> >
> > 2009/12/8 Saul Rennison 
> >
> >> What about VDF, DLL, EXE, CFG, and more?
> >>
> >> On Tuesday, December 8, 2009, Maximilian L.  wrote:
> >> > Quote myself from IRC:
> >> > [ "Added checks to prevent transferring .smx, .gcf, and .sys files
> >> > between client/server" <- does that mean i can still remotely download
> >> > my .ini including my  SQL logins?]
> >> >
> >> > I think .ini's are more importand to secure than .smx?!!
> >> >
> >> > --
> >> > Mailing List Conversations - mail...@ml86.de - Please don´t spam :)
> >> >
> >> >
> >> > ___
> >> > To unsubscribe, edit your list preferences, or view the list archives,
> >> please visit:
> >> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >> >
> >>
> >> --
> >>
> >> Thanks,
> >>  - Saul.
> >>
> >> ___
> >> To unsubscribe, edit your list preferences, or view the list archives,
> >> please visit:
> >> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >>
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
>
> --
>
> Thanks,
>  - Saul.
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-08 Thread Saul Rennison
How come I could download server CFGs before this update then?

On Tuesday, December 8, 2009, Didrole  wrote:
> Already blacklisted since ages.
>
> 2009/12/8 Saul Rennison 
>
>> What about VDF, DLL, EXE, CFG, and more?
>>
>> On Tuesday, December 8, 2009, Maximilian L.  wrote:
>> > Quote myself from IRC:
>> > [ "Added checks to prevent transferring .smx, .gcf, and .sys files
>> > between client/server" <- does that mean i can still remotely download
>> > my .ini including my  SQL logins?]
>> >
>> > I think .ini's are more importand to secure than .smx?!!
>> >
>> > --
>> > Mailing List Conversations - mail...@ml86.de - Please don´t spam :)
>> >
>> >
>> > ___
>> > To unsubscribe, edit your list preferences, or view the list archives,
>> please visit:
>> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>> >
>>
>> --
>>
>> Thanks,
>>  - Saul.
>>
>> ___
>> To unsubscribe, edit your list preferences, or view the list archives,
>> please visit:
>> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>>
> ___
> To unsubscribe, edit your list preferences, or view the list archives, please 
> visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>

-- 

Thanks,
 - Saul.

___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-08 Thread Didrole
Already blacklisted since ages.

2009/12/8 Saul Rennison 

> What about VDF, DLL, EXE, CFG, and more?
>
> On Tuesday, December 8, 2009, Maximilian L.  wrote:
> > Quote myself from IRC:
> > [ "Added checks to prevent transferring .smx, .gcf, and .sys files
> > between client/server" <- does that mean i can still remotely download
> > my .ini including my  SQL logins?]
> >
> > I think .ini's are more importand to secure than .smx?!!
> >
> > --
> > Mailing List Conversations - mail...@ml86.de - Please don´t spam :)
> >
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
>
> --
>
> Thanks,
>  - Saul.
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-08 Thread Saul Rennison
What about VDF, DLL, EXE, CFG, and more?

On Tuesday, December 8, 2009, Maximilian L.  wrote:
> Quote myself from IRC:
> [ "Added checks to prevent transferring .smx, .gcf, and .sys files
> between client/server" <- does that mean i can still remotely download
> my .ini including my  SQL logins?]
>
> I think .ini's are more importand to secure than .smx?!!
>
> --
> Mailing List Conversations - mail...@ml86.de - Please don´t spam :)
>
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives, please 
> visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>

-- 

Thanks,
 - Saul.

___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread Ben B
more specifically, disabling pRed's cbase extension for pre-connect admin
checking fixes it.

On Mon, Dec 7, 2009 at 7:52 PM, DontWannaName! wrote:

> Removing metamod fixes the connect problem.
>
> On Mon, Dec 7, 2009 at 6:47 PM, Nephyrin Zey 
> wrote:
>
> >  Why not just have a IClientResource API where the client stores a
> > resource of a certain type (ie SPRAY) and the server decides where to
> > put it and what to name it, and makes sure one client isn't uploading 90
> > sprays, etc. The assumption that there needs to be a direct filesystem
> > API seems terribly flawed, even if that's the easy/quick way to do it.
> >
> > - Neph
> >
> > On 12/07/2009 06:44 PM, David Parker wrote:
> > > I agree, that's a very good point.  It seems to me like one solution
> > would be for them to put a folder within the srcds directory for uploads
> and
> > make the engine use it.  They could always create a cvar to specify a
> > different location for uploaded files which admins could use if they
> wanted
> > to override the default.  Similar to how logging works right now.
> > >
> > >  - Dave
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> > please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread DontWannaName!
Ok, everything will work if you remove cbase extension or rename it which
makes it not load.

On Mon, Dec 7, 2009 at 6:52 PM, DontWannaName! wrote:

> Removing metamod fixes the connect problem.
>
>
> On Mon, Dec 7, 2009 at 6:47 PM, Nephyrin Zey wrote:
>
>>  Why not just have a IClientResource API where the client stores a
>> resource of a certain type (ie SPRAY) and the server decides where to
>> put it and what to name it, and makes sure one client isn't uploading 90
>> sprays, etc. The assumption that there needs to be a direct filesystem
>> API seems terribly flawed, even if that's the easy/quick way to do it.
>>
>> - Neph
>>
>> On 12/07/2009 06:44 PM, David Parker wrote:
>> > I agree, that's a very good point.  It seems to me like one solution
>> would be for them to put a folder within the srcds directory for uploads and
>> make the engine use it.  They could always create a cvar to specify a
>> different location for uploaded files which admins could use if they wanted
>> to override the default.  Similar to how logging works right now.
>> >
>> >  - Dave
>>
>> ___
>> To unsubscribe, edit your list preferences, or view the list archives,
>> please visit:
>> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>>
>
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread DontWannaName!
Removing metamod fixes the connect problem.

On Mon, Dec 7, 2009 at 6:47 PM, Nephyrin Zey  wrote:

>  Why not just have a IClientResource API where the client stores a
> resource of a certain type (ie SPRAY) and the server decides where to
> put it and what to name it, and makes sure one client isn't uploading 90
> sprays, etc. The assumption that there needs to be a direct filesystem
> API seems terribly flawed, even if that's the easy/quick way to do it.
>
> - Neph
>
> On 12/07/2009 06:44 PM, David Parker wrote:
> > I agree, that's a very good point.  It seems to me like one solution
> would be for them to put a folder within the srcds directory for uploads and
> make the engine use it.  They could always create a cvar to specify a
> different location for uploaded files which admins could use if they wanted
> to override the default.  Similar to how logging works right now.
> >
> >  - Dave
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread Nephyrin Zey
  Why not just have a IClientResource API where the client stores a 
resource of a certain type (ie SPRAY) and the server decides where to 
put it and what to name it, and makes sure one client isn't uploading 90 
sprays, etc. The assumption that there needs to be a direct filesystem 
API seems terribly flawed, even if that's the easy/quick way to do it.

- Neph

On 12/07/2009 06:44 PM, David Parker wrote:
> I agree, that's a very good point.  It seems to me like one solution would be 
> for them to put a folder within the srcds directory for uploads and make the 
> engine use it.  They could always create a cvar to specify a different 
> location for uploaded files which admins could use if they wanted to override 
> the default.  Similar to how logging works right now.
>
>  - Dave

___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread DontWannaName!
Getting bad challenge after updating, when you connect it says that. It
doesnt show as online on my server list from Steam.

On Mon, Dec 7, 2009 at 6:36 PM, Jeff Sugar  wrote:

> Well put, neph.
>
> On Mon, Dec 7, 2009 at 6:29 PM, Nephyrin Zey 
> wrote:
>
> >
> > > Engine:
> > > - Added checks to prevent transferring .smx, .gcf, and .sys files
> between
> > client/server
> > > - Fixed upload/download exploits with spaces in the file extension or a
> > path separator at the beginning of the requested file (as reported on the
> > HLDS mailing lists)
> >
> >
> > This is sad. You can still upload/download random files as long as their
> > extension isn't blacklisted? There's so many ways to cause problems with
> > this... even if you switch to an extension WHITELIST there'd still be
> > problems. Whose to say addons dont use other extensions to store
> > settings? Or bash/apache/other services dont read certain files? Is
> > .bashrc blocked? What if someone uses their home directory as the server
> > root? What if someone doesn't want script kiddies uploading
> > special_note_from_valve.readme to their server?
> >
> > Why not replace this interface with something that doesn't allow
> > arbitrary file uploads/downloads with something as laughable as a
> > extension blacklist making 'safe'. When someone finds yet another way to
> > abuse this (I can think of two separate ways to continue to use this
> > exploit for remote code execution) its going to come up again, years
> > after the issues with it was first noted...
> >
> > - Neph
> >
> >
> > On 12/07/2009 06:20 PM, Jason Ruymen wrote:
> > > Required updates for Team Fortress 2 and Day of Defeat: Source are now
> > available.  Please run hldsupdatetool to receive the updates.  The
> specific
> > changes include:
> > >
> > > Engine:
> > > - Added checks to prevent transferring .smx, .gcf, and .sys files
> between
> > client/server
> > > - Fixed upload/download exploits with spaces in the file extension or a
> > path separator at the beginning of the requested file (as reported on the
> > HLDS mailing lists)
> > >
> > > Team Fortress 2:
> > > - Fixed custom particle systems inside maps causing particles to break
> in
> > successive maps
> > > - Fixed a rare vphysics crash
> > > - Fixed background highlight for KOTH timers not being aligned properly
> > in minmode
> > > - Fixed the Heavy's fists being hidden while taunting
> > > - Fixed cloaked Spies having the critboost effect on their weapon
> > > - Fixed banned clients being able to spamming a server with the
> "joined"
> > chat text
> > > - Fixed seeing the wrong class counts if the game swapped teams while
> the
> > class menu was open
> > > - Fixed Spies being able to disguise while performing a taunt
> > > - Fixed having to press the voice menu key twice if the menu timed out
> > and closed itself last time it was open
> > > - Fixed the "Confirm Delete" dialog in the Items menu not handling the
> > key correctly
> > > - Fixed dispenser not healing players at the correct rate if it's
> > upgraded while the players are already touching the dispenser
> > > - Fixed exec'ing the .cfg file for a class change before the player has
> > actually changed class
> > >
> > > Jason
> > >
> > >
> > > ___
> > > To unsubscribe, edit your list preferences, or view the list archives,
> > please visit:
> > > http://list.valvesoftware.com/mailman/listinfo/hlds
> >
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> > please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread David Parker
I agree, that's a very good point.  It seems to me like one solution would be 
for them to put a folder within the srcds directory for uploads and make the 
engine use it.  They could always create a cvar to specify a different location 
for uploaded files which admins could use if they wanted to override the 
default.  Similar to how logging works right now.

    - Dave

- Original Message -
From: Jeff Sugar 
Date: Monday, December 7, 2009 9:37 pm
Subject: Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source  Update 
Released
To: Half-Life dedicated Linux server mailing list 


> Well put, neph.
> 
> On Mon, Dec 7, 2009 at 6:29 PM, Nephyrin Zey 
>  wrote:
> 
> >
> > > Engine:
> > > - Added checks to prevent transferring .smx, .gcf, and .sys 
> files between
> > client/server
> > > - Fixed upload/download exploits with spaces in the file 
> extension or a
> > path separator at the beginning of the requested file (as 
> reported on the
> > HLDS mailing lists)
> >
> >
> > This is sad. You can still upload/download random files as 
> long as their
> > extension isn't blacklisted? There's so many ways to cause 
> problems with
> > this... even if you switch to an extension WHITELIST there'd 
> still be
> > problems. Whose to say addons dont use other extensions to store
> > settings? Or bash/apache/other services dont read certain 
> files? Is
> > .bashrc blocked? What if someone uses their home directory as 
> the server
> > root? What if someone doesn't want script kiddies uploading
> > special_note_from_valve.readme to their server?
> >
> > Why not replace this interface with something that doesn't allow
> > arbitrary file uploads/downloads with something as laughable 
> as a
> > extension blacklist making 'safe'. When someone finds yet 
> another way to
> > abuse this (I can think of two separate ways to continue to 
> use this
> > exploit for remote code execution) its going to come up again, years
> > after the issues with it was first noted...
> >
> > - Neph
> >
> >
> > On 12/07/2009 06:20 PM, Jason Ruymen wrote:
> > > Required updates for Team Fortress 2 and Day of Defeat: 
> Source are now
> > available.  Please run hldsupdatetool to receive the 
> updates.  The specific
> > changes include:
> > >
> > > Engine:
> > > - Added checks to prevent transferring .smx, .gcf, and .sys 
> files between
> > client/server
> > > - Fixed upload/download exploits with spaces in the file 
> extension or a
> > path separator at the beginning of the requested file (as 
> reported on the
> > HLDS mailing lists)
> > >
> > > Team Fortress 2:
> > > - Fixed custom particle systems inside maps causing 
> particles to break in
> > successive maps
> > > - Fixed a rare vphysics crash
> > > - Fixed background highlight for KOTH timers not being 
> aligned properly
> > in minmode
> > > - Fixed the Heavy's fists being hidden while taunting
> > > - Fixed cloaked Spies having the critboost effect on their weapon
> > > - Fixed banned clients being able to spamming a server with 
> the "joined"
> > chat text
> > > - Fixed seeing the wrong class counts if the game swapped 
> teams while the
> > class menu was open
> > > - Fixed Spies being able to disguise while performing a taunt
> > > - Fixed having to press the voice menu key twice if the menu 
> timed out
> > and closed itself last time it was open
> > > - Fixed the "Confirm Delete" dialog in the Items menu not 
> handling the
> > key correctly
> > > - Fixed dispenser not healing players at the correct rate if it's
> > upgraded while the players are already touching the dispenser
> > > - Fixed exec'ing the .cfg file for a class change before the 
> player has
> > actually changed class
> > >
> > > Jason
> > >
> > >
> > > ___
> > > To unsubscribe, edit your list preferences, or view the list 
> archives,> please visit:
> > > http://list.valvesoftware.com/mailman/listinfo/hlds
> >
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list 
> archives,> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
> ___
> To unsubscribe, edit your list preferences, or view the list 
> archives, please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread Jeff Sugar
Well put, neph.

On Mon, Dec 7, 2009 at 6:29 PM, Nephyrin Zey  wrote:

>
> > Engine:
> > - Added checks to prevent transferring .smx, .gcf, and .sys files between
> client/server
> > - Fixed upload/download exploits with spaces in the file extension or a
> path separator at the beginning of the requested file (as reported on the
> HLDS mailing lists)
>
>
> This is sad. You can still upload/download random files as long as their
> extension isn't blacklisted? There's so many ways to cause problems with
> this... even if you switch to an extension WHITELIST there'd still be
> problems. Whose to say addons dont use other extensions to store
> settings? Or bash/apache/other services dont read certain files? Is
> .bashrc blocked? What if someone uses their home directory as the server
> root? What if someone doesn't want script kiddies uploading
> special_note_from_valve.readme to their server?
>
> Why not replace this interface with something that doesn't allow
> arbitrary file uploads/downloads with something as laughable as a
> extension blacklist making 'safe'. When someone finds yet another way to
> abuse this (I can think of two separate ways to continue to use this
> exploit for remote code execution) its going to come up again, years
> after the issues with it was first noted...
>
> - Neph
>
>
> On 12/07/2009 06:20 PM, Jason Ruymen wrote:
> > Required updates for Team Fortress 2 and Day of Defeat: Source are now
> available.  Please run hldsupdatetool to receive the updates.  The specific
> changes include:
> >
> > Engine:
> > - Added checks to prevent transferring .smx, .gcf, and .sys files between
> client/server
> > - Fixed upload/download exploits with spaces in the file extension or a
> path separator at the beginning of the requested file (as reported on the
> HLDS mailing lists)
> >
> > Team Fortress 2:
> > - Fixed custom particle systems inside maps causing particles to break in
> successive maps
> > - Fixed a rare vphysics crash
> > - Fixed background highlight for KOTH timers not being aligned properly
> in minmode
> > - Fixed the Heavy's fists being hidden while taunting
> > - Fixed cloaked Spies having the critboost effect on their weapon
> > - Fixed banned clients being able to spamming a server with the "joined"
> chat text
> > - Fixed seeing the wrong class counts if the game swapped teams while the
> class menu was open
> > - Fixed Spies being able to disguise while performing a taunt
> > - Fixed having to press the voice menu key twice if the menu timed out
> and closed itself last time it was open
> > - Fixed the "Confirm Delete" dialog in the Items menu not handling the
> key correctly
> > - Fixed dispenser not healing players at the correct rate if it's
> upgraded while the players are already touching the dispenser
> > - Fixed exec'ing the .cfg file for a class change before the player has
> actually changed class
> >
> > Jason
> >
> >
> > ___
> > To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds
>
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux


Re: [hlds_linux] [hlds] Team Fortress 2/Day of Defeat: Source Update Released

2009-12-07 Thread Nephyrin Zey

> Engine:
> - Added checks to prevent transferring .smx, .gcf, and .sys files between 
> client/server
> - Fixed upload/download exploits with spaces in the file extension or a path 
> separator at the beginning of the requested file (as reported on the HLDS 
> mailing lists)


This is sad. You can still upload/download random files as long as their 
extension isn't blacklisted? There's so many ways to cause problems with 
this... even if you switch to an extension WHITELIST there'd still be 
problems. Whose to say addons dont use other extensions to store 
settings? Or bash/apache/other services dont read certain files? Is 
.bashrc blocked? What if someone uses their home directory as the server 
root? What if someone doesn't want script kiddies uploading 
special_note_from_valve.readme to their server?

Why not replace this interface with something that doesn't allow 
arbitrary file uploads/downloads with something as laughable as a 
extension blacklist making 'safe'. When someone finds yet another way to 
abuse this (I can think of two separate ways to continue to use this 
exploit for remote code execution) its going to come up again, years 
after the issues with it was first noted...

- Neph


On 12/07/2009 06:20 PM, Jason Ruymen wrote:
> Required updates for Team Fortress 2 and Day of Defeat: Source are now 
> available.  Please run hldsupdatetool to receive the updates.  The specific 
> changes include:
>
> Engine:
> - Added checks to prevent transferring .smx, .gcf, and .sys files between 
> client/server
> - Fixed upload/download exploits with spaces in the file extension or a path 
> separator at the beginning of the requested file (as reported on the HLDS 
> mailing lists)
>
> Team Fortress 2:
> - Fixed custom particle systems inside maps causing particles to break in 
> successive maps
> - Fixed a rare vphysics crash
> - Fixed background highlight for KOTH timers not being aligned properly in 
> minmode
> - Fixed the Heavy's fists being hidden while taunting
> - Fixed cloaked Spies having the critboost effect on their weapon
> - Fixed banned clients being able to spamming a server with the "joined" chat 
> text
> - Fixed seeing the wrong class counts if the game swapped teams while the 
> class menu was open
> - Fixed Spies being able to disguise while performing a taunt
> - Fixed having to press the voice menu key twice if the menu timed out and 
> closed itself last time it was open
> - Fixed the "Confirm Delete" dialog in the Items menu not handling the key 
> correctly
> - Fixed dispenser not healing players at the correct rate if it's upgraded 
> while the players are already touching the dispenser
> - Fixed exec'ing the .cfg file for a class change before the player has 
> actually changed class
>
> Jason
>
>
> ___
> To unsubscribe, edit your list preferences, or view the list archives, please 
> visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds


___
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux