To Everyone Using Admin Mod...

CatgirlCatgirl Join Date: 2002-11-03 Member: 5741Members
<div class="IPBDescription">...here's why you shouldn't.</div> <a href='http://online.securityfocus.com/archive/1/306120/2003-01-07/2003-01-13/0' target='_blank'>Read.</a>

Comments

  • greydmiyugreydmiyu Join Date: 2002-11-18 Member: 9234Members
    Not to mention try understanding how miniscule a problem it really is and from what direction. I mean since you worded it that way I bet you're not aware that the exploit results in a remote shell from <b>clients</b> connecting to the game server and that it requires the attacker to know the rcon password of the server. If they know the rcon server they can do a lot more to the server. IE, this is not a problem that should be addressed to server operators like it is some big issue for them. For most it isn't. It should be addressed to the <b>players</b> as an attacker could set up a server and wait for an unsuspecting client to connect.
  • BioHazardBioHazard Join Date: 2002-11-07 Member: 7495Members
    edited January 2003
    do you guys remember when a person spoofed the idSoftware ip's and changed all the quake server names and would restart the servers over and over?
    all it took was banning the specific block of ip's that idsoftware owned.
    such is the case with this... don't use a rcon password. problem solved.
    need rcon? search this forum for the plugin released to allow those with auth on ns to rcon without the password.
    case solved.
  • playerhaterplayerhater Join Date: 2002-11-13 Member: 8405Members
    <!--QuoteBegin--Catgirl+Jan 13 2003, 04:57 AM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Catgirl @ Jan 13 2003, 04:57 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--><a href='http://online.securityfocus.com/archive/1/306120/2003-01-07/2003-01-13/0' target='_blank'>Read.</a><!--QuoteEnd--></td></tr></table><span class='postcolor'><!--QuoteEEnd-->
    If you had "read" you wouldnt have posted <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile.gif' border='0' valign='absmiddle' alt='smile.gif'><!--endemo-->
  • CatgirlCatgirl Join Date: 2002-11-03 Member: 5741Members
    Okay since I haven't been able to see the forum for about a billion days...

    Kilmster: Just saw it that day on PHL, assumed it was new news.
  • sh1nysh1ny Join Date: 2002-11-02 Member: 3880Members
    My Personal preference
    <a href='http://amxmod.net' target='_blank'>http://amxmod.net</a>
    ownz !
  • cracker_jackmaccracker_jackmac Join Date: 2002-11-04 Member: 6891Members, Constellation, Reinforced - Shadow
    riiiiiiight....and your post does what to this topic?

    lemme think....
    nada.
  • mathyoumathyou Join Date: 2002-11-28 Member: 10131Members
    edited February 2003
    Moreover, AM has been patched to address the exploit. The only remaining expliots are for HLDS. Those would work regardless of AM/AMX. But thanks for the FUD.

    All that said, I've converted to AMX.
  • BonelessBoneless Join Date: 2002-09-03 Member: 1270Members
    AMX is ok... I'm currently using it, but sometimes I miss the ease of use and documentation of Adminmod.
Sign In or Register to comment.