Urban Terror Forums: q3a server vulnerability - Urban Terror Forums

Jump to content

 Login | Register 
Advertisement
  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

q3a server vulnerability Rate Topic: -----

#11 User is offline   illogical Icon

  •   verified user   
    Retired Master Server Administrator
  • Account: illogical
  • Main tag: 6th|
  • Country:
  • Joined: 08-March 10
  • Posts: 2,349

Posted 18 February 2005 - 08:01 PM

Already looked at patch-o-matic. I "may" write a case-insensitive string match module.

As for modifying the q3ded and it not pissing off pure or PB, that's bad, really bad. With the right knowledge a programmer/server admin could code some unfair advantages in for his team. If their server is used for a match... I see a problem.

#12 User is offline   Woekele Icon

  •   former FS member   
    Public Relations
  • Account: woekele
  • Country:
  • Joined: 26-January 10
  • Posts: 11,575

Posted 18 February 2005 - 08:13 PM

I think this thread and the links in it should be deleted. We dont want people to find about this :o

#13 User is offline   Heldenhaft (old) Icon

  • Joined: 07-February 04
  • Posts: 126
  • LocationGermany

Posted 18 February 2005 - 08:27 PM

Its not the q3ded to path with the fix, its the quake3.x86 where Luigi Auriemma advice to change Offset 0005a95c from 01 to 03 with the fix/patcher. Doesn't work (still vulnerable) for me (with urt), maybe someone else have more luck with this.

Anyway think the way with the iptables is the better one, unless there is a working official patch.

And no deletion/concealment is not the right way, aslong you not working for a well known software company ;>

#14 User is offline   illogical Icon

  •   verified user   
    Retired Master Server Administrator
  • Account: illogical
  • Main tag: 6th|
  • Country:
  • Joined: 08-March 10
  • Posts: 2,349

Posted 18 February 2005 - 09:01 PM

The iptables rules may be best... Or a passthrough server (something I've always wanted to play with)...

#15 User is offline   Jagged (old) Icon

  • Joined: 29-June 04
  • Posts: 153

Posted 18 February 2005 - 09:24 PM

Quote

Its not the q3ded to path with the fix, its the quake3.x86 where Luigi Auriemma advice to change Offset 0005a95c from 01 to 03 with the fix/patcher. Doesn't work (still vulnerable) for me (with urt), maybe someone else have more luck with this.

Anyway think the way with the iptables is the better one, unless there is a working official patch.

And no deletion/concealment is not the right way, aslong you not working for a well known software company ;>


Yeah, it doesnt fix it in every case. However, quake3.x86 is the linux client, q3ded is the linux server. Patching quake3.x86 will not do any good at all.

bullet_loaderAdvertisement

#16 User is offline   Jagged (old) Icon

  • Joined: 29-June 04
  • Posts: 153

Posted 18 February 2005 - 09:27 PM

Quote

I think this thread and the links in it should be deleted. We dont want people to find about this :o


Security through obscurity, eh? Must be a Windows user :). Seriously, though, it's better to be informed than uninformed.

#17 User is offline   Woekele Icon

  •   former FS member   
    Public Relations
  • Account: woekele
  • Country:
  • Joined: 26-January 10
  • Posts: 11,575

Posted 18 February 2005 - 09:32 PM

Haha, well... I just think there should be a good working fix before showing the bug.

#18 User is offline   Jagged (old) Icon

  • Joined: 29-June 04
  • Posts: 153

Posted 18 February 2005 - 09:43 PM

Quote

Already looked at patch-o-matic. I "may" write a case-insensitive string match module.

As for modifying the q3ded and it not pissing off pure or PB, that's bad, really bad. With the right knowledge a programmer/server admin could code some unfair advantages in for his team. If their server is used for a match... I see a problem.


I do agree somewhat w/ you here.. Just wait for the q3 source code to be released... Course, by then we'll probably be moving on to etut.

#19 User is offline   Jagged (old) Icon

  • Joined: 29-June 04
  • Posts: 153

Posted 18 February 2005 - 09:45 PM

Another thing to point out is that iptables doesn't help the Windows server admins at all (shame on them for not using linux anyways)

-Jagged

#20 User is offline   illogical Icon

  •   verified user   
    Retired Master Server Administrator
  • Account: illogical
  • Main tag: 6th|
  • Country:
  • Joined: 08-March 10
  • Posts: 2,349

Posted 18 February 2005 - 09:52 PM

Windows server admins were screwed from the beginning, I'm mean really, they're using Windows. But on a serious not, this is where a pass through server would be perfect.

Clients connect to the passthrough. The passthrough filters data if neccessary, then passes it to the Quake 3 server. Basically, it's like a NAT, having to keep track of what's what and who's.

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

3 User(s) are reading this topic
0 members, 3 guests, 0 anonymous users

Sponsored link
https://www.frozensand.com/


Copyright © 1999-2024 Frozensand Games Limited  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of Frozensand Games Limited

Frozensand Games is a Limited company registered in England and Wales. Company Reg No: 10343942