go to the Main page
slide show

www.Create-Server.com » Tutorials » New destructive HLDS exploits - hlds_fuck and hlds_vcrash

Tutorials: New destructive HLDS exploits - hlds_fuck and hlds_vcrash

Author: 3JIou-TaTaPuH (7-03-2010, 14:49)


I) hlds_vcrash

New destructive HLDS exploits - hlds_fuck and hlds_vcrash

Description: Other names of this exploit is hlds_vcrash2, hlds_vcrash_fuck, hlds_vshell and numerous variations for use in cron. This exploit causes the error "FATAL ERROR (shutting down): Host_Error: SV_ParseVoiceData: invalid incoming packet".

Vulnerable/Protected: It affects to all server protocols 47/48. Very old 46 protocol builds can withstand the attack due to an exploits authorization error on the server.
The first information about the vulnerability appeared in 2002 (proove). Hlds_vcrash exploits the error in processing SV_ParseVoiceData (voice data's from the clients).
And this is what we get in a server console: (you can see attacker IP in there )

Treatment?! Now the most interesting - how to fight?
1. The first and easiest option - install Anti CS-DoS by Shockler. Starting from version 3.5 it comes with a fix for the "Host_Error: SV_ParseVoiceData". However, easiest - not always the right one. Tools itself periodically crashes with "OUT OF MEMORY", and the author self says "Use at your own risk".
For Linux you can install HLShield 2.10.
2. Use patch VUP 2.7 (ViTYAN's GameServers Universal Patch) or newer from vityan666 (supports both Windows and Linux).
3. Another option is patching server binaries with hex-editor, for example, HxD.
4. For sick bonkers. You can install Orpheu Module 2.2 + special plugin + script which can protect the server. How much memory will consume this module itself, wouldn't this add new problems - nobody knows. But conditionally this is the only legal way of protection from this exploit (perfect for sick STEAM lovers 25 ).
P.S: On the Internet lined out a lot of ready patched libraries for different version servers builds. Remember that you must download proper patched .dll (.so) which is compatible with your server! Also, some info about patched .so from Shocker (Anti CSDoS Developer)
Quote: Originally Posted by SH@RK (translate from Russian language)

Anti CSDoS Author laid out here http://www.freakz.ro/forum/FIX-Host_Error-...ata-t31559.html patched .so (from vcrash). He leave Host_Error, but he corrected Host_Error call function itself. It avoid call of CL_WriteMessageHistory, Con_Printf, Host_ShutdownServer, Sys_Error functions, and calls CL_Disconnect only. Well Con_Printf he apparently avoid in vain, but basically idea of editing Host_Error - a wonderful solution.

page 1-of-2 | >> Next
Custom Search
Views: 17181  Comments (12)  Print
Related News...:

Administrators
Joined: 3.01.2010, ICQ:
#1: Enzo Matrix (10 March 2010 17:11)
Wow nice article by the way, and this 2 exploit can be really dangerous tool in some young kid hands.
P.S If some one needs
hlds_crash
hlds_fuck
kill_cs
kill_csv2
PM me and probably Ill give it to you 08 05

--------------------
Stop writing "Sorry for my bad english, Im from insert random country here". Noone cares. Almost noone here speaks native english. ... cXhristian (c)

Competently asked question is 50 % of success in reception of the answer to it.
    

Administrators
Joined: 26.03.2009, ICQ:
#2: 3JIou-TaTaPuH (11 March 2010 16:11)
    

Administrators
Joined: 3.01.2010, ICQ:
#3: Enzo Matrix (9 July 2010 04:11)
There are new modification of this exploit calls failds.

--------------------
Stop writing "Sorry for my bad english, Im from insert random country here". Noone cares. Almost noone here speaks native english. ... cXhristian (c)

Competently asked question is 50 % of success in reception of the answer to it.
    

Guests
Joined: --, ICQ:
#4: 0p (9 July 2010 18:24)
yep i know
    

Guests
Joined: --, ICQ:
#5: SOURABH (1 October 2010 10:07)
10/1/2010 - 81411 PM: Cannot fix SV_ParseVoiceData for 3588. Already fixed or unsupported SWDS version?
10/1/2010 - 81411 PM: There was an error while patching HLDS with PID 3588. Process not active?


help !!!
    

Users
Joined: 15.12.2010, ICQ:
#6: ArtaN (5 January 2011 08:56)
new HLDS Exploits 1.1 By I-T-N-I
Fuck Dproto <<< This bug Pls help me
    

Users
Joined: 21.01.2011, ICQ:
#7: dENKEbURAZ (22 January 2011 06:51)
MY SERVER IS SHUT DOWN and write text Sv_ParseVoiceData .... !!!!! :SS =.=
    

Users
Joined: 20.09.2010, ICQ:
#8: Deepak101 (24 January 2011 05:36)
dENKEbURAZ,
Use Anticsdos 3.5 by Shocker..
    

Users
Joined: 2.12.2010, ICQ:
#9: ankush (8 February 2011 23:01)
yO administrator wAssup :D
    

Users
Joined: 1.05.2011, ICQ:
#10: syedrajashah (2 May 2011 07:22)
where to download this crash file can u tell me
    

Users
Joined: 2.12.2010, ICQ:
#11: ankush (12 May 2011 11:52)
wasSSSup admins :D
iam FRom INDIA ...
    

Users
Joined: 30.07.2011, ICQ: pratham966@gmail.com
#12: pratham966 (30 July 2011 14:16)
can any one tell me whether new hldsupdate removes such bugs or it still present???????

also i need stable hlds configuration to run on 64 bit machine as windows & linux os. Please help me its urgent for me or post any page/site link here or just mail me at pratham966@gmail.com.

Please help & thanks in advance.

Regards,
Pratham :)
    
Information
Information
Members of Guests cannot leave comments.



Copyright © 2009-2010. All rights reserved.
Terms of Use - Use of this site signifies your agreement. www.Create-Server.com ™