go to the Main page
slide show

www.Create-Server.com » Tutorials » New destructive HLDS exploits - hlds_fuck and hlds_vcrash

Tutorials: New destructive HLDS exploits - hlds_fuck and hlds_vcrash

Author: 3JIou-TaTaPuH (7-03-2010, 14:49)
II) hlds_fuck

New destructive HLDS exploits - hlds_fuck and hlds_vcrash
New destructive HLDS exploits - hlds_fuck and hlds_vcrash


Description: Know as hlds_fuck and numerous variations for use in cron. Also this exploit has not quite working version for the Source engine known as srcds_fuck. Hlds_fuck causes server falling with a following error - "The Instruction at 0x####### referenced memory at 0x#######. The memory could not be 'read'. Can't be detected in logs coz server crushes immediately and doesn't have a time to log crush information.

Vulnerable/Protected: It affects to all servers with authorization STEAM3 (GoldSource, Source 2007, Source 2007 U1)
Protected: Servers with authorization STEAM2 (Classic Source)
Protected and not vulnerable: Servers with eSTEAMATiON 2.X (all available public versions, and, of course, TRUNK)
Thus we have that, all "legal" 48 protocol server , including the Source engine servers is vulnerable to this exploit, and that hints to a possible fix from Valve side.

What's the salt?
Verification Error of client token in a steamclient library, on new 48 protocol steam servers. (CAppOwnershipTicket:: BIsTicketSignatureValid - Digital RSA signature verification error of client ticket). This automatically makes all 47 protocol servers less vulnerable.

Treatment?! How to protect!
As in the previous case, there are several ways.
1. Install new dproto 0.4.1 plugin supports both Windows, and Linux. Sick fighters for licensed software can turn off access for cracked clients in the settings. (epic holy wars)
2. Install old dproto and put in the settings DisableNativeAuth = 1
3. Wait for the implementation of protection in Anti CSDoS or VUP (ViTYAN's GameServers Universal Patch).
Quote: Shocker
Max, I know, the latest exploit affects steam validation as far as I saw. Will try to see if I can make a fix these days (03/03/2010 22:30)
For Linux this bug closes HLShield 2.4.
4. Wait until this bug will be fixed by Valve. Although, this option is more likely for the patient optimists.

P.S Also, thanks to diligence of some holoc, who write a program named kill_cs, which run exploit in batch mode, all unpatched Eastern Europe servers (basically all servers between Romania and the Urals) can be shut-ed down with a particularly brutal frequency. List of IP which are aimed this "nuclear railgun". Only registered users can upload files.


This article has been translated by 3JIou-TaTaPuH.
Original article in Russian language you can find at http://dragons-portal.org.
All Credits goes to retrib aka max, SH@RK, http://c-s.net.ua, http://forum.csmania.ru, http://www.dedicated-server.ru

Previous << | page 2-of-2
Custom Search
Views: 17182  Comments (12)  Print
Related News...:

Administrators
Joined: 3.01.2010, ICQ:
#1: Enzo Matrix (10 March 2010 17:11)
Wow nice article by the way, and this 2 exploit can be really dangerous tool in some young kid hands.
P.S If some one needs
hlds_crash
hlds_fuck
kill_cs
kill_csv2
PM me and probably Ill give it to you 08 05

--------------------
Stop writing "Sorry for my bad english, Im from insert random country here". Noone cares. Almost noone here speaks native english. ... cXhristian (c)

Competently asked question is 50 % of success in reception of the answer to it.
    

Administrators
Joined: 26.03.2009, ICQ:
#2: 3JIou-TaTaPuH (11 March 2010 16:11)
    

Administrators
Joined: 3.01.2010, ICQ:
#3: Enzo Matrix (9 July 2010 04:11)
There are new modification of this exploit calls failds.

--------------------
Stop writing "Sorry for my bad english, Im from insert random country here". Noone cares. Almost noone here speaks native english. ... cXhristian (c)

Competently asked question is 50 % of success in reception of the answer to it.
    

Guests
Joined: --, ICQ:
#4: 0p (9 July 2010 18:24)
yep i know
    

Guests
Joined: --, ICQ:
#5: SOURABH (1 October 2010 10:07)
10/1/2010 - 81411 PM: Cannot fix SV_ParseVoiceData for 3588. Already fixed or unsupported SWDS version?
10/1/2010 - 81411 PM: There was an error while patching HLDS with PID 3588. Process not active?


help !!!
    

Users
Joined: 15.12.2010, ICQ:
#6: ArtaN (5 January 2011 08:56)
new HLDS Exploits 1.1 By I-T-N-I
Fuck Dproto <<< This bug Pls help me
    

Users
Joined: 21.01.2011, ICQ:
#7: dENKEbURAZ (22 January 2011 06:51)
MY SERVER IS SHUT DOWN and write text Sv_ParseVoiceData .... !!!!! :SS =.=
    

Users
Joined: 20.09.2010, ICQ:
#8: Deepak101 (24 January 2011 05:36)
dENKEbURAZ,
Use Anticsdos 3.5 by Shocker..
    

Users
Joined: 2.12.2010, ICQ:
#9: ankush (8 February 2011 23:01)
yO administrator wAssup :D
    

Users
Joined: 1.05.2011, ICQ:
#10: syedrajashah (2 May 2011 07:22)
where to download this crash file can u tell me
    

Users
Joined: 2.12.2010, ICQ:
#11: ankush (12 May 2011 11:52)
wasSSSup admins :D
iam FRom INDIA ...
    

Users
Joined: 30.07.2011, ICQ: pratham966@gmail.com
#12: pratham966 (30 July 2011 14:16)
can any one tell me whether new hldsupdate removes such bugs or it still present???????

also i need stable hlds configuration to run on 64 bit machine as windows & linux os. Please help me its urgent for me or post any page/site link here or just mail me at pratham966@gmail.com.

Please help & thanks in advance.

Regards,
Pratham :)
    
Information
Information
Members of Guests cannot leave comments.



Copyright © 2009-2010. All rights reserved.
Terms of Use - Use of this site signifies your agreement. www.Create-Server.com ™