Official Won Dlfile Exploit Fix!
Andyonce
Join Date: 2003-08-16 Member: 19799Members
From the hlds_announcement list:
<!--QuoteBegin--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->We have released an update to the 4.1.1.1/3.1.1.1 series of the HL
server. This update can be applied to any version of the 4.1.1.1 series
to get it up to date.
The update can be downloaded from:
via BitTorrent
<a href='http://www.steampowered.com/bittorrent/hlds4111e_beta.exe.torrent' target='_blank'>http://www.steampowered.com/bittorrent/hld...eta.exe.torrent</a>
<a href='http://www.steampowered.com/bittorrent/hlds_l_3111e_update.tar.gz.torrent' target='_blank'>http://www.steampowered.com/bittorrent/hld....tar.gz.torrent</a>
or via ftp
ftp.valvesoftware.com
Login: hlserver
Password: hlserver
Directory: x.1.1.1/Win32 or x.1.1.1/Linux
md5sum information:
f81c50fe8d6a7a8914403697c719b824 hlds4111e_beta.exe
79baaaf4b3c7902928047f30917dc635 hlds_l_3111e_update.tar.gz
Changes/Additions:
------------------
* Added list of file extensions that cannot be downloaded with the
dlfile command. The exclude list is currently: .cfg .ini .bat .exe .vbs
.com .dll .lst .log. This prevents the published dlfile exploit.
Bug Fixes:
----------
* Fixed incorrect time base being used for client prediction on server.
----------
Just a quick reminder, DO NOT apply this over a Steam install. This is
ONLY for WON (CS 1.5) servers.
- Alfred<!--QuoteEnd--></td></tr></table><span class='postcolor'><!--QuoteEEnd-->
At last <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif'><!--endemo-->
<!--QuoteBegin--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->We have released an update to the 4.1.1.1/3.1.1.1 series of the HL
server. This update can be applied to any version of the 4.1.1.1 series
to get it up to date.
The update can be downloaded from:
via BitTorrent
<a href='http://www.steampowered.com/bittorrent/hlds4111e_beta.exe.torrent' target='_blank'>http://www.steampowered.com/bittorrent/hld...eta.exe.torrent</a>
<a href='http://www.steampowered.com/bittorrent/hlds_l_3111e_update.tar.gz.torrent' target='_blank'>http://www.steampowered.com/bittorrent/hld....tar.gz.torrent</a>
or via ftp
ftp.valvesoftware.com
Login: hlserver
Password: hlserver
Directory: x.1.1.1/Win32 or x.1.1.1/Linux
md5sum information:
f81c50fe8d6a7a8914403697c719b824 hlds4111e_beta.exe
79baaaf4b3c7902928047f30917dc635 hlds_l_3111e_update.tar.gz
Changes/Additions:
------------------
* Added list of file extensions that cannot be downloaded with the
dlfile command. The exclude list is currently: .cfg .ini .bat .exe .vbs
.com .dll .lst .log. This prevents the published dlfile exploit.
Bug Fixes:
----------
* Fixed incorrect time base being used for client prediction on server.
----------
Just a quick reminder, DO NOT apply this over a Steam install. This is
ONLY for WON (CS 1.5) servers.
- Alfred<!--QuoteEnd--></td></tr></table><span class='postcolor'><!--QuoteEEnd-->
At last <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif'><!--endemo-->
Comments
*dies
The solution some people have come up with is a wrapper for the hlds 3.1.1.0 binary to filter out offending commands. You can find this wrapper here:
<a href='http://site.3dwire.net/code/dlfile-boffix_1.3.zip' target='_blank'>http://site.3dwire.net/code/dlfile-boffix_1.3.zip</a>
Eww this is digusting candy <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif'><!--endemo-->
I have adminmod and metamod working fine on my system and I use the boffix patch on 3.1.1.0c HLDS.
but the instant i add a plugin besides stuck or whichbot it crashes/plugin never loads
and i doubt it has to do anything with i386.so or i686.so at the end? thats the only diffrence i see
This started happening right after we got a virus on our server and had to get it reformated
then servermatrix reinstalled linux
I would check to make sure that the paths are correct to the metamod files and that you are using the latest version of metamod (1.17), you can check this by typing "meta version" in the server's console while it is running. You can find out what plugins are running on metamod by typing "meta list"
Maybe that will help.
Edit: Anyway im using Redhat 9.0 supposingly ( i cant check the OS tho :-\ and the operating system could be mested up for all i know and ive done this sooo many times)