Page 1 of 1

vulnerability exploit

Posted: Sat Sep 14, 2019 8:04 am
by eeben
There is a vulnerability on server. [link removed] fix is please. Linux still have good serstaring when crash happens. :geek:

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 10:17 am
by a domestic cat
This is known and also patched bug.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 10:58 am
by eeben
no its not. when server is empty and you type /readyteams and join ans type /teamfollow2 to team whole server crash.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:01 am
by c0rnn
It's been fixed years ago.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:05 am
by a domestic cat
Both /readyteams nor /teamfollow2 are not valid commands (but I get what you meant by that). Installed globalcombined.lua limits team command argument to be r, b or s, nothing else. As all Hirntot servers use that Lua module, they're not vulnerable.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:06 am
by eeben
I teester it on the morning and server restarted. :|

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:15 am
by eeben
You must be alone on the server its not working otherwise. Trust me it crashes.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:17 am
by a domestic cat
EDIT: I'm still not able to reproduce.

Re: vulnerability exploit

Posted: Sat Sep 14, 2019 11:26 am
by eeben
dID U SEE?