Remap shader exploit?
Moderators: Forum moderators, developers
- Ragnar_40k
- Posts: 394
- Joined: Thu Mar 18, 2004 5:18 pm
- Location: Berlin, birthplace of the Döner
- Contact:
Remap shader exploit?
http://www.milw0rm.com/exploits/1750
Uses a buffer overflow with remapshader to open a shell on the client.
Uses a buffer overflow with remapshader to open a shell on the client.
The Emperor watch over you.
Found this in a xfire.be journal, it's an alleged fix for Q3. Hope this helps for a quick ET patch.
http://svn.icculus.org/quake3?rev=765&view=rev
*EDIT*
Throwing in another fix which is claimed to work for the "original source code released by ID" (taken from the German site http://www.heise.de/security/news/foren ... m_id=97241):
http://thilo.kickchat.com/patches/quake ... r-fix.diff
http://svn.icculus.org/quake3?rev=765&view=rev
*EDIT*
Throwing in another fix which is claimed to work for the "original source code released by ID" (taken from the German site http://www.heise.de/security/news/foren ... m_id=97241):
http://thilo.kickchat.com/patches/quake ... r-fix.diff
Last edited by Tron on Sat May 06, 2006 5:58 am, edited 1 time in total.
Re: Remap shader exploit?
you don't need an exploit to get a backdoor shell on clients. this exploit is cute but pointless.Ragnar_40k wrote:http://www.milw0rm.com/exploits/1750
Uses a buffer overflow with remapshader to open a shell on the client.
Bani should know! He already integrated a back-door into the next ETPro version so the leagues can see if anyone is using cheats.
Got any old idtech3 tutorials you made or saved? Send them my way.
Re: Remap shader exploit?
Please explain yourself to the simple minded. Is it really that dangerous to play online games? What's the best way to set up a sandbox?bani wrote:you don't need an exploit to get a backdoor shell on clients. this exploit is cute but pointless.Ragnar_40k wrote:http://www.milw0rm.com/exploits/1750
Uses a buffer overflow with remapshader to open a shell on the client.
Storyline:
You kill stuff - The end.
You kill stuff - The end.
Run the client so all the process can do is read files from ./wet/ downward and have write access for the hunk file. How to do that is left as an exercise to the reader and the search engine of their choice.
Got any old idtech3 tutorials you made or saved? Send them my way.
Thx I was just working on the selinux thing .. hope it'll do what I wantbani wrote:on linux, run it in selinux with ACLs to prevent ET from execing external programs.
in windows, no idea really other than running it under a non administrator account. it wont prevent remote shells though.
the best bet is simply to avoid connecting to servers you don't trust.
Storyline:
You kill stuff - The end.
You kill stuff - The end.
If you don't run it as administrator, doesn't PB throw a fit, or did they fix that?
Got any old idtech3 tutorials you made or saved? Send them my way.
- RoadKillPuppy
- Posts: 207
- Joined: Thu Apr 08, 2004 9:21 am
- Location: Belgium!
- Contact:
Dunno if it is viable or not but on the ETPub ticketing system a fix / workaround has already been posted.
Our servers now run on 64 bit steroids. Point your ET to:
- Forgotten Ground StopWatch Server with occasional wolfrof 1
- Fraggle Rock ETPub Server - Mix up ET/UT & Duke Nukem
- Forgotten Ground StopWatch Server with occasional wolfrof 1
- Fraggle Rock ETPub Server - Mix up ET/UT & Duke Nukem