Remap shader exploit?

Discussion for any ET/ETPro/BayonET bugs or cheats you find...

Moderators: Forum moderators, developers

User avatar
Ragnar_40k
Posts: 394
Joined: Thu Mar 18, 2004 5:18 pm
Location: Berlin, birthplace of the Döner
Contact:

Remap shader exploit?

Post by Ragnar_40k »

http://www.milw0rm.com/exploits/1750

Uses a buffer overflow with remapshader to open a shell on the client.
The Emperor watch over you.
Tron
Posts: 22
Joined: Mon Apr 18, 2005 7:30 pm

Post by Tron »

Found this in a xfire.be journal, it's an alleged fix for Q3. Hope this helps for a quick ET patch. ;)

http://svn.icculus.org/quake3?rev=765&view=rev

*EDIT*
Throwing in another fix which is claimed to work for the "original source code released by ID" (taken from the German site http://www.heise.de/security/news/foren ... m_id=97241):

http://thilo.kickchat.com/patches/quake ... r-fix.diff
Last edited by Tron on Sat May 06, 2006 5:58 am, edited 1 time in total.
kracho
Posts: 8
Joined: Wed Aug 17, 2005 9:26 am

Post by kracho »

Well we need an official patch, hope it will be released soon :cry:
Storyline:
You kill stuff - The end.
User avatar
bani
Site Admin
Posts: 2780
Joined: Sun Jul 21, 2002 3:58 am
Contact:

Re: Remap shader exploit?

Post by bani »

Ragnar_40k wrote:http://www.milw0rm.com/exploits/1750

Uses a buffer overflow with remapshader to open a shell on the client.
you don't need an exploit to get a backdoor shell on clients. this exploit is cute but pointless.
User avatar
WeblionX
Posts: 762
Joined: Sun Sep 08, 2002 1:03 pm
Contact:

Post by WeblionX »

Bani should know! He already integrated a back-door into the next ETPro version so the leagues can see if anyone is using cheats.
Got any old idtech3 tutorials you made or saved? Send them my way.
kracho
Posts: 8
Joined: Wed Aug 17, 2005 9:26 am

Re: Remap shader exploit?

Post by kracho »

bani wrote:
Ragnar_40k wrote:http://www.milw0rm.com/exploits/1750

Uses a buffer overflow with remapshader to open a shell on the client.
you don't need an exploit to get a backdoor shell on clients. this exploit is cute but pointless.
Please explain yourself to the simple minded. Is it really that dangerous to play online games? What's the best way to set up a sandbox?
Storyline:
You kill stuff - The end.
User avatar
WeblionX
Posts: 762
Joined: Sun Sep 08, 2002 1:03 pm
Contact:

Post by WeblionX »

Run the client so all the process can do is read files from ./wet/ downward and have write access for the hunk file. How to do that is left as an exercise to the reader and the search engine of their choice.
Got any old idtech3 tutorials you made or saved? Send them my way.
User avatar
bani
Site Admin
Posts: 2780
Joined: Sun Jul 21, 2002 3:58 am
Contact:

Post by bani »

on linux, run it in selinux with ACLs to prevent ET from execing external programs.

in windows, no idea really other than running it under a non administrator account. it wont prevent remote shells though.

the best bet is simply to avoid connecting to servers you don't trust.
kracho
Posts: 8
Joined: Wed Aug 17, 2005 9:26 am

Post by kracho »

bani wrote:on linux, run it in selinux with ACLs to prevent ET from execing external programs.

in windows, no idea really other than running it under a non administrator account. it wont prevent remote shells though.

the best bet is simply to avoid connecting to servers you don't trust.
Thx I was just working on the selinux thing .. hope it'll do what I want
Storyline:
You kill stuff - The end.
User avatar
WeblionX
Posts: 762
Joined: Sun Sep 08, 2002 1:03 pm
Contact:

Post by WeblionX »

If you don't run it as administrator, doesn't PB throw a fit, or did they fix that?
Got any old idtech3 tutorials you made or saved? Send them my way.
User avatar
ReyalP
Posts: 1663
Joined: Fri Jul 25, 2003 11:44 am

Post by ReyalP »

WeblionX wrote:If you don't run it as administrator, doesn't PB throw a fit, or did they fix that?
PB doesn't explicitly require administrator, but the rights it does require pretty much scream "pwn me!"
send lawyers, guns and money
Decade
Posts: 101
Joined: Tue Dec 07, 2004 2:47 pm

Post by Decade »

I think that the damage that can be done by a regular user (removing personal files) is worse than the damage that only an administrator can do (you can always reinstall the os if system files are damaged, but you usually don't have backup for all personal files)
User avatar
RoadKillPuppy
Posts: 207
Joined: Thu Apr 08, 2004 9:21 am
Location: Belgium!
Contact:

Post by RoadKillPuppy »

an admin can remove *all* files, including the personal ones
Decade
Posts: 101
Joined: Tue Dec 07, 2004 2:47 pm

Post by Decade »

Exactly, "only" is the key word :P
User avatar
deej
Posts: 743
Joined: Fri Mar 19, 2004 12:44 am
Location: Belgium!
Contact:

Post by deej »

Dunno if it is viable or not but on the ETPub ticketing system a fix / workaround has already been posted.
Our servers now run on 64 bit steroids. Point your ET to:
- Forgotten Ground StopWatch Server with occasional wolfrof 1
- Fraggle Rock ETPub Server - Mix up ET/UT & Duke Nukem
Post Reply