Zero Day Exploit in SRCDS… - By cold on August 25th, 2009

ALL ALMOST ALL NONE of our servers will be offline until Garry patches the exploit uncovered in SRCDS which allows anyone to upload/download files to a server.

Update
All servers are back online.

35 Responses to “Zero Day Exploit in SRCDS…”

RobotWaterMelon wrote:

I hope that’s soon. ‘.’


john freeman wrote:

no more wepon! :O


Chuck Norris wrote:

NOOOOO!!!!!!!!!!! CMON! I JUST GOT ON DEATHRUN, AND BOOM ITS GONE!


Sharkey wrote:

That sucks. I Was wondering where they were.

Work Garry! Work!


Sharkey wrote:

My Garry’s Mod just updated, i think garry might of released it.


Bloodstealer wrote:

This might be a while >.<


daveman wrote:

well sarkey we don’t know yet and it will maybe be a while or few week >.> till it fix I will say turn off your server and look in your lua file for any lua virues and don’t get any ideas to hack any servers now and garry is on it right now.


ninjers wrote:

hay im ninjers and my ip is 24.1.3.138

im also gay


Ðestroyer [i wrote:

Q.Q i hope garry fixes it!


daveman wrote:

ninjer it just begin today >.> like 5 server been hack just today


Deershark wrote:

This started a few days ago. How do I know? Because Sunrise was taken down for the same reason a few days ago, I think Monday.


district 9 deadly force wrote:

I wonder if in that last update he fixed it besides just adding achivemnts which i hvae no idea what the point of those were for.


Sharkey wrote:

looks like garry after all might have fixed it:
Changelog:
-Added an initial 15 Steamworks Achievements
-Fixed TF2 player and hat models being black
{{{{-Fixed some server lagging exploits}}}}
That’s probally it. He wouldn’t want to say the real reason because it looks bad on his side :P


Unreal_Me wrote:

Valve released an engine update fixing the issue, but Garry has to merge the files into garrysmod.
Not sure if the latest gmod update did that.


Sharkey wrote:

Okay guys @ Sass :P Everything should be fixed noa :P TURN ON OUR SERBS :D


daveman wrote:

well yes your right Deershark but they were testing it and fixing it so they can get a better % to get the gamemode but they dont got sunrise yet >.> and what i say then they had it that the best %


Effektiv wrote:

The fixes mentioned in the recent patch were submitted before the exploit was leaked and went public so there’s still no fix and no way to identify if files are being downloaded/uploaded till its too late.


Hizan wrote:

Just received the update :3


daveman wrote:

well it’s not fix yet this what garry said “This isn’t something I can fix. It’s on Valve’s side. I can’t change anything that updates the engine. I think the base HL2 engine needs to be updated.

I’ve emailed Valve but they haven’t replied yet. ”

so we have to wait on Valve >.>


Sharkey wrote:

Counter-Strike: Source Just updated (That’s a first) and look at one of the changes:

-Fixed an exploit that allowed files to be uploaded to the server at arbitrary locations in the file system

I hope they remember to update Gmod too :D


Off the Boat \ Cris wrote:

I told u guys this would happen but who didnt listen?


Metronome wrote:

Well, i doubt garry could fix it anyways… but how exactly does achievements screw up servers like that Q.Q


Deershark wrote:

Metronome, the achievements didn’t do shit to the servers. This happen before that came out. Garry can’t fix it, that is why is emailed value about it.


Sharkey wrote:

My Source Engine was updated, and in the changelog it said it was fixed… weird. I would think it’s safe now.


daveman wrote:

well it not fix >.>


daveman wrote:

sorry for 2 posting >.> Valve didn’t send the fix yet


Kalin1223 wrote:

Shit, I forgot my password and i cant change it D:


Dingle wrote:

Lol kalin, that’s the exact same spot im in right now. I guess we just have to wait. Back to climb/deathrun!


subwar wrote:

From Wikipedia:

A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit computer application vulnerabilities that are unknown to others, undisclosed to the software vendor, or for which no security fix is available. Zero-day exploits (actual code that can use a security hole to carry out an attack) are used or shared by attackers before the software vendor knows about the vulnerability.

To ninjers:

Good job trying to be a smartass and failing at it. !11


Kalin1223 wrote:

Can I change password without joining to lounge ?
Maybe Admins can change it ? I need it fast coz i want VIP ^^


c00t3r wrote:

Oh c’mon! Why is it still down?
Sharkey just said its save now. O_o’

When is it going to be on again?
I can’t wait any longer, although I got pretty much other stuff to do. ^^


Sharkey wrote:

It’s been over a week and I can’t live!


Sharkey wrote:

Garry says the update will be this week. I can’t wait!


Sharkey wrote:

Triple Post =\

But, Yay :D


Sickshot wrote:

This wasn’t a zero day exploit, it had been privately known for months before it was leeked.

Subwar is an idiot, herp derp lets use wikipedia for a source!!!111 It’s not like anyone can edit it.. the definition he used is incorrect, a zero day exploit is an exploit which is found the same day as the release of the software.

To subwar:

Good job trying to be a smartass and failing at it. !11


Leave a Reply


Login