[cod] Cfg download hacking

Morpheus morpheus at clantoc.org
Tue Sep 14 12:25:06 EDT 2010


  We're talking about the built-in download system, not the http 
redirect one, which you can control with symlinks and htaccess features. 
It's about a security hole that virtually exists in all q3-based games 
(at least for the net code).

Le 14/09/2010 18:21, Mavrick a écrit :
> Anyone tried symbolic links?
>
> On 14/09/2010 3:11 AM, Nosjp Nosjp wrote:
>> The only one solution:  set sv_allowDownload "0"
>>
>> On Mon, Sep 13, 2010 at 7:45 PM, Marco Padovan 
>> <evolutioncrazy at gmail.com <mailto:evolutioncrazy at gmail.com>> wrote:
>>
>>     We are having major hack attempts that consist in people
>>     downloading the cfg files....  currently we had to use random
>>     file names...
>>
>>     is there any solid work around?
>>
>>
>>     _______________________________________________
>>     cod mailing list
>>     cod at icculus.org <mailto:cod at icculus.org>
>>     http://icculus.org/mailman/listinfo/cod
>>
>>
>>
>> _______________________________________________
>> cod mailing list
>> cod at icculus.org
>> http://icculus.org/mailman/listinfo/cod
>
>
> _______________________________________________
> cod mailing list
> cod at icculus.org
> http://icculus.org/mailman/listinfo/cod
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://icculus.org/pipermail/cod/attachments/20100914/ae8a564f/attachment.htm>


More information about the cod mailing list