New FDS exploit fix (players can use admin commands) [message #164626] |
Thu, 28 July 2005 16:24 |
TimeFX
Messages: 25 Registered: January 2004 Location: Germany
Karma:
|
Recruit |
|
|
While going through linux server code I found a function what allows players to execute any console command on the server. For example every player can kick every other player on the server, players can send host message, players can shutdown the server and so on.
I made the patch for linux RH7 & RH8 and Windows dedicated server. Patching the windows game client isn't possible since RenGuard would disallow the change. I compiled the linux binary under SuSE 9.2 - hope it works.
Remember: You should make a backup of your renegade binary before patching.
To use the patch use "./rr_patch01 <your binary>"
Using the patch again will remove the changes.
Linux patcher: http://www.icefinch.net/rr/rr_patch01
Windows patcher: http://www.icefinch.net/rr/rr_patch01.exe
If you experience crashes after patching (which shouldn't happen) please report me your FDS version and the address where the crash occurred.
Greets,
TimeFX
IMPORTANT NOTE:
RenGuard 1.03 does NOT protect you from this exploit.
**EDIT**
This patch is CP1 compatible.
RH8: successfully tested
RH7: no feedback
WIN: no feedback
[Updated on: Thu, 28 July 2005 16:43] Report message to a moderator
|
|
|