OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: VOID.AT Security (crew_at_void.at)
Date: Fri Jan 10 2003 - 11:50:37 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    [void.at Security Advisory VSA0305]

    HLTV offers the ability to have thousands of spectators watch
    online games on Half-Life-servers.

    Overview
    ========

    By sending a specially crafted packet to the hltv-server,
    an attacker can cause the server to crash.

    Affected Versions
    =================

    The one that comes with hlds 3.1.1.0; possibly others.

    Impact
    ======

    Medium. The remote server simply crashes.

    Details
    =======

    Packets querying things like player-status etc always start
    with \xff\xff\xff\xff, followed by a query command and terminated
    by a \0.

    When you simply send \xff\xff\xff\xff\0 to the server, it crashes.

    Solution
    ========

    Vendor patch needed!

    Exploit
    =======

    Come on :-)

    Discovered by
    =============

    greuff <greuffvoid.at>

    Credits
    =======

    void.at
    everyone who was at 19c3

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (MingW32)
    Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

    iD8DBQE+Hwftzxi8qAgTjUMRAhzOAJ0fqNJQozxC4D+zLcHZlFoeWBvejACfXQWo
    4ajOCoouqK+oc05TpPrnvz0=
    =kWZm
    -----END PGP SIGNATURE-----