CS.RIN.RU - Steam Underground Community
http://cs.rin.ru/forum/

[Release] dproto [0.9.356] - HLDS serverside crack (13/11/2013)
http://cs.rin.ru/forum/viewtopic.php?f=29&t=55986
Page 13 of 153

Author:  kam821 [ Thursday, 08 Jul 2010, 21:17 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Thanks Crock for this update, but more, we need fix the VAC problem.

Author:  pizdauskas [ Thursday, 08 Jul 2010, 21:21 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Crock you god ::D thanks

Author:  europe [ Thursday, 08 Jul 2010, 21:32 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

didnt fixed my server, x64 wont allow to start anymore at all.

Author:  retrib [ Thursday, 08 Jul 2010, 21:42 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Crock, thanx! You're HLDS god!

Author:  europe [ Thursday, 08 Jul 2010, 21:57 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

I overwrited old dproto_i386.so and old .cfg file then hit start server but it wont start. nothing in the log. help ?!

Author:  pizdauskas [ Thursday, 08 Jul 2010, 22:04 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Crock Condition-Zero + dproto 0.4.8 only show in setti master server, in steam master no showing , why :?:

Build 4883

Author:  La_Vladimir [ Thursday, 08 Jul 2010, 22:33 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Crock, many thanks, as always helped everybody!

Author:  vityan666 [ Thursday, 08 Jul 2010, 22:42 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

The most interesting note about failds(The new exploit) is that it uses ticket stolen from licensed Valve CS 1.6 user and thus can possibly 0wn legit servers too before ticket will trigger expiration.

SCI_BIsTicketSignatureValid: TicketSize = 48, SignatureSize = 128

SCI_BIsTicketSignatureValid: EVP_VerifyFinal finished. Result: SIGNATURE VALID
SCI_BIsTicketExpired has been called.
pAuthenticationTicket = 0x1141C34, uSizeOfAuthenticationTicket = 48

Placing correct RSA signature without having Valve's Private RSA-2048 key is not possible task unless ticket was dumped from legit user...

Works as following:


.text:01DAB4DF sub_1DAB4DF proc near ; DATA XREF: .data:01E665DCo
.text:01DAB4DF
.text:01DAB4DF var_100 = byte ptr -100h
.text:01DAB4DF arg_0 = dword ptr 8
.text:01DAB4DF
.text:01DAB4DF push ebp
.text:01DAB4E0 mov ebp, esp
.text:01DAB4E2 sub esp, 100h
.text:01DAB4E8 push ebx
.text:01DAB4E9 push esi
.text:01DAB4EA push edi
.text:01DAB4EB call sub_1D368D0
.text:01DAB4F0 mov esi, eax
.text:01DAB4F2 call sub_1D369D0
.text:01DAB4F7 push eax
.text:01DAB4F8 lea eax, [ebp+var_100]
.text:01DAB4FE push eax ; destination_string = ret_addr - 0x104
.text:01DAB4FE ;
.text:01DAB4FE ; Bet that Valve designed char cmd_opbuf[100];
.text:01DAB4FF call strcpy_func ; WEAK POINT
.text:01DAB4FF ; strcpy doesnt specify limit for copying - should never be used with networked data.
.text:01DAB4FF ;
.text:01DAB4FF ; Proper usage strncpy(target,Internet-Source,100) but Valve never learn...
; As a result return address gets overwritten with "ffff" = 0x66666666
.text:01DAB504 add esp, 8
.text:01DAB507 call sub_1D369D0
.text:01DAB50C mov ebx, [ebp+arg_0]
.text:01DAB50F mov edi, eax
.text:01DAB511 mov eax, dword_2124DD0

Author:  PWA [ Thursday, 08 Jul 2010, 23:24 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

faster, need fixed dproto or smtg like that :S :S

Author:  beastlt [ Friday, 09 Jul 2010, 00:27 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Random servers wont start with the newest dproto. Please fix ASAP.

Author:  kobri [ Friday, 09 Jul 2010, 03:08 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Huge thanks!

Author:  omgitsme [ Friday, 09 Jul 2010, 13:38 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

can someone help me with this error?
  1. Error:libsteam_api_c.so: cannot open shared object file: No such file or directory

Author:  kobri [ Friday, 09 Jul 2010, 15:35 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

Strange, after updating, the setinfo doesn't seem to be working properly anymore.

Like some of the infostrings get "lost in translation" even though clientside string length is not exceeded.

Author:  pizdauskas [ Friday, 09 Jul 2010, 23:51 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

We have released a beta update for Half-Life 1 Dedicated servers. To get this beta run the hldsupdatetool with "-beta hlbeta" on the command line.

This beta fixes a crash exploit in the dedicated server caused by a malicious client packet after a proper user connect. It also contains rebuilt linux binaries using a newer internal build system so please report any load problems you may see under linux.

- Alfred

[DPROTO]: Version 0.4.8p Linux
[DPROTO]: Loading config './cstrike/dproto.cfg'
[DPROTO]: LoggingMode = 2
[DPROTO]: Config sucessfully loaded.
[DPROTO]: Parse_Jumps: ERROR: JMP for SV_RejectConnection() not found
[DPROTO]: Failed to find jumps to functions
Sorry, this version of engine does not supported

Author:  pron00b [ Saturday, 10 Jul 2010, 03:29 ]
Post subject:  Re: dproto [0.4.8p] - HLDS serverside crack (08/07/2010)

[ 3] dproto fail - dproto_i386.so v0.4.8p ini Start Never

How do I fix that?

Page 13 of 153 All times are UTC + 3 hours
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/