Half Life Dedicated Server Information Leak and DoS
19 Nov. 2003
Summary
In Half Life's server configuration if "allowdownload = 1" has been set, it's possible to download any file from the directory of the current game or from the 'valve' directory (NOTE: allowdownload is required if you want to allow clients to retrieve new maps from server).
Credit:
The information has been provided by SYZo[SND].
Vulnerable systems:
* Half Life Dedicated Server version 47 1.1
Impact:
It's possible to download configuration files (like server.cfg, configuration files for different mods, etc) with sensitive information, including passwords. Additionally, downloading large file (for example map) causes server to crash.