|
|
| |
| In Half Life's server configuration if "allowdownload = 1" has been set, it's possible to download any file from the directory of the current game or from the 'valve' directory (NOTE: allowdownload is required if you want to allow clients to retrieve new maps from server). |
| |
Credit:
The information has been provided by SYZo[SND].
|
| |
Vulnerable systems:
* Half Life Dedicated Server version 47 1.1
Impact:
It's possible to download configuration files (like server.cfg, configuration files for different mods, etc) with sensitive information, including passwords. Additionally, downloading large file (for example map) causes server to crash.
Example:
cmd dlfile server.cfg
cmd dlfile addons/amx/users.ini
cmd dlfile addons/amx/mysql.cfg
cmd dlfile maps/de_torn.bsp
|
| Subject:
|
Performing Exploit |
Date: |
8 Aug. 2007 |
| From: |
Fire_Wire |
| How does one actually go about executing this vulnerability? I tried it on my personal HLDS (Which is another computer on the LAN) but it doesnt do anything. |
|
|
|
|