ULX

Author Topic: Danger Will Robinson, danger! Be on the lookout for exploits.  (Read 2551 times)

0 Members and 1 Guest are viewing this topic.

Offline Megiddo

  • Ulysses Team Member
  • Hero Member
  • *****
  • Posts: 6214
  • Karma: 394
  • Project Lead
Danger Will Robinson, danger! Be on the lookout for exploits.
« on: September 05, 2007, 03:43:50 PM »
We reimplemented our command hexxer. This was and still is a last ditch effort to get around garry's concommand blocks.

However! We removed it a few versions ago because we suspected (but never confirmed) that it was causing a security exploit. I now believe (Not sure what spbogie thinks :P) that this exploit was caused by something entirely different that we fixed in 3.11, and given our need for the hexxer, decided to give it another try.

Looking back it was a pretty bad idea for us to just remove it without actually confirming that it was causing the bug, but we can't afford a time machine so oh well.

What does this mean?
It means you should be on high alert for a while. Watch very carefully to see if anyone's gaining privileges they should not have. We want to know if you see anything, really!
Experiencing God's grace one day at a time.

Offline JamminR

  • Ulysses Team Member
  • Hero Member
  • *****
  • Posts: 8096
  • Karma: 390
  • Sertafide Ulysses Jenius
    • Team Ulysses [ULib/ULX, other fine releases]
Re: Danger Will Robinson, danger! Be on the lookout for exploits.
« Reply #1 on: September 05, 2007, 07:34:05 PM »
Please remember. Don't just post "it has an exploit! Don't use it!!" and leave.
Though you may not wish to share exact details here in public, please email megiddo@ulyssesmod.net , jamminr@ulyssesmod.net (and, does spbogie have a ulysses mail account?)
THanks
"Though a program be but three lines long, someday it will have to be maintained." -- The Tao of Programming