Be Right Back, Uninstalling

Full Version: TF2 Server Crash Exploit
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Had a couple of griefers that were able to send some kind of command or DDoS to the server to crash it, not sure what it is, and Ive not seen anything about new exploits on the HLDS, if anyone knows what this might be or any fixes let me know
Can you get connection/security logs from the hosting company? They might indicate if it was a DoS or some kind of network related attack.
(08-04-2010, 07:10 AM)Evil Cheese link Wrote: [ -> ]Can you get connection/security logs from the hosting company? They might indicate if it was a DoS or some kind of network related attack.

It was way too quick for a DoS attack, I couldn't find anything from parsing the logs last night but I was planning on submitting a ticket to them
Was it the application/process that was brought down or the entire physical server? I'm not sure how your hosting service works, but I'm assuming you're on a shared physical box with various other application/processes running on it. How much control do you have over the space you're hosted on?
(08-04-2010, 09:18 AM)Evil Cheese link Wrote: [ -> ]Was it the application/process that was brought down or the entire physical server? I'm not sure how your hosting service works, but I'm assuming you're on a shared physical box with various other application/processes running on it. How much control do you have over the space you're hosted on?

I don't have access to the physical box or VM, so I doubt it would be the whole physical server that went down. Possibly a signal sent to the proc, but I'm not sure. Also a DDoS wont cause the server necessarily to crash, but it will cause lag outs, not a reset of the executable.
(08-04-2010, 09:21 AM)Caffeine link Wrote: [ -> ][quote author=Evil Cheese link=topic=4872.msg167572#msg167572 date=1280931485]
Was it the application/process that was brought down or the entire physical server? I'm not sure how your hosting service works, but I'm assuming you're on a shared physical box with various other application/processes running on it. How much control do you have over the space you're hosted on?

I don't have access to the physical box or VM, so I doubt it would be the whole physical server that went down. Possibly a signal sent to the proc, but I'm not sure. Also a DDoS wont cause the server necessarily to crash, but it will cause lag outs, not a reset of the executable.
[/quote]

strip out what you want and send me a copy of teh logaround the time, I'd like to read it line by line >_>
It happened to Jiggly's FunHouse late last night as well...
Lol, the name of that server always makes me laugh.  I'd submit something to valve as well, caff, tho I'm guessing it's probably already known at this stage.  I'd be surprised if something isn't mentioned on the list in the next few days.  These sorts of exploits do seem to come around periodically. 
you can crash a server just by constantly spamming two scripts full of timeleft and nextmap repeated with a wait command inbetween