Encerrado

Q3 engine infostring crash bug

The Quake 3 engine has problems to handle big queries allowing an

attacker to shutdown any game server based on this engine:

ERROR: Info_SetValueForKey: oversize infostring

In some of the vulnerable games is also possible to crash the server.

"I have released an universal patcher that limits the amount of handled

data in the queries from 1023 to 512 solving the problem in any game:

http://aluigi.altervista.org/patches/q3infofix.zip"

Using a malware script that floods the server with getstatus requests (aaaaaaaaa), you can take them down - especially Soldier of Fortune 2.

The patch doesnt work fully. When adding a mod to the game, it is still crashable.

More info will be presented to the person that gets hired for the project.

Habilidades:

Ver mais: crash engine, quake infostring bug, engine bug, oversize infostring, crash quake engine server, engine crash, engine crasher, quake info_setvalueforkey oversize infostring, crash q3engine, crash server engine, vulnerable, soldier, patch, Fortune , error bug, engine data, bug problem, problem presented, game error, gets, person games, project engine, project based games, error solving, engine based project

Acerca do Empregador:
( 2 comentários ) Amsterdam, Netherlands

ID do Projeto: #24778