Security holes

News for the main page
Post Reply
User avatar
Edge100x
Founder
Founder
Posts: 12948
https://www.youtube.com/channel/UC40BgXanDqOYoVCYFDSTfHA
Joined: Thu Apr 18, 2002 11:04 pm
Location: Seattle
Contact:

Security holes

Post by Edge100x »

Last night it became known that there is a major problem with HLDS that leads to easy security compromises through such addons as StatsME, AdminMod, and ClanMod. These compromises generally require someone to have rcon-level access (either directly or through the mod), although that's not always the case. Currently it is being recommended on several news sites to set your rcon_password to "" so that users with rcon cannot use it against the server; this does not entirely fix the problem, but you may want to do it as a stopgap.

As soon as Valve releases a security update to HLDS, we will be loading it onto all the servers.
[MiD]Arcticman-TPF-
New to forums
New to forums
Posts: 4
Joined: Thu Aug 15, 2002 8:19 am
Location: Alaska
Contact:

Post by [MiD]Arcticman-TPF- »

Are you saying this opening is only for people with rcon?
User avatar
Edge100x
Founder
Founder
Posts: 12948
Joined: Thu Apr 18, 2002 11:04 pm
Location: Seattle
Contact:

Post by Edge100x »

Most of the security holes require the use of rcon, yes.
Post Reply