Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[All][SRCDS][Critical] Spray Exploit #3249

Open
RoonMoonlight opened this issue Apr 21, 2020 · 18 comments
Open

[All][SRCDS][Critical] Spray Exploit #3249

RoonMoonlight opened this issue Apr 21, 2020 · 18 comments

Comments

@RoonMoonlight
Copy link

Hello,

I found a bug regarding the spray exploit on All Source 1 Games. This time it is different with Crash Bot Issue. The others could crash the server by abusing Spray features using invalid spray.

@RoonMoonlight RoonMoonlight changed the title [All Source 1 Games][Critical] Spray Exploit [All][SRCDS][Critical] Spray Exploit Apr 22, 2020
@Pinsplash
Copy link

apparently this was just fixed, but only for tf2..?

@RoonMoonlight
Copy link
Author

RoonMoonlight commented May 2, 2020

Yeah the other games is not fixed. Hopefully valve should patch the exploit on all games.
EDIT: Negative, they should patch all Source Engine branch to avoid malformed spray crash exploit.

@CanadianJeff
Copy link

sourcemod offers a plugin that will scan detect and remove all invalid sprays from a server look on alliedmodders forums

@destoer
Copy link

destoer commented Dec 4, 2020

This is still broken on css

@CanadianJeff
Copy link

valve should just open source all source engine 1

@CanadianJeff
Copy link

this bug also posted here too

Tsuey/L4D2-Community-Update#115

@destoer
Copy link

destoer commented Oct 22, 2021

a fix was attempted but setting the "unknown bit" inside the header flags is enough to get around it

@CanadianJeff
Copy link

CanadianJeff commented Oct 23, 2021

because the Tsuey issues pages removed all video links demoing the crash I thought I would put them back here

https://www.youtube.com/watch?v=rhzaKbmDg0Q
https://streamable.com/pi8jus

these 2 videos are demos of L4D2 however several other games are also vuln using the same method

@CanadianJeff
Copy link

razzy — Today at 12:30 AM
a 128x128 render target with that is a depth buffer that doesnt have a depth buffer doesnt seem to make any sense, but it's the source code engine so :anything goes:™️

@alexiscoutinho
Copy link

because the Tsuey issues pages removed all video links demoing the crash I thought I would put them back here

https://www.youtube.com/watch?v=rhzaKbmDg0Q https://streamable.com/pi8jus

these 2 videos are demos of L4D2 however several other games are also vuln using the same method

They can still be found in the comments' history though.

@CanadianJeff
Copy link

still cringe that Tsuey would remove the video links from his github I mean it is within his right todo so but if no one knows how this crash is done it will most likely never get fixed

@CanadianJeff
Copy link

can anyone confirm if garrys mod is vuln to this crashing spray?

@CanadianJeff
Copy link

CanadianJeff commented Nov 21, 2021

pretty sure just like the official forums steam/valve does not care anymore

its been well over 1 year and still not patched

https://www.youtube.com/watch?v=yzbkUYvKOmg
https://streamable.com/h5uzwg

@CanadianJeff
Copy link

I guess this is now patched in L4D2 still not confirmed if this is patched if any of the other source 1 based games I have personally notified to the Goldeneye Source devs about the sourcemod plugin and they have applied the fix

@ghost
Copy link

ghost commented Dec 24, 2021

The issue is not fixed yet, today a new exploit is released and doing the same thing, crash players games...tested this exploit in left 4 dead 2.
spray.zip

@AshThe9thSurvivor
Copy link

I just saw a publication referring to L4D1, where it mentions this exploit, and as they always marked it as repeated, what's the point of doing this if they're not going to fix it, besides they always forget about L4D1, I've been reporting errors here several times and never I have been heard, the errors are still there, even requests that are not even reviewed, it seems to me.

@CanadianJeff
Copy link

has this crap ever been reported to hacker one???????

@CanadianJeff
Copy link

looks like Tsuey on the L4D2 thread has considered this issue closed but that does not mean it is not still an issue with other source based games so I will leave this issue open

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants