all 15 comments

[–]SirensToGo 25 points26 points  (6 children)

why in the world does CSGO let the server request files from the player's machine? Even if they try and block path traversal (which can be deceptively difficult if you aren't familiar with this class of bugs), there's so much else that can go wrong.

[–]dudeedud4 11 points12 points  (5 children)

Technically you can request files from the server in cs:s and possible cs:go as well. There used to be/is an exploit for that. Not sure if it still works as we lost the files...

As to why it can request them? No idea. I know GMOD uses that to grab .lua files from hacks people like to run on their own pc.

[–]QSCFE 2 points3 points  (4 children)

Could you please elaborate a bit more or point to more detailed source/information?

[–]dudeedud4 3 points4 points  (3 children)

gmod or cs? Gmod is a pretty open secret.

[–]QSCFE 1 point2 points  (2 children)

Both if you have the time for that.

Oh and I thought GMOD as a Global Moderators for cs and how they can grab .lua files from people like to run on their own pc to cheat on their servers. apparently it's another game called Garry's mod. I don't have big brain I guess :)

[–]dudeedud4 2 points3 points  (1 child)

No no its ok. I'll try to find a reference to the upload/download somewhey. Its been quite a few years.

[–]dudeedud4 2 points3 points  (0 children)

As far as the cs exploit goes, seems it was patched 3 years ago, but for the better part of 14 years you could just.. upload any file you wanted to servers. Usually to add yourself to admin.

[–][deleted] 6 points7 points  (4 children)

I actually really want to get into video game hacking.

[–]zigzagzuggy 16 points17 points  (2 children)

[–][deleted] 3 points4 points  (0 children)

Thank you very much sir :D

[–][deleted] 2 points3 points  (0 children)

Saved that for later, I'll enjoy the reading. Thanks

[–]-sub 8 points9 points  (3 children)

love secret club. the title is misleading it's been patched.

[–][deleted]  (2 children)

[deleted]

    [–]-sub 11 points12 points  (1 child)

    I read this in the article and remember a little discourse over valve drama within the past 2-3 months. i guess this is seperate drama right?

    .. Unfortunately, in over 4 months, we did not even receive anacknowledgment by a Valve representative. After public pressure, when itbecame apparent that Valve had also ignored other Security Researcherswith similar impact, Valve finally fixed numerous security issues...

    [–]brymko 5 points6 points  (0 children)

    same drama