Urban Terror Forums: Security Update - 27th January 2012 - Urban Terror Forums

Jump to content

 Login | Register 
  urt_home downloads support news HD | members groups servers forums    Follow on external_facebookexternal_twitterexternal_youtubeexternal_rss_feed  
  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

Security Update - 27th January 2012 Rate Topic: ****- 1 Votes


#2 User is offline   MajkiFajki Icon

  •   QA member   

    newbie player
  • UrT Account: majkifajki
  • Country:
  • Joined: 11-January 11
  • Posts: 1216

Posted 27 January 2012 - 10:47 PM

Wasn't 4.2 were tagged to address those issues? After decision to release HD.

#3 User is offline   e-junkie Icon

  • newbie player
  • UrT Account: ejunkie
  • Joined: 14-June 11
  • Posts: 135

Posted 27 January 2012 - 11:19 PM

is this only for server admins or should i also download this?
i used to tell jokes about arrows to knees, but then i lost my legs...


#5 User is offline   SubJunk Icon

  •   QA member   

    newbie player
  • UrT Account: subjunk
  • Main tag: -WAR-
  • Country:
  • Joined: 18-May 09
  • Posts: 1619

Posted 28 January 2012 - 12:41 AM

Thanks a lot for the release guys :)
Posted Image

#6 User is offline   mogul Icon

  • newbie player
  • UrT Account: mogul
  • Main tag: |<3|
  • Country:
  • Joined: 20-February 11
  • Posts: 314

Posted 28 January 2012 - 02:51 AM

Thanks Barbatos, & Rambetter for pursuing the issue so vehemently (not sure who else takes credit as well)

Security fixes are always good thing,in most cases
Posted Image______Posted Image

#7 User is offline   Pussnboots Icon

  • newbie player
  • UrT Account: pussnboots
  • Joined: 01-March 10
  • Posts: 522

Posted 28 January 2012 - 05:49 AM

Progress is AWESOME! And I'm glad you guys are bustin' your ***** to get sh** done.. But I still urge you (FS and ALL Server operators) to read my last post.. This can be VERY serious business with HUGE implications if not adhered to.

http://www.urbanterr...150#entry324082

I don't mean to be a downer, but the above link should describe the true severity of the situation. It could literally cost people hundreds to THOUSANDS of dollars. I don't know about where the laws are elsewhere, but when is this punk is caught in the U.S., He's facing some MAJOR time in the slammer with some NASTY fines as well as some unforgivable and permanent Felonies..


#9 User is offline   Creation Icon

  • newbie player
  • UrT Account: creation
  • Country:
  • Joined: 03-March 10
  • Posts: 102

Posted 28 January 2012 - 12:07 PM

View PostRaideR, on 28 January 2012 - 11:13 AM, said:

...

Do i need to install this fix if i had compiled an linux binary(with the exploit fix in it) before this release was available ?

#10 User is offline   ItsMe Icon

  • newbie player
  • UrT Account: itsme
  • Main tag: bc`
  • Joined: 28-February 10
  • Posts: 34

Posted 28 January 2012 - 12:35 PM

@RaideR

View PostRaideR, on 28 January 2012 - 11:13 AM, said:

snip...

This fix removes there ability to use UrT Servers as vunerable proxys. I will be putting into operation in the next few days a master server ban filter that will remove "non-patched" servers from the master list.

At first I want to say that I appreciate the way you take this seriously (TBH, at first [mid/ end December] I've had some doubts about that -> my Post here).

But consider that you walk on a fine line near censorship with this.
Is it really _your_ business to decide what's good (for "the internet", the server owners, the victims of that DDoS) by filtering unpatched servers out? Is it maybe the part of the ISP/ Carrier to see/ find out that these Attacks are happening and do preventing it?

NO! Its the responsibility of the owner of every single server himself! He has to make sure that he is using your provided binary or another fixed one and/ or have a call at his Provider and _order_ him to track those Attacks and block them on the Datacenters Router/ Switch.
When hes not -> his decision -> he has to bear the consequences.

You've asked the Community about if or not to do the Blackout of the Website against SOPA for a free Internet...

Quote

This will make it so much harder for the DDoSers to find the server instances (not impossible sadley).

True, because lots of servers send their Heartbeats to monster.idsoftware.com and/ or master.gamespy.com

Quote

The downside is this WILL remove servers which are not updated.

Thats the goal of it :)

Quote

So take this as a friendly warning! Update now!

Here comes _the_ Question where I want to point to.
I've updated my Servers long _before_ FS released the official Securityfix from the source of ioquake (the ioquake Team fixed the issue in January 2010).
So will you block block _all_ servers out there that are not using _your_ binary?
I don't know what masterserver software do you use - dpmaster (--game-policy reject $NONPATCHEDSERVER)?
How you can make sure that you block just servers that are unpatched (here is the small line of censorship I've talked above) and not servers who use other/ selfcompiled binarys?

PS.
Don't get me wrong - I do not want to troll you I just want to point my finger onto some Problems I see with your decisions regarding these Blocking on the Masterlist. It solves _not_ the Problem.

This post has been edited by ItsMe: 28 January 2012 - 12:38 PM

Posted Image

Posted Image

  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users



Copyright © 2012 FrozenSand / 0870760 B.C. Ltd  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of 0870760 B.C. Ltd