Urban Terror Forums: Security Update - 27th January 2012 - Urban Terror Forums

Jump to content

 Login | Register 
Advertisement
  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

Security Update - 27th January 2012 Rate Topic: ****- 1 Votes

#11 User is offline   looza Icon

  • Account: looza
  • Main tag: gXS.
  • Country:
  • Joined: 21-September 10
  • Posts: 56

Posted 28 January 2012 - 12:49 PM

Quote

I will be putting into operation in the next few days a master server ban filter that will remove "non-patched" servers from the master list.


I updated my server but i compiled it by myself... will this be filtered out too ?
and how do you detect updated servers? with relese date of the binary?

would be cool to know

i think its a good idea, this should be taken serious...
and its cool to sort out the "forgotton" servers were nobody cares about :)

This post has been edited by looza: 28 January 2012 - 12:54 PM



#13 User is offline   ItsMe Icon

  • Account: itsme
  • Main tag: bc`
  • Joined: 28-February 10
  • Posts: 76

Posted 28 January 2012 - 02:12 PM

@RaideR

View PostRaideR, on 28 January 2012 - 01:02 PM, said:

Also in reply to a somewhat unfair post at me, which i'm just gonna ignore. I am NOT censoring anything, i am removing comprimised servers from "our" and by "our" i mean

It is hard to make my point of view clear as a not native English speaker. I did not mean that you actually censoring anything nor do it intentionally. I've said:

But consider that you walk on a fine line _near_ censorship with this.

That's my opinion - Maybe its not yours, but that's life.

Quote


FS Owned master servers, so that we "FS" have done everything in our power to prevent DDoS from being organised via our central master servers.

Your Servers -> Your rules

Quote

There is a difference here, i'm not removing them because i'm loosing money, i'm removing them to save innocent people money. How can you compare my actions here in anyway similar to censorship.

Censorship is the suppression of speech or other public communication which may be considered objectionable, harmful, sensitive, or inconvenient to the general body of people as determined by a government, media outlet, or other controlling body.

Source: Wikipedia (Censorship)

Quote

Frankly i find that insulting,

I'm sorry, that was never my intention to do something like that. As I wrote in my other post, I do not want to troll/ insult/ presume you in any Way.
I've just told my _fears_ about that.

Quote

I am doing my very best at this time to protect this communitys interests.

Be _sure_ I know and _appreciate_ your Work for this Game and the community!

Quote

If the community disagrees with me, then i will do as they ask and let them rack up huge overage BW bills, sure because we are all really nice people for letting that happen. Or if the community agrees with my actions to do everything i can to stop these attacks,

It sounds a bit polemic and with this argumentation politicians all over the world account for more governmental rights.
I say: when ppl are not be able to host gameservers and protect them properly they have to _learn_ it before they do.


I do not comment this further because
1. as i mentioned before I'm not a native speaker and its hard for me to translate it in that way i want to be say it.
2. this is not the right place to discuss this kind of stuff here in the forum - but you can spam me at anytime when you want to talk about

Quote

frankly i would like an appology from you.

For saying my opinion? _Never_!

But I apologize to make my point of View not that clear that I wanted to. I say it again: It was never intended to insult you nor the FS Team. I never assumed that you _do_ censor something.
I just wanted to say it is the _Server owner_ that has to make _his_ Server secure as he can.
Your Way to blocking Heartbeats from nonpatched servers on the Master solves not the problem as long the server is up and running but is _maybe_ the first step, in a well-intentioned manner, into a wrong way...

I always loved to play UrT for so many years now because its Gameplay and _freedom_ + the independency from Money from/ and the big players like valve (i do not know about some relationships with id).
Please keep this game like it ever was - free (and no I do _not_ mean money to)

Quote

I believe in a free internet very strongly, and i will defend that belief as stongly as i can!


Thats a sentence I love to hear - When you need help doing that just spam me!


--
ItsMe

#14 User is offline   Nexu Icon

  •   clan leader   
  • Account: nexu
  • Main tag: |it|
  • Country:
  • Joined: 26-June 07
  • Posts: 4,265

Posted 28 January 2012 - 02:18 PM

DDoS is NOT an expression of speech, it's plain and simple abuse of infrastructure. Measures taken to limit 'scriptkiddies' ability to DDoS doesn't fall under censorship.


bullet_loaderAdvertisement

#16 User is offline   Nitro Icon

  •   QA member   
  • Account: nitro
  • Main tag: |P|
  • Country:
  • Joined: 15-March 10
  • Posts: 1,133

Posted 28 January 2012 - 07:48 PM

View PostRaideR, on 28 January 2012 - 11:13 AM, said:

Yes, the news was posted about a week early (we wanted to keep the testing up a little longer) until yesterday i received a call saying that we were DDoSing some poor ladies website.

After investigation it was not "our network" but "THE network", of Urban Terror servers DDoS-ing innocent people.

This fix removes there ability to use UrT Servers as vulnerable proxy's. I will be putting into operation in the next few days a master server ban filter that will remove "non-patched" servers from the master list. This will make it so much harder for the DDoS-ers to find the server instances (not impossible sadly). The downside is this WILL remove servers which are not updated.

So take this as a friendly warning! Update now!



What about those that uses their own patches or other third party patches such as rambetters server binary? is their anything those people will need to do to count as a "patched" server?
Lian Li pc-o11dw Der 8auer Edition · Gigabyte x570 Aorus Xtreme · AMD Ryzen 9 5950x 16-Core
32GB DDR4 3800MHz CL16 · 2x 1TB Samsung NVMe RAID 0 · 16GB Radeon RX 6900XT Liquid Cooled


#18 User is offline   Nitro Icon

  •   QA member   
  • Account: nitro
  • Main tag: |P|
  • Country:
  • Joined: 15-March 10
  • Posts: 1,133

Posted 28 January 2012 - 09:00 PM

View PostFrankie V, on 28 January 2012 - 08:52 PM, said:

A patch is a patch regardless of the build used to run the game. The issue is to stop the DdoS attacks coming from un-patched servers. Poor Raider is the guy that has to handle the calls that comes in and if we don’t handle the problem on our end someone somewhere will.



sorry - in my rush i responded without realising there was a page 2, what I am trying to say is rather than just blocking the old 2007 build there could be a naming convention something like:


ioq3 1.36-p01 linux-i386 Jan 28 2012



that way the master server could filter out *ALL* server not with "-p01" in there platform name, this way when a new exploit comes out all server will be forced to patch to platform "-p02" to say they are patched.
Lian Li pc-o11dw Der 8auer Edition · Gigabyte x570 Aorus Xtreme · AMD Ryzen 9 5950x 16-Core
32GB DDR4 3800MHz CL16 · 2x 1TB Samsung NVMe RAID 0 · 16GB Radeon RX 6900XT Liquid Cooled

#19 User is offline   Nexu Icon

  •   clan leader   
  • Account: nexu
  • Main tag: |it|
  • Country:
  • Joined: 26-June 07
  • Posts: 4,265

Posted 28 January 2012 - 09:13 PM

This new update for Linux need an additional compiled version against GLIBC 2.6 or older (2.5). Users hosting on CentOS 5 environment doesn't have GLIBC 2.7.

#20 User is offline   ItsMe Icon

  • Account: itsme
  • Main tag: bc`
  • Joined: 28-February 10
  • Posts: 76

Posted 28 January 2012 - 10:05 PM

View PostNexu, on 28 January 2012 - 09:13 PM, said:

This new update for Linux need an additional compiled version against GLIBC 2.6 or older (2.5). Users hosting on CentOS 5 environment doesn't have GLIBC 2.7.

I've posted here the binarys I've compiled the latest ioquake trunk that includes a Fix for the DDoS.

Copy and Paste:

After a short thought I've uploaded prebuilded binarys (i386 and x86_64) from the latest ioquake trunk (without the changes that I've made to the sourcecode) for downloading.
I use the x86_64 binary since December without any Problems.

They should work out of the box - so I hope :) Just Test it or take a Look at the Spoiler for the used glibc.

Download:
Both: http://www.bubbleclu.../binarys.tar.gz

i386: http://www.bubbleclu...rt/ioq3ded.i386
MD5: e0321c3412347c4508f092e21d9ff116

x86_64: http://www.bubbleclu.../ioq3ded.x86_64
MD5: 6c4645d764a31cdc5b2c585e900189ba


Build against:
Spoiler


Those are compiled on a CentOS 5.5 Box and should work out of the box.

PS.
I'm on the run into a Club, so I've no time to do it now but I'll compile the ones done by Barbatos tomorrow and post a Download Link here.


Update:
As Promised I've compiled Binaries from the official Sources given by Barbatos on github on a CentOS 5.5 Box.

Download:
Both: http://www.bubbleclu...barbatos.tar.gz

i386: http://www.bubbleclu...t/ioUrTded.i386
MD5: 1f5b519f24612b76fc0724b1bd309f8a

x86_64: http://www.bubbleclu...ioUrTded.x86_64
MD5: 8c93a85c4e7d599df003464c1a27f016

Build against:
Spoiler


--
ItsMe

This post has been edited by ItsMe: 29 January 2012 - 12:19 PM


  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Advertisement


Copyright © 1999-2024 Frozensand Games Limited  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of Frozensand Games Limited

Frozensand Games is a Limited company registered in England and Wales. Company Reg No: 10343942