Urban Terror Forums: Security related Issue on UrTUpdater - Urban Terror Forums

Jump to content

 Login | Register 
Advertisement
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Security related Issue on UrTUpdater Rate Topic: -----

#1 User is offline   ItsMe Icon

  • Account: itsme
  • Main tag: bc`
  • Joined: 28-February 10
  • Posts: 76

Posted 28 October 2012 - 11:59 AM

I've read some threads about the urtdownloader does not download the updated files but the index.html from urbanterror.info.
I can reproduce this failure for weeks now...
<rant>
r00t suggests here to put the download IP to the hosts file of your system, but thats not a solution, I'll not change the DNS settings of my Server just because the devs setup an ill-conceived load balance.

The worst thing about this issue is:
The updater shows that the files are downloaded correctly but download some totally different files from a different location.
So this shit piece of software does not even check what it downloads - that's a serious security hole.

Proof:
Spoiler

What i get downloaded is:
Spoiler


Do you really think I'll run that (again) on a production server?

Maybe I bring up my own fabulous, just a bit corrected, updater that loads from a ru domain some stuff like a nice trojan.

I just hope the devs will not answer me like they always do: we do that in our free time, it does not cost any money so what do you want from us, you don't have to use it, pay money and play other games, blafaselblub - that is not an answer!
</rant>

Why don't you let the people download UrT the old fashion way and bring the updater as an addition

Why don't you build the necessary infrastructure before you give it to the masses?

Sometimes I think the devs do not want UrT become successful/ popular - sigh

--
ItsMe

PS.
The best joke is what the updater says about itself:
The UrTUpdater is a smart piece of software that makes it easy to keep your copy of Urban Terror up to date.

#2 User is offline   matt Icon

  • Account: matt
  • Country:
  • Joined: 06-August 10
  • Posts: 45

Posted 29 October 2012 - 06:29 PM

I wonder that it does no filename or MD5 checks. Even my http://software.open...rbanterror-data workaround is more reliable than that. But it is GUI only so of no use for your server.

#3 User is offline   ItsMe Icon

  • Account: itsme
  • Main tag: bc`
  • Joined: 28-February 10
  • Posts: 76

Posted 03 November 2012 - 07:02 PM

@FS
No answer? No? Why? Wrong Forum?

@matt
The graphical installer from FS has the same issues... - But I gave in gracefully with 4.2. HD will not become that better - in this I trust FS

So UrT will die (not because of me :])- I do not hope so, maybe FS proof me wrong but I have my doubts...

--
ItsMe

#4 User is offline   wonderkins Icon

  • Account: wonderkins
  • Country:
  • Joined: 09-March 10
  • Posts: 14

Posted 03 November 2012 - 10:49 PM

I don't see the problem. Seems straight forward to me. I guess I'm not a technical as you. That's alright. Seems to download exactly what it says it will. I don't understand the updater problems everyone is having. Everything downloads and works perfectly for me. Why don't you just do a virus scan if you have so little trust for Frozen Sand and think they are stuffing your computer with viruses? I personally have never had a reason to stop trusting downloads from these guys, whether it was for Windows or Linux, so...

#5 User is offline   Driller Icon

  •   community admin   
  • Account: driller
  • Main tag: uJ|
  • Country:
  • Joined: 28-February 10
  • Posts: 1,001

Posted 03 November 2012 - 11:40 PM

View Postwonderkins, on 03 November 2012 - 10:49 PM, said:

I don't see the problem. Seems straight forward to me. I guess I'm not a technical as you. That's alright. Seems to download exactly what it says it will. I don't understand the updater problems everyone is having. Everything downloads and works perfectly for me. Why don't you just do a virus scan if you have so little trust for Frozen Sand and think they are stuffing your computer with viruses? I personally have never had a reason to stop trusting downloads from these guys, whether it was for Windows or Linux, so...


Updating from 4.2.003 to 4.2.004 was messy because FS had not their servers synchronised or so (im not really into that stuff). So lot of servers went offline because the updater downloaded not the correct files. Updater was good, serverssettings were bad if im correct.
Now updatingfrom .004 to .005, the updater doesnt overwrite old files.....

So yes, not related to security issues. But its a little problematic, some guys are living on the edge and they dont like 4.2 a lot, and they only need 1 more reason to cry and shit on FS again and again.


@Itsme, accept that it is a alpha version of the updater. You are now testing it, so in urtHD it will be flawless working. Im sorry, 4.2 players are all guinea pigs for urtHD, accept it.

bullet_loaderAdvertisement

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Advertisement


Copyright © 1999-2024 Frozensand Games Limited  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of Frozensand Games Limited

Frozensand Games is a Limited company registered in England and Wales. Company Reg No: 10343942