not sure if this is the right place but.....

11 replies [Last post]
(*WASP..BROKEN*)
trime's picture
Offline
Joined: Feb 2008
Posts:

ive never seen this before anyone else??? Shock

Login or register to view attached files

CZE|BEAZT
beazt's picture
Offline
Joined: Apr 2006
Posts:
CZ Czech Republic
not sure if this is the right place but.....

it shows you version of q3 and version of e+ running on that server

Apple Mac mini M4 + Apple Magic Keyboard + Logitech G603

mow Q [EN]
Offline
Joined: Nov 2003
Posts:
not sure if this is the right place but.....

Didnt know that e+ is open source and everyone can make a own version of it?

PITBULL[ERA]
Offline
Joined: Feb 2006
Posts:
Re: not sure if this is the right place but.....
(*WASP..BROKEN*) wrote:

ive never seen this before anyone else??? Shock

Weird, it should state xp 1.03 and 1.32c, I really can't tell why there's the TSU part with a date from this year's september.

WASP*KILLER
Killer's picture
Offline
Joined: Feb 2005
Posts:
not sure if this is the right place but.....

joey
Offline
Joined: Aug 2005
Posts:
not sure if this is the right place but.....

what are the differences between the initial 1.32 release and 1.32c?
I've been using the default 1.32 since.. it came out

cml
Forum moderator Rank moderator LIVING LEGEND
camel-xp's picture
Offline
Joined: Mar 2006
Posts:
not sure if this is the right place but.....
joey wrote:

what are the differences between the initial 1.32 release and 1.32c?
I've been using the default 1.32 since.. it came out

updated security mostlly.

x.foksie'loy.drt?
foksie's picture
Offline
Joined: Jun 2005
Posts:
not sure if this is the right place but.....

main exploit before 1.32c was that someone could access the entire file system of the server using just a q3 client, if autodownload was 1.

generally versions prior to 1.32c would let you "autodownload" anything, if you specifically asked for it, and knew, or guessed the servers file tree.

So generally you could get stuff like ../../../../etc/passwd and download it to your comp, then just birthday attack it, and voilla you have full access to the targets root.

and other nasty stuff.

it was usually easier if you had rcon to the server, since you could then turn on autodownload and use fdir to check the file structure, instead of guess it.

I am proud of spreading a pirated Excessive Plus version and claim to be the original author, yay!

cml
Forum moderator Rank moderator LIVING LEGEND
camel-xp's picture
Offline
Joined: Mar 2006
Posts:
not sure if this is the right place but.....

Now the question, how they changed q3 & e+ version description ?
Maybe they used something like 'Hex Workshop'.

x.foksie'loy.drt?
foksie's picture
Offline
Joined: Jun 2005
Posts:
not sure if this is the right place but.....

the version information is written in the qagame.qvm file, which was most likely edited.

I am proud of spreading a pirated Excessive Plus version and claim to be the original author, yay!

cml
Forum moderator Rank moderator LIVING LEGEND
camel-xp's picture
Offline
Joined: Mar 2006
Posts:
not sure if this is the right place but.....

but not with simple notepad ? Happy

I tried smth simillar many years ago but if I edited and saved the file whole q3 wasnt working anymore.