Page 1 of 1

L U A Source Scripting Addon

Posted: Sun Jun 13, 2010 1:05 am
by Mikey11
Hello, I know kigen has discontinued blocking the lua source scripting addon, but I've had players pausing my server. How can I continue to block it? I noticed kigen edited the CVar Lua-Engine from Lua_engine to Lua-Engine

Re: L U A Source Scripting Addon

Posted: Sun Jun 13, 2010 9:43 am
by Kigen
LUA wasn't unblocked. They just found a way around the block that I had in place.

Anyhow, KAC 1.2.1.0 should prevent the pause exploit.

Re: L U A Source Scripting Addon

Posted: Sun Jun 13, 2010 1:50 pm
by JBV
Kigen wrote:LUA wasn't unblocked. They just found a way around the block that I had in place.

Anyhow, KAC 1.2.1.0 should prevent the pause exploit.
of what i know you blocked disconnect messages that was longer than 254 chars, so if they got a disconnect script thats shorter than that, then it might work

though i don't know exactly how your block works, anyway some people are selling disconnect exploits and saying that they can be used on servers with kac

Re: L U A Source Scripting Addon

Posted: Sun Jun 13, 2010 5:26 pm
by Kigen
The disconnect exploit looks for two forms. One is a buffer overflow attack in the disconnect message and the other is control characters. As far as the people advertising that its "KAC proof", well, it ain't. They just advertise it that way because it generates more sales for them regardless of the truth of what they say because no one is likely going to be able to get their money back from them.

Anyhow, if you got server logs those would be helpful. The disconnect exploit is printed quite clearly in the general SRCDS logs that are created if you have "log on" setup.