Get fraggged, get owned

Discussion in 'Tech Talk' started by holtmanium, Jul 20, 2017.

Tags:
  1. Thought this was a great exploitation of a vulnerability found in some Source games. It's already been patched by Valve, but if you've been playing custom maps or servers with custom resources like sounds or textures, I'd check your shit for odd behavior when idle.

    https://oneupsecurity.com/research/remote-code-execution-in-source-games

    tl;dr
    Server can create a custom ragdoll model that replaces the default which you autodownload. Upon getting fragged, the custom ragdoll model can then run remote code on your box. Probably unlikely it was exploited in the wild.
     
    Antivanity likes this.
  2. Good times! Hopefully a patch comes out for source shortly. Game devs will have to update asap.