Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> There's also "illegal" amx plugins and commands, which are generally frowned upon and extremely abusable, but quite useful in these situations. My favorite (which most of the "illegal plugins" are based around) is amx_exec which essentially gives admins direct access to any client's in-game console, to run any command or set any setting!

Yes, we have something similar for UT2004, but only a handful of people are even aware it exists. It's too powerful and too easily abused. I have yet to share it, even with other admins.



Isn't this a huge security vulnerability for the client?


It can be. There have been in-game commands with code execution vulnerabilities that turn into RCE because the game server can make clients run commands.


Yes, it's why I don't share knowledge of it. There are less than 300 people actively playing this game (maybe fewer) so any impact of something like a RCE running wild is relatively small.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: