Author Topic: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4  (Read 17671 times)

0 Members and 5 Guests are viewing this topic.

Offline EnEsCe

  • Retired Soldat Developer
  • Flamebow Warrior
  • ******
  • Posts: 3101
  • http://enesce.com/
    • [eC] Official Website
CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« on: March 08, 2007, 08:56:54 pm »
As some of you may be aware, an exploit was discovered earlier today which allows skiddies to send poisoned strings to ANY Soldat Dedicated Server and download your soldat.ini file, aswell as ANY other file on the system hosting the Soldat Server.

Download Link: http://enesce.com/go.php?id=23 [/color]

If you run a Dedicated server, you MUST download and install this fix A.S.A.P!
And change your admin password while you are at it.


Addendum: Choose a new admin password when you upgrade; over 100 servers are known at this time to have had the admin password stolen.

Offline Clawbug

  • Veteran
  • *****
  • Posts: 1393
  • 1184!
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #1 on: March 08, 2007, 08:58:31 pm »
Good job there. ;)
Fight! Win! Prevail!

Offline khoacalacan

  • Major(1)
  • Posts: 37
    • XDreamer
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #2 on: March 08, 2007, 08:59:57 pm »
EnEsCe is always there when theres serious trouble in soldat. Good Job!

Offline EnEsCe

  • Retired Soldat Developer
  • Flamebow Warrior
  • ******
  • Posts: 3101
  • http://enesce.com/
    • [eC] Official Website
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #3 on: March 08, 2007, 09:48:09 pm »
I forgot to mention, this also includes a fix for the invisible pants cheat.

Offline deevus

  • Major(1)
  • Posts: 16
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #4 on: March 09, 2007, 02:57:22 am »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.

Offline EnEsCe

  • Retired Soldat Developer
  • Flamebow Warrior
  • ******
  • Posts: 3101
  • http://enesce.com/
    • [eC] Official Website
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #5 on: March 09, 2007, 02:58:51 am »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.
Its not a cover up, lurk the forums more.

Offline Replica

  • Major
  • *
  • Posts: 96
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #6 on: March 09, 2007, 03:00:12 am »
I don't think this'd be just me, but apparently since I loaded this version up it shows everyone in the f1 screen is registered, when not everyone there is... 

Pretty minor bug, but still. 

Offline deevus

  • Major(1)
  • Posts: 16
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #7 on: March 09, 2007, 03:04:17 am »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.
Its not a cover up, lurk the forums more.

The reason I called it a cover up was that the hacker told you that was how they retrieved the passwords, which isnt the case. I am aware that the invisible pants program could retrieve such information, but it was used to cover up (by the hackers) that there was another exploit being used.

Offline Toumaz

  • Veteran
  • *****
  • Posts: 1904
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #8 on: March 09, 2007, 04:38:35 am »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.
Its not a cover up, lurk the forums more.

The reason I called it a cover up was that the hacker told you that was how they retrieved the passwords, which isnt the case. I am aware that the invisible pants program could retrieve such information, but it was used to cover up (by the hackers) that there was another exploit being used.
Then explain to me how the registration keys were stolen. Unless that file download exploit could download registry values showhow, it was on behalf of the skin hack trojan.

Offline Replica

  • Major
  • *
  • Posts: 96
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #9 on: March 09, 2007, 05:39:22 am »
That trojan has nothing to do with the problem that deevus is talking about.  If it was the trojan, how could a server fix clear that up?  Look at what NSC wrote in the first line there... this server version fixes an exploit that allows for files to be downloaded from the server. 



But yes, another problem in 2.5.4 is that in DeathMatch all player names in the f1 screen are erroneously the same colour. 

I'm not sure if this has been the case since 2.5.3 since GA never upgraded to that version. 
« Last Edit: March 09, 2007, 05:44:46 am by Replica »

Offline Toumaz

  • Veteran
  • *****
  • Posts: 1904
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #10 on: March 09, 2007, 01:01:55 pm »
But yes, another problem in 2.5.4 is that in DeathMatch all player names in the f1 screen are erroneously the same colour. 

Indeed, and all players got a star next to their name no matter if they registered or not.

Offline chrisgbk

  • Inactive Staff
  • Veteran
  • *****
  • Posts: 1739
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #11 on: March 09, 2007, 01:56:03 pm »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.
Its not a cover up, lurk the forums more.

The reason I called it a cover up was that the hacker told you that was how they retrieved the passwords, which isnt the case. I am aware that the invisible pants program could retrieve such information, but it was used to cover up (by the hackers) that there was another exploit being used.
Then explain to me how the registration keys were stolen. Unless that file download exploit could download registry values showhow, it was on behalf of the skin hack trojan.
He's not saying that that trojan -didn't- do anything; it did. He's saying that it was used as a cover story behind the real way all the -admin- passwords were stolen; which it was.

Offline Toumaz

  • Veteran
  • *****
  • Posts: 1904
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #12 on: March 09, 2007, 02:09:41 pm »
Well I'm glad I could help prove the "invisble pants" trojan was a coverup.
Its not a cover up, lurk the forums more.

The reason I called it a cover up was that the hacker told you that was how they retrieved the passwords, which isnt the case. I am aware that the invisible pants program could retrieve such information, but it was used to cover up (by the hackers) that there was another exploit being used.
Then explain to me how the registration keys were stolen. Unless that file download exploit could download registry values showhow, it was on behalf of the skin hack trojan.
He's not saying that that trojan -didn't- do anything; it did. He's saying that it was used as a cover story behind the real way all the -admin- passwords were stolen; which it was.
Ah sorry, misunderstood it then.

Offline HEX

  • Major
  • *
  • Posts: 77
  • =tNt=
    • SoldatX Brazilian Community
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #13 on: March 09, 2007, 03:09:48 pm »
I thought my servers were hacked and changed the password twice. Thank you very much :)



Offline The Bone Collector

  • Veteran
  • *****
  • Posts: 1126
  • I'm so sexy.
    • Daniel Rutter Films
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #14 on: March 12, 2007, 07:25:44 pm »
EnEsCe....I don't mean to be rude...but....

Were you in a hurry to release the new dedicated server.....cause you seem to be releasing alot of bug fixes and stuff....Maybe you should revise your code a bit more before you release.....This might make server owners a little less antsy when using your program....
Just another soul to burn.

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #15 on: March 12, 2007, 07:33:30 pm »
EnEsCe....I don't mean to be rude...but....

Were you in a hurry to release the new dedicated server.....cause you seem to be releasing alot of bug fixes and stuff....Maybe you should revise your code a bit more before you release.....This might make server owners a little less antsy when using your program....

Overall, the new server versions have been much more complete and bug-less than they were before he started maintaing the server.  The hackers are just getting better at finding and exploiting bugs.

The other difference is that a lot of these updates he's releasing contain many anti-hacks.  Before EnEsCe took over, these hacks would have had little or nothing done to prevent them being used, and it wouldn't have happened before a new version of Soldat is out.  He's releasing new servers more often to help keep up with new hacks and exploits being found in Soldat.  Only of the many things addressed in these updates have been attacks through the server itself, the rest have been the additions of anti-hacks

Lastly, he added in the entire scripting engine for 2.5.2 and has been constantly updating that and adding new features.  There's nothing wrong with making more release of the server if it means increasing the quality and adding tons of new features...

Offline The Bone Collector

  • Veteran
  • *****
  • Posts: 1126
  • I'm so sexy.
    • Daniel Rutter Films
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #16 on: March 12, 2007, 08:08:15 pm »
Ahh....My mistake....I thought the frequent releases were to cover his ass for being careless. Simple mis-understanding.
But, this goes without saying.....There is still alot of bugs in the code....right? (not that this is EnEsCe's fault....). It's alot of work....but is there ANY way that you could rewrite the coding, from scratch? Maybe this might take the work out of searching for bugs. From what I have read in the forums over the last 2 years I've prowled here....MM fucked up badly with the original netcode in Soldat, and the Dedicated server....So a new netcode from scratch might not be a bad idea.

EnEsCe....A little suggestion....why don't you write a program to go with the dedicated server, that auto-updates everytime you release a new version....This could make it ALOT easier for server owners, and other people who use the dedicated server.
Just another soul to burn.

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #17 on: March 12, 2007, 09:17:29 pm »
Ahh....My mistake....I thought the frequent releases were to cover his ass for being careless. Simple mis-understanding.
But, this goes without saying.....There is still alot of bugs in the code....right? (not that this is EnEsCe's fault....). It's alot of work....but is there ANY way that you could rewrite the coding, from scratch? Maybe this might take the work out of searching for bugs. From what I have read in the forums over the last 2 years I've prowled here....MM ****ed up badly with the original netcode in Soldat, and the Dedicated server....So a new netcode from scratch might not be a bad idea.

EnEsCe....A little suggestion....why don't you write a program to go with the dedicated server, that auto-updates everytime you release a new version....This could make it ALOT easier for server owners, and other people who use the dedicated server.

1) He has been cleaning up MM's code ever since he took over the Dedicated server from MM
2) He plans to add something like that since we're working on a new lobby.  We're going to add something that will have it check periodically, and the lobby will say if there is a new version available

Offline iDante

  • Veteran
  • *****
  • Posts: 1967
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #18 on: March 12, 2007, 10:32:19 pm »
so basically MM is god and enesce is jesus?

yes, any server I go on says that everyone is registered and all have little stars.

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Re: CRITICAL UPGRADE: Soldat Dedicated Server 2.5.4
« Reply #19 on: March 13, 2007, 12:01:49 am »
I don't think this'd be just me, but apparently since I loaded this version up it shows everyone in the f1 screen is registered, when not everyone there is... 

Pretty minor bug, but still. 
so basically MM is god and enesce is jesus?

yes, any server I go on says that everyone is registered and all have little stars.
But yes, another problem in 2.5.4 is that in DeathMatch all player names in the f1 screen are erroneously the same colour. 

Indeed, and all players got a star next to their name no matter if they registered or not.

see this thread: http://forums.soldat.pl/index.php?topic=11674.msg131529#msg131529