Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
 FAQ •  Search •  Register •  Login 
It is currently 20 Oct 2014 22:09

All times are UTC [ DST ]



Welcome
ARCHIVE-ONLY FORUM!


Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 143 posts ]  Go to page Previous  1, 2, 3, 4, 5  Next
Author Message
 Post subject:
PostPosted: 22 Nov 2007 02:23 

Joined: 19 Nov 2007 02:40
Posts: 8
thank you, i didnt test the exploit yet but i applied the patch and the server is up


Top
 Profile  
 
 
 Post subject:
PostPosted: 22 Nov 2007 03:08 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
i recommend testing it, always test it


Top
 Profile  
 
 Post subject:
PostPosted: 23 Nov 2007 16:12 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
luigi, i try to use q3fill sometimes with the q3fill.ini file, and it never seems to want to work, i get this error

C:\>q3engine\q3fill\q3fill -n 80.80.80.80 28070

Quake 3 engine fake players DoS 0.4.1
by Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org

- open file q3fill.ini

Error: No such file or directory


Top
 Profile  
 
 Post subject:
PostPosted: 23 Nov 2007 16:57 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
Sure that doesn't want to work, it tries to load the q3fill.ini file in the current directory which is c:\ (since you launch the tool from c:\).
if you place q3fill.ini in c:\ it will work otherwise you must change the current directory to c:\q3engine\q3fill


Top
 Profile  
 
 Post subject:
PostPosted: 23 Nov 2007 17:48 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
ohhhhhhhhhhhh, lol! im stupid :P


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 04:23 

Joined: 17 Oct 2007 08:10
Posts: 31
Location: South Carolina
aluigi wrote:
the first PORT is that of the server in which you want to join (28960 is the default one of CoD) while the second PORT is your local server.
In the video on my website I have used 1234 for example, check the Video section if you have doubts


I'm testing this on a server that I have that isn't local. So my command line is like this:

sudppipe -l plugins\q3unban_sudp.dll xxx.xxx.xxx.xxx 28960 28960

Then I get the part where it says its ready and I try to connect and all I get is awaiting connection. I know the server is up and running fine since its my server. Is there something I'm doing wrong?


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 12:06 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
when you connect to 127.0.0.1:28960 from the game client you should see a message like "q3unban activated" displayed in the sudppipe console.
Do you see other errors or messages?

Then in case of doubts you could also launch wireshark for sniffing where go the packets from sudppipe to your server and so if everything is correct.


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 14:49 

Joined: 17 Oct 2007 08:10
Posts: 31
Location: South Carolina
aluigi wrote:
when you connect to 127.0.0.1:28960 from the game client you should see a message like "q3unban activated" displayed in the sudppipe console.
Do you see other errors or messages?

Then in case of doubts you could also launch wireshark for sniffing where go the packets from sudppipe to your server and so if everything is correct.


Its not a local server. I get the messages that its been activated and then I try to connect and I just get the awaiting connection. I think it has something to do with the ports. You said the first port was the game port and the second was the local port. I'm using 28960 for both since I didn't change the port and its not local.


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 14:56 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
You must connect to 127.0.0.1 in any case since you connect to sudppipe on 127.0.0.1 and sudppipe connects to the real server


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 16:42 

Joined: 17 Oct 2007 08:10
Posts: 31
Location: South Carolina
aluigi wrote:
You must connect to 127.0.0.1 in any case since you connect to sudppipe on 127.0.0.1 and sudppipe connects to the real server


Alright. I understand what you mean now. But what is the 'xp' thing that you enter? Is that just the name you assign to your server? I think its different for CoD.


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 18:11 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
yes xp is the name of one of my machines 8-)
All my tools support both IP addresses and hostnames.


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 22:54 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
Quote:
03 Dec 2007 Patches: jampded Windows 1.0.0.0 and 1.0.1.0 q3infoboom fix 0.1
a bit late but I have fixed the q3infoboom bug in this game


OK, uh questions..

1. does that mean linux is also fixed 100% from infoboom?

2. Can you still download these 2 and patch it urself using lpatch for jampded
Quake 3 engine infostring crash universal fix 0.1.3 (Windows)
Quake 3 engine infostring crash universal fix 0.1.2a (Linux)


Top
 Profile  
 
 Post subject:
PostPosted: 05 Dec 2007 23:24 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
1)
from my tests and those of the JA admins seems that linux + q3infofix are ok versus the q3infoboom bug

2)
who has JA for windows must download only the new patch (legacy section) for fixing q3infoboom
who has JA for linux must use q3infofix


Top
 Profile  
 
 Post subject:
PostPosted: 06 Dec 2007 01:16 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
why not use lpatch for jampded win?


Top
 Profile  
 
 Post subject:
PostPosted: 06 Dec 2007 12:02 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
It's ever lpatch but the binary diff version, I used it because was more confortable than the .lpatch file in this specific case.


Top
 Profile  
 
 Post subject:
PostPosted: 07 Dec 2007 00:16 

Joined: 07 Dec 2007 00:13
Posts: 8
K so with the noclient what would i type if the servers ip was 55.467.157.21:29070 ? as a jka server?

please explain guys i have no clue :(


Top
 Profile  
 
 Post subject:
PostPosted: 07 Dec 2007 12:34 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
A parameter is still missing, the IP of the client you want to disconnect.

Anyway the example is the same showed above:

q3noclient -s 29070 -c 29070 55.467.157.21 CLIENT_IP


Top
 Profile  
 
 Post subject:
PostPosted: 07 Dec 2007 19:40 

Joined: 07 Dec 2007 00:13
Posts: 8
so so im tryign to do my freinds Ip and port this is what i did

q3noclient -s 29070 -c 2936 72.6.248.14 128.198.22.70

i changed up 1 # in both ips for my freinds sake... so how do i do it and it say client dissconnect but nothing happends :/


any ideas?

thanks for help


Top
 Profile  
 
 Post subject:
PostPosted: 07 Dec 2007 21:37 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
Nothing happens for at least 2 possible reasons:
- the IP address of your friend (the client) is wrong
- you can't send spoofed packets

usually, moreover today with our current type of network connections and devices (I talk moreover about routers and NAT), spoofing packets is the major problem and although the program sends the packet doesn't mean that the packet has been "accepted" by the router or by the ISP since could exist also the possibility that your ISP doesn't allow spoofed source addresses.
Then could also exists the possibility that your OS blocks raw sockets but I think that if this was the case you got an error message from the program.

For example, here if I want to send a spoofed UDP packet I must set my router in bridge mode and connecting to Internet via the pppoe protocol of the operating system (like raspppoe for Windows).
The result is that the computer is directly connected to internet with its own public IP address and the spoofed packet can be sent without problems.


Top
 Profile  
 
 Post subject:
PostPosted: 07 Dec 2007 23:51 

Joined: 07 Dec 2007 00:13
Posts: 8
thanks for repliey..

the Ips are right and i can do Q3infoboom and the Q3fill one.. but not this... are the packets anydifferent?


Top
 Profile  
 
 Post subject:
PostPosted: 08 Dec 2007 12:08 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
sure that are different, they are spoofed which means that you customize the source IP address


Top
 Profile  
 
 Post subject:
PostPosted: 09 Dec 2007 12:25 

Joined: 09 Dec 2007 12:23
Posts: 2
Alu...
Where from can i download q3fill.exe.
Coz i got q3fill.rar => It doesnt working on rar, so i changed to exe, and it fuc*ed up =,=

And i should use for example: C:\q3fill -n 27960 77.79.210.71 ?


Top
 Profile  
 
 Post subject:
PostPosted: 09 Dec 2007 12:47 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
Uhmmm have you tried on that "aluigi.org" which is camping on the header of this forum or the first link that is found by google when you insert my name in it? 8-)

Then go in the Fake Players section and search q3fill with CTRL-F

And the right example is C:\q3fill -n 77.79.210.71 27960


Top
 Profile  
 
 Post subject:
PostPosted: 13 Dec 2007 12:58 

Joined: 13 Dec 2007 12:50
Posts: 1
Quick question relating to q3fill.

When using the tool, I get the following response:

Quote:
- parameters in use:
compression on
protocol 82
punkbuster on
password off
key/guid random

- Fake players:

Player: .. "h4UTyBU02gv54EjIdt" ...
Error: socket timeout, no reply received


Any idea what could be causing this? Game is Enemy Territory version 2.55.

Thanks.

//EDIT

I'm using:

Quote:
C:\q3fill xx.xx.xxx.xx xxxxx


Top
 Profile  
 
 Post subject:
PostPosted: 13 Dec 2007 15:33 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
Hey Glitch, the answer to your question is in the -B ? option where it's all explained in detail.

In short you need to use a valid guid and PB guid, that's why you need to get yours and use it, with -B ? you will find also find some methods to get these data


Top
 Profile  
 
 Post subject:
PostPosted: 13 Dec 2007 22:26 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
luigi on the first page i talked about noclient, well i unplugged the router and disabled firewall and it still gives the same error


Top
 Profile  
 
 Post subject:
PostPosted: 15 Dec 2007 00:29 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
is still not clear what really causes that OS error on some Windows installations, probably a limitation of some versions of the OS or something else.
On Internet the only information most close to a possible explanation is about the impossibility to use the raw sockets (probably the home version of XP can't access the raw layer, who knows).
Here I don't have that problem so I can't check it


Top
 Profile  
 
 Post subject:
PostPosted: 15 Dec 2007 18:31 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
oh ok

also, is it possible (dont know if i asked u this) to connect and not have ur ip shown under status? and can u add a option that allows u to choose how fast q3fill connects, like if u q3fill it does it instantly, can u add an option that'll add it every second, 5 second, 10, or no second?


Top
 Profile  
 
 Post subject:
PostPosted: 15 Dec 2007 21:24 

Joined: 13 Aug 2007 21:44
Posts: 4071
Location: http://aluigi.org
the IP thing about you refer probably is possible forcing the auto unbanning feature (naturally on games which are vulnerable to the q3unban bug), probably I can add an option for forcing it.

While for the other thing I think you refer to wait some seconds between each fake player, right?
I can add an option for it if needed


Top
 Profile  
 
 Post subject:
PostPosted: 15 Dec 2007 22:25 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
yeah thats the option im talking about, and 1 more option on top of that making it so it only sends 1 fake player instead of filling, just make an option like -o for one :), and yeah i'd like having a time between each connect

no no im not talking about the unban, i mean when a fake player connects an admin can go "rcon status" and see the ip, is there anyway to connect and not see the ip address so u cannot be detected


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 143 posts ]  Go to page Previous  1, 2, 3, 4, 5  Next

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
suspicion-preferred