-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [void.at Security Advisory VSA0305] HLTV offers the ability to have thousands of spectators watch online games on Half-Life-servers. Overview ======== By sending a specially crafted packet to the hltv-server, an attacker can cause the server to crash. Affected Versions ================= The one that comes with hlds 3.1.1.0; possibly others. Impact ====== Medium. The remote server simply crashes. Details ======= Packets querying things like player-status etc always start with \xff\xff\xff\xff, followed by a query command and terminated by a \0. When you simply send \xff\xff\xff\xff\0 to the server, it crashes. Solution ======== Vendor patch needed! Exploit ======= Come on :-) Discovered by ============= greuff Credits ======= void.at everyone who was at 19c3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iEYEARECAAYFAj4uaRoACgkQzxi8qAgTjUPSVACgiPiFgrRDqi1ysSeK8RfqXprR c58AnRfbTZzDPhoUa9mIUjWfcyzuZhfd =jLII -----END PGP SIGNATURE-----