Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spray Crash Exploit #115

Closed
lDrDooml opened this issue Oct 15, 2021 · 17 comments
Closed

Spray Crash Exploit #115

lDrDooml opened this issue Oct 15, 2021 · 17 comments
Labels
bug Something isn't working high priority live In the live game

Comments

@lDrDooml
Copy link

lDrDooml commented Oct 15, 2021

Hi recently a new exploit related to the spray has been circulating, it consists of placing the spray in front of everyone so that it causes a crash in the game of the players, then I leave a video and clarify that the creator of the video has also uploaded other exploits more.

Video: thanks!

@Tsuey
Copy link
Owner

Tsuey commented Oct 15, 2021

Sadly aware and I know it's getting pretty bad. Getting it fixed officially won't be easy, but community servers can at least use this plugin:

https://forums.alliedmods.net/showthread.php?t=323447

@alexiscoutinho
Copy link
Contributor

I swear I thought it had been fixed when I read "- Blocked an exploit that could be used to crash servers." from the latest game patch notes. Very evil exploit... Disabling sprays seems to be the best defense so far.

@alexiscoutinho
Copy link
Contributor

alexiscoutinho commented Oct 16, 2021

Do you have an idea how it works/what specifically causes the crash?

@lDrDooml
Copy link
Author

lDrDooml commented Oct 16, 2021

Do you have an idea how it works/what specifically causes the crash?

It is a damaged or invalid spray that you can upload normally like any other, here is another video and in its description is the file that causes it

Video: thanks!

@alexiscoutinho
Copy link
Contributor

But the bind also seems important. I tested once without the bind and only I crashed.

@lDrDooml
Copy link
Author

But the bind also seems important. I tested once without the bind and only I crashed.

It is because the purpose is to crash the game of the players not to the server, in fact if you disable the sprays visualization you can use it anyway but with the difference that nothing will happen to you.

In other words, you just put that in and anyone who gets the spray rendered will crash.

@alexiscoutinho
Copy link
Contributor

I wasn't clear above. I tested/know all of what you just said. It's just that when I tried without the bind, my friend was literally able to stare at it just fine. But I need more testing.

@lDrDooml
Copy link
Author

I wasn't clear above. I tested/know all of what you just said. It's just that when I tried without the bind, my friend was literally able to stare at it just fine. But I need more testing.

I for my part I can confirm that it works, I clarify from now that I have only used it for the purpose of testing.

@CanadianJeff
Copy link

CanadianJeff commented Oct 22, 2021

in my video I actually look at the spray file in a hex editor its just a bunch of FF FF FF FF FF FF

@CanadianJeff
Copy link

@Eyedolll how do you disable the render of sprays? to prevent crashing

@CanadianJeff
Copy link

my game does not seem to have that option?

@lDrDooml
Copy link
Author

my game does not seem to have that option?

https://i.imgur.com/Z758NbY.jpeg

@CanadianJeff
Copy link

ok cool did you manage to look at my streamable that shows off the HEX EDITOR of the spray itself?

@alexiscoutinho
Copy link
Contributor

I wonder if an image can actually be embedded in these broken vtfs...

@Nesciuse
Copy link
Collaborator

if it's useful to anyone these are some values in the header.
Screenshot 2021-10-22 at 19 44 07

Repository owner deleted a comment from CanadianJeff Oct 22, 2021
Repository owner locked and limited conversation to collaborators Oct 22, 2021
@Tsuey
Copy link
Owner

Tsuey commented Oct 22, 2021

We'll submit a comprehensive report for this to Valve soon. Thanks for bringing the issue to our attention here.

@Tsuey
Copy link
Owner

Tsuey commented Apr 14, 2022

Fixed on Feb 1 2022:

https://steamcommunity.com/games/L4D2/announcements/detail/5301301606975705899

Haven't heard about this in a few months; assumed resolved.

@Tsuey Tsuey closed this as completed Apr 14, 2022
@Tsuey Tsuey added the live In the live game label Apr 14, 2022
@Treescrub Treescrub added bug Something isn't working and removed game bug labels Oct 9, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working high priority live In the live game
Projects
None yet
Development

No branches or pull requests

6 participants