View Single Post
Author Message
BAILOPAN
Join Date: Jan 2004
Old 01-19-2006 , 19:38   Security Notice - SteamID Bug
#1

Since many people have been complaining on hlds_linux and IRC about this, I thought I'd make a public announcement to the AMX Mod X community.

Currently, there are various bugs in the Half-Life 1 engine server concerning player steamids. There are widespread reports of players getting each other's steamids, players not authenticating (STEAM_ID_PENDING), and related bugs.

This is not a bug with AMX Mod X, but with Valve's software. However, it can drastically affect administration tools -- if a connecting player is accidentally assigned a Steam ID which happens to be an admin on your server, they will get admin access unknowingly. This is not a rare coincidence. It can happen if an administrator joins, disconnects, and then another player joins into the same slot.

If this is happening on your server, I highly recommend that you either implement passwords for your admins or use name/password based authentication. This will make it so players who accidentally get an admin steamid by the HL engine will be kicked, rather than granted administrative rights.

You can read more about this method of AMX Mod X authentication here:
http://wiki.tcwonline.org/index.php/...28AMX_Mod_X%29

If you are not experiencing this problem on your server, you can disregard this message.
__________________
egg
BAILOPAN is offline