Game yang biasa dikompetisikan di WCG ini ternyata masih memiliki Exploit/Vulnerability, lebih tepatnya Crash Exploit.
Untuk mengeksploitasinya sangat sederhana sekali, tetapi efek yang ditimbulkan dapat menyebabkan Crash Secara CLIENT SIDE!!! Jika anda membuat Server menggunakan HLDS pastilah banyak pemain yang Crash saat bermain di Server anda. Bagaimana cara mengeksploitasinya???
=========================================
Counter-Strike 1.6 No Steam Crash Exploit
=========================================
:------------------------------------------------------------------------------------------------------------------------------------------------------------:
: # Exploit Title : Counter-Strike 1.6 No Steam Crash Exploit
: # Date : March 4th 2012
: # Author : X-Cisadane
: # Software Link :
http://blog.counter-strike.net/: # Version : 1.6
: # Category : Desktop (Windows) Applications
: # Platform : Win32
: # Vulnerability : Crash Exploit
: # Tested On : Windows XP Professional Service Pack 3 w/ IE 7
: # Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane, Borneo Crew, Dunia Santai, Jiban Crew, CodeNesia, Axon Code, Jember Hacker, Winda Utari
:------------------------------------------------------------------------------------------------------------------------------------------------------------:
Proof Of Concept
================
[ENGLISH]
1.This my default Counter-Strike No Steam installation directory : C:\Program Files\Counter-Strike 1.6\
2.Open default Counter-Strike No Steam installation directory and open the directory named cstrike (C:\Program Files\Counter-Strike 1.6\cstrike\)
3.Find & Open motd.txt and replace the contents with this code :
<HTML><BODY><IFRAME src="file://þ:/filename"></BODY></HTML>
4.Save!
5.Run Counter-Strike 1.6 No Steam
- Create a new game, Choose the map & set the gameplay.
- Start your game! Waiting until map loaded & the motd show
- And Counter-Strike 1.6 No Steam Forcibly Closed (Crash).
[INDONESIAN]
1.Ini direktori saya tempat menginstall Counter-Strike No Steam : C:\Program Files\Counter-Strike 1.6\
2.Buka direktori tempat menginstall Counter-Strike No Steam dan buka direktori bernama cstrike (C:\Program Files\Counter-Strike 1.6\cstrike\)
3.Temukan dan buka file motd.txt dan ganti isi file tersebut dengan koding di bawah ini :
<HTML><BODY><IFRAME src="file://þ:/filename"></BODY></HTML>
4.Simpan!
5.Jalankan Counter-Strike 1.6 No Steam
- Buat sebuah Server, Pilih map dan atur permainan.
- Mulailah permainan! Tunggu hingga progress bar selesai dan map berhasil dimuat serta motdnya muncul.
- Dan secara paksa Counter-Strike 1.6 No Steam akan tertutup.
NB : Exploit ini bisa dikembangan, monggo yang jago .html Exploit kembangkan ya
Sumber :
http://cxsecurity.com/issue/WLB-2012030020