Skip to content
This repository has been archived by the owner on Nov 23, 2018. It is now read-only.

accidental file list, possible code injection #1

Open
Mercotui opened this issue Aug 16, 2017 · 3 comments
Open

accidental file list, possible code injection #1

Mercotui opened this issue Aug 16, 2017 · 3 comments

Comments

@Mercotui
Copy link

Hi, in the most recent CSGO update log, I noticed the format was broken, and weird text was inserted between the patch notes. It turns out, the wierd text is actually the directory listing of your server:
eztv_magnets.sh hi_valve twdsc.py warhuryeah_streaming.py www yt_subs.sh, and the places it inserts this text is in places where the original blog post uses a *. I attached an example image displaying the latest cs-go update, with your file names inserted.

I have not read the code, but it points to the possibility of code injection, valve @ldesgoui pls fix

image

@ldesgoui
Copy link
Owner

Thanks for reporting, fixing !
I should be more careful 😨

@ldesgoui
Copy link
Owner

Temporarily fixed with last commit, has been tested and pushed, I'll look into it further tomorrow. Thanks again very much

@Mercotui
Copy link
Author

Response within an hour, and a patch within 2! 👍 Thank you for the (hot)fix, and the bot in general 🤘

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants