Denial of Service bounty hunters 64
lightPhoenix writes "Get this, John Carmack, god of id & quake 3 arena, is offering a bounty for exposure of game server exploits. Check it out. " It's down the page a bit-but it's there. That's a cool idea.
sell the exploits on E-Bay! (Score:1)
It's kinda like back when Netscape was offering a cheesy free t-shirt to people who found bugs in the code. I mean, it's gotta be worth more than a t-shirt. Some private entity should have outbid them, because that sort of info is worth a LOT more than a t-shirt to the right interests.
Then again, the government has floors full of people at the NSA pounding away at anything and everything to find useful exploits to use in spying. So many more exploits are known by them than will ever be revealed.
Re:sell the exploits on E-Bay! == evil (Score:1)
Would you appreciate if I found keys to your car and sold them in e-bay? I'm sure there are people out there who'd pay more than you.
Carmack is offering a small finders fee, just like you would for your car keys.
Re:Aww gee... (Score:1)
Stands to reason that you wouldn't be able to connect to it via TCP then...
/AE
Re:Which port does Quake use? (Score:2)
Quake: 26000
QuakeWorld: 27500
Quake2: 27800(?)
Quake3: 27960
Re:Now would be a good time to ask... (Score:1)
Uh, Knuth Thought it Up First (Score:2)
Re:No, 6.02e23 is a mole! :) (Score:1)
10^9 = billion
10^12 = trillion
10^15 = quadrillion
10^18 = quintillion
10^21 = sextillion
10^24 = septillion
Assuming you're American. Elsewhere, YMMV.
Re:Hmm, all that praise... (Score:2)
If you meant "find", rather than "fix"... I'm still not sure it would accomplish much of anything. I mean, there are enough MS users out there that someone has got to be reporting the bugs... They _have_ to know about them. They just aren't fixing them.
As Bill Gates said, there are no significant bugs in Microsoft's software. Everyone's just using it wrong...
(Methinks someone's in denial...)
Why wasn't DOS a problem with Quake 1? (Score:2)
It's kind of sad to see that there is even a need for this kind of bounty. I mean, what kind of loser takes down a game server? It's not like you're gonna get root and be l88T. You're just gonna cause inconvenience to people trying to have fun, and to a company that has a pretty shining record of being all-around good guys.
(although I bet if Romero find a good one he's not going to send it in...
THIS IS HOW IT SHOULD WORK!! (Score:2)
First you do your best to make sure there is nothing obvious or dumb. Then you basically offer a prize (money, recognition, hardware, etc.) to those who show you where your weaknesses are!
Bravo! I wish more people took after this methodology. Encourage, don't discourage the young minds!
Re:No, 6.02e23 is a mole! :) (Score:1)
Re:Why wasn't DOS a problem with Quake 1? (Score:1)
Re:Uh, Knuth Thought it Up First (Score:1)
Woo.
Re:Not all Denial of Service attacks count (Score:1)
Now would be a good time to ask... (Score:1)
Think you can code this? Email me. I'll tell ya what other *major* functionality a tool like this would bring.
Yours Truly,
Dan Kaminsky
DoxPara Research
Once you pull the pin, Mr. Grenade is no longer your friend.
Re:Now would be a good time to ask... (Score:1)
Once you pull the pin, Mr. Grenade is no longer your friend.
Not all Denial of Service attacks count (Score:1)
Here's the exact quote from his
Operating system level attacks don't count -- only things that I can actually
fix or protect against in my code.
Denial of service attacks don't count if they require upkeep, but if there is
a fire-and-forget DOS attack, it will still count.
Re:Uh, Knuth Thought it Up First (Score:2)
Re:No, 6.02e23 is a mole! :) (Score:1)
On a tangent from this, here's the big list of metric prefixes:
10e-24 yocto- y
10e-21 zepto- z
10e-18 atto- a
10e-15 femto- f
10e-12 pico- p
10e-9 nano- n
10e-6 micro- u
10e-3 milli- m
10e-2 centi- c
10e-1 deci- d
10e1 deka- da
10e2 hecto- h
10e3 kilo- k
10e6 mega- M
10e9 giga- G
10e12 tera- T
10e15 peta- P
10e18 exa- E
10e21 zetta- Z
10e24 yotta- Y
The Jargon file mentions a few proposed additional SI units based on the SI-friendly names of the Marx Brothers, and the IEEE wants to create new, different SI multiples for powers of 2, so that we computer folk will quit screwing up the regular decimal system. Yeah, like that's going to happen. Next we'll all be on metric time. ;)
Which port does Quake use? (Score:1)
Hmm, all that praise... (Score:2)
What if Microsoft offered a similar bounty for fixing security holes in their software?
What would you say then?
(Besides the completely obvious joke about how they would shortly find themselves bankrupt...)
$asbestos = 1;
wait;
Excellent! (Score:5)
A) Something positive for hackers to get a hold of, and actually get attention for their exploits, and even get them fixed!
B) Positive feedback from the developer of the software, and appriciation.
C) A final product that would be far superior in security from DoS then if it had been released without this testing.
Definitely makes everyone happy.
-- Give him Head? Be a Beacon?
Re:Which port does Quake use? (Score:1)
Re:He's got a nerve (Score:3)
It was a piece of test code that got left QuakeWorld (and Quake2 inherited in the code base). QuakeWorld was never an "official" prouduct--it was only a test platform for new networking ideas such as prediction. As soon as it was identified, both games were patched and new versions were made available.
The exploit page you cite lists Quake1 (regular Quake) as vulnerable, which is bogus since Quake1 doesn't even have rcon facilities. It also states it isn't logged which is false since every rcon prints out on the console with the address it came from.
Root compromise? Any decent sysadmin would never run a Quakeworld or Quake2 server as root to begin with (the servers do not need special privledges).
This issue was dealt with quickly and appropriately.
Re:Which port does Quake use? (Score:1)
I have an obvious one! (Score:1)
:-)
screw the money... (Score:1)
I knew I liked him... (Score:1)
-earl
Re:sell the exploits on E-Bay! (Score:1)
Re:No, 6.02e23 is a mole! :) (Score:1)
--Corey
Re: Assuming you're American (Score:1)
but the former British world uses a system like this:
10E6=million
10E9=thousand million
10E12=billion
etc. which is quite different from the US system (but in line with the system used in continental europe.)
He's got a nerve (Score:2)
Uh, maybe this was because 'ID software blatantly put a backdoor in Quake 1/2 and QuakeWorld including both the Linux/Solaris Quake2. RCON commands sent from the subnet 192.246.40.0/24 and containing the password "tms" are automaticly executed on the server without being logged.'
'Vulnerable Systems: Those running Quake 1, QuakeWorld, Quake 2, Quake 2 Linux and Quake 2 Solaris, all versions. Thus many Windows and UNIX boxes are affected.'
'Compromise: root (remote).'
'Notes: Quake was always a horrible security hole, but I never thought Id would stoop to introducing an intentional backdoor to allow them access to systems running Quake. I am surprised this didn't get more publicity.'
The exploit was discovered by Mark Zielinski [mailto] and is documented at www.insecure.org [insecure.org]. You can find the fix [insecure.org] here, but if you're looking for a patch, dream on...
First bug found (Score:2)
Re:Why wasn't DOS a problem with Quake 1? (Score:1)
Excuse me. Someone who abuses apostraphes should not be giving out grammatical advice, even with tongue firmly in place amongst cheek.
Not quite (Score:1)
That's exactly the point. (Score:1)
Re:Why wasn't DOS a problem with Quake 1? (Score:1)
Re:Why wasn't DOS a problem with Quake 1? (Score:3)
Sad indeed. I was one of the many that was put out when script kiddies blew up all the q2 servers and no one could play for a couple weeks. My only guess was 'sour grapes' where ppl didn't have enough hardware or good enough connection to be able to play, so they decided *noone* would play.
Re:OT: Avogadro's Number (Score:1)
Re:That name looks familiar! (Score:1)
>So! Who else recognizes that name? Does the name 'Future Crew' ring a bell? ^_^/
>Hehe. It's nice to see that those guys are still hanging in there.
Shit the name sounds right. Would that be possible? I loved they're second reality demo so much (because of the soundtrack)... And screamtracker!
Hey Sami! Maybe you're even reading this! Yes you! What happened?
aaaanyway, nostalgia...
That name looks familiar! (Score:1)
So! Who else recognizes that name? Does the name 'Future Crew' ring a bell? ^_^/
Hehe. It's nice to see that those guys are still hanging in there.
Re:I knew I liked him... (Score:2)
John made some ajustement in the refresh that produce a less jagged game, even with my low 56k connection, i manage to "foresee" the oponent movement without lanching a rocket in the wall !!
Less lagged in the deplacement.
Great game overall.
I waiting for the other release with great expectations.
Re:First bug found (Score:1)
Golden Ticket anyone? Who'll be next?!?!!? Let's just hope it's not that bitch Veruca (sp?) Salt.