Author Topic: Jeetlor's Master Server spam  (Read 40518 times)

After reviewing both Chrisbot's and Ocelotus' versions of Support_Renderman, Support_AdminEvents.cs is both in v3 and v4 of Support_Renderman, but v3 contains the non-exploitable version.
V3
Exploitable V4


Wasn't Ocelotus banned from the forum/revoked recently?

I have placed a limit on the number of server listings a single ID can have.  The limit will be relaxed once things settle down.

I have confirmed that there is an eval injection exploit in the add-on script Support_AdminEvents.cs.  Multiple add-ons include this script for some reason.  I will be releasing an update to prevent execution of this script.
Please just CRC ban the bad one
The real version is a perfectly legitimate script

Wasn't Ocelotus banned from the forum/revoked recently?
yes and i believe he went on a spree of spam topics
after he claimed that his mother had lung cancer

Wow, so this all happened while I was gone? Can't believe I missed this

Zapk's Server_ServerMusic does indeed contain the tainted version of Support_AdminEvents.cs.
Mirror, since his repository site was taken offline

Wow, so this all happened while I was gone? Can't believe I missed this
Yes it was pretty entertaining while it lasted. It sucked being blamed for doing this though.

So is it over now or what?


I have placed a limit on the number of server listings a single ID can have.  The limit will be relaxed once things settle down.

I have confirmed that there is an eval injection exploit in the add-on script Support_AdminEvents.cs.  Multiple add-ons include this script for some reason.  I will be releasing an update to prevent execution of this script.
Oh thank Badspot!

I also got the update ;3

yes and i believe he went on a spree of spam topics
after he claimed that his mother had lung cancer
Who would even download something made by Ocelotus? He has zero coding ability.

Asked zapk where he might have gotten it:



It turns out Visolator, Zapk, and Summet were the main ones involved in this problem.

Visolator sent me his goodbye message to me over steam, and since his keys got revoked, he wasn't able to post it. Here it is:



holy stuff, well that solves that

One good thing came out of this, and it's that Summet is gone forever (hopefully)