Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exploiting these bugs requires you to connect to external servers which is not something you are really supposed to do in csgo.


Community servers are a built in feature to Counter-Strike: Global Offensive, accessible for regular users via the main menu. Many of the professional scene exclusively use them (via MM services like FACEIT, and training servers like BrutalCS).

Connecting to these services safely is absolutely something players should have trust in.


Doesn't take much to assume that a Source game is full of RCEs.


I'll gladly take research that helps protect tens of millions of players over generic defeatist hand waving that "source games are broken".


Hosting own servers is a feature of CSGO.

A feature provided by all well designed client/server software. Thus avoiding vendor lock-in and dependence. Good for LAN-Parties, bad or no networking, original developer doesn’t exist anymore or doesn’t care.

And then there as these developers which are the only ones with the server code and shutdown their servers by intention - I recommend to avoid software which such a planned obsolescence.


Have you even played CS:GO? Some of the modes aren't available on official servers - kreedz, aim maps, etc.


How do you know this? Is there strong cryptographic integrity protection for traffic from the official servers that prevents active attacks injecting malicious messages?

(Also, why aren't you supposed to use other servers?)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: