| 
 
|  | Luigi Auriemmaaluigi.org (ARCHIVE-ONLY FORUM!) |  
		
		
			|  | It is currently 19 Jul 2012 11:28 
 |  
	
	
		View unanswered posts | View active topics
		
	 
	
	
		|     | Page 1 of 1 
 | [ 3 posts ] |  |  
	
		
			| Author | Message |  
			| menthos | 
				
				
					|  Post subject: Directory listing with CoD4  Posted:  12 Dec 2010 14:30  |  |  
			| Joined: 12 Dec 2010 14:20
 Posts: 3
 | 
				
					| Hey guys. I couldn't believe it when Q3 Directory transversal PoC worked! i can download files from almost ANY server. To start with, i test if the server is vulnerable. The easiest way which works all the time is this command : /download /pb/svlogs/00000001.log
 That file ALWAYS exists in cod4 punkbuster enabled servers. However, the file which contains the rcon pass, is sometimes not /main/server.cfg
 So my question is, is there any exploit that allows me to get the list of files in a given directory? that would save so much time!
 (btw, i have many rcon passes, but i don't use them, i do this just4fun!)
 
 
 |  |  
			| Top |   |  
		|  |  
	
			| menthos | 
				
				
					|  Post subject: Re: Directory listing with CoD4  Posted:  12 Dec 2010 14:45  |  |  
			| Joined: 12 Dec 2010 14:20
 Posts: 3
 | 
				
					| also, is there any workaround for the "cannot validate pure client" error ? 
 
 |  |  
			| Top |   |  
		|  |  
	
			| Kane491 | 
				
				
					|  Post subject: Re: Directory listing with CoD4  Posted:  16 Dec 2010 04:12  |  |  
			| Joined: 07 Aug 2008 06:01
 Posts: 45
 | 
				
					| 1) no. the most you could do is /sv_referencedIwdNames2) dont join sv_pure servers
 
 
 |  |  
			| Top |   |  
		|  |  
	
		|     | Page 1 of 1 
 | [ 3 posts ] |  |  
	|  | You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot post attachments in this forum
 
 |  
   |