Quote:
1) Why different servers return differents info ? I mean why return to me only there names and other - names and players info ?
it can depend by various reasons, obviously only having an own server locally on which making the tests could answer to more questions BUT will not change the results: this is a passive vulnerability where you don't have the control of the output so you "get" info but can't decide arbitrarily what to get.
this is important and I thought it was clear, so take it in mind.
in my opinion more info are collected when the admin or some scripts perform operations on the server and so you get parts of his results but obviously I can't confirm it... it's only a hypothesis.
Quote:
2) If I want to get rcon/settings of specific server, I need to launch udpsz and wait before admin send packet with dvar info and then udpsz can catch it on the fly ? Am I right ?
you need to launch it and waiting but nobody can say how much you need to wait because it's not a vulnerability that doesn't have a fixed and clear result, it's something like fishing on the sea where you don't know if and when you will catch something.
Quote:
Only one returned to rcon. It works, but not for everyone. Or the time was not enough.
it's all about time and maybe in some cases even the "right moment".
after all it's almost a statistic things: scanning a whole C or B range gives more interesting results than monitoring one single server.
at least this is what I noticed because, in case it wasn't clear, I almost didn't spent time and packets on this bug because I don't test things not located on my computers and even with this big limitations I casually captured highly important informations (rcon).
in this vulnerability the "luck factor" is important.
then you catched one rcon so in my opinion it's a huge positive result, moreover for a passive bug like this one.