ну как минимум heap buffer overflow осуществить возможно, это уже я думаю достойно патчаа был ли мальчик? калкор что-то там фиксил в R4, но была ли действительно возможность исполнять код - хз
ну как минимум heap buffer overflow осуществить возможно, это уже я думаю достойно патчаа был ли мальчик? калкор что-то там фиксил в R4, но была ли действительно возможность исполнять код - хз
ну как минимум heap buffer overflow осуществить возможно, это уже я думаю достойно патча
в R4-2 была исправлена совершенно другая уязвимостькоторый он пытался пофиксить в samp 0.3.7-r4-2
память немного подвела)в R4-2 была исправлена совершенно другая уязвимость
и разве геймтекст патчился в R4-2? мне казалось в R5
Why couldn't you just post fix of this exploit on the forum and now you're crying? StupidIt's lame that the guy that created this exploit reported it to OpenMP team so they can make a fix, Amyr then gives it to SampAddon creator and you suddenly make a fix like 5 days after. To the SAME exploit we reported. Coincidence? I think not.
Next time just a "thanks" would be nice for it, these things make you think to report an exploit like this again or just sell it like some of you do.
no need to insult buddy. publishing a fix like this has the downside of exposing the vulnerability, that's the only reason why i didn't want to.Why couldn't you just post fix of this exploit on the forum and now you're crying? Stupid
i've actually discovered it myself, if you wanna see my rce pawn code, dm meno need to insult buddy. publishing a fix like this has the downside of exposing the vulnerability, that's the only reason why i didn't want to.
now be prepared for this to be exploited in the wild, with the majority of SA-MP players not knowing about this fix or even this forum.
to the post creator, thanks for writting the patch and sharing it. but it will be fair if you give me some credit, as i'm pretty sure you got my PoC (or any relevant info about the vuln) from what i shared with some open-mp devs a few weeks ago.
PS: nice vuln report
That dude thinks that he is fucking genius and only he can discover this exploit. I stay by side that more people acquainted with these more people will have this fix. More projects will fix this in theirs clients. Nothing helps players who play on small rp dumpsi've actually discovered it myself, if you wanna see my rce pawn code, dm me
of course you have the knowledge to write your own exploit, that's not the point.i've actually discovered it myself, if you wanna see my rce pawn code, dm me
i have no relation to openmp, you can ask them if you wantof course you have the knowledge to write your own exploit, that's not the point.
but it is hard to believe that you discovered it by yourself just a few days after i disclosed information about it with some people. just too much coincidence.
It all looks like an episode from Rick and Morty, where Beth didn't apologize to Tommy for what she did to him, and decided to go the radical way by killing everyone.06/29/2024 XXXXXXX - Posted PoC of the exploit
03/07/2024 7:21 PM - Disclosure of the exploit to the OpenMP guy
10/07/2024 00:13 AM - SAMPAddon guy tells Evgen that OpenMP guy messaged him about the exploit (Without any permission) -
07/12/2024 18:13 PM - SAMPAddon guy releases a fix, one could imagine he discovered the RCE since he doesn't thank the original author. Translating the text seems like he discovered it but you could help on that, if not, at least credit the author or say "thanks". - https://vk.com/wall-50232903_447662
07/17/2024 00:40 AM - You release this fix
Again, coincidence? I think not. Either someone gave you this info or you RE'd SAMPAddon, but we don't think this is a coincidence. At the end, users are protected which is what he wanted, but, it's the matter of saying "thanks".