Guild icon
Teeworlds
IRC / bridge
One-way IRC channel bridge. If you want to be able to send messages to IRC, contact @Dune or @heinrich5991. https://www.teeworlds.com/?page=docs&wiki=rules/irc_rules
Between 2019-11-03 00:00:00Z and 2019-11-04 00:00:00Z
Avatar
does svg really has an attack surface oO
00:07
when will you fix emote 16 btw?
Avatar
every piece of code interacting with the network has an attack surface
Avatar
prob. true
00:10
the svg would be embedded into the map
00:11
so the channel is already "secure" if you want
00:11
how is the map transportet over the network?
00:11
I imagine as complete blob
Avatar
no, it's not secure. the server can send arbitrary data over the network. bug in the svg library, bug in teeworlds
Avatar
don't you think you are highly pessimistic talking about attack surface in something as simple as svg support?
Avatar
I think I'm pessimistic that I'm talking about attack surface (see above). by no means however, is svg simple
00:16
it's a complex format based on xml. the good news is that the lib reading it is nowadays written in rust, so there's some hope against exploits
00:17
it does seem to have a fairly good track record as well, but I'm not sure whether that's just because it's not popular enough: https://www.cvedetails.com/product/23082/Gnome-Librsvg.html?vendor_id=283
Gnome Librsvg security vulnerabilities, exploits, metasploit modules, vulnerability statistics and list of versions
00:19
(the same applies to putting stuff like pngs into maps. even map files itself are an attack surface; they even have unpatched security vulnerabilities)
Avatar
i am surprised how many bugs that are
00:20
but i just entered sdl2 for comparison ...
Avatar
welcome to the happy state of software security
Avatar
time to dropper
Avatar
hm?
00:23
Docker Docker security vulnerabilities, exploits, metasploit modules, vulnerability statistics and list of versions
00:25
@heinrich5991 want some fun? Enter Excel
Avatar
note that people try harder to find vulnerablities in more popular software
00:26
so just because there are more reported security vulnerabilities, it might not mean that it's buggier, it might even mean the opposite thing if the authors are more prudent in requesting cves
Avatar
i just entered firefox and see what you mean
Avatar
or try chrome
00:28
etc.
Avatar
I wonder if you can still hack people with the now known vulnerabilities
Avatar
software vendors usually patch security vulnerabilities when they become aware of them
00:32
however there are always people running outdated software
00:32
so yes
00:32
there are even pre-written exploits IIRC
Avatar
@heinrich5991 we need the latest client versions, clanmembers just found a bug in the latest version where your tee gets invisible (client side)
Avatar
@Assa I don't understand
Avatar
Current official version: 0.7.3.1, latest version: pre-0.7.4
01:02
latest version may have a bug where your tee gets invisible
Avatar
oh
Avatar
and i can't confirm because i can't compile <.<
Avatar
[quakenet] redix_ BOT 2019-11-03 02:20:29Z
invisible tees should by fixed by this: https://github.com/teeworlds/teeworlds/pull/2216
When a snapitem is invalidated, its entry in the list of keys is set to -1. This breaks the binary search, introduced by #2129. Instead of modifying the list itself, I only modify the key value ins...
02:23
however... considering snapshots and demos... there are issues that might be used for malicious things
Avatar
thumbsup ❤
Avatar
ChillerDragon 2019-11-03 09:14:17Z
@Assa what do you mean by emote 16 fixes? You mean that doubled emote thingy? Thats fixed already
Avatar
@ChillerDragon exactly and nice 😄
Avatar
I think the teeworlds mapper should have blueprints 🤔
Avatar
@Dune my server is running now for more than 10.000 minutes, without any master server warning - because i havent logged into rcon since the start.
13:37
if i would login now, it would fail again
13:37
what could have gone wrong here?
13:37
i didnt edit the source in any way that should cause this
Avatar
If it happens on your mod and not on vanilla, it's a bug from something you changed
Avatar
Yes, sure
13:41
But I still cant find why
Avatar
Try econ, if it triggers the issue
Avatar
no idea how it works
Avatar
ChillerDragon 2019-11-03 14:03:57Z
You need that in your config ec_port "port" ec_password "password"
14:04
so server has to restarted :/
14:05
The you can connect to it using telnet or netcat. If you are logged in on the vps nc localhost port should do the thing. Btw is econ documented anywhere?
Avatar
@fokkonaut there is a good tutorial on the foruls
Avatar
[quakenet] rand BOT 2019-11-03 14:44:14Z
you may overflow and overwrite wrong bits at some point
14:44
I did this once, valgrind helped
Avatar
@Dune :'( would you mind spending some of your free time to take a look at the forum. I think spam escalated a little bit there.
Avatar
This spam literally happened 1min ago, do you have a subscription or something
17:51
I'm lucky to have taken a look at the right time.
17:53
I mean the 209 new topics about weight watchers. Some are from some hours ago ._.
17:53
ty very much
Avatar
[quakenet] minus BOT 2019-11-03 18:01:01Z
just move the forum to reddit
Avatar
Can't bump old posts with updates and releases and what not there
18:32
Manual registration approval is possible but meh
Exported 70 message(s)