citizenfx/fivem-docs

CWE-406 DDoS Amplification code brought over from quake3 netcode

Closed this issue · 1 comments

Hey blattersturm,
Just bringing your attention to something that was pulled across from old quake3 netcode pointed out in sections of FiveM code:

I've linked to both lines in your repository on the write-up here:
https://github.com/Phenomite/AMP-Research/tree/master/FiveM%20port%2030120

Hope you dont mind putting this into scope as something you can fix like how Valve introduced
checksums in their a2s_player query - https://developer.valvesoftware.com/wiki/Server_queries#A2S_PLAYER.

Thanks!

I see you patched in a rate limiter per IP, thanks @blattersturm .

citizenfx/fivem@512e410#diff-2c779bbd89c5d6653a7b390ad22bdb4f

You can close at your discretion.