TheDuckDie / darkrp

Automatically exported from code.google.com/p/darkrp
0 stars 0 forks source link

Normal people able to edit admin settings: #180

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
I got a report from a person that there is a glitch where people are able to 
edit admin settings.The glitch only happens within 1st minute of server start 
though but is a big security issue.How its done:

If you push F3 & F4 at same time at spawn start it sometimes happens that the 
the admin panel appears in the DarkRP menu for anyone who did it and they are 
able to change the settings.

Original issue reported on code.google.com by zygimant...@gmail.com on 26 Jan 2010 at 9:17

GoogleCodeExporter commented 9 years ago
Even though non-admins are able to see the admin tab in the F4 menu with certain
tricks (like making yourself admin clientside), it is impossible for that 
person to
actually change things unless he really is an admin.

It is checked serverside. See if you can do it yourself in other servers or if 
the
person who told you this is not the only one who can do this.

Original comment by fpeijnen...@gmail.com on 27 Jan 2010 at 7:15

GoogleCodeExporter commented 9 years ago
Well the thing is he is not admin in any way,but he was able to change couple 
of 
settings that way.When I asked him how he told me that's what he did.

Original comment by zygimant...@gmail.com on 27 Jan 2010 at 7:59

GoogleCodeExporter commented 9 years ago
Has he ever been admin or RP admin?

Original comment by fpeijnen...@gmail.com on 27 Jan 2010 at 12:05

GoogleCodeExporter commented 9 years ago
He has been an admin long time ago,but he is not in ULX admin list anymore as 
thats 
what we use for administration.Server has been reinstalled allot of times since 
then.

Original comment by zygimant...@gmail.com on 27 Jan 2010 at 5:18

GoogleCodeExporter commented 9 years ago
P.S he said its a DarkRP glitch which works in the servers he has tried.

Original comment by zygimant...@gmail.com on 27 Jan 2010 at 5:18

GoogleCodeExporter commented 9 years ago
It's an old bug. It doesn't happen anymore, but if it happened before the update
doesn't fix it.

When he's in the server run rp_revoke name admin
And he won't be able to change settings anymore.

Original comment by fpeijnen...@gmail.com on 27 Jan 2010 at 6:45