MapVote3 Feature or Hack?

  • Two Factor Authentication is now available on BeyondUnreal Forums. To configure it, visit your Profile and look for the "Two Step Verification" option on the left side. We can send codes via email (may be slower) or you can set up any TOTP Authenticator app on your phone (Authy, Google Authenticator, etc) to deliver codes. It is highly recommended that you configure this to keep your account safe.

DeeZNutZ

New Member
Jan 22, 2002
21
0
0
Pacific Beach, CA
www.badstreak.com
I saw something occur on my server last night that caused me a good deal of concern. I watched a single player connected to my server "Force" a CTF map (CTF-November) from BDBMapVote3 into play that I don't even have in my map rotation. Is this something that can easily be done from the client side, or is this a "hack" of sorts? I've checked the documentation on BDBMapVote3, and see nothing that indicates this can be done from the client side. (I do have the "Use the Map Cycle List instead of all maps" box checked in my MapVote3 in the Admin section, Misc section of the MapVote config...)
The info - BDBMapVote 3.00, UT dedicated server 4.36, UTPure RC5b w/ Valhalla Avatar 0.9 Beta, Windows 2000 Pro O/S. I've attached a portion of the log file and my Map lists.
Any comments or suggestions would be appreciated here (other than the "remove the maps you don't want to cycle from the \UnrealTournament\Maps folder"....)
 

BDB

New Member
May 9, 2000
398
0
0
NC, USA
www.planetunreal.com
I don't know of any hacks that would allow a player to vote for a
map that isn't in the list.
When a player submits a vote for a map it is validated on the
server side against the map list. If the map name isn't in
the list then the vote is not counted.
So, I don't know how he was able to do this.

I will review the code and think about it.
If it happens again send me the whole zipped log and the
MapVote config section from the ini in Email so I can
anaylyze everything.

Thanks
 

DeeZNutZ

New Member
Jan 22, 2002
21
0
0
Pacific Beach, CA
www.badstreak.com
I appreciate the response, and any input here. I have this posted in a few other forums as well, but no-one has EVER seen this happen. I know the player wasn't logged in under ADMINLOGIN, but I have disabled remote login for the time being.
I've tried to recreate this, and have been unable to do so. For now, I've moved all maps not in rotation into a seperate directory.
Thank you for any light you might be able to shed on this.
BTW - Ironman_Oz has put some screenshots of you handing some of our clan members their asses last week. lol Have you seen them? www.bsoz.com
{BSC}DeeZNutZ
 

BDB

New Member
May 9, 2000
398
0
0
NC, USA
www.planetunreal.com
No, I haven't seen those screen shots before.
That's cool.

I like all the different player models on your server but
it took forever to download the first time.

Anyway, It was fun playing on your server.