<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Garry&#039;s Mod Archives - Arweth</title>
	<atom:link href="https://arweth.com/category/games/garrys-mod/feed/" rel="self" type="application/rss+xml" />
	<link>https://arweth.com/category/games/garrys-mod/</link>
	<description></description>
	<lastBuildDate>Tue, 25 Jan 2022 19:00:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Garry&#8217;s Mod LUA Malware</title>
		<link>https://arweth.com/2014/04/garrys-mod-lua-malware/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=garrys-mod-lua-malware</link>
					<comments>https://arweth.com/2014/04/garrys-mod-lua-malware/#respond</comments>
		
		<dc:creator><![CDATA[Arweth]]></dc:creator>
		<pubDate>Sat, 19 Apr 2014 04:22:26 +0000</pubDate>
				<category><![CDATA[Garry's Mod]]></category>
		<category><![CDATA[Tech News]]></category>
		<guid isPermaLink="false">http://arweth.com/?p=169</guid>

					<description><![CDATA[<p>A new piece of malware that is targeting Garry&#8217;s Mod servers and client&#8217;s has been identified within the last 3 hours (Around 1:00AM GMT 19th April 2014). This malware runs thougha LUA script that downloads files to clients and uploads the script &#8230;</p>
<p class="read-more"> <a class="more-link" href="https://arweth.com/2014/04/garrys-mod-lua-malware/"> <span class="screen-reader-text">Garry&#8217;s Mod LUA Malware</span> Read More &#187;</a></p>
<p>The post <a href="https://arweth.com/2014/04/garrys-mod-lua-malware/">Garry&#8217;s Mod LUA Malware</a> appeared first on <a href="https://arweth.com">Arweth</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A new piece of malware that is targeting Garry&#8217;s Mod servers and client&#8217;s has been identified within the last 3 hours (Around 1:00AM GMT 19<sup>th</sup> April 2014). This malware runs thougha LUA script that downloads files to clients and uploads the script to the server to allow it to spread to more clients.</p>
<p><a href="#update">Jump to updated information</a></p>
<p>&nbsp;</p>
<p>The purpose of the malware is not completely know at this stage. However it has been identified to steal the servers RCon password if it is stored in the servers config file and spam messages though steam to your friends list when joining an infected server. A update to patch this should be made available tomorrow in a update to the game. There could be other underlying functions to this malware that has not be identified as of yet. I will keep this post updated as more news becomes available. You can find the post on FacePunch forums here: <a href="http://facepunch.com/showthread.php?t=1386818">http://facepunch.com/showthread.php?t=1386818</a></p>
<p>&nbsp;</p>
<p><strong>Garry&#8217;s Mod Clients:</strong></p>
<p>You can check if your infected by checking your installation of Garry&#8217;s Mod for the following files. These will be located in your SteamApps folder under Common\Garrys Mod  (Please note that some of these files may be hidden):</p>
<p><em>garrysmod/engine_win32.dll</em><br />
<em> garrysmod/download/engine_win32.dll</em><br />
<em> garrysmod/bin/game_shader_generic_engine.dll</em><br />
<em> garrysmod/materials/cooltexture.vtf</em></p>
<p>&nbsp;</p>
<p>These files can be deleted safely &#8211; It so far has been confirmed that <em>game_shader_generic_engine.dll</em> and <em>cooltexture.vtf</em> are the main port of infection but the other two are files that should not be there in a standard Garry&#8217;s Mod install.</p>
<p>&nbsp;</p>
<p><span style="text-decoration: underline;">Please be aware that joining an infected server will cause you to become infected again</span></p>
<p>&nbsp;</p>
<p><strong>For Server Owners:</strong></p>
<p>Your server config should be defined to have the following variable set:</p>
<p><em>sv_allowdownload 0 // Stop clients downloading files directly from server, FastDL will still be functional</em><br />
<em> sv_allowupload 0 // Stop files from uploading files directly to the server</em></p>
<p><em>rcon_password &#8220;&#8221; // alternatively, move your rcon password to be defined in your server&#8217;s startup command line</em></p>
<p>&nbsp;</p>
<p>The following files will be present on an infected server (Please note that some of these files may be hidden):</p>
<p><em>garrysmod/engine_win32.dll</em><br />
<em> garrysmod/download/engine_win32.dll</em><br />
<em> garrysmod/lua/autorun/server/default.lua</em></p>
<p>&nbsp;</p>
<h2 id="update">Update as of 5:30AM 19<sup>th</sup> April 2014 GMT</h2>
<p>It has now been identified that servers with !!! (3 exclamation marks) in the server name / title are likely to be infected with the malware and should be avoided. This is yet to be confirmed officially but so far is the general consensus.</p>
<p>Also deleting the above files may not be an absolute fix for the issue at this stage. If you have been infected beware you may still be infected after following the steps.</p>
<h2>Update as of 6:21Am 19<sup>th</sup> April 2014 GMT</h2>
<p>Garry has confirmed the knowledge of the issue and that a fix is in production that should be available within a few hours.</p>
<blockquote class="twitter-tweet" lang="en"><p>We&#8217;re aware of the Source net_File exploit &#8211; fixing it now, should have a patch out within a couple of hours.</p>
<p>— Garry Newman (@garrynewman) <a href="https://twitter.com/garrynewman/statuses/457393548300926976">April 19, 2014</a></p></blockquote>
<p><script src="//platform.twitter.com/widgets.js" async="" charset="utf-8"></script></p>
<p>It currently does not appear to be malicious in nature and just spams steam and server chat&#8217;s while attempting to play music and render a image on the client&#8217;s screen. The attack also does not appear to effect Linux or mac servers. Or servers without the RCon password in the config file.</p>
<h2>Update 7:00Am 19<sup>th</sup> April 2014</h2>
<p>An update has now been pushed out to Garry&#8217;s Mod to fix the issue. Steam should automatically download this now.</p>
<p>Official post available now at:<br />
<a href="http://www.garrysmod.com/2014/04/19/exploit-fix-released/">http://www.garrysmod.com/2014/04/19/exploit-fix-released/</a></p>
<p>The post <a href="https://arweth.com/2014/04/garrys-mod-lua-malware/">Garry&#8217;s Mod LUA Malware</a> appeared first on <a href="https://arweth.com">Arweth</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://arweth.com/2014/04/garrys-mod-lua-malware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 12/107 objects using Disk
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk
Database Caching using Disk (Request-wide modification query)

Served from: arweth.com @ 2026-06-20 10:35:05 by W3 Total Cache
-->