Garry's Mod "Cough" virus is cured, but it could have been worse

You may have noticed some strange behavior in Garry's Mod if you played it a couple of days ago. An exploit that took advantage of the Source Engine's file sending mechanism made it possible to send files with any extension to the client or server. Strangely, this was used to change users' Steam name to “VINH'LL FIX IT,” and using them to spam friends and players with the word “cough” over chat. The exploit is mostly fixed now, but Garry's Mod's own Garry Newman tells us it could have been a lot worse.

“The worm as I understand it was transferred to the client as a dll, then when it loaded it crashed the client, in the hope that they'd join another server,” Newman told PC Gamer in an email. “When they did it downloaded the server's config file and looked for a rcon password.” RCON, or “remote console,” allows you to control a server remotely. “If it got one, it infected the server by uploading the dll and running it (it didn't need rcon to upload the dll, only to run it). And then the cycle continued.”

Newman said he patched Garry's Mod within an hour of finding out about it, and that Valve did the same, but that it's still possible for the bug to spread via different Source Engine mods, so be careful what you download.

“The effects of the worm were mostly non-destructive as far as we know,” Newman said. “Luckily the creator kept it pretty tame. It could have been a hell of a lot worse. I hope by being proactive and patching it quickly we avoided anyone using it maliciously.”

TOPICS
Latest in FPS
Team Fortress Spy being shocked
An FPS studio pulled its game from Steam after it got caught linking to malware disguised as a demo, but the dev insists it was actually the victim of a labyrinthine conspiracy
Neighbors Suburban Warfare screenshot a child aims a slingshot at a man from across a cul-de-sac.
A beta of backyard FPS Neighbors: Suburban Warfare is out now, and the balance discussion is hysterical: nerf trash can lids and children
Fragpunk
Somebody finally figured out casual Counter-Strike
Image for
Warhammer 40,000: Darktide’s getting a new roguelite wave defense mode that sounds a whole lot like a souped-up take on Killing Floor
Destiny 2: Season of Plunder promo image.
'We made one big mistake': Destiny 2 developer reveals how a small team dedicated to player retention led to a 20 hour server outage and character rollback
Bears in Space
I downloaded this bear-obsessed comedy FPS to kill time before Doom: The Dark Ages and discovered the most underrated shooter on Steam
Latest in News
A True Kin knight stands in a ruin in Caves of Qud, flanked by bloodstained furniture and a freshly mortalized corpse.
Despite making a roguelike where you can have countless arms and legs, Caves of Qud's creators say the ideal form is a limbless sphere: 'We started in perfection and only moved farther from God'
Civilization 7 Great Britain - Modern Civ art (via YouTube)
As Civilization 7 struggles to keep up with Civ 5 player counts, a new patch is coming tomorrow with still more UI changes and gameplay tweaks
Metaphor: ReFantazio character art
Metaphor: ReFantazio battle director says turn-based RPGs can still be just as popular as action RPGs: 'I personally believe turn-based games have a long future ahead of them'
assassin's creed shadows review
Assassin's Creed Shadows streamer goes viral after confronting whining commenters: 'Normal people don't get upset about this sh***'
Assassin's Creed Shadows change seasons - An upper-body shot of Yasuke looking cheerfully up into the distance.
'This is just the beginning': Assassin's Creed Shadows dev team thanks fans for their support and promises more to come in the future
Geralt sitting on a wall wearing a Cyberpunk jacket modded by TheRealArdCarraigh
The Witcher 3 devs had to practically remake the game engine to make official modding possible