Posts: 15,941
Threads: 0
Joined: Jun 2008
References like that aren't even valid in a global scope in C++ unless you declare and define them at the same time (even them I'm not sure), and you can't define things that might be referenced like that globally in PAWN anyway. Those are just for function parameters.
Posts: 2,187
Threads: 81
Joined: Aug 2011
Reputation:
0
Oh cool, and yes, my mistake, I should have tried to &My_Var in a function or something. So, PAWN supports reference variables, but is it of any other use except for call by reference (thingy)? I mean I can't think of the requirement of a &e_Var for SA-MP scripts. OFF TOPIC: Why do appear offline even when you are online, is it your mod tweak thingy?
Posts: 15,941
Threads: 0
Joined: Jun 2008
Call by reference IS the requirement and very useful (think "GetPlayerPos").
And its a user setting.
Posts: 2,187
Threads: 81
Joined: Aug 2011
Reputation:
0
So, you could actually exploit the use of reference vars, don't you think? I saw this program online, which tracks the memory locations being accessed by a program, and from where they are being accessed(Not sure of it's name)! You type in a certain value/string, and it looks for the line/memory address/line in the program that is being accessed. You know the max players in a server, so while a player connects, I am sure it checks if the max_player_count < players on server, you could type in the MAX_PLAYER_VALUE (500, etc) and it would bring you the location, and you just reference var it, so you could basically do a lot of harm, right?
Or am I wrong in some of my assumptions regarding the security SA-MP has, etc?
ALSO, aren't we going a bit off topic?
Posts: 15,941
Threads: 0
Joined: Jun 2008
We are talking about PAWN, not the server itself. PAWN is in a sandbox so you can only reference things within it's memory space (in theory, this encapsulation has been broken). However, there is no single place where "MAX_PLAYERS" is defined in the compiled server so you can't change it. Like a mode using "gVar[MAX_PLAYERS]" in multiple places, once the mode is compiled you would have to alter everything to increase that array.
Posts: 2,187
Threads: 81
Joined: Aug 2011
Reputation:
0
MAX_PLAYERS is just something I am using as an example. Admittedly, searching for locations being accessed for the value '500' would return tons of line, but if it was a lot more unique than that, IsValidNick or so.
And about the sandbox, you yourself said, the box has been broken out of.
Posts: 15,941
Threads: 0
Joined: Jun 2008
That's, erm, quite horrendous! But awesome at the same time - nice.
Posts: 367
Threads: 55
Joined: Oct 2011
Reputation:
0
any updates? are you still working on it?