Skip to content

Security: WindowsGSH/WindowsGSH.UT2004

Security

SECURITY.md

Security policy

Security and trust

The UT2004 module executes C# and starts a user-supplied retired retail server installation with the current user's Windows permissions. WindowsGSH cannot guarantee arbitrary third-party or modified modules. Review source, manifests, dependencies, and download origins before use.

Download modules safely

Obtain UT2004 lawfully; this module does not distribute or bypass retired retail files, keys, or authentication. Obtain community patches/master-server changes only from sources you independently trust and review their licences and binaries.

Protect credentials and server data

Protect CD keys, game/admin passwords, WebAdmin credentials, player data, configs, logs, custom content, and backups. Keep WebAdmin private and redact command lines and diagnostics.

Report a vulnerability

Use the private repository advisory page. Do not publish exploits, credentials, private server data, or unredacted diagnostics.

Include in a report

Include module/WindowsGSH/game and optional patch versions, lawful package provenance, reproduction steps, impact, and sanitized diagnostics.

Supported versions

Security fixes target the latest module release and current WindowsGSH module API unless stated otherwise.

There aren't any published security advisories