AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   SourceMod Anti-Cheat (https://forums.alliedmods.net/forumdisplay.php?f=133)
-   -   SMAC by-pass hack? (https://forums.alliedmods.net/showthread.php?t=293984)

Mitchell 09-28-2017 09:57

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by arne1288 (Post 2495970)
You are using plugins that aren't doing their "Steam ID" checks properly. In other words, plugins created by lazy people.

Sounds like a pain in the ass to guard against.
What should the plugins do, kick players that don't validate?
Can this method ever return "STEAM_ID_STOP_IGNORING_RETVALS" after the player has already connected and has previously stored his steamid?
Some gameplay factors require retrieving the steamid, so should we continuously keep trying to get the player's steamid and force them in spectator until it returns true?
I have never really encountered this but if it were to happen i'd rather just kick the player then trying to figure out a way to retrieve player stats after they have already been playing for a given period of time.
Any other documentation when this will be returned?

bobotov 09-28-2017 17:32

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by Mitchell (Post 2551282)
Any other documentation when this will be returned?

When I decide to do it again.

TheXeon 09-28-2017 18:52

Re: SMAC by-pass hack?
 
Had a fun run-in with ya @bobotov. The whole time I was trying to block the IP through ufw or IPTables, that didn't work for whatever reason.

I feel like Sourcebans++'s SourceSleuth should have done a bit of checking (since sm_banip does work and your IP was correctly added to the DB) and at least kicked. addip from the server console didn't work, that might just be me rusty with it though.

EDIT: The whole time it was STEAM_ID_STOP_IGNORING_RETVALS. I feel like trying to get people's auth every few seconds might be a bit much, thing below is proof-of-concept and working(?)

EDIT 2: THIS DOESNT WORK, USE https://forums.alliedmods.net/showpo...2&postcount=25

bobotov 09-28-2017 19:14

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by TheXeon (Post 2551357)
Had a fun run-in with ya @bobotov. The whole time I was trying to block the IP through ufw or IPTables, that didn't work for whatever reason.

I feel like Sourcebans++'s SourceSleuth should have done a bit of checking (since sm_banip does work and your IP was correctly added to the DB) and at least kicked. addip from the server console didn't work, that might just be me rusty with it though.

Was the server I was on Wonderland?

And hi. :D

TheXeon 09-28-2017 19:24

Re: SMAC by-pass hack?
 
Care to help me test out the pseudofix? No, you weren't on Wonderland XD

bobotov 09-28-2017 19:26

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by TheXeon (Post 2551361)
Care to help me test out the pseudofix? No, you weren't on Wonderland XD

Yea sure. Give me the ip.

TheXeon 09-28-2017 19:30

Re: SMAC by-pass hack?
 
~sig or url on proof-of-concept?

bobotov 09-28-2017 19:35

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by TheXeon (Post 2551363)
~sig or url on proof-of-concept?

What do you mean?

TheXeon 09-28-2017 19:37

Re: SMAC by-pass hack?
 
IP: neogenesisnetwork.net or 104.153.106.174, guess my signature isn't showing up.

bobotov 09-28-2017 19:38

Re: SMAC by-pass hack?
 
Quote:

Originally Posted by TheXeon (Post 2551366)
IP: neogenesisnetwork.net or 104.153.106.174, guess my signature isn't showing up.

Huh. It's not letting me connect. This tends to happen sometimes while I'm doing this method. Let me restart stuff and try again.


All times are GMT -4. The time now is 18:18.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.