AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   SourceBans / SourceBans++ (https://forums.alliedmods.net/forumdisplay.php?f=152)
-   -   (not a Sourcebans issue) All players reported as having the same IP address (https://forums.alliedmods.net/showthread.php?t=345502)

DNA.styx 01-21-2024 15:28

(not a Sourcebans issue) All players reported as having the same IP address
 
Subject was: Everyone gets flagged as "[SourceSleuth] Duplicate account" after aimbot ban

After an aimbot user was banned everyone joining my server, including myself, is being banned/flagged "[SourceSleuth] Duplicate account" saying they have the same IP address. Is this a known issue? Any fix?


Software:
SourceBans++ 1.8.0 | Git: 1294
Little Anti-Cheat 1.7.4

Events:
Aimbot user banned by Little Anti-Cheat while I was on the server. This is the first cheat ban logged, previous bans have been manual steamID only bans.
Spoiler

Next person to join the server gets banned with SourceSleuth Duplicate account

Spoiler


Checked SourceBans++ log and both players have the same IP address. I presume they had an alt-account.

Restarted map to set the SourceBans++ language to English (server default) and I got kicked for [SourceSleuth] Duplicate account as well

Spoiler


Changed Sleuth Ban Type to notify only and now anyone joining the server,including myself getflaged as having an active ban

Spoiler


Tried restarting map and server. No better.

DNA.styx 01-30-2024 18:38

Re: Everyone gets flagged as "[SourceSleuth] Duplicate account" after aimbot ban
 
Have just discovered that the IP address listed above, 88.198.27.9, is one of the gameME stats servers.

DNA.styx 02-01-2024 17:13

Re: (not a Sourcebans issue) All players reported as having the IP address
 
Have installed a couple of other plugins that use GetClientIP and they all return the same IP address, which has been confirmed as one of the GameME servers. All very strange....but not a SourceBan issue.

PHP Code:

19:56:00 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9CONNECTED from <Germany>
20:03:42 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 27 minutes. <Disconnect by user.>
20:03:46 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9CONNECTED from <Germany>
20:06:46 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 4 minutes. <Disconnect by user.>
20:56:03 - <QUACKATTACK_3_1> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 10 minutes. <Disconnect by user.>
21:03:43 - <Oly> <STEAM_0:0:xxxx> <88.198.27.9DISCONNECTED after 26 minutes. <Disconnect by user.>
21:04:21 - <KARIS CZ> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 27 minutes. <Disconnect by user.> 


Bacardi 02-01-2024 22:19

Re: (not a Sourcebans issue) All players reported as having the IP address
 
Plugin_print
Meta list
Sm exts list
Sm plugins list


Status

DNA.styx 02-03-2024 04:21

Re: (not a Sourcebans issue) All players reported as having the IP address
 
Plugin_print
PHP Code:

Loaded plugins:
---------------------
0:    "Metamod:Source 1.12.0-dev+1157"
--------------------- 

Meta list
PHP Code:

Listing 5 plugins:
  [
01RCBot2 (1.51 (apg-nosoop-caxanga334)-3a3a3a41by CheesehRoboCopnosoopcaxanga334
  
[02SourceMod (1.11.0.6947by AlliedModders LLC
  
[03SDK Tools (1.11.0.6947by AlliedModders LLC
  
[04SDK Hooks (1.11.0.6947by AlliedModders LLC
  
[05SteamWorks Extension (1.2.3by Kyle Sanderson 

Sm exts list
PHP Code:

[SMDisplaying 17 extensions:
[
01Automatic Updater (1.11.0.6947): Updates SourceMod gamedata files
[02Webternet (1.11.0.6947): Extension for interacting with URLs
[03RCBot2 (1.51 (apg-nosoop-caxanga334)-3a3a3a41): Bot for HL2DMTF2 and DOD:S
[04SDK Tools (1.11.0.6947): Source SDK Tools
[05BinTools (1.11.0.6947): Low-level C/C++ Calling API
[06Top Menus (1.11.0.6947): Creates sorted nested menus
[07Client Preferences (1.11.0.6947): Saves client preference settings
[08SQLite (1.11.0.6947): SQLite Driver
[09System2 (3.3.2): HTTP/FTP Request and System API for Sourcemod
[10Regex (1.11.0.6947): Provides regex natives for plugins
[11REST in Pawn (1.3.1): Provides HTTP and JSON natives for plugins
[12SDK Hooks (1.11.0.6947): Source SDK Hooks
[13SMJansson (2.6.0/1): JSON parser/writer
[14SteamWorks Extension (1.2.3): Exposes SteamWorks functions to Developers
[15GeoIP (1.11.0.6947): Geographical IP information
[16] <OPTIONALfile "socket.ext.dll"The specified module could not be found.
[
17MySQL-DBI (1.11.0.6947): MySQL driver implementation for DBI 

Sm plugins list
PHP Code:

[SMListing 48 plugins:
  
01 "[DoD TMS] Addon - AFK Manager" (1.22by FeuerSturmmodif Micmacx
  02 
"[DoD TMS] Addon - Anti-VoiceCmdSpam" (1.22by FeuerSturmmodif Micmacx
  03 
"[DoD TMS] Addon - AutoTeamBalance" (1.22by FeuerSturmmodif Micmacx
  04 
"[DoD TMS] Addon - ClanTag Protection" (1.22by FeuerSturmmodif Micmacx
  05 
"[DoD TMS] Addon - High Ping Kicker" (1.22by FeuerSturmmodif Micmacx
  06 
"[DoD TMS] Addon - Secret Spectate" (1.22by FeuerSturmmodif Micmacx
  07 
"[DoD TMS] Addon - Class Restrictions" (1.22by FeuerSturmmodif Micmacx
  08 
"Admin File Reader" (1.11.0.6947by AlliedModders LLC
  09 
"Admin Help" (1.11.0.6947by AlliedModders LLC
  10 
"Admin Menu" (1.11.0.6947by AlliedModders LLC
  11 
"Advertisements" (2.1.1by Tsunami
  12 
"Anti-Flood" (1.11.0.6947by AlliedModders LLC
  13 
"Basic Chat" (1.11.0.6947by AlliedModders LLC
  14 
"Basic Comm Control" (1.11.0.6947by AlliedModders LLC
  15 
"Basic Commands" (1.11.0.6947by AlliedModders LLC
  16 
"Basic Info Triggers" (1.11.0.6947by AlliedModders LLC
  17 
"Basic Votes" (1.11.0.6947by AlliedModders LLC
  18 
"Client Preferences" (1.11.0.6947by AlliedModders LLC
  19 
"Cronjobs" (2.0by dordnung
  20 
"Discord Relay" (0.7.8by log-ical
  21 
"Discord API" (0.1.107by Deathknife
  22 
"Discord Logger!" (v2by MbK
  23 
"DOD:S Ammo Settings" (1.0by Silent_Water
  24 
"DoD BasicGore" (1.1by FeuerSturm
  25 
"DoD:S DetoNades" (1.0by Root
  26 
"DOD:S Fireworks" (1.3by Silent_Waterplayboycyberclub
  27 
"Dod Grenade Trails" (1.1by Andi67Modif Micmacx
  28 
"DoD Medic" (1.1.1by Tsunami,DNA.styx
  29 
"[DoD TMS] Base  - DoD TeamManager Source" (1.22by FeuerSturmmodif Micmacx
  30 
"Dog's Prop Bonus Round" (1.13.1by <eVa>Dog (edited byretsamDNA.styx)
  
31 "Dynamic MotD Replacer" (3.0.0by psychonic
  32 
"First bot" (1.0by Micmacx
  33 
"Fun Commands" (1.11.0.6947by AlliedModders LLC
  34 
"Fun Votes" (1.11.0.6947by AlliedModders LLC
  35 
"gameME Plugin" (4.8.1by TTS Oetzel Goerz GmbH
  36 
"DoD:S Instant Respawn" (1.5by Andersso
  37 
"[Lilac] Little Anti-Cheat" (1.7.4by J_Tanzanite
  38 
"Log Connections" (1.4by XanderIT-KiLLERDosergen
  39 
"Player Commands" (1.11.0.6947by AlliedModders LLC
  40 
"Reserved Slots" (1.11.0.6947by AlliedModders LLC
  41 
"SourceBans++: Admin Config Loader" (1.8.0by AlliedModders LLCSourceBans++ Dev Team
  42 
"SourceBans++: Bans Checker" (1.8.0by psychonicCa$h MunnySourceBans++ Dev Team
  43 
"SourceBans++: SourceComms" (1.8.0by AlexSourceBans++ Dev Team
  44 
"SourceBans++: Main Plugin" (1.8.0by SourceBans Development TeamSourceBans++ Dev Team
  45 
"SourceBans++ Report Plugin" (1.8.0by RumbleFrogSourceBans++ Dev Team
  46 
"SourceBans++: SourceSleuth" (1.8.0by eccaSourceBans++ Dev Team
  47 
"SpeedUp" (1.0.1by MosalarBacardi
  48 
"Tidy Chat" (0.5by linux_lover 

Status
PHP Code:

hostnameDNAGames 24/7 Ava | +Grens QuickSpawn SneakyBots
version 
6630498/24 6630498 secure
udp
/ip  185.216.145.132:27015  (public ip185.216.145.132)
steamid : [A:1:209xxxxxxx:25199] (9018022xxxxxxxxxx)
map     dod_avalanche at0 x0 y0 z
tags    
Bots,alltalk,quickspawn,gameME
players 
1 humans9 bots (12 max)
edicts  : -66149 used of 2048 max
# userid name                uniqueid            connected ping loss state  adr
#    508 "[RCB]WooHoo"       BOT                                     active
#    482 "[RCB]Goose"        BOT                                     active
#    509 "[RCB]Leeroy"       BOT                                     active
#    507 "[RCB]Mouse"        BOT                                     active
#    497 "[RCB]Ratatat"      BOT                                     active
#    493 "[RCB]Goddard"      BOT                                     active
#    505 "[RCB]Rambo"        BOT                                     active
#    511 "[RCB]Peake"        BOT                                     active
#    506 "[RCB]SirRobin"     BOT                                     active
#    510 "DNA.styx"          [U:1:40203]         03:55       40    0 active 82.69.xx.xxx:27005 

Connection log
PHP Code:

09:09:36 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany

edit: I was AFK the whole day yesterday and the connection logger recorded the below. 82.69.xxx.xxx = my IP. It flipped between the GameME and my IP address. Note there is an automated server restart at ~0600.

PHP Code:

02:46:23 - <fmauro64> <STEAM_0:0:103703320> <82.69.xxx.xxxDISCONNECTED after 13 minutes. <Disconnect by user.>
13:25:22 - <DonneTaCarabine> <STEAM_0:0:9512374> <88.198.27.9DISCONNECTED after 9 minutes. <Disconnect by user.>
16:58:15 - <DARK> <STEAM_0:0:77628340> <88.198.27.9DISCONNECTED after 7 minutes. <Disconnect by user.>
17:31:14 - <bodyelectrich> <STEAM_0:1:45452862> <88.198.27.9DISCONNECTED after 8 minutes. <Disconnect by user.>
19:52:32 - <ManOs> <STEAM_0:0:5904043> <82.69.xxx.xxxDISCONNECTED after 7 minutes. <Disconnect by user.>
20:15:35 - <boba {VoD}> <STEAM_0:1:9310115> <82.69.xxx.xxxDISCONNECTED after 9 minutes. <Disconnect by user.>
20:21:32 - <ManOs> <STEAM_0:0:5904043> <82.69.xxx.xxxDISCONNECTED after 29 minutes. <Disconnect by user.>
20:21:38 - <Kannixx> <STEAM_0:0:165973253> <82.69.xxx.xxxDISCONNECTED after 35 minutes. <Disconnect by user.>
20:21:38 - <der.lexan> <STEAM_0:0:15852015> <82.69.xxx.xxxDISCONNECTED after 28 minutes. <Disconnect by user.>
20:23:18 - <G â&#732;…man> <STEAM_0:0:540124302> <82.69.xxx.xxx> DISCONNECTED after 8 minutes. <Disconnect by user.>
20:23:31 - <TORPE> <STEAM_0:0:7741798> <82.69.xxx.xxxDISCONNECTED after 12 minutes. <Disconnect by user.>
20:28:13 - <bjwilliams010> <STEAM_0:1:797692874> <82.69.xxx.xxxDISCONNECTED after 1 minutes. <Disconnect by user.>
20:49:12 - <BlackSkyline> <STEAM_0:0:514068672> <82.69.xxx.xxxDISCONNECTED after 54 minutes. <Disconnect by user.>
22:48:54 - <gael the metropolice> <STEAM_0:1:484483357> <82.69.xxx.xxxDISCONNECTED after 3 minutes. <Disconnect by user.>
09:09:36 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany>
09:26:46 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9DISCONNECTED after 18 minutes. <Disconnect by user.>
09:26:50 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany


DNA.styx 02-03-2024 16:58

Re: (not a Sourcebans issue) All players reported as having the same IP address
 
It's beginning to feel like it's something to do with remote rcon/logaddress.

I've got an app on my phone that allows me to perform console actions on the server: status/plugin_print/meta list etc.

It appears that anytime I use that that app from home all players get my home IP (82.69.xxx.xxx).

M server's autoexec.cfg has a logaddress_delall & logaddress_add (as per gameme instructions), so that could be why I've noticed that restarting the server results in 88.198.27.9 appearing as everyone's IP address again.

PHP Code:

L 02/03/2024 20:39:50: -------- Mapchange to dod_avalanche --------
L 02/03/2024 20:39:50DNA.styx<90><[U:1:40203]><><88.198.27.9connected.
L 02/03/2024 20:41:40DNA.styx<90><[U:1:40203]><><88.198.27.9disconnected.
L 02/03/2024 20:49:22DNA.styx<123><[U:1:40203]><><88.198.27.9connected.
L 02/03/2024 21:01:33DNA.styx<123><[U:1:40203]><><88.198.27.9disconnected.
L 02/03/2024 21:03:25adrian shephard<137><[U:1:1516896097]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:03:42adrian shephard<137><[U:1:1516896097]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:03:43DNA.styx<139><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:09:24DNA.styx<139><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:10:51DNA.styx<160><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:12:44DNA.styx<160><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:12:48DNA.styx<163><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:13:46DNA.styx<163><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:14:21DNA.styx<181><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:18:0624007kb/s<183><[U:1:37019763]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:18:0624007kb/s<183><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0724007kb/s<184><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0824007kb/s<185><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0824007kb/s<186><STEAM_ID_PENDING><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0924007kb/s<187><STEAM_ID_PENDING><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0924007kb/s<188><[U:1:37019763]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:26:1224007kb/s<188><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:33:50lchristopherl<193><[U:1:175137150]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:47:21lchristopherl<193><[U:1:175137150]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:52:13seano<201><[U:1:1036576658]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:52:31seano<201><[U:1:1036576658]><><82.69.xxx.xxxdisconnected

I'm using this plugin to generate the above log.

Bacardi 02-03-2024 21:53

Re: (not a Sourcebans issue) All players reported as having the same IP address
 
...interested.
I'm wondering does this happen only SourceMod GetClientIP.

You could look status command more often, do players have same IP.

One thing what could cause this is, plugin is trying to get client IP too soon when connecting to server.
It maybe fail to get IP, there is no check for that.

...I could write different plugin, when I have time.

DNA.styx 02-04-2024 15:33

Re: (not a Sourcebans issue) All players reported as having the same IP address
 
Yes, very strange one. Thanks for checking.

Here's some console logs. There is a point were they all switch from returning their real IP address to one of the others (my IP or GameME).

Will grab some status command outputs as well.

Spoiler


Spoiler


Spoiler


Spoiler


Edit: When I disable gameme's logaddress_add from the server autoexec.cfg all players IP addresses are reported correctly. Seems that what ever I set logaddress_add to gets returns as the players GetClientIP (example below where I set logaddress_add to 8.8.8.8. :)
Spoiler


All times are GMT -4. The time now is 00:37.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.