AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   HL1 Servers (HLDS) (https://forums.alliedmods.net/forumdisplay.php?f=131)
-   -   Anti server hack methods[ simple ] that worked and tested! (https://forums.alliedmods.net/showthread.php?t=254652)

Ton Perneis 01-04-2015 09:40

Anti server hack methods[ simple ] that worked and tested!
 
I have a solution read below!

Hello my server just hacked by a programme named steam id changer or whatever its name is.
The hack must be new!

How that programme works?

The attacker uses a command in console that copies any steam id is inserted into users.ini,using that he has all the access flags that steam id has.

EXAMPLE: "STEAM_0:0:187827677" "abcdefghijklmnopqrstu" "a"
so the hacker having the copy of this steam id will have also its access flags.

How to prevent the server from attacker?
Just use access only with setinfo _pw in users.ini

Another hack!
Also there is enother one using setinfo _pw ""

How to prevent this?
Delete server.cfg
use only autoexec.cfg so the attacker cannot do any changes at map change because he needs to!

Tell me if this is helpfull im not professional at this stuff but all i did is just research and experimentation i dont want to be criticised because i help.

All i want is to share easy methods.

Kia 01-04-2015 09:43

Re: Anti server hack methods[ simple ] that worked and tested!
 
Quote:

Originally Posted by Ton Perneis (Post 2244624)
How to prevent the server from attacker?

Remove DProto. Best method available.

Fr33m@n 01-04-2015 09:44

Re: Anti server hack methods[ simple ] that worked and tested!
 
damm faster than me.

Yeah, dproto off is the better way. ;)

Freezo Begin 01-04-2015 09:47

Re: Anti server hack methods[ simple ] that worked and tested!
 
there is no hack of ' setinfo _pw ' its without '_' like rate ....
As kia said the best method is to remove dproto !

AmineKyo 01-04-2015 10:08

Re: Anti server hack methods[ simple ] that worked and tested!
 
Quote:

Originally Posted by Ton Perneis (Post 2244624)
How to prevent this?
Delete server.cfg
use only autoexec.cfg so the attacker cannot do any changes at map change because he needs to!

mapchangecfg server.cfg

Ton Perneis 01-04-2015 10:10

Re: Anti server hack methods[ simple ] that worked and tested!
 
So i need to update HLDS you mean?

Also i found that dproto allows non steamers to play on server, i understood that they can use it to find <<doors>> behind that addon and attack on server , i removed it.

But i cannot prevent ddos or other programme attacks i think.thats why that happens or im wrong?

So i must update also hlds but if i cannot better find another host right?
Because removing dproto itself does nothing on some kind of attacks.

YamiKaitou 01-04-2015 12:00

Re: Anti server hack methods[ simple ] that worked and tested!
 
What attacks are you saying still exist with your up-to-date and dproto free server?

Ton Perneis 01-04-2015 12:27

Re: Anti server hack methods[ simple ] that worked and tested!
 
No,I say that i cannot update the hlds to newer version because of my host company.So i mean that removing dproto itself without updating hlds does nothing to these attacks.

Never mind i will somehow convince them to update my hlds to newer version.
And i think that it will be ok.
Thanks for your info.
[Also iptables would help or no ]because all i have is ftp of server files and the server running on linux.
[Just asking if its not a big deal]
Just answer me with yes or no to this:[Also iptables would help or no ] i dont want you guys to write a big paragraph for me.:D

YamiKaitou 01-04-2015 14:02

Re: Anti server hack methods[ simple ] that worked and tested!
 
What version is your server? What kind of attacks are still occuring?

Ton Perneis 01-05-2015 09:21

Re: Anti server hack methods[ simple ] that worked and tested!
 
My problem solved thank you.


All times are GMT -4. The time now is 15:48.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.