Raised This Month: $ Target: $400
 0% 

Hmm, any loopholes? Got hacked. Help :)


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Jouho
Junior Member
Join Date: Nov 2008
Old 01-30-2010 , 21:16   Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #1

Hi guys. My server just got hacked again, it was a while since it last happened, and that one previously was maybe from the es_tools loophole, which I removed.

However, I just got hacked again, but mani only (seems to be the popular one).

Via sm plugins in console outputs:

"Basic Comm Control" (1.2.1) by AlliedModders LLC
"Sound Commands" (1.2.1) by AlliedModders LLC
"Client Preferences" (1.2.1) by AlliedModders LLC
"Model Fun" (0.5) by Arg!
"Get TickRate" (1.0) by Liam
"Basic Info Triggers" (1.2.1) by AlliedModders LLC
"Anti-Flood" (1.2.1) by AlliedModders LLC
"Knife Fight" (1.3.7) by XARiUS, Otstrel.Ru Team
"Basic Ban Commands" (1.2.1) by AlliedModders LLC
"Surf Tools" (1.6) by Fredd

Are any of these known to have loopholes?
Also, what are some protection mod/addon(s) that I could use to prevent this crap from happening again. It's a hassle readding people to mani. X_x.

Thank you
Jouho is offline
Kigen
BANNED
Join Date: Feb 2008
Old 01-30-2010 , 21:54   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #2

D-FENS
http://forums.alliedmods.net/showthread.php?t=109453

And I don't know about Mani. Anyhow, there is a major issue at the moment with exploits within the engine itself that are beyond the abilities of KAC to patch at this point. Your best bet is to use D-FENS and a little permission editing.
Kigen is offline
Jouho
Junior Member
Join Date: Nov 2008
Old 01-30-2010 , 22:00   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #3

Thank you, but the server is linux based, :/. Not quite sure what to do to get it to work with Linux, if it's possible.

Last edited by Jouho; 01-30-2010 at 22:02.
Jouho is offline
anonpiss
Senior Member
Join Date: Jan 2010
Old 01-31-2010 , 00:17   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #4

Get the linux binaries of D-FENS.
Most likely the hacker downloaded your server.cfg and of course got your rcon password.
anonpiss is offline
KyleS
SourceMod Plugin Approver
Join Date: Jul 2009
Location: Segmentation Fault.
Old 01-31-2010 , 22:59   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #5

D-Fens isn't that good, I was still attacked with it enabled

The best thing you can do is make every single directory read only except for your local DBs, Logs, and your downloads directory for sprays. That way, the worst they can do is just clear your databases which you can backup daily.
KyleS is offline
NoS
Senior Member
Join Date: Nov 2006
Old 02-01-2010 , 05:48   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #6

Correct me if I am wrong, but KAC is not on that list. Unless you provided every other plugin other than KAC.
NoS is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 02-01-2010 , 11:54   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #7

Your problem is most likely because you are using Mani as well. Both Mani and ES have holes that their devs refuse to acknowledge. If you can help it, remove Mani and install D-FENS and "rcon locker" by devicenull.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
propaganda
Member
Join Date: Oct 2006
Old 02-02-2010 , 12:41   Re: Hmm, any loopholes? Got hacked. Help :)
Reply With Quote #8

Yeah stay clear of mani entirely if you can. We had nothing but problems and since we went to sourcemod it cleared up 99% of them.
propaganda is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:18.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode