Raised This Month: $ Target: $400
 0% 

Files Somehow Getting Deleted


Post New Thread Reply   
 
Thread Tools Display Modes
Powerlord
AlliedModders Donor
Join Date: Jun 2008
Location: Seduce Me!
Old 07-21-2012 , 09:52   Re: Files Somehow Getting Deleted
Reply With Quote #11

Quote:
Originally Posted by culexor View Post
Here's a list of plugins running on the server
Code:
admin_logging.smx
admin-flatfile.smx
adminhelp.smx
AdminList.smx
adminmenu.smx
antiflood.smx
basechat.smx
basecomm.smx
basecommands.smx
basetriggers.smx
basevotes.smx
clientprefs.smx
disabled
extendedcomm.smx
firewallradio_v1.02.smx
forlix_floodcheck.smx
funcommands.smx
funvotes.smx
glow.smx
hlstatsx.smx
infinite_aux_power.smx
kigen-ac-pub.smx
list.txt
mapchooser.smx
nextmap.smx
nominations.smx
playercommands.smx
playersvotes.smx
randomcycle.smx
rcon_lock.smx
reloadmaponserverstart.smx
reservedslots.smx
rockthevote.smx
serverhop.smx
sm_downloader.smx
sm_skinchooser_hl2dm.smx
smac.smx
sounds.smx
sourcebans.smx
spraytrace.smx
st_gamedesc_override.smx
superlogs-hl2mp.smx
votemute_p.smx
webshortcuts.smx
It would help immensely if you gave us the output of plugin_print, meta list, sm exts list, and sm plugins list rather than the output of ls -1 on your plugins directory.
__________________
Not currently working on SourceMod plugin development.

Last edited by Powerlord; 07-21-2012 at 09:53.
Powerlord is offline
culexor
Junior Member
Join Date: Nov 2011
Old 07-21-2012 , 20:04   Re: Files Somehow Getting Deleted
Reply With Quote #12

I managed to find out which server was deleting all of the files. So it's a safe assumption that there is a buggy/rogue plugin installed on that server. After some digging, I checked the source of a few of the files, but didn't come up with anything. I then decompiled those same plugins and one of them revealed something interesting.

One of the roleplay plugins I was running was from an older RP mod that I must have forgotten to delete (I switched to a new mod). It's a prop saving plugin, so people can add furniture to their houses, etc. Anyway, after decompiling the plugin using lysis, I found that it contained a couple hundred more lines than the source file.

Here's a pastebin of the source file (.sp): http://pastebin.com/XJcLshgn

And a pastebin of the lysis output (decompilation): http://pastebin.com/BB9meNpm

I'm not all that familiar with sourcepawn/c++ but some things still stuck out to me. Specifically, the last 200 lines or so (which were not in the .sp file), starting at line 674 (of the decompiled version, not the source).

Again, I'm not all that familiar with this stuff, so I could very well be mistaken. But it would be greatly appreciated if someone who did know this stuff well could just have a look and let me know what they think.
culexor is offline
Nolongerinthegame
AlliedModders Donor
Join Date: Sep 2005
Old 07-21-2012 , 20:21   Re: Files Somehow Getting Deleted
Reply With Quote #13

Yep looks like its been edited by a dodgy person from a dodgy website. But you said you had the mod for a while so why had it just started to delete the files recently

Last edited by Nolongerinthegame; 07-21-2012 at 20:21.
Nolongerinthegame is offline
culexor
Junior Member
Join Date: Nov 2011
Old 07-21-2012 , 20:52   Re: Files Somehow Getting Deleted
Reply With Quote #14

Quote:
Originally Posted by nelioneil View Post
Yep looks like its been edited by a dodgy person from a dodgy website. But you said you had the mod for a while so why had it just started to delete the files recently
It happened once a few months back as well.
culexor is offline
TheAvengers2
BANNED
Join Date: Jul 2011
Old 07-21-2012 , 21:24   Re: Files Somehow Getting Deleted
Reply With Quote #15

Quote:
Originally Posted by nelioneil View Post
you said you had the mod for a while so why had it just started to delete the files recently
I think it's some kind of backdoor. The guy who made it probably visited recently.

RegConsoleCmd("sm_version", CommandHelp, "Roleplay Version", 0);

^ lmao

Last edited by TheAvengers2; 07-21-2012 at 21:29.
TheAvengers2 is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 07-21-2012 , 21:45   Re: Files Somehow Getting Deleted
Reply With Quote #16

It is a backdoor, and it is why your files are being deleted. It lets him issue ServerCommands as well as navigate/check/edit/delete files/directories. It's all in the code. But it's anyone that knows about it, it's not restricted to an IP or steam. So if they know !version and know the parameters, you're effed!
__________________

Last edited by thetwistedpanda; 07-21-2012 at 21:46.
thetwistedpanda is offline
culexor
Junior Member
Join Date: Nov 2011
Old 07-21-2012 , 22:43   Re: Files Somehow Getting Deleted
Reply With Quote #17

Well I had a chat with the author of the plugin and he admits to creating the backdoor but not executing it. I know there's nothing I can do now but I just want to warn anyone out there not to use this guy's plugins.

Here's a log of the chat:
http://pastebin.com/ua1yQ6KX
culexor is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 07-21-2012 , 23:15   Re: Files Somehow Getting Deleted
Reply With Quote #18

*sigh*, out of curiosity, where did you download the plugin from.
__________________
thetwistedpanda is offline
culexor
Junior Member
Join Date: Nov 2011
Old 07-21-2012 , 23:17   Re: Files Somehow Getting Deleted
Reply With Quote #19

Here: https://forums.alliedmods.net/showthread.php?p=1216685

He took the plugin down a while ago. I switched to a different plugin when that happened but forgot to take out the saveit.smx From what I remember, he only releases the plugin to people who rent servers from him now.
culexor is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 07-21-2012 , 23:57   Re: Files Somehow Getting Deleted
Reply With Quote #20

So he was uploading binaries that didn't match the source to distribute his backdoor >.<, I wonder how many other servers were subject to it. Safe to say his reputation is trashed now though. Amusing how the thread was edited today and is asking for removal. Bleh.
__________________

Last edited by thetwistedpanda; 07-22-2012 at 00:07.
thetwistedpanda is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 05:11.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode