Raised This Month: $51 Target: $400
 12% 

HACKER SourceMod 1.4.0 Injector : By Rod286 !


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
SilentBr
Veteran Member
Join Date: Jan 2009
Old 01-05-2012 , 21:46   HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #1

Mates, my server was hacked and I need help as soon as possible.

It's 00: 30 AM here, my ZR server was full 42/42 and suddenly the map changed to de_dust2. Immediately I knew it was hacker because was server was hacking every day by Mani Admin plugin, I disabled it to try avoid this, but I was wrong. The hacker could get my server by sourcemod.

Immediatelly I got Log from HLSW Look:
PHP Code:
00:06:57 L 01/05/2012 23:50:25rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:25rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:25rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:25rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:26rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:26rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:26rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:26rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:27rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:27rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:27rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:06:57 L 01/05/2012 23:50:27rcon from "201.41.88.145:64439"command "say SourceMod 1.4.0 Injector : By Rod286 !"
00:07:07 L 01/05/2012 23:50:35rcon from "201.41.88.145:64439"command "say Own3D!"
00:07:24 L 01/05/2012 23:50:52rcon from "201.41.88.145:64439"command "sv_cheats 1"
00:07:30 L 01/05/2012 23:50:57rcon from "201.41.88.145:64439"command "sm_noclip @all"
00:07:44 L 01/05/2012 23:51:12rcon from "201.41.88.145:64439"command "sm_map zm_base_day_Se" 
After this, he started kick everyone.

In the folder "logs" by css I just found this
PHP Code:
L 01/05/2012 23:54:41rcon from "201.41.88.145:64450"Bad Password 
I use as protection:
SMAC
Rcon Exploit
ServerSecure
DAF
And a difficult rcon_password with "a A $ ! *&% 1"

Please someone help me. How do I protect my server?
Is there any .cfg file that he could change (maybe to put him admin access)?

I banned his IP so he'll think the server is offline. But not sure how many time my server will be safe.

PS: I use sourcebans.

Please help me
SilentBr is offline
Afronanny
Veteran Member
Join Date: Aug 2009
Old 01-05-2012 , 22:02   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #2

Do you have your rcon password set in server.cfg? If so, moving it to the command line would be beneficial to security. Locking down rcon with iptables so that only a select few IP addresses will also help.

Although, ever since sm_rcon started putting the log spew into the client console, the need for rcon has been virtually eliminated, save for a select few external applications such as HLSW and SourceBans.
ducks

Last edited by Afronanny; 01-05-2012 at 22:36. Reason: fixed derp sentence
Afronanny is offline
SilentBr
Veteran Member
Join Date: Jan 2009
Old 01-05-2012 , 22:16   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #3

Quote:
Originally Posted by Afronanny View Post
Do you have your rcon password set in server.cfg? If so, moving it to the command line would be beneficial to security. Locking down rcon with iptables so that only a select few IP addresses may even attempt rcon.
Yes, my rcon_password is in server.cfg. I'll ask to the company move to command line.
What about if the company BLOCK rcon connections for everyone, what do you think? I don't care if I don't have acces

Now is 01: 14 AM the company only opens at 03: 00 PM. I need a way to protect my server while this.

What is Sourcemod Injector? How is possible this hacker doing this?

I installed right now this plugin in my server [ANY] Rcon Password Protect http://forums.alliedmods.net/showthread.php?p=1414157

Thank you.
SilentBr is offline
Afronanny
Veteran Member
Join Date: Aug 2009
Old 01-05-2012 , 22:38   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #4

I have not heard of this particular exploit tool, but it's quite likely that it is the old Upload/Download exploit that valve does not want to fix. If you can remove the rcon password from server.cfg, he won't be able to download it.
ducks
Afronanny is offline
Nolongerinthegame
AlliedModders Donor
Join Date: Sep 2005
Old 01-06-2012 , 05:20   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #5

Quote:
Originally Posted by Afronanny View Post
I have not heard of this particular exploit tool, but it's quite likely that it is the old Upload/Download exploit that valve does not want to fix. If you can remove the rcon password from server.cfg, he won't be able to download it.
ducks
I thought server secure was supposed to fix the upload/download exploit
Nolongerinthegame is offline
SilentBr
Veteran Member
Join Date: Jan 2009
Old 01-06-2012 , 12:00   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #6

Quote:
Originally Posted by nelioneil View Post
I thought server secure was supposed to fix the upload/download exploit
I thought the same, but I guess ServerSecure need some fixes. It's loaded ok but didn't stop that hacker

PHP Code:
[03Server Secure Files Only (1.0.0): The finest defence 

Last edited by SilentBr; 01-06-2012 at 12:01.
SilentBr is offline
Larsen
Senior Member
Join Date: Oct 2011
Old 01-08-2012 , 19:59   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #7

Quote:
Originally Posted by Afronanny View Post
Do you have your rcon password set in server.cfg? If so, moving it to the command line would be beneficial to security. Locking down rcon with iptables so that only a select few IP addresses will also help.

ducks
How would one do this? Just append this to the existing one? -rcon password?
__________________

Larsen is offline
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 01-08-2012 , 20:05  
Reply With Quote #8

ServerSecure can't be bypassed to download a config file, it's considerably more likely you're running an outdated version of SourceBans which has known, public vulnerabilities and the attacker just pulled your rcon password from SourceBans.
__________________

Last edited by asherkin; 01-08-2012 at 20:06.
asherkin is offline
Despirator
Senior Member
Join Date: Jun 2011
Location: Kazakhstan ->Shymkent
Old 01-09-2012 , 12:13   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #9

or maybe you are running infected plugin
Despirator is offline
MindeLT
Senior Member
Join Date: Dec 2010
Location: Lithuania
Old 01-09-2012 , 14:14   Re: HACKER SourceMod 1.4.0 Injector : By Rod286 !
Reply With Quote #10

use zblock, and forget about problems.
__________________

Last edited by MindeLT; 01-09-2012 at 14:14.
MindeLT is offline
Send a message via Skype™ to MindeLT
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 21:07.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode