Raised This Month: $51 Target: $400
 12% 

Hackers running around on my servers?


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
JohnXina55
Junior Member
Join Date: Jun 2012
Old 04-04-2013 , 02:19   Hackers running around on my servers?
Reply With Quote #1

My server has VAC enabled and is a dedicated server, I have run it for a year or so about now and have had no issues, but lately with a few cross players that were banned, i've had an incident where the chat was spammed.

It said things like:

Console:WWWWWWWWWWWWW

This was in the regular text box at the bottom.

How would they have done this? Is there a security issue? Or was it just simple hacks?
I'm quite disturbed it said Console:

From inspection of the logs the only command I saw used was sm_chat and I only saw this used once and saw no other traces.
JohnXina55 is offline
Sreaper
髪を用心
Join Date: Nov 2009
Old 04-04-2013 , 02:29   Re: Hackers running around on my servers?
Reply With Quote #2

You should change your rcon_password asap as someone is remotely calling commands.
It's also possible that the map you are playing on is causing those messages to appear.

I suggest installing SMAC.

Last edited by Sreaper; 04-04-2013 at 02:30.
Sreaper is offline
JohnXina55
Junior Member
Join Date: Jun 2012
Old 04-04-2013 , 02:34   Re: Hackers running around on my servers?
Reply With Quote #3

Ah I complete forgot about the rcon password, will do.

Any idea how they could have figured out what it was? Really bothers me.

Last edited by JohnXina55; 04-04-2013 at 02:39.
JohnXina55 is offline
VJScope
Senior Member
Join Date: Jul 2012
Location: Finland
Old 04-04-2013 , 07:41   Re: Hackers running around on my servers?
Reply With Quote #4

Can't figure out any other ways to get your rcon password but just hack it... You could get HLSW so you might see IP of the person who wrote those things via console (you can see these things in your logs but HLSW sees them immediately). Then just IP-ban him. Not sure if ip-ban blocks those console-messages but give it a try.

Tips:

Your rcon password shouldn't be any real word (nothing like cucumber245) and it should include numbers and capital letters like sdfDE93OIu87Pswrd. Don't know if you can use other marks like @¤# or something like that.

Then go to launch options and write +rcon_address xx.xx.xxx.xxxxxxx +rcon_password xxxxxxxxxxx (that IP-address is your servers address) so you don't have to remember your password everytime you connect to server.
__________________
Strange women lying in ponds distributing swords is no basis for a system of government. Supreme executive power derives from a mandate from the masses, not from some farcical aquatic ceremony.

Last edited by VJScope; 04-04-2013 at 07:45.
VJScope is offline
minimoney1
SourceMod Donor
Join Date: Dec 2010
Old 04-04-2013 , 10:20   Re: Hackers running around on my servers?
Reply With Quote #5

This may be because of a hacked rcon but this also may not be rcon at all. Ive seen players try to trick others by using a bind that says something like this in the chat:
"hi




Console: WWWWWW"
__________________
Need help? PM me or add me on Steam.
My Steam




Quote:
Originally Posted by Rp.KryptoNite View Post
For some reason his Plugin never worked for me ,
@credits were added
im not stealing any plugins dude its my THING
minimoney1 is offline
MasterOfTheXP
Veteran Member
Join Date: Aug 2011
Location: Cloudbank
Old 04-04-2013 , 10:37   Re: Hackers running around on my servers?
Reply With Quote #6

Ah yea, good point; are you using Chat Fixer? IIRC, one of the things it fixes is being able to make lots of newlines in the chat. If the name Console was in a standard text colour, they might have been using that exploit. Keep an eye on RCON though, too. Have your rcon_password set on the server's command line, not stored in any config.
__________________
Plugins / My Steam / TF2 Sandbox (plugin beta testing!)

Last edited by MasterOfTheXP; 04-04-2013 at 10:39.
MasterOfTheXP is offline
Dr_Knuckles
AlliedModders Donor
Join Date: Mar 2005
Location: SW Florida
Old 04-04-2013 , 14:26   Re: Hackers running around on my servers?
Reply With Quote #7

If you're renting the server someone from there might have done it on accident as well.
__________________
Dr_Knuckles is offline
JohnXina55
Junior Member
Join Date: Jun 2012
Old 04-04-2013 , 22:49   Re: Hackers running around on my servers?
Reply With Quote #8

Naw, i'm sure it was rogue users, as my Admins and Moderators reported it as, it was a rogue group.
JohnXina55 is offline
Ade
I love purple
Join Date: May 2010
Old 04-05-2013 , 03:43   Re: Hackers running around on my servers?
Reply With Quote #9

Quote:
Originally Posted by minimoney1 View Post
This may be because of a hacked rcon but this also may not be rcon at all. Ive seen players try to trick others by using a bind that says something like this in the chat:
"hi




Console: WWWWWW"
this lol

or what if they were named Console
__________________
Ade is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:11.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode