Raised This Month: $120 Target: $400
 30% 

xBrute Attack


Post New Thread Reply   
 
Thread Tools Display Modes
.:cs.stambeto:.
Senior Member
Join Date: Feb 2010
Location: Bulgaria
Old 06-24-2013 , 14:20   Re: xBrute Attack
Reply With Quote #11

Can you tell me some solution of this new exploit because I can not see my console server from the flood.

Quote:
rcon 1430000571 "2446" echo XBrute by ZeaL
L 06/24/2013 - 20:18:44: Bad Rcon: "rcon 1430000571 "2446" echo XBrute by ZeaL"
from "194.44.115.184:27005"
Bad rcon_password.
No password set for this server.
Bad Rcon from 79.112.153.19:27006:
rcon 1868345902 "24452445" echo XBrute by ZeaL
L 06/24/2013 - 20:18:49: Bad Rcon: "rcon 1868345902 "24452445" echo XBrute by Ze
aL" from "79.112.153.19:27006"
Bad rcon_password.
No password set for this server.
Bad Rcon from 178.89.63.219:27007:
rcon 306058196 "24312431" echo XBrute by ZeaL
L 06/24/2013 - 20:18:55: Bad Rcon: "rcon 306058196 "24312431" echo XBrute by Zea
L" from "178.89.63.219:27007"
Bad rcon_password.
No password set for this server.
Bad Rcon from 178.172.242.26:27006:
rcon 660417837 "24462446" echo XBrute by ZeaL
L 06/24/2013 - 20:19:06: Bad Rcon: "rcon 660417837 "24462446" echo XBrute by Zea
L" from "178.172.242.26:27006"
Bad rcon_password.
No password set for this server.
Bad Rcon from 46.247.232.37:27010:
rcon 581538785 "24422442" echo XBrute by ZeaL
L 06/24/2013 - 20:19:14: Bad Rcon: "rcon 581538785 "24422442" echo XBrute by Zea
L" from "46.247.232.37:27010"
Bad rcon_password.
No password set for this server.
Bad Rcon from 80.80.193.121:27006:
rcon 429559347 "244244244" echo XBrute by ZeaL
L 06/24/2013 - 20:19:17: Bad Rcon: "rcon 429559347 "244244244" echo XBrute by Ze
aL" from "80.80.193.121:27006"
Bad rcon_password.
No password set for this server.
Bad Rcon from 86.122.39.35:27006:
rcon 1749029682 "2447" echo XBrute by ZeaL
L 06/24/2013 - 20:190: Bad Rcon: "rcon 1749029682 "2447" echo XBrute by ZeaL"
from "86.122.39.35:27006"
Bad rcon_password.
No password set for this server.
Bad Rcon from 94.242.23.26:27006:
rcon 1912807624 "2445" echo XBrute by ZeaL
L 06/24/2013 - 20:190: Bad Rcon: "rcon 1912807624 "2445" echo XBrute by ZeaL"
from "94.242.23.26:27006"
Bad rcon_password.
No password set for this server.
.:cs.stambeto:. is offline
^SmileY
Veteran Member
Join Date: Jan 2010
Location: Brazil [<o>]
Old 06-24-2013 , 17:37   Re: xBrute Attack
Reply With Quote #12

It is curious about same exploit for various servers and different IPS for each test of rcon??
The rcon is not a problem, but the exploit..

And it detecting various ips ports?
__________________
Projects:

- See my Git Hub: https://github.com/SmileYzn
PHP Code:
set_pcvar_num(pCvar,get_pcvar_num(pCvar) ? 1); 
^SmileY is offline
Send a message via MSN to ^SmileY Send a message via Skype™ to ^SmileY
yokomo
Surprise Ascot!
Join Date: May 2010
Old 06-25-2013 , 02:05   Re: xBrute Attack
Reply With Quote #13

Quote:
Last HLDS update have an exploit :S, with 1 command you can crash the server ( only using last HLDS update )
Any proof of what are you saying above? with 1 command, that is cool. "rcon quit".

Ya same to me, it's hard to ban this exploit since it comes with many ips, how the hell it can change ip so fast. It's true not worry about this since the random password is stupid, but i hate the spams in server console.. Valve need to block this shit.

Last edited by yokomo; 06-25-2013 at 02:09.
yokomo is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 06-25-2013 , 02:12   Re: xBrute Attack
Reply With Quote #14

Quote:
Originally Posted by yokomo View Post
how the hell it can change ip so fast
Probably all spoofed IPs
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (intervening in a thread, asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
Kia
AlliedModders Donor
Join Date: Apr 2010
Location: In a world of madness
Old 06-25-2013 , 05:51   Re: xBrute Attack
Reply With Quote #15

I remember a plugin which prevents that flooding, but I don't remember it's name.
Disabling the rcon won't help as you will get this messages anyway.
__________________
Kia is offline
XpoHuk
Junior Member
Join Date: Apr 2013
Old 06-25-2013 , 09:58   Re: xBrute Attack
Reply With Quote #16

Quote:
Originally Posted by Kia View Post
I remember a plugin which prevents that flooding, but I don't remember it's name.
Disabling the rcon won't help as you will get this messages anyway.
anti_hlbrute_v1.1
XpoHuk is offline
DC32
Member
Join Date: Jun 2010
Old 06-25-2013 , 10:46   Re: xBrute Attack
Reply With Quote #17

Alright, thanks guys

btw, a little off-topic thing, where can i learn AMXX coding?
DC32 is offline
Kia
AlliedModders Donor
Join Date: Apr 2010
Location: In a world of madness
Old 06-25-2013 , 12:57   Re: xBrute Attack
Reply With Quote #18

AlliedMods
__________________
Kia is offline
seriousspot
BANNED
Join Date: Mar 2013
Location: Lithuania / Norway
Old 06-25-2013 , 13:12   Re: xBrute Attack
Reply With Quote #19

again new info about exploit, the infected .exe infects users - infected users controlled by zeal(center) they attacking random servers that listed on various masterlists, i guess this is what i call botnet, tested myself on vmware
seriousspot is offline
Kia
AlliedModders Donor
Join Date: Apr 2010
Location: In a world of madness
Old 06-25-2013 , 15:12   Re: xBrute Attack
Reply With Quote #20

Quote:
i guess this is what i call botnet
Correct. The other people (called slaves) have a RAT (Remote Administration Tool) installed which is controlled by one person.
__________________
Kia is offline
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 00:42.


Powered by vBulletin®
Copyright ©2000 - 2018, vBulletin Solutions, Inc.
Theme made by Freecode