Raised This Month: $ Target: $400
 0% 

Rcon locker / exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 07-03-2009 , 13:49   Re: Rcon locker / exploit fix
Reply With Quote #31

Update:
Cvar bounds are removed on sv_rcon_minfailures and sv_rcon_maxfailures. These are also set to 10,000 if they are not changed in your config file.

This will leave your server vulnerable to brute force attacks, though that's easily fixed.. just use a secure rcon password. This was necessary to prevent a server crash that happens when a user is banned.

To generate a secure rcon password go here. These passwords are randomly generated and change each time you refresh the page. If you use these, there are 62^24 possible passwords, so they won't be brute forced any time soon.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
rautamiekka
Veteran Member
Join Date: Jan 2009
Location: Finland
Old 07-03-2009 , 13:52   Re: Rcon locker / exploit fix
Reply With Quote #32

Quote:
Originally Posted by devicenull View Post
Update:
Cvar bounds are removed on sv_rcon_minfailures and sv_rcon_maxfailures. These are also set to 10,000 if they are not changed in your config file.

This will leave your server vulnerable to brute force attacks, though that's easily fixed.. just use a secure rcon password. This was necessary to prevent a server crash that happens when a user is banned.

To generate a secure rcon password go here. These passwords are randomly generated and change each time you refresh the page. If you use these, there are 62^24 possible passwords, so they won't be brute forced any time soon.
Okkey, will update and try that page. Tack

EDIT: Just remembered to that I had edited the Plugin to not enforce Mani stuff.
__________________
Links to posts I received Karma from:
Big thanks to all who gave Karma

Last edited by rautamiekka; 07-03-2009 at 13:57.
rautamiekka is offline
Send a message via ICQ to rautamiekka Send a message via AIM to rautamiekka Send a message via MSN to rautamiekka Send a message via Yahoo to rautamiekka Send a message via Skype™ to rautamiekka
Kenny Loggins
SourceMod Donor
Join Date: Jun 2008
Location: Rochester, MN
Old 07-07-2009 , 00:27   Re: Rcon locker / exploit fix
Reply With Quote #33

Forgive me if this is a stupid question but i'm at work now and can’t play with this plugin.

Does this stop the blocked commands from being executed client side? Do commands like “quit” and “restart” still work via the server console? Can sm_ commands still be executed from the clients machine if they have the correct rcon?

You still need to set the value on “sv_rcon_maxfailures” to the desiered number or does the plugin set the cvar when its loaded?
__________________

Server Admin / Leader
ClanAO.com
Kenny Loggins is offline
Jamster
Veteran Member
Join Date: Jun 2008
Old 07-07-2009 , 09:40   Re: Rcon locker / exploit fix
Reply With Quote #34

This plugin will basically block all illegitimate access to the commands. You yourself should notice no difference.
Jamster is offline
rautamiekka
Veteran Member
Join Date: Jan 2009
Location: Finland
Old 07-07-2009 , 09:56   Re: Rcon locker / exploit fix
Reply With Quote #35

Quote:
Originally Posted by Jamster View Post
This plugin will basically block all illegitimate access to the commands. You yourself should notice no difference.
Agree.
__________________
Links to posts I received Karma from:
Big thanks to all who gave Karma
rautamiekka is offline
Send a message via ICQ to rautamiekka Send a message via AIM to rautamiekka Send a message via MSN to rautamiekka Send a message via Yahoo to rautamiekka Send a message via Skype™ to rautamiekka
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 07-09-2009 , 00:30   Re: Rcon locker / exploit fix
Reply With Quote #36

Indeed, normal users should not notice any difference in the server. The commands blocked are not ones used under normal circumstances.

Also note, slight update. I added another blocked command, and added kicks if the player is using the "unnamed" exploit.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
retsam
Veteran Member
Join Date: Aug 2008
Location: so-cal
Old 07-09-2009 , 00:41   Re: Rcon locker / exploit fix
Reply With Quote #37

I dont know if its appropriate for this plugin, since there already is a plugin that handles this but... for an idea, you could put a simple block that kicks players doing the unassigned team exploit as well. That one actually will crash your server.

Like I said, there already is a solo plugin that does it with many options so, maybe its not necessary. Might be nice for an all-in-one solution plugin that covers all exploits though..
retsam is offline
clutchh
SourceMod Donor
Join Date: Feb 2008
Old 07-09-2009 , 19:26   Re: Rcon locker / exploit fix
Reply With Quote #38

Awesome work, thank you!

So this is more effective than the plugin hlstriker posted in bloking the exploit?
clutchh is offline
m4ster
Senior Member
Join Date: Mar 2007
Old 07-11-2009 , 20:14   Re: Rcon locker / exploit fix
Reply With Quote #39

unnamed exploit? You mean unconnected?
__________________
m4ster is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 07-12-2009 , 13:09   Re: Rcon locker / exploit fix
Reply With Quote #40

Indeed, it is the unconnected exploit. This was added at the request of someone, and there are many plugins that provide blocking of it.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 20:42.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode