Raised This Month: $ Target: $400
 0% 

Small "Hack my server" Competition!


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
binderjeep
Member
Join Date: Jan 2015
Old 01-21-2016 , 22:15   Small "Hack my server" Competition!
Reply With Quote #1

Hey everyone, i want to thank the community for all the great suggestions and resolutions you have provided to my scripting problems over the last year. I have a couple of CSGO servers now that i am looking to take public shortly and I want to test the integrity of the game server (CSGO) and the underlying system (linux) based in general.

With that in mind i thought the best way to find out if people are able to deploy hacks within my CSGO game, or break into my server is to provide an incentive. I want to host a small hacking competition so that you can try to hack, break, disrupt my server (other than DDOS) so that i can ultimately make things more secure. I am happy to offer a $20 reward for anyone that discovers a useful exploit.

Can i have anyone that is interested post below of PM me and we can setup a time period for this to go down?

Thanks.
binderjeep is offline
Potato Uno
Veteran Member
Join Date: Jan 2014
Location: Atlanta, Georgia
Old 01-21-2016 , 22:54   Re: Small "Hack my server" Competition!
Reply With Quote #2

If you didn't firewall rcon off, or even disable rcon entirely, then I win (jk).

But really, firewall rcon or disable it entirely and use the superior alternative sm_rcon.

Also ensure you set on your operating system permissions system that srcds has only read & write privileges to only the gamedir folder, and execute privileges elsewhere (i.e. no reading or writing OUTSIDE of that directory).

Last edited by Potato Uno; 01-21-2016 at 22:58.
Potato Uno is offline
binderjeep
Member
Join Date: Jan 2015
Old 01-22-2016 , 07:19   Re: Small "Hack my server" Competition!
Reply With Quote #3

Quote:
Originally Posted by Potato Uno View Post
If you didn't firewall rcon off, or even disable rcon entirely, then I win (jk).

But really, firewall rcon or disable it entirely and use the superior alternative sm_rcon.

Also ensure you set on your operating system permissions system that srcds has only read & write privileges to only the gamedir folder, and execute privileges elsewhere (i.e. no reading or writing OUTSIDE of that directory).

How does one, "firewall rcon" or disable it entirely? Do you mean in the server.cfg, set "alias rcon_password "Echo Blocked command!"

I believe this does not people to change the password from within the console, even if they are able to obtain it. are you referrring to something else?
binderjeep is offline
Powerlord
AlliedModders Donor
Join Date: Jun 2008
Location: Seduce Me!
Old 01-22-2016 , 11:35   Re: Small "Hack my server" Competition!
Reply With Quote #4

Quote:
Originally Posted by binderjeep View Post
How does one, "firewall rcon" or disable it entirely? Do you mean in the server.cfg, set "alias rcon_password "Echo Blocked command!"

I believe this does not people to change the password from within the console, even if they are able to obtain it. are you referrring to something else?
By default, RCON works on TCP port 27015 (or whatever -port your server uses). The actual server uses UDP only for connections.

Sooo... you can firewall off TCP 27015 and thus rcon isn't useable.

As for disabling rcon, just don't set an rcon_password.
__________________
Not currently working on SourceMod plugin development.

Last edited by Powerlord; 01-22-2016 at 11:37.
Powerlord is offline
MaloModo
Veteran Member
Join Date: Aug 2008
Old 01-25-2016 , 01:11   Re: Small "Hack my server" Competition!
Reply With Quote #5

Is it really that easy to "hack" rcon? Would the effort really be worth the reward?
MaloModo is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 23:09.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode