Raised This Month: $51 Target: $400
 12% 

Admins figuring out my RCON password


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
404UserNotFound
BANNED
Join Date: Dec 2011
Old 10-29-2013 , 22:50   Admins figuring out my RCON password
Reply With Quote #1

Had this problem for a while until I put my RCON password into the command line (in my "start.sh" file).

Just wondering if anyone knows how admins are able to find out the RCON password? Is it from using the "Exec cfg" option in the admin menu to execute the "server.cfg" file?
404UserNotFound is offline
Dravu
Senior Member
Join Date: May 2010
Old 10-29-2013 , 23:03   Re: Admins figuring out my RCON password
Reply With Quote #2

What powers are you giving them?

sm_cvar rcon_password
Dravu is offline
friagram
Veteran Member
Join Date: Sep 2012
Location: Silicon Valley
Old 10-30-2013 , 02:29   Re: Admins figuring out my RCON password
Reply With Quote #3

If you have it in your command line, you can view the process list and see the password, since you can see the command lines...

so if it's a shared box, that isn't maintained only by you, it's likely that someone that isn't an idiot will find it out easily. There's also protection against giving admins the rcon password, you're probably giving them too many flags.
__________________
Profile - Plugins
Add me on steam if you are seeking sp/map/model commissions.
friagram is offline
sdz
Senior Member
Join Date: Feb 2012
Old 10-31-2013 , 16:44   Re: Admins figuring out my RCON password
Reply With Quote #4

Just comment out the "rcon_password" option in server.cfg.
sdz is offline
404UserNotFound
BANNED
Join Date: Dec 2011
Old 11-02-2013 , 17:13   Re: Admins figuring out my RCON password
Reply With Quote #5

The way I think my admins were finding it was through some method of the aforementioned "Exec cfg" option, but using it in command form to execute "server.cfg"

Since moving the password to the command line and removing it from server.cfg, I've not had any issues of rogue admins fucking with my server.
404UserNotFound is offline
TnTSCS
AlliedModders Donor
Join Date: Oct 2010
Location: Undisclosed...
Old 11-02-2013 , 17:39   Re: Admins figuring out my RCON password
Reply With Quote #6

Is there any real benefit to having rcon password if you have sourcemod installed?
__________________
View my Plugins | Donate
TnTSCS is offline
pcmaster
AlliedModders Donor
Join Date: Sep 2009
Old 11-02-2013 , 18:24   Re: Admins figuring out my RCON password
Reply With Quote #7

Why don't you simply remove the Admins messing with your RCon?
__________________
Stopped hosting servers as of November 2018, no longer active around here.
pcmaster is offline
hamilton5
Veteran Member
Join Date: Oct 2012
Location: USA
Old 11-02-2013 , 19:49   Re: Admins figuring out my RCON password
Reply With Quote #8

Quote:
real benefit to having rcon password if you have sourcemod installed?
yeah, I doubt it... I cant believe the guy is worried about his precious rcon pass and blindly handing out rcon and cvar access to his admins..
hamilton5 is offline
Visual77
Veteran Member
Join Date: Jan 2009
Old 11-03-2013 , 03:35   Re: Admins figuring out my RCON password
Reply With Quote #9

Quote:
Originally Posted by hamilton5 View Post
yeah, I doubt it... I cant believe the guy is worried about his precious rcon pass and blindly handing out rcon and cvar access to his admins..
There's also this: https://forums.alliedmods.net/showthread.php?p=1414157 to block the output of sm_cvar rcon_password & sm_rcon rcon_password

But the basic rule is to never give your admins the h or the m admin-flag - then they shoudn't be able to find it unless you also gave them ftp

Last edited by Visual77; 11-03-2013 at 03:39.
Visual77 is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 11-03-2013 , 17:32   Re: Admins figuring out my RCON password
Reply With Quote #10

Just use SMAC's Rcon plugin along with the ext and whitelist only your home IP (or any IPs that need to use Rcon). That way even if they know what it is they can't use it.
__________________
Fearts is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 19:05.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode