Raised This Month: $51 Target: $400
 12% 

[SOLVED] Hlds Redirecting Hack or Exploit


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
real sap
Member
Join Date: Aug 2015
Location: India
Old 09-04-2016 , 09:10   [SOLVED] Hlds Redirecting Hack or Exploit
Reply With Quote #1

Hi my server was running fine and good but one day i see my server Host name changed to "We_have_moved_to" .
And there is no error in hlds console but i see ERROR in client console

BUILD 6153 SERVER (0 CRC)
Server # 1
Server tried to send invalid command: echo;wait;clear
Server tried to send invalid command: motdfile default.cfg;motd_write Connect ip xyz
Server tried to send invalid command: wait;wait;wait;wait;wait;motdfile default.cfg;motd_write Connect ip xyz
Server tried to send invalid command: echo;wait;clear
Server tried to send invalid command: motdfile autoexec.cfg;motd_write Connect ip xyz
Server tried to send invalid command: wait;wait;wait;wait;wait;motdfile autoexec.cfg;motd_write Connect ip xyz
Server tried to send invalid command: echo;wait;clear
Server tried to send invalid command: motdfile autoexec.cfg;motd_write Connect ip xyz
Server tried to send invalid command: wait;wait;wait;wait;wait;motdfile autoexec.cfg;motd_write Connect ip xyz
Server tried to send invalid command: echo;wait;clear
Connecting to IP xyz
Trying p48/auth3/revEmu...
Connection accepted by ip xyz


I found some Legistic Solution Here's Sma + Other requirements

It requires Orphenu Module and Amx mod-X Above 1.8.1

Authors: DJ_WEST
Version: 1.2



This plugin allows you to protect your server RCON password from various kinds of exploits and backdoors (in plug-ins without the source code). The essence of the plugin is that you do not need to register anywhere rcon_password "your_password". Therefore, it is not visible either in config or in the server startup line, as well as the password can not be obtained through a variety of functions that are called from other AMXX plugins. RCON is indicated in the source code plug-in (in encrypted form), it follows that the password will be stored in skompilennom plugin. With this plug-in will run the management server via RCON, as usual via the game client, HLSW or other applications.

With version 1.2 adds the ability to restrict access to the RCON IP address.

First of all, pay attention to the fact that putting on your server. This includes plug-ins without a source, when you are not sure about their safety. RCON Defencer help protect your server from them, as well as other various exploits that allow you to view server.cfg file or get the value from rcon_password server.


Used modules:
Orpheu



Settings:

Be sure to list the rcon_password "" in the server startup line or in the file server.cfg
File SV_Rcon_Validate SV_Rcon and should be in the directory .. \ addons \ amxmodx \ the configs \ Orpheu \ functions The .
File rcon_defencer.ini must be in the directory .. \ addons \ amxmodx \ the configs (create it manually if it does not exist).

Prescribe your RCON password in the source plug-in (in the MD5 format):
#define RCON_PASSWORD "vash_rkon_parol"


To encrypt your password in MD5 format, you can use the service www.md5.cz

For example the word rconpassword in MD5 format will be as follows:


b34e8ca138a94e443644a665d4eb2be1
The password must be no more than 32 characters!

Then compile it and put rcon_defencer.amxx directory of the plugins .



In order to restrict access to the RCON over IP should be in the file .. /amxmodx/configs/rcon_defencer.ini register IP addresses (each address must begin on a new line).
rcon_defencer_type 0 - indicates that the file rcon_defencer.ini not in use and access to the RCON opened from any IP address, if the user knows the password.
rcon_defencer_type 1 - used rcon_defencer.ini as white list, namely only the specified file IP addresses have access to the RCON.
rcon_defencer_type 2 - used rcon_defencer.ini as a black list (banned), that is, except those that are registered in the file access RCON have all IP addresses.

ALL FILES are in ANti recon.zip
Attached Files
File Type: zip ANti recon.zip (466.7 KB, 169 views)

Last edited by real sap; 09-04-2016 at 13:02. Reason: found soltion
real sap is offline
Send a message via Skype™ to real sap
wickedd
Veteran Member
Join Date: Nov 2009
Old 09-04-2016 , 10:21   Re: Hlds Redirecting Hack
Reply With Quote #2

Did you add any plugins right before this started happening?
__________________
Just buy the fucking game!!!!
I hate No-Steamers and lazy ass people.
wickedd is offline
real sap
Member
Join Date: Aug 2015
Location: India
Old 09-04-2016 , 10:38   Re: Hlds Redirecting Hack
Reply With Quote #3

Quote:
Originally Posted by wickedd View Post
Did you add any plugins right before this started happening?
yes i add some but i checked their .sma its fine
real sap is offline
Send a message via Skype™ to real sap
wickedd
Veteran Member
Join Date: Nov 2009
Old 09-04-2016 , 10:48   Re: Hlds Redirecting Hack
Reply With Quote #4

Are you sure? Also, does anyone else besides you have access to the server files?
__________________
Just buy the fucking game!!!!
I hate No-Steamers and lazy ass people.
wickedd is offline
real sap
Member
Join Date: Aug 2015
Location: India
Old 09-04-2016 , 10:57   Re: Hlds Redirecting Hack
Reply With Quote #5

Quote:
Originally Posted by wickedd View Post
Are you sure? Also, does anyone else besides you have access to the server files?
You mean H or A flags of Admin ?
Else i have only access to my host
real sap is offline
Send a message via Skype™ to real sap
wickedd
Veteran Member
Join Date: Nov 2009
Old 09-04-2016 , 11:08   Re: Hlds Redirecting Hack
Reply With Quote #6

To save time just do a full reinstall.
__________________
Just buy the fucking game!!!!
I hate No-Steamers and lazy ass people.
wickedd is offline
real sap
Member
Join Date: Aug 2015
Location: India
Old 09-04-2016 , 11:13   Re: Hlds Redirecting Hack
Reply With Quote #7

Do you mean i just reinstal HLDS . And then copy paste Folders Addons maps , sounds , spirtes and models ?
real sap is offline
Send a message via Skype™ to real sap
HamletEagle
AMX Mod X Plugin Approver
Join Date: Sep 2013
Location: Romania
Old 09-04-2016 , 11:27   Re: Hlds Redirecting Hack
Reply With Quote #8

Are you using dproto? It looks like raiz0 exploit.
__________________
HamletEagle is offline
real sap
Member
Join Date: Aug 2015
Location: India
Old 09-04-2016 , 11:32   Re: Hlds Redirecting Hack
Reply With Quote #9

Quote:
Originally Posted by HamletEagle View Post
Are you using dproto? It looks like raiz0 exploit.
Nope i dont use Dropto its Clear HLDS on Steam based by CMD STEAM USERS ONLY .
real sap is offline
Send a message via Skype™ to real sap
tousif
AlliedModders Donor
Join Date: Nov 2014
Location: India
Old 09-04-2016 , 11:42   Re: Hlds Redirecting Hack
Reply With Quote #10

Some plugin is trying to modify clients files , since they are steam users( cl_filterstuffcmd is set 1) it can't modify their settings. Try to reinstall your server and don't use plugins from unknown source. I would like to check your server , I'll try to fix without reinstall , if you allow me , pm me if you want .
tousif is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:35.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode