Raised This Month: $51 Target: $400
 12% 

(not a Sourcebans issue) All players reported as having the same IP address


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
DNA.styx
Junior Member
Join Date: Dec 2023
Old 01-21-2024 , 15:28   (not a Sourcebans issue) All players reported as having the same IP address
Reply With Quote #1

Subject was: Everyone gets flagged as "[SourceSleuth] Duplicate account" after aimbot ban

After an aimbot user was banned everyone joining my server, including myself, is being banned/flagged "[SourceSleuth] Duplicate account" saying they have the same IP address. Is this a known issue? Any fix?


Software:
SourceBans++ 1.8.0 | Git: 1294
Little Anti-Cheat 1.7.4

Events:
Aimbot user banned by Little Anti-Cheat while I was on the server. This is the first cheat ban logged, previous bans have been manual steamID only bans.
Spoiler

Next person to join the server gets banned with SourceSleuth Duplicate account

Spoiler


Checked SourceBans++ log and both players have the same IP address. I presume they had an alt-account.

Restarted map to set the SourceBans++ language to English (server default) and I got kicked for [SourceSleuth] Duplicate account as well

Spoiler


Changed Sleuth Ban Type to notify only and now anyone joining the server,including myself getflaged as having an active ban

Spoiler


Tried restarting map and server. No better.
__________________

Last edited by DNA.styx; 02-03-2024 at 12:27.
DNA.styx is offline
DNA.styx
Junior Member
Join Date: Dec 2023
Old 01-30-2024 , 18:38   Re: Everyone gets flagged as "[SourceSleuth] Duplicate account" after aimbot ban
Reply With Quote #2

Have just discovered that the IP address listed above, 88.198.27.9, is one of the gameME stats servers.
__________________
DNA.styx is offline
DNA.styx
Junior Member
Join Date: Dec 2023
Old 02-01-2024 , 17:13   Re: (not a Sourcebans issue) All players reported as having the IP address
Reply With Quote #3

Have installed a couple of other plugins that use GetClientIP and they all return the same IP address, which has been confirmed as one of the GameME servers. All very strange....but not a SourceBan issue.

PHP Code:
19:56:00 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9CONNECTED from <Germany>
20:03:42 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 27 minutes. <Disconnect by user.>
20:03:46 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9CONNECTED from <Germany>
20:06:46 - <DNA.styx> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 4 minutes. <Disconnect by user.>
20:56:03 - <QUACKATTACK_3_1> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 10 minutes. <Disconnect by user.>
21:03:43 - <Oly> <STEAM_0:0:xxxx> <88.198.27.9DISCONNECTED after 26 minutes. <Disconnect by user.>
21:04:21 - <KARIS CZ> <STEAM_0:1:xxxx> <88.198.27.9DISCONNECTED after 27 minutes. <Disconnect by user.> 
__________________
DNA.styx is offline
Bacardi
Veteran Member
Join Date: Jan 2010
Location: mom's basement
Old 02-01-2024 , 22:19   Re: (not a Sourcebans issue) All players reported as having the IP address
Reply With Quote #4

Plugin_print
Meta list
Sm exts list
Sm plugins list


Status
__________________
Do not Private Message @me
Bacardi is offline
DNA.styx
Junior Member
Join Date: Dec 2023
Old 02-03-2024 , 04:21   Re: (not a Sourcebans issue) All players reported as having the IP address
Reply With Quote #5

Plugin_print
PHP Code:
Loaded plugins:
---------------------
0:    "Metamod:Source 1.12.0-dev+1157"
--------------------- 
Meta list
PHP Code:
Listing 5 plugins:
  [
01RCBot2 (1.51 (apg-nosoop-caxanga334)-3a3a3a41by CheesehRoboCopnosoopcaxanga334
  
[02SourceMod (1.11.0.6947by AlliedModders LLC
  
[03SDK Tools (1.11.0.6947by AlliedModders LLC
  
[04SDK Hooks (1.11.0.6947by AlliedModders LLC
  
[05SteamWorks Extension (1.2.3by Kyle Sanderson 
Sm exts list
PHP Code:
[SMDisplaying 17 extensions:
[
01Automatic Updater (1.11.0.6947): Updates SourceMod gamedata files
[02Webternet (1.11.0.6947): Extension for interacting with URLs
[03RCBot2 (1.51 (apg-nosoop-caxanga334)-3a3a3a41): Bot for HL2DMTF2 and DOD:S
[04SDK Tools (1.11.0.6947): Source SDK Tools
[05BinTools (1.11.0.6947): Low-level C/C++ Calling API
[06Top Menus (1.11.0.6947): Creates sorted nested menus
[07Client Preferences (1.11.0.6947): Saves client preference settings
[08SQLite (1.11.0.6947): SQLite Driver
[09System2 (3.3.2): HTTP/FTP Request and System API for Sourcemod
[10Regex (1.11.0.6947): Provides regex natives for plugins
[11REST in Pawn (1.3.1): Provides HTTP and JSON natives for plugins
[12SDK Hooks (1.11.0.6947): Source SDK Hooks
[13SMJansson (2.6.0/1): JSON parser/writer
[14SteamWorks Extension (1.2.3): Exposes SteamWorks functions to Developers
[15GeoIP (1.11.0.6947): Geographical IP information
[16] <OPTIONALfile "socket.ext.dll"The specified module could not be found.
[
17MySQL-DBI (1.11.0.6947): MySQL driver implementation for DBI 
Sm plugins list
PHP Code:
[SMListing 48 plugins:
  
01 "[DoD TMS] Addon - AFK Manager" (1.22by FeuerSturmmodif Micmacx
  02 
"[DoD TMS] Addon - Anti-VoiceCmdSpam" (1.22by FeuerSturmmodif Micmacx
  03 
"[DoD TMS] Addon - AutoTeamBalance" (1.22by FeuerSturmmodif Micmacx
  04 
"[DoD TMS] Addon - ClanTag Protection" (1.22by FeuerSturmmodif Micmacx
  05 
"[DoD TMS] Addon - High Ping Kicker" (1.22by FeuerSturmmodif Micmacx
  06 
"[DoD TMS] Addon - Secret Spectate" (1.22by FeuerSturmmodif Micmacx
  07 
"[DoD TMS] Addon - Class Restrictions" (1.22by FeuerSturmmodif Micmacx
  08 
"Admin File Reader" (1.11.0.6947by AlliedModders LLC
  09 
"Admin Help" (1.11.0.6947by AlliedModders LLC
  10 
"Admin Menu" (1.11.0.6947by AlliedModders LLC
  11 
"Advertisements" (2.1.1by Tsunami
  12 
"Anti-Flood" (1.11.0.6947by AlliedModders LLC
  13 
"Basic Chat" (1.11.0.6947by AlliedModders LLC
  14 
"Basic Comm Control" (1.11.0.6947by AlliedModders LLC
  15 
"Basic Commands" (1.11.0.6947by AlliedModders LLC
  16 
"Basic Info Triggers" (1.11.0.6947by AlliedModders LLC
  17 
"Basic Votes" (1.11.0.6947by AlliedModders LLC
  18 
"Client Preferences" (1.11.0.6947by AlliedModders LLC
  19 
"Cronjobs" (2.0by dordnung
  20 
"Discord Relay" (0.7.8by log-ical
  21 
"Discord API" (0.1.107by Deathknife
  22 
"Discord Logger!" (v2by MbK
  23 
"DOD:S Ammo Settings" (1.0by Silent_Water
  24 
"DoD BasicGore" (1.1by FeuerSturm
  25 
"DoD:S DetoNades" (1.0by Root
  26 
"DOD:S Fireworks" (1.3by Silent_Waterplayboycyberclub
  27 
"Dod Grenade Trails" (1.1by Andi67Modif Micmacx
  28 
"DoD Medic" (1.1.1by Tsunami,DNA.styx
  29 
"[DoD TMS] Base  - DoD TeamManager Source" (1.22by FeuerSturmmodif Micmacx
  30 
"Dog's Prop Bonus Round" (1.13.1by <eVa>Dog (edited byretsamDNA.styx)
  
31 "Dynamic MotD Replacer" (3.0.0by psychonic
  32 
"First bot" (1.0by Micmacx
  33 
"Fun Commands" (1.11.0.6947by AlliedModders LLC
  34 
"Fun Votes" (1.11.0.6947by AlliedModders LLC
  35 
"gameME Plugin" (4.8.1by TTS Oetzel Goerz GmbH
  36 
"DoD:S Instant Respawn" (1.5by Andersso
  37 
"[Lilac] Little Anti-Cheat" (1.7.4by J_Tanzanite
  38 
"Log Connections" (1.4by XanderIT-KiLLERDosergen
  39 
"Player Commands" (1.11.0.6947by AlliedModders LLC
  40 
"Reserved Slots" (1.11.0.6947by AlliedModders LLC
  41 
"SourceBans++: Admin Config Loader" (1.8.0by AlliedModders LLCSourceBans++ Dev Team
  42 
"SourceBans++: Bans Checker" (1.8.0by psychonicCa$h MunnySourceBans++ Dev Team
  43 
"SourceBans++: SourceComms" (1.8.0by AlexSourceBans++ Dev Team
  44 
"SourceBans++: Main Plugin" (1.8.0by SourceBans Development TeamSourceBans++ Dev Team
  45 
"SourceBans++ Report Plugin" (1.8.0by RumbleFrogSourceBans++ Dev Team
  46 
"SourceBans++: SourceSleuth" (1.8.0by eccaSourceBans++ Dev Team
  47 
"SpeedUp" (1.0.1by MosalarBacardi
  48 
"Tidy Chat" (0.5by linux_lover 
Status
PHP Code:
hostnameDNAGames 24/7 Ava | +Grens QuickSpawn SneakyBots
version 
6630498/24 6630498 secure
udp
/ip  185.216.145.132:27015  (public ip185.216.145.132)
steamid : [A:1:209xxxxxxx:25199] (9018022xxxxxxxxxx)
map     dod_avalanche at0 x0 y0 z
tags    
Bots,alltalk,quickspawn,gameME
players 
1 humans9 bots (12 max)
edicts  : -66149 used of 2048 max
# userid name                uniqueid            connected ping loss state  adr
#    508 "[RCB]WooHoo"       BOT                                     active
#    482 "[RCB]Goose"        BOT                                     active
#    509 "[RCB]Leeroy"       BOT                                     active
#    507 "[RCB]Mouse"        BOT                                     active
#    497 "[RCB]Ratatat"      BOT                                     active
#    493 "[RCB]Goddard"      BOT                                     active
#    505 "[RCB]Rambo"        BOT                                     active
#    511 "[RCB]Peake"        BOT                                     active
#    506 "[RCB]SirRobin"     BOT                                     active
#    510 "DNA.styx"          [U:1:40203]         03:55       40    0 active 82.69.xx.xxx:27005 
Connection log
PHP Code:
09:09:36 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany
edit: I was AFK the whole day yesterday and the connection logger recorded the below. 82.69.xxx.xxx = my IP. It flipped between the GameME and my IP address. Note there is an automated server restart at ~0600.

PHP Code:
02:46:23 - <fmauro64> <STEAM_0:0:103703320> <82.69.xxx.xxxDISCONNECTED after 13 minutes. <Disconnect by user.>
13:25:22 - <DonneTaCarabine> <STEAM_0:0:9512374> <88.198.27.9DISCONNECTED after 9 minutes. <Disconnect by user.>
16:58:15 - <DARK> <STEAM_0:0:77628340> <88.198.27.9DISCONNECTED after 7 minutes. <Disconnect by user.>
17:31:14 - <bodyelectrich> <STEAM_0:1:45452862> <88.198.27.9DISCONNECTED after 8 minutes. <Disconnect by user.>
19:52:32 - <ManOs> <STEAM_0:0:5904043> <82.69.xxx.xxxDISCONNECTED after 7 minutes. <Disconnect by user.>
20:15:35 - <boba {VoD}> <STEAM_0:1:9310115> <82.69.xxx.xxxDISCONNECTED after 9 minutes. <Disconnect by user.>
20:21:32 - <ManOs> <STEAM_0:0:5904043> <82.69.xxx.xxxDISCONNECTED after 29 minutes. <Disconnect by user.>
20:21:38 - <Kannixx> <STEAM_0:0:165973253> <82.69.xxx.xxxDISCONNECTED after 35 minutes. <Disconnect by user.>
20:21:38 - <der.lexan> <STEAM_0:0:15852015> <82.69.xxx.xxxDISCONNECTED after 28 minutes. <Disconnect by user.>
20:23:18 - <G â&#732;…man> <STEAM_0:0:540124302> <82.69.xxx.xxx> DISCONNECTED after 8 minutes. <Disconnect by user.>
20:23:31 - <TORPE> <STEAM_0:0:7741798> <82.69.xxx.xxxDISCONNECTED after 12 minutes. <Disconnect by user.>
20:28:13 - <bjwilliams010> <STEAM_0:1:797692874> <82.69.xxx.xxxDISCONNECTED after 1 minutes. <Disconnect by user.>
20:49:12 - <BlackSkyline> <STEAM_0:0:514068672> <82.69.xxx.xxxDISCONNECTED after 54 minutes. <Disconnect by user.>
22:48:54 - <gael the metropolice> <STEAM_0:1:484483357> <82.69.xxx.xxxDISCONNECTED after 3 minutes. <Disconnect by user.>
09:09:36 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany>
09:26:46 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9DISCONNECTED after 18 minutes. <Disconnect by user.>
09:26:50 - <DNA.styx> <STEAM_0:1:20101> <88.198.27.9CONNECTED from <Germany
__________________

Last edited by DNA.styx; 02-03-2024 at 04:56.
DNA.styx is offline
DNA.styx
Junior Member
Join Date: Dec 2023
Old 02-03-2024 , 16:58   Re: (not a Sourcebans issue) All players reported as having the same IP address
Reply With Quote #6

It's beginning to feel like it's something to do with remote rcon/logaddress.

I've got an app on my phone that allows me to perform console actions on the server: status/plugin_print/meta list etc.

It appears that anytime I use that that app from home all players get my home IP (82.69.xxx.xxx).

M server's autoexec.cfg has a logaddress_delall & logaddress_add (as per gameme instructions), so that could be why I've noticed that restarting the server results in 88.198.27.9 appearing as everyone's IP address again.

PHP Code:
L 02/03/2024 20:39:50: -------- Mapchange to dod_avalanche --------
L 02/03/2024 20:39:50DNA.styx<90><[U:1:40203]><><88.198.27.9connected.
L 02/03/2024 20:41:40DNA.styx<90><[U:1:40203]><><88.198.27.9disconnected.
L 02/03/2024 20:49:22DNA.styx<123><[U:1:40203]><><88.198.27.9connected.
L 02/03/2024 21:01:33DNA.styx<123><[U:1:40203]><><88.198.27.9disconnected.
L 02/03/2024 21:03:25adrian shephard<137><[U:1:1516896097]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:03:42adrian shephard<137><[U:1:1516896097]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:03:43DNA.styx<139><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:09:24DNA.styx<139><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:10:51DNA.styx<160><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:12:44DNA.styx<160><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:12:48DNA.styx<163><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:13:46DNA.styx<163><[U:1:40203]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:14:21DNA.styx<181><[U:1:40203]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:18:0624007kb/s<183><[U:1:37019763]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:18:0624007kb/s<183><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0724007kb/s<184><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0824007kb/s<185><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0824007kb/s<186><STEAM_ID_PENDING><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0924007kb/s<187><STEAM_ID_PENDING><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:18:0924007kb/s<188><[U:1:37019763]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:26:1224007kb/s<188><[U:1:37019763]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:33:50lchristopherl<193><[U:1:175137150]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:47:21lchristopherl<193><[U:1:175137150]><><82.69.xxx.xxxdisconnected.
L 02/03/2024 21:52:13seano<201><[U:1:1036576658]><><82.69.xxx.xxxconnected.
L 02/03/2024 21:52:31seano<201><[U:1:1036576658]><><82.69.xxx.xxxdisconnected
I'm using this plugin to generate the above log.
__________________

Last edited by DNA.styx; 02-03-2024 at 17:14.
DNA.styx is offline
Bacardi
Veteran Member
Join Date: Jan 2010
Location: mom's basement
Old 02-03-2024 , 21:53   Re: (not a Sourcebans issue) All players reported as having the same IP address
Reply With Quote #7

...interested.
I'm wondering does this happen only SourceMod GetClientIP.

You could look status command more often, do players have same IP.

One thing what could cause this is, plugin is trying to get client IP too soon when connecting to server.
It maybe fail to get IP, there is no check for that.

...I could write different plugin, when I have time.
__________________
Do not Private Message @me
Bacardi is offline
DNA.styx
Junior Member
Join Date: Dec 2023
Old 02-04-2024 , 15:33   Re: (not a Sourcebans issue) All players reported as having the same IP address
Reply With Quote #8

Yes, very strange one. Thanks for checking.

Here's some console logs. There is a point were they all switch from returning their real IP address to one of the others (my IP or GameME).

Will grab some status command outputs as well.

Spoiler


Spoiler


Spoiler


Spoiler


Edit: When I disable gameme's logaddress_add from the server autoexec.cfg all players IP addresses are reported correctly. Seems that what ever I set logaddress_add to gets returns as the players GetClientIP (example below where I set logaddress_add to 8.8.8.8.
Spoiler
__________________

Last edited by DNA.styx; 03-04-2024 at 18:05. Reason: More info...
DNA.styx is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:00.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode