Raised This Month: $51 Target: $400
 12% 

New RCON exploit


Post New Thread Reply   
 
Thread Tools Display Modes
cheeeeese
Junior Member
Join Date: Nov 2009
Old 11-11-2009 , 22:01   Re: New RCON exploit
Reply With Quote #21

I'm not sure, but I can't find them in the logs folder.

Its as if he deleted the logs ;-;
cheeeeese is offline
Isias
Senior Member
Join Date: Apr 2006
Old 11-12-2009 , 12:34   Re: New RCON exploit
Reply With Quote #22

It's quit hard to start fixing something, without any informations where to look for it in first place. But if you're running Eventscripts 1.5, update it to the latest version, there was a rcon exploit. Also it is possible to overtake the server once sv_cheats 1 is set, wether with or without any plugin installed. So check for this two possiblitys please.

Last edited by Isias; 11-12-2009 at 12:43.
Isias is offline
cheeeeese
Junior Member
Join Date: Nov 2009
Old 11-12-2009 , 18:11   Re: New RCON exploit
Reply With Quote #23

Well the server is running ES 2.0+

and the server is on sv_cheats 0.

Also, isnt it possible to make one with the log that the thread starter posted?

Last edited by cheeeeese; 11-12-2009 at 22:46.
cheeeeese is offline
Fearts
ferts of daeth
Join Date: Oct 2008
Old 11-13-2009 , 02:34   Re: New RCON exploit
Reply With Quote #24

Here is his SteamID and IP so you can just ban him from your server. It wont stop anyone else who has the script but at least the creator wont be able to connect.

CaMeRoN187
STEAM_0:19273
68.41.41.69
__________________
Fearts is offline
Wolfman
Member
Join Date: Apr 2009
Location: Australia
Old 11-19-2009 , 03:52   Re: New RCON exploit
Reply With Quote #25

hate to say this but ive spoken to this hacker and he has been attacking me on this hack he is using a VPN to hide his IP address and also he has over 100+ steam account bcoz ive already banned like 10 steam accounts and ip address so banning wont stop him but the answer would be remove mani admin plugin and use sourcemod but you could also get a coder to recode mani admin or find a fix for it or something idk but banning him wont stop him.
Wolfman is offline
Wolfman
Member
Join Date: Apr 2009
Location: Australia
Old 11-19-2009 , 04:02   Re: New RCON exploit
Reply With Quote #26

btw he has told me that he uses a exploit in the CSS engine or source engine of valve that he hacks in i dont know if this is true or not but idk ive put everything i think in place and he said he is planning on taking my server down for good so we will see what happens on my server coz he got it out for me
Wolfman is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 11-19-2009 , 15:15   Re: New RCON exploit
Reply With Quote #27

While there are some suspicions as to how this works, posting them publicly is not really a great idea for this exploit. I'm usually all for releasing the details, but in this case we have no full patch, and valve will take forever to fix this.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Isias
Senior Member
Join Date: Apr 2006
Old 11-20-2009 , 16:20   Re: New RCON exploit
Reply With Quote #28

Quote:
valve will take forever to fix this
Since you had a look at the exploit, was it engine-only related, so working on any server even with sv_cheats 0 and without any plugins at all? I hope it's not another exploit allowing to upload all kind of files to the server, like the one Valve fixed with the latest engine update -.-

And:
Quote:
I can verify this at some point this week, but I don't have CSS installed on my laptop right now.
Have you had some time to have a look at it? Sry for bugging :- )

Last edited by Isias; 11-20-2009 at 16:22.
Isias is offline
NouveauJoueur
SourceMod Donor
Join Date: May 2009
Old 11-21-2009 , 03:47   Re: New RCON exploit
Reply With Quote #29

Quote:
Originally Posted by devicenull View Post
While there are some suspicions as to how this works, posting them publicly is not really a great idea for this exploit. I'm usually all for releasing the details, but in this case we have no full patch, and valve will take forever to fix this.
And how we're supposed to find a fix for ou servers if we don't even know how this exploit works ?
__________________
NouveauJoueur is offline
Wolfman
Member
Join Date: Apr 2009
Location: Australia
Old 11-21-2009 , 08:12   Re: New RCON exploit
Reply With Quote #30

well i recon you should remove mani admin plugin coz thats how he gets control of it and maybe put some bugs into mani admin about this coz what ive seen him do is does a brute force of rcon password and get it to right a adminlist.txt file to your plugin folder so if you remove mani admin and use SM it should fix this but i found a program called that devicenull has made which has seem to stop him so far.

File upload exploit (1.0.0.2) by devicenull

you should find it easy. on this forums
Wolfman is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 17:50.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode