Raised This Month: $51 Target: $400
 12% 

Rcon locker / exploit fix


Post New Thread Reply   
 
Thread Tools Display Modes
Whosat
Senior Member
Join Date: Nov 2007
Location: Singapore
Old 08-31-2009 , 10:43   Re: Rcon locker / exploit fix
Reply With Quote #121

Thanks ghosty!
__________________
Whosat is offline
ducky93
New Member
Join Date: Aug 2009
Old 08-31-2009 , 13:49   Re: Rcon locker / exploit fix
Reply With Quote #122

I was doing some testing and found a few commands you may not know of to lag/crash a server.

groundlist
report_entities
ListServerUserMessages

Hope this helps
ducky93 is offline
thetwistedpanda
Good Little Panda
Join Date: Sep 2008
Old 08-31-2009 , 14:02   Re: Rcon locker / exploit fix
Reply With Quote #123

Quote:
Originally Posted by ducky93 View Post
I was doing some testing and found a few commands you may not know of to lag/crash a server.

groundlist
report_entities
ListServerUserMessages

Hope this helps
Only groundlist is something to be worried about; the other two not so much. report_entities shouldn't function unless sv_cheats is on, and listserverusermessage doesn't seem to affect any cpu/server load.
thetwistedpanda is offline
johns3
New Member
Join Date: Aug 2009
Old 08-31-2009 , 20:55   Re: Rcon locker / exploit fix
Reply With Quote #124

I have just put the rcon locker on my server. However, the hacker still managed to introduce "Client dropped" error, whereby, nobody can join the server after the "Client dropped" message appeared. Can anyone advice any counter for this?
johns3 is offline
SooStoked
Junior Member
Join Date: May 2009
Old 09-07-2009 , 19:09   Re: Rcon locker / exploit fix
Reply With Quote #125

Thanks
good stuff
SooStoked is offline
Hollanda
Senior Member
Join Date: Sep 2006
Location: Netherlands
Old 09-19-2009 , 08:29   Re: Rcon locker / exploit fix
Reply With Quote #126

sourcebans integration would be welcome!
Hollanda is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 09-20-2009 , 23:11   Re: Rcon locker / exploit fix
Reply With Quote #127

Quote:
Originally Posted by Hollanda View Post
sourcebans integration would be welcome!
I can't tell with 100% certainty that some of these things are on purpose. Some can possibly occur accidentally, and I'd rather have someone kicked from the server rather then being banned forever or w/e. If you want to ban people like that, all the exploits are logged to the SourceMod logs, so it should be trivial to grab people's info from those.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Hollanda
Senior Member
Join Date: Sep 2006
Location: Netherlands
Old 09-22-2009 , 06:50   Re: Rcon locker / exploit fix
Reply With Quote #128

Quote:
Originally Posted by devicenull View Post
I can't tell with 100% certainty that some of these things are on purpose. Some can possibly occur accidentally, and I'd rather have someone kicked from the server rather then being banned forever or w/e. If you want to ban people like that, all the exploits are logged to the SourceMod logs, so it should be trivial to grab people's info from those.
Quote:
L 09/18/2009 - 16:234: rcon from "82.168.99.148:21898": Bad Password
L 09/18/2009 - 16:234: rcon from "82.168.99.148:21898": Bad Password
L 09/18/2009 - 16:23:48: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:51: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:51: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:53: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:53: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:54: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:54: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:55: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:55: rcon from "unknown": Bad Password
L 09/18/2009 - 16:23:56: rcon from "unknown": Bad Password
At the above example the server crashed about every 2 rounds.

Running multiple servers it's not easy to check all logs...

Some exploits like above, I think, are obvious enough to ban into sourcebans?
Hollanda is offline
toString
Senior Member
Join Date: Jun 2009
Old 09-22-2009 , 08:43   Re: Rcon locker / exploit fix
Reply With Quote #129

Code:
13:40:39 L 09/22/2009 - 13:42:01: [SM] Native "RegConsoleCmd" reported: Cannot override "sm" command
13:40:39 L 09/22/2009 - 13:42:01: [SM] Displaying call stack trace for plugin "rcon_lock.smx":
13:40:39 L 09/22/2009 - 13:42:01: [SM]   [0]  Line 95, /home/groups/alliedmodders/forums/files/7/2/43224.attach::OnPluginStart()
Is this not supported in 1.3.0?

sourcemod-1.3.0-hg2805
toString is offline
devicenull
Veteran Member
Join Date: Mar 2004
Location: CT
Old 09-22-2009 , 11:41   Re: Rcon locker / exploit fix
Reply With Quote #130

Quote:
Originally Posted by Hollanda View Post
At the above example the server crashed about every 2 rounds.

Running multiple servers it's not easy to check all logs...

Some exploits like above, I think, are obvious enough to ban into sourcebans?
That exploit can't be fixed from a sourcemod plugin. Nor will banning the user's steamid/ip have any real effect. You would need to add firewall rules to prevent this.
__________________
Various bits of semi-useful code in a bunch of languages: http://code.devicenull.org/
devicenull is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:36.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode