Raised This Month: $51 Target: $400
 12% 

my server got hacked or got a backdoor?...


Post New Thread Closed Thread   
 
Thread Tools Display Modes
SomeoneS
Junior Member
Join Date: Jan 2008
Location: localhost
Old 02-20-2008 , 09:48   Re: my server got hacked or got a backdoor?...
#11

you cannot disable rcon! set it to a cryptic pass, if you dont want to use it.

if u set rcon (what i think) to rcon_password "" than its free for all.
most tools have problem with an empty password, so u can think that u disabled it.
but try the ingame console
SomeoneS is offline
hoboman
Senior Member
Join Date: Jul 2007
Old 02-20-2008 , 16:10   Re: my server got hacked or got a backdoor?...
#12

Quote:
Originally Posted by Brad View Post
Did you get any of the plugins from somewhere other than this site? Presumably you have the source for each?
no

Quote:
amx_mode?
no idea what that is, so it is probably the default


Quote:
I think they used rcon cus youre rcon lenght have to be 6< someone said that if rcon lenght is >6 theres is a trick,,, but its only my opinion ;)
but is that is this even a fact?
my rcon length was well over 6...
__________________
hoboman is offline
Roach
Writes love letters to sawce Daily
Join Date: Jul 2006
Location: Internet
Old 02-20-2008 , 16:13   Re: my server got hacked or got a backdoor?...
#13

Never seen those names before in my research when looking for the original backdoor.

You got me on that one hombre. All of those kicks, however, look like rcon console kicks, and not amxx kicks.
__________________
Quote:
Originally Posted by Brad View Post
That sounds like a really good idea!
Now replace the word "good" with "dumb".
What was your rationale for proposing such a thing?
Roach is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 02-20-2008 , 17:11   Re: my server got hacked or got a backdoor?...
#14

If you are using GameServers.com as your host (assuming because of the GameTracker banner), look in your gsconsole.log file for rcon logins. This file get overwritten everytime you press the Restart Server button in the Members Area.

Otherwise, it may be logging it to the general HLDS logs, just maybe.


But yeah, those kicks are definitely rcon kicks.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
bmann_420
AMX_Super Pooper
Join Date: Jan 2005
Location: [SuperCentral.co]
Old 02-20-2008 , 22:46   Re: my server got hacked or got a backdoor?...
#15

I believe he mentioned Nuclear Fallout as the host.
__________________
bmann_420 is offline
Jellric
Member
Join Date: Dec 2007
Old 02-23-2008 , 14:08   Re: my server got hacked or got a backdoor?...
#16

I can almost guarantee you it's rcon. You don't have to give it out for someone to get your rcon password. The password is sent out over the internet in plain text (unencrypted) everytime rcon is used. Someone with an rcon sniffer program can easily intercept that traffic and read your password. Then, using a program such as HLSW, take remote control of your server. It has happened to me before.

The only solution in this case is to remove the rcon password for a few days or more by setting rcon_password "". If you feel sure those guys were the ones hacking your server, ban them.

If they are using a packet sniffer, changing the password to something more complex won't help for the reason I mentioned.

If you ban them, be sure to ban them by IP address also. Otherwise they could remotely remove themselves from your ban list. Banning their IP will keep them from using a remote program such as HLSW. Your server won't even show up on their steam servers list anymore.
Jellric is offline
[X]-RayCat
Senior Member
Join Date: Sep 2006
Old 02-26-2008 , 17:30   Re: my server got hacked or got a backdoor?...
#17

How about vote? It may sound stupid (im stupid)... ^^
[X]-RayCat is offline
hoboman
Senior Member
Join Date: Jul 2007
Old 02-28-2008 , 15:21   Re: my server got hacked or got a backdoor?...
#18

Quote:
Originally Posted by [X]-RayCat View Post
How about vote? It may sound stupid (im stupid)... ^^
if it was a vote it would have been logged in the amxx admin logs...and it wasn't

After doing some googling it turns out that Jellric is probably correct about what has happened here...I had no idea that it was that easy to get a hold of the rcon
__________________
hoboman is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 02-28-2008 , 15:24   Re: my server got hacked or got a backdoor?...
#19

There is a votekick and a voteban command that comes with HL that anyone can use.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
cs1.6
Senior Member
Join Date: Dec 2006
Old 03-03-2008 , 20:37   Re: my server got hacked or got a backdoor?...
#20

hi,

i want to contribute to security of the forum members and so i would like to say something, as well.

It seems to me that nowadays alot of these kind of things are happening. I would in my humble opinion/guess say that i assume some kind of 'rcon sniffer program' has been made available for abuse. I am sure this has happened to alot of ppl, just that they have not realized it. Shortly ago i experrienced the exact same thing. Obviously someone respectively serveral ppl are using this program to hack the console password.

I have luckily one copy of those messages still in my notes.

Code:
Bad Rcon from 74.138.253.184:49786:
rcon 2079285343 "amber"  status
I had for a short time alot of similar messages in the console. If i remember right, it was allways the same command (status) just with a different user name. Note that all those messages had a female name in them, like 'amy' 'jessica' and alikes which points out the fishy nature of the whole thing. And also there was no player with thsese kind of names on the server!! which would indicate a remote program/scanner/person.

bye
cs1.6 is offline
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 19:14.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode