Raised This Month: $32 Target: $400
 8% 

xBrute Attack


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
DC32
Member
Join Date: Jun 2010
Old 06-24-2013 , 08:31   xBrute Attack
Reply With Quote #1

Hello Modders!

Iam occuring an attack against my servers.. Below you can see a part of a log of attacks who arrives to my server at the moment right now

Quote:

Bad Rcon from 92.255.174.241:27006:
rcon 2136931807 "615" echo XBrute by ZeaL
Bad rcon_password.
Bad Rcon from 171.14.202.140:27005:
rcon 594454996 "617" echo XBrute by ZeaL
Bad rcon_password.
Bad Rcon from 92.80.162.49:10072:
rcon 1318364471 "550" echo XBrute by ZeaL
Bad rcon_password.
Bad Rcon from 77.122.9.90:27006:
rcon 1452884912 "547" echo XBrute by ZeaL
Bad rcon_password.
Bad Rcon from 46.99.18.38:23012:
rcon 1605288065 "549" echo XBrute by ZeaL
Bad rcon_password.
How can i prevent this? :S

Quote:
sv_rcon_banpenalty 60
sv_rcon_maxfailures 2
sv_rcon_minfailures 1
sv_rcon_minfailuretime 60
is the rcon settings i use.

I've heard that you can use a blank rcon password, but then the users can access the rcon commands with no problems, or what?..


Also, those attacks, from my experience within emulation, those attacks should be slowing down my server, making it lagg and more unstable, is it true?

a huge thanks in advance

-DC32
DC32 is offline
^SmileY
Veteran Member
Join Date: Jan 2010
Location: Brazil [<o>]
Old 06-24-2013 , 08:42   Re: xBrute Attack
Reply With Quote #2

Yeah its a new exploit or hack, i think its better to disable rcon or put the strong password
I have the same issue yesterday.. And change the port / ip of the server but the hack persists.

Tip: If you are running Skype on same machine of server, remove it because its the main reason for the "exploiter"
find server ip (I think)

Thanks.
__________________
Projects:

- See my Git Hub: https://github.com/SmileYzn
PHP Code:
set_pcvar_num(pCvar, !get_pcvar_num(pCvar)); 
^SmileY is offline
Send a message via MSN to ^SmileY Send a message via Skype™ to ^SmileY
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 06-24-2013 , 09:29   Re: xBrute Attack
Reply With Quote #3

If you have a complex password, ignore it.
If you don't have a password set at all, ignore it since they will never be able to get in
If you have a simple password, make it more complex or remove it
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
DC32
Member
Join Date: Jun 2010
Old 06-24-2013 , 09:49   Re: xBrute Attack
Reply With Quote #4

so the users cant use the rcon if theres no password?

and HLDS wont startup with a blank rcon pw
DC32 is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 06-24-2013 , 09:55   Re: xBrute Attack
Reply With Quote #5

HLDS runs fine without a rcon password, my test server doesn't have one set.
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
AmineKyo
فوق سريرك
Join Date: Oct 2011
Location: Morocco
Old 06-24-2013 , 11:39   Re: xBrute Attack
Reply With Quote #6

Quote:
Originally Posted by dc32 View Post
so the users cant use the rcon if theres no password?

and HLDS wont startup with a blank rcon pw
Start it with a command line.
__________________
AmineKyo is offline
kwpd
AlliedModders Donor
Join Date: Mar 2009
Location: panama
Old 06-24-2013 , 12:07   Re: xBrute Attack
Reply With Quote #7

ataques masivo

__________________
kwpd is offline
AmineKyo
فوق سريرك
Join Date: Oct 2011
Location: Morocco
Old 06-24-2013 , 12:11   Re: xBrute Attack
Reply With Quote #8

Quote:
Originally Posted by kwpd View Post
Massive attacks
Quote:
Originally Posted by YamiKaitou View Post
If you have a complex password, ignore it.
If you don't have a password set at all, ignore it since they will never be able to get in
If you have a simple password, make it more complex or remove it
__________________
AmineKyo is offline
TheDS1337
Veteran Member
Join Date: Jun 2012
Old 06-24-2013 , 12:20   Re: xBrute Attack
Reply With Quote #9

Last HLDS update have an exploit :S, with 1 command you can crash the server ( only using last HLDS update )
TheDS1337 is offline
Mikado
Senior Member
Join Date: Nov 2012
Location: don't know where :/
Old 06-24-2013 , 12:38   Re: xBrute Attack
Reply With Quote #10

Disable rcon
Mikado is offline
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 11:41.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode