Raised This Month: $32 Target: $400
 8% 

SMAC Rcon Locker and bizarre cvar values


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
IceCucumber
Member
Join Date: Dec 2011
Old 02-24-2014 , 04:43   SMAC Rcon Locker and bizarre cvar values
Reply With Quote #1

I noticed the "SMAC Rcon locker" plugin forcing sv_rcon_minfailuretime (number of seconds to track failed rcon authentications) to a value of 1, and sv_rcon_minfailures/maxfailures (number of times a user can fail rcon authentication before being banned) to 9999999.

This seems to break the anti-bruteforce IP banning completely, as nobody's going to fail a password 9999999 times within a timeframe of just 1 second.

Is there any reason behind this?

edit: After some googling, apparently there is (was?) an exploit crashing servers with incorrect password flood. I suppose that's why. Still feels a little iffy giving unlimited amount of tries with the password.

Last edited by IceCucumber; 02-25-2014 at 10:38.
IceCucumber is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 07:20.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode