Raised This Month: $12 Target: $400
 3% 

Attention: Sourcebans/Server Hacker!


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Cr(+)sshair
Member
Join Date: Mar 2010
Old 08-07-2010 , 12:28   Attention: Sourcebans/Server Hacker!
Reply With Quote #1

About a week ago, we had an emergency. Someone was attacking our servers. This person somehow managed to put himself as a God Admin on our sourcebans and used our own web rcon to attack us. This went from renaming the server to Operation Gamma, changing the map to hardware tests, to banning everyone in it.

When I banned him from in game I was able to grab a quick IP address before the person deleted his ban.

His info: STEAM_0:1:29452626, IP: 188.177.169.182

He came back later with: STEAM_0:0: 33334377, IP: 85.82.170.148

There were a lot more IP's but he was only seen on these two steamID's. I even had to go as far as making a little plugin that blocked him from our servers because he kept bypassing SB no matter what. This worked and no more attacks happened.

Recently, he posted a video on the attack http://www.youtube.com/watch?v=oqBweXiatjI



I recommend all server owners to ban him, then ban him from your sourcebans page by banning his IP ranges. I am currently in the process of getting logs and everything from the attack both server/sb wise and will report it to the Steam Community to hopefully get his accounts deleted.

Please don't flame in here, this is only a warning of what may happen to you!
Cr(+)sshair is offline
Groger
Veteran Member
Join Date: Oct 2009
Location: Belgium
Old 08-11-2010 , 11:23   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #2

You could disable the web rcon in your sourcebans by mannually deleting it from the php files

But thx for the heads up, I banned his steamID, IP etc but i dont think banning him by IP does make a difference, its easy to change your ip..


Thx anyway !
EDIT: Did you informed the SB-Crew about this?

Last edited by Groger; 08-11-2010 at 11:29.
Groger is offline
NouveauJoueur
SourceMod Donor
Join Date: May 2009
Old 08-11-2010 , 12:13   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #3

It's useless to inform SB coders about this until he can prove that he exploited a security hole from SB php's script.

Anyway that's a reason why i've never installed this kind of plugin, security holes can be fixed, but meanwhile you get your server burned by kids.
__________________
NouveauJoueur is offline
atom0s
Senior Member
Join Date: Jul 2009
Old 08-12-2010 , 09:29   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #4

There was a known exploit in an old version of the web script for SourceBans that could allow anyone to reset the admin email/password and obtain rcon access to any servers linked to the SourceBans install. If you are using an old copy of SourceBans you may want to update to the latest version. (Currently 1.4.6 as of this post.)
atom0s is offline
Peace-Maker
SourceMod Plugin Approver
Join Date: Aug 2008
Location: Germany
Old 08-21-2010 , 13:28   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #5

Quote:
Originally Posted by NouveauJoueur View Post
It's useless to inform SB coders about this until he can prove that he exploited a security hole from SB php's script.
No, if there's proof, that the attacker was sending rcon commands through the webpanel in the system log, we're going to check how this could happen.
Since SourceBans is such an widely used system, we try hard to keep it secure.
__________________
Peace-Maker is offline
Gunners
Junior Member
Join Date: Apr 2010
Old 08-21-2010 , 23:43   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #6

They hax
http://www.youtube.com/watch?v=hGVaXM9vidQ
Gunners is offline
meecrob
Senior Member
Join Date: Jan 2010
Old 08-21-2010 , 23:53   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #7

I don't run CS servers, but if I did I would block their entire group.

http://steamcommunity.com/groups/operationgamma
__________________
meecrob is offline
atom0s
Senior Member
Join Date: Jul 2009
Old 08-22-2010 , 18:01   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #8

Quote:
Originally Posted by Gunners View Post
This isn't proof that SourceBans is to blame.
atom0s is offline
tigerox
AlliedModders Donor
Join Date: Oct 2008
Location: Canada
Old 08-23-2010 , 14:17   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #9

If your MySQL DB will accept connections from any ip then it is possible to retrieve the DB login and password from your server's databases.cfg.

Then anyone could log into your Sourcebans DB and change a password to allow them to login. You should always only allow your server's ip to connect to your MySQL DB.

Just a theory.
__________________
tigerox is offline
omgitsme
Veteran Member
Join Date: Mar 2010
Old 08-23-2010 , 15:00   Re: Attention: Sourcebans/Server Hacker!
Reply With Quote #10

so are they still hacking? i just installed it on my test css server (acctually first time lucky, when i tried with amxbans it took me ages ) and i just don't want to regret it
__________________
omgitsme is offline
Send a message via Skype™ to omgitsme
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 20:20.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode