Raised This Month: $ Target: $400
 0% 

RCON Brute-force... WITH A TWIST!


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Skamadix
New Member
Join Date: Feb 2015
Old 02-16-2015 , 08:58   RCON Brute-force... WITH A TWIST!
Reply With Quote #1

Another community is taking a list of IPs that connect to their servers, and spoofing RCON commands with this list of IP addresses against our servers - causing Sourcemod to automatically ban their IP.

Has anyone ran into this before?

Disabling RCON for us unfortunately is not an option.
Skamadix is offline
JoB2C
AlliedModders Donor
Join Date: Jan 2014
Location: France
Old 02-16-2015 , 09:18   Re: RCON Brute-force... WITH A TWIST!
Reply With Quote #2

Is whitelisting by IP an option?
JoB2C is offline
psychonic

BAFFLED
Join Date: May 2008
Old 02-16-2015 , 10:02   Re: RCON Brute-force... WITH A TWIST!
Reply With Quote #3

You can't spoof RCon packet addresses; RCon goes over TCP. Additionally, SourceMod itself does not do any such automatic banning.

It's possible that they are spoofing game traffic (UDP) from those addresses and that the engine or something else is banning them. RCon and game traffic share the same ban list for IP bans.
psychonic is offline
Zephyrus
Cool Pig B)
Join Date: Jun 2010
Location: Hungary
Old 02-16-2015 , 11:27   Re: RCON Brute-force... WITH A TWIST!
Reply With Quote #4

Quote:
Originally Posted by psychonic View Post
You can't spoof RCon packet addresses; RCon goes over TCP. Additionally, SourceMod itself does not do any such automatic banning.

It's possible that they are spoofing game traffic (UDP) from those addresses and that the engine or something else is banning them. RCon and game traffic share the same ban list for IP bans.
they are opening a page in the motd with a websocket to the target server's rcon address and spam that.
__________________
Taking private C++/PHP/SourcePawn requests, PM me.
Zephyrus is offline
psychonic

BAFFLED
Join Date: May 2008
Old 02-16-2015 , 13:15   Re: RCON Brute-force... WITH A TWIST!
Reply With Quote #6

Quote:
Originally Posted by Zephyrus View Post
Quote:
Originally Posted by psychonic View Post
You can't spoof RCon packet addresses; RCon goes over TCP. Additionally, SourceMod itself does not do any such automatic banning.

It's possible that they are spoofing game traffic (UDP) from those addresses and that the engine or something else is banning them. RCon and game traffic share the same ban list for IP bans.
they are opening a page in the motd with a websocket to the target server's rcon address and spam that.
That's not spoofing, nor SM doing the resulting ban. My statement holds.

Last edited by psychonic; 02-16-2015 at 13:16.
psychonic is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:28.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode