Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length



Pages: [1]
  Print  
Author Topic: *IMPORTANT PLEASE READ*  (Read 380 times)
evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« on: February 08, 2010, 07:11:35 PM »

As some of you might know there have been a couple of people going around breaking into servers. (Buck Nasty's surf shack being one of them) Recently we have caught a couple of these guys, but I feel we may have found the main culprit behind this.
L 02/08/2010 - 01:17:22: [rcon_lock.smx] Blocking changelevel from '-[Lg]- мвѕυяғзя': 2 "ma_say;rcon_Password hacked"
L 02/08/2010 - 01:17:22: [rcon_lock.smx] Blocking changelevel from '-[Lg]- мвѕυяғзя': 3 "ma_say;rcon_Password hacked"
As you can see our logs have recorded -[Lg]- мвѕυяғзя has attempted to break into our rcon (Thank god for rcon_lock.smx). After doing a check up on this user we have traced it to the user MBSurfer.

He managed to somehow gain access to sourcemod/mani admin and removed all our admins/ banned a bunch of people in our server. (I believe D-Fens saved us from unauthorized plugin uploads, which had happened to us before.)

If there is a global banlist anyone would like to add this too, it will save you alot of trouble before this skiddie attempts to break in using mani/sm upload exploit.
« Last Edit: February 08, 2010, 11:18:21 PM by evolv » Logged

spoz
Hero Member
*****
Online Online

Posts: 1,391


My Tra-la-la.


View Profile WWW
« Reply #1 on: February 08, 2010, 07:13:05 PM »

Dupe thread, just email his ISP's abuse department regarding a unauthorized breach and circumvention of network protection Smile


Also, sup MB
« Last Edit: February 08, 2010, 07:17:17 PM by spoz » Logged


Quote
But if u really wanna see a screwed up map take a look at that greatriver awesome 1... freaked the shit out of me... its like a child molestation adventure.....
evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #2 on: February 08, 2010, 07:17:48 PM »

Dupe thread, just email his ISP's abuse department regarding a unauthorized breach and circumvention of network protection Smile

You make a very good point, I would like to contact MBSurfer before I begin to use drastic measures. Thanks for your help ^^
Logged

spoz
Hero Member
*****
Online Online

Posts: 1,391


My Tra-la-la.


View Profile WWW
« Reply #3 on: February 08, 2010, 07:22:04 PM »

I'll just leave this here.

Quote
843-602-8273


Very Happy
Logged


Quote
But if u really wanna see a screwed up map take a look at that greatriver awesome 1... freaked the shit out of me... its like a child molestation adventure.....
Daaniel
Jr. Member
**
Offline Offline

Posts: 78


View Profile
« Reply #4 on: February 08, 2010, 07:25:47 PM »

http://www.facebook.com/people/Cory-Shaw/565397880

Oh hey there sup Cory.

protip: NEVER give your full name out on a css forum Very Happy
Logged

spoz
Hero Member
*****
Online Online

Posts: 1,391


My Tra-la-la.


View Profile WWW
« Reply #5 on: February 08, 2010, 07:26:18 PM »

http://www.facebook.com/people/Cory-Shaw/565397880

Oh hey there sup Cory.

protip: NEVER give your full name out on a css forum Very Happy
protip: NEVER post your cell on twitter
Logged


Quote
But if u really wanna see a screwed up map take a look at that greatriver awesome 1... freaked the shit out of me... its like a child molestation adventure.....
Ryan_S
SolidSurf Elite
Hero Member
******
Online Online

Posts: 1,870


Z҉A҉L҉G҉O̚̕̚


View Profile
« Reply #6 on: February 08, 2010, 07:26:38 PM »

IP Location Lookup results for 98.122.44.29 in South Carolina
IP Address Region: South Carolina
IP Address City: Myrtle Beach
IP Address Latitude: (33.6985)
IP Address Longtitude: (-78.9032)

Hahahaha Myrtle Beach is such a fun place.
Logged

evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #7 on: February 08, 2010, 07:28:04 PM »

I'll just leave this here.
 

Very Happy

no way lol spoz u so 1337  Thumbs Up
Logged

RazerSurf
SolidSurf Elite
Sr. Member
******
Offline Offline

Posts: 826



View Profile
« Reply #8 on: February 08, 2010, 07:35:19 PM »

I'll just leave this here.
 

Very Happy

wtf is that? : o his phone number or sumethin?
Logged

evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #9 on: February 14, 2010, 03:33:23 PM »

Well another exploit attempt today.
L 02/14/2010 - 10:18:58: rcon from "68.102.137.254:62194": command "say OWNEDBYSKY"
L 02/14/2010 - 10:18:58: "Console<0><Console><Console>" say "OWNEDBYSKY"

I dont know who this is but I got there IP. For any global ban list one might have.
Logged

Paul
Full Member
***
Offline Offline

Posts: 340


Blinky! :D


View Profile
« Reply #10 on: February 14, 2010, 03:52:14 PM »

I think I was there, and I think someone dos attacked the server today...
Logged


evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #11 on: February 14, 2010, 04:12:51 PM »

Yeah its the same old exploit they keep using that allows them to gain rcon access. I am running nearly every single patch you could think of and I still dont know how they managed it  Mad
Logged

spoz
Hero Member
*****
Online Online

Posts: 1,391


My Tra-la-la.


View Profile WWW
« Reply #12 on: February 14, 2010, 05:06:55 PM »

https://forums.alliedmods.net/showthread.php?p=841590
https://forums.alliedmods.net/showthread.php?t=109453
Logged


Quote
But if u really wanna see a screwed up map take a look at that greatriver awesome 1... freaked the shit out of me... its like a child molestation adventure.....
evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #13 on: February 14, 2010, 06:24:23 PM »

We are running both of those + basically every other exploit patch/fix. Including scortchedearth.smx. We have decided to just now completely firewall off the rcon. This is what they are using http://pastebin.com/f78d3e858

and D-Fens does not patch it >< Apparently any servers running Mani or Sourcemod are exploitable.
Logged

evolv
Jr. Member
**
Offline Offline

Posts: 74



View Profile WWW
« Reply #14 on: February 14, 2010, 06:25:07 PM »

also as a note, making files that are accessible through rcon, readme only might patch it.
Logged

silverlol
Full Member
***
Offline Offline

Posts: 348


nut sauce


View Profile
« Reply #15 on: February 14, 2010, 06:43:01 PM »

thanks for announcing this evolv.

and spoz, you sir, are leet as fuck. holy shit.
Logged

silver? lol!
spoz
Hero Member
*****
Online Online

Posts: 1,391


My Tra-la-la.


View Profile WWW
« Reply #16 on: February 14, 2010, 08:02:09 PM »

if you're able to request it from your GSP, change server.cfg to something random like server_lol-hax0rz.cfg and get your GSP to add the +servercfgfile CLS
Logged


Quote
But if u really wanna see a screwed up map take a look at that greatriver awesome 1... freaked the shit out of me... its like a child molestation adventure.....
Arjenlodder
Full Member
***
Offline Offline

Posts: 286


View Profile
« Reply #17 on: February 14, 2010, 08:58:49 PM »

if you're able to request it from your GSP, change server.cfg to something random like server_lol-hax0rz.cfg and get your GSP to add the +servercfgfile CLS

This... is one smart solution! I own a couple of servers myself (never got hacked) and changed it directly :p Thnx.
Anyway, those instruction... are there files too? like a .sp file of the actual sourcemod plugin? If so, could someone link me to it?
Ty Wink Freaking hackers... (BTW, Isn't hacking a server VAC-Bannable?)
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
Akust by Fakdordes
Valid XHTML 1.0! Valid CSS!
Green Web Hosting! This site hosted by DreamHost.