HACKER PROBLEM

Have a question you need to ask? Need help? Ask here!

Moderator: Core Staff

Post Reply
Noobie36
CJ Wannabe
CJ Wannabe
Posts: 4
Joined: January 10th, 2011, 10:57 pm

HACKER PROBLEM

Post by Noobie36 » January 11th, 2011, 3:01 pm

I've got a homemad server with redirect download, but my problem is that i don't know how to protect it very well. There is a programm that dowloand your server server.cfg file from my computer. In that he can find my rcon pw.
I know i can put download of but then people won't be able to download my mod:(. Do you know how I can fix this?
set sv_allowdownload "1"
seta sv_wwwDownload "1"
seta sv_wwwBaseURL "http://xxx.xxx.xxx/xxx"
seta sv_wwwDlDisconnected "0"
seta sv_dl_maxRate "42000"
Ty alot of someone can help me

Noobie36
CJ Wannabe
CJ Wannabe
Posts: 4
Joined: January 10th, 2011, 10:57 pm

Re: HACKER PROBLEM

Post by Noobie36 » January 11th, 2011, 3:14 pm

I allready have the solution if anyone is interrested i will give it.

Pedsdude
Site Admin
Site Admin
Posts: 15909
Joined: October 15th, 2004, 7:18 pm
Location: UK

Re: HACKER PROBLEM

Post by Pedsdude » January 11th, 2011, 3:35 pm

Image
Image

F |Madness| U
CJ G0D!
CJ G0D!
Posts: 1575
Joined: June 3rd, 2009, 9:02 pm
Location: Cardiff University, UK

Re: HACKER PROBLEM

Post by F |Madness| U » January 17th, 2011, 8:52 pm

In regards to that thread, the OP stated there isn't a fix for it.

There is a fix on aluigi.org (he has patches, exploits fixes and such for a HUGE variety of games), which just slightly changes a few bytes in your exec file using lpatch. Also has fixes for server crash bugs, which 1.7 servers are still vulnerable to.
-

IzNoGoD
CJ Worshipper
CJ Worshipper
Posts: 343
Joined: January 6th, 2009, 8:39 pm
Location: Netherlands/Holland

Re: HACKER PROBLEM

Post by IzNoGoD » January 17th, 2011, 9:46 pm

in cod2 it just works when you turn sv_allowdownload to 0
but then you need a wwwredirect, but that doesnt seems to be the problem with cod4.
LMGTFY!

Its not a glitch... Its the future!

User avatar
Drofder2004
Core Staff
Core Staff
Posts: 13313
Joined: April 13th, 2005, 8:22 pm
Location: UK, London

Re: HACKER PROBLEM

Post by Drofder2004 » January 18th, 2011, 12:13 am

xSnipeZx wrote:In regards to that thread, the OP stated there isn't a fix for it.
In regards to your reading of that thread, 4 solutions have been given.
- Use a redirect for downloads and only turn on "www" downloads.
- Change your command line for starting the server to add "+rcon_password your_password"
- Change your command line and config to a random filename "+exec asdfgh.cfg"
- Manually enter a new RCON password AFTER the server has started.
Image
Virgin Media 20Mb Broadband:
"Perfect for families going online at the same time, downloading movies, online gaming and more."
Borked internet since: 22-07-2010

F |Madness| U
CJ G0D!
CJ G0D!
Posts: 1575
Joined: June 3rd, 2009, 9:02 pm
Location: Cardiff University, UK

Re: HACKER PROBLEM

Post by F |Madness| U » January 18th, 2011, 9:13 pm

Drofder2004 wrote:
xSnipeZx wrote:In regards to that thread, the OP stated there isn't a fix for it.
In regards to your reading of that thread, 4 solutions have been given.
- Use a redirect for downloads and only turn on "www" downloads.
- Change your command line for starting the server to add "+rcon_password your_password"
- Change your command line and config to a random filename "+exec asdfgh.cfg"
- Manually enter a new RCON password AFTER the server has started.
None of these FIX it though. (Turning off www downloads should prevent it in all cases, but many people need it on for mods/custom maps).

With all of those applied you can still download other cfgs and text files that could be potentially useful for a hacker- not going to name with ones.

The FIX actually changes the Server exec file, and files cannot be downloaded from the server in this way. (You can still have normal downloads working fine etc).
-

IzNoGoD
CJ Worshipper
CJ Worshipper
Posts: 343
Joined: January 6th, 2009, 8:39 pm
Location: Netherlands/Holland

Re: HACKER PROBLEM

Post by IzNoGoD » January 18th, 2011, 9:32 pm

sv_allowdownload 0 should fix the downloading from the server.
Then,
sv_wwwdownload 1 should allow users to download from the www mirror, specified in
sv_wwwbasurl
LMGTFY!

Its not a glitch... Its the future!

User avatar
Drofder2004
Core Staff
Core Staff
Posts: 13313
Joined: April 13th, 2005, 8:22 pm
Location: UK, London

Re: HACKER PROBLEM

Post by Drofder2004 » January 19th, 2011, 9:03 pm

xSnipeZx wrote:The FIX actually changes the Server exec file, and files cannot be downloaded from the server in this way. (You can still have normal downloads working fine etc).
It may not be a fix, but it IS a solution.
All of those WILL prevent you from using the exploit.

Find me ONE good quality Game Server Provider who is going to willingly let you upload a cracked EXE file...

The only REAL fix, is an official release, everything else, is a solution.
Image
Virgin Media 20Mb Broadband:
"Perfect for families going online at the same time, downloading movies, online gaming and more."
Borked internet since: 22-07-2010

F |Madness| U
CJ G0D!
CJ G0D!
Posts: 1575
Joined: June 3rd, 2009, 9:02 pm
Location: Cardiff University, UK

Re: HACKER PROBLEM

Post by F |Madness| U » January 19th, 2011, 10:12 pm

Drofder2004 wrote: It may not be a fix, but it IS a solution.
All of those WILL prevent you from using the exploit.
Only the sv_allowdownload one prevents people from using the exploit, you can still download other files off of the server from any of the other `solutions` (unless of course they rename every file to something unguessable).
Drofder2004 wrote: Find me ONE good quality Game Server Provider who is going to willingly let you upload a cracked EXE file...
Gameservers.com. -And its not a cracked EXE file (well I don't know the sure definition of cracked, but I know it doesn't create a cracked server, meaning no fake keys can use it).
Drofder2004 wrote: The only REAL fix, is an official release, everything else, is a solution.
[/quote]

It is a real fix, if IW did decide to make a fix for it (which they obviously havn't) it would be along the lines of changing the executable anyway I assume, which is what this fix does.
-

User avatar
Drofder2004
Core Staff
Core Staff
Posts: 13313
Joined: April 13th, 2005, 8:22 pm
Location: UK, London

Re: HACKER PROBLEM

Post by Drofder2004 » January 20th, 2011, 12:23 am

xSnipeZx wrote:...
To avoid a long post of excalated opinion, I leave you with this.

All 4 suggested solutions will stop your rcon from being hacked. If you do not want somebody to get access to any server file, turn off your server downloading.
Image
Virgin Media 20Mb Broadband:
"Perfect for families going online at the same time, downloading movies, online gaming and more."
Borked internet since: 22-07-2010

F |Madness| U
CJ G0D!
CJ G0D!
Posts: 1575
Joined: June 3rd, 2009, 9:02 pm
Location: Cardiff University, UK

Re: HACKER PROBLEM

Post by F |Madness| U » January 20th, 2011, 12:28 am

Partially agree.
-

Pedsdude
Site Admin
Site Admin
Posts: 15909
Joined: October 15th, 2004, 7:18 pm
Location: UK

Re: HACKER PROBLEM

Post by Pedsdude » January 20th, 2011, 2:49 am

lol'd.
Image
Image

Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests