07-01-2009, 04:57 PM | #1 | ||
FF Whiner
Server Owner
Beta Tester Join Date: Sep 2007
Location: Chair.. sometimes a couch
Class/Position: D Engy, D Soldier Gametype: Capture the Flag Posts Rated Helpful 1 Times
|
Servers under attack and crashing
Greetings,
It seems there's someone from the ip address 75.108.37.173 sending false rcon attempts to my server. Normally, this wouldn't even catch my attention yet my servers are suddenly crashing after getting 15 (or more) of the "bad rcon password for 75.108.37.173" on my console. Quote:
Anyone happen to have any idea who / what this ip leads to? My pc can ping the address and gets a 139ms signal yet not dns entries seems to be available... Trace results: Quote:
Last edited by Rawh; 07-01-2009 at 05:05 PM. |
||
|
07-01-2009, 05:08 PM | #2 |
FF Whiner
Server Owner
Beta Tester Join Date: Sep 2007
Location: Chair.. sometimes a couch
Class/Position: D Engy, D Soldier Gametype: Capture the Flag Posts Rated Helpful 1 Times
|
http://cqcounter.com/whois/ is able to give more detailed info about the ip.
|
|
07-01-2009, 06:28 PM | #3 |
Retired FF Staff
Join Date: Mar 2007
Posts Rated Helpful 0 Times
|
Could be just a proxy nah?
|
|
07-01-2009, 07:52 PM | #4 |
Retired FF Staff
Join Date: Mar 2007
Posts Rated Helpful 0 Times
|
Change the max number of rcon failures to 2 thats a rcon exploit that was just discovered, see this thread http://forums.alliedmods.net/showthread.php?t=96069.
__________________
I Love GenghisTron . I miss you sooooo Much. LOL. |
|
07-02-2009, 12:58 AM | #5 |
Community Member
Server Owner
Beta Tester Forum Moderator Join Date: Mar 2007
Location: Hawthorne, California
Class/Position: Soldier/Spy/Scout Gametype: AvD Affiliations: :e0:Eternal Order Leader Posts Rated Helpful 12 Times
|
That ip did not match anyone on these forums
__________________
|
|
07-02-2009, 05:59 AM | #6 |
Retired FF Staff
Join Date: Mar 2007
Posts Rated Helpful 0 Times
|
__________________
I Love GenghisTron . I miss you sooooo Much. LOL. Last edited by [AE] 82694; 07-02-2009 at 06:02 AM. |
|
07-03-2009, 07:45 AM | #7 |
FF Whiner
Server Owner
Beta Tester Join Date: Sep 2007
Location: Chair.. sometimes a couch
Class/Position: D Engy, D Soldier Gametype: Capture the Flag Posts Rated Helpful 1 Times
|
Hlstriker made a plugin which removes the max value for sv_rcon_maxfailures. You can now set the value as high as 999999 which in turn seems to stop the crash attacks (hopefully).
More info about it on the alliedmods forum. |
|
07-03-2009, 08:39 AM | #8 |
Keep On Keepin' On
|
That doesn't sound like a very good fix.... they'll be able to just bruteforce the password, if they want to.
Last edited by PartialSchism; 07-03-2009 at 08:40 AM. |
|
07-03-2009, 08:57 AM | #9 |
FF Whiner
Server Owner
Beta Tester Join Date: Sep 2007
Location: Chair.. sometimes a couch
Class/Position: D Engy, D Soldier Gametype: Capture the Flag Posts Rated Helpful 1 Times
|
Sure, if valve would just fix it themselfs, it would be better. But since the bug / exploit seems to be already more then 6 months old and valve being an arse about it not being an exploit, in their eyes... well I guess you could say this would be a temp-fix.
And if people want to bruteforce my empty rcon_password field I wish them the best of luck Last edited by Rawh; 07-03-2009 at 08:57 AM. |
|
07-03-2009, 04:33 PM | #10 |
Retired FF Staff
Join Date: Mar 2007
Posts Rated Helpful 0 Times
|
Your welcome for pointing you in the right direction again Rawh.
__________________
I Love GenghisTron . I miss you sooooo Much. LOL. |
|
07-04-2009, 12:26 PM | #11 |
FF Whiner
Server Owner
Beta Tester Join Date: Sep 2007
Location: Chair.. sometimes a couch
Class/Position: D Engy, D Soldier Gametype: Capture the Flag Posts Rated Helpful 1 Times
|
|
|
07-07-2009, 07:38 PM | #12 |
SGM Division ******
Wiki Team
|
A plug-in which helps combat the rcon exploit and that also stops several other exploits (which we will leave unnamed) has been made by devicenull and can be downloaded here.
__________________
[SG-X] Clan - SGM Division leader ICQ #: 154706095 * E-mail * IRC: irc.gamesurge.net #sgm & #[sg-x] |
|
07-08-2009, 01:11 AM | #13 | |
QUAD ROCKET
Server Owner
Fortress Forever Staff Join Date: Jul 2007
Class/Position: Soldier Gametype: Rocket Jumping Affiliations: -g1 ]qS[ -eC- :e0: [ESAD] Posts Rated Helpful 11 Times
|
Quote:
|
|
|
07-08-2009, 02:08 AM | #14 |
Keep On Keepin' On
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|