Author Topic: Security Breach -Biggest in Trem History?  (Read 29321 times)

Rawr

  • Posts: 918
  • Turrets: +1/-1
Security Breach -Biggest in Trem History?
« on: February 15, 2007, 04:48:20 pm »
Quote from: Mario
As of Feb. 14, 2007 i've been informed that a Server Operator by the name of Pol (the one who controls the S11 Info server) has been !setleveling certain players with GUID's to gain access to their servers using their own GUID's. Because I was setleveled on his server, my GUID has been compromised and i've had no choice but to !setlevel myself to 0 for the time being. Servers across Tremulous have been attacked due to compromised GUID's of admins and operators. If you've been setleveled on his server then let me know immediately. I'll come back with more details soon to follow.



Pol has been stealing GUID's from who ever goes onto his server. My suggestion to you, Change your RCON, get a new GUID.

Note: The Dev's have been informed of this.
img]http://dvclan.org/statsig/statsig.php/3826/4.jpg[/img]

Smokey

  • Posts: 793
  • Turrets: +23/-58
    • Zilla Clan
Re: Security Breach -Biggest in Trem History?
« Reply #1 on: February 15, 2007, 05:29:41 pm »
Quote from: "bazuka_poo"
Quote from: Mario
As of Feb. 14, 2007 i've been informed that a Server Operator by the name of Pol (the one who controls the S11 Info server) has been !setleveling certain players with GUID's to gain access to their servers using their own GUID's. Because I was setleveled on his server, my GUID has been compromised and i've had no choice but to !setlevel myself to 0 for the time being. Servers across Tremulous have been attacked due to compromised GUID's of admins and operators. If you've been setleveled on his server then let me know immediately. I'll come back with more details soon to follow.



Pol has been stealing GUID's from who ever goes onto his server. My suggestion to you, Change your RCON, get a new GUID.

Note: The Dev's have been informed of this.

He can't get your rcon password just by knowing your guid, and this is not at all new. Popupman has been known to do it for a while.

vcxzet

  • Guest
Security Breach -Biggest in Trem History?
« Reply #2 on: February 15, 2007, 06:09:56 pm »
lol
and I thought I was evil

-:GoDz:-Devil

  • Guest
Security Breach -Biggest in Trem History?
« Reply #3 on: February 15, 2007, 07:36:28 pm »
LOL he setlevel me, but I change my GUID ID daily, so I have np with it, and also, I am working on something that will change my guid I everytime I start trem and keep logs of all the guid's I use. I will keep you updated.

Smokey

  • Posts: 793
  • Turrets: +23/-58
    • Zilla Clan
Security Breach -Biggest in Trem History?
« Reply #4 on: February 15, 2007, 07:50:59 pm »
Quote from: "-:GoDz:-Devil"
LOL he setlevel me, but I change my GUID ID daily, so I have np with it, and also, I am working on something that will change my guid I everytime I start trem and keep logs of all the guid's I use. I will keep you updated.


Well, isn't that just pointless.

vcxzet

  • Guest
Security Breach -Biggest in Trem History?
« Reply #5 on: February 15, 2007, 08:18:03 pm »
Quote from: "Smokey"
Quote from: "-:GoDz:-Devil"
LOL he setlevel me, but I change my GUID ID daily, so I have np with it, and also, I am working on something that will change my guid I everytime I start trem and keep logs of all the guid's I use. I will keep you updated.


Well, isn't that just pointless.

pointless as hell
looks like he is not admin anywhere :D

yesterday was one of my better days
ip spoofing and guid take over

you should be thankful to polly This guid thing was known before but tjw didnt care till polly exploited it like crazy. then tjw fixed it . ie guid per server solution. and tjw also released the new binaries for using this

ip spoofing was something I was using( and I thought it did not work :P). Untill polly told me it is actually working. Then he reported to r1ch -> tjw fixed

actually he is useful to community. highly flamable though :P

David

  • Spam Killer
  • *
  • Posts: 3543
  • Turrets: +249/-273
Security Breach -Biggest in Trem History?
« Reply #6 on: February 15, 2007, 09:44:24 pm »
Was he using his server S11 to get the GUIDs?
If so it should be permanently de-listed.
Just ban is IP from the master server. That'll teach him.
Any maps not in the MG repo?  Email me or come to irc.freenode.net/#mg.
--
My words are mine and mine alone.  I can't speak for anyone else, and there is no one who can speak for me.  If I ever make a post that gives the opinions or positions of other users or groups, then they will be clearly labeled as such.
I'm disappointed that people's past actions have forced me to state what should be obvious.
I am not a dev.  Nothing I say counts for anything.

-:GoDz:-Devil

  • Guest
Security Breach -Biggest in Trem History?
« Reply #7 on: February 15, 2007, 10:14:57 pm »
Quote from: "Smokey"
Quote from: "-:GoDz:-Devil"
LOL he setlevel me, but I change my GUID ID daily, so I have np with it, and also, I am working on something that will change my guid I everytime I start trem and keep logs of all the guid's I use. I will keep you updated.


Well, isn't that just pointless.


Na its not pointless, if you understood what I was doing you would get it.

David

  • Spam Killer
  • *
  • Posts: 3543
  • Turrets: +249/-273
Security Breach -Biggest in Trem History?
« Reply #8 on: February 15, 2007, 10:22:12 pm »
Quote from: "-:GoDz:-Devil"
LOL he setlevel me, but I change my GUID ID daily, so I have np with it, and also, I am working on something that will change my guid I everytime I start trem and keep logs of all the guid's I use. I will keep you updated.


I was going to do that, but then TJW fixed it, so problem solved!
Any maps not in the MG repo?  Email me or come to irc.freenode.net/#mg.
--
My words are mine and mine alone.  I can't speak for anyone else, and there is no one who can speak for me.  If I ever make a post that gives the opinions or positions of other users or groups, then they will be clearly labeled as such.
I'm disappointed that people's past actions have forced me to state what should be obvious.
I am not a dev.  Nothing I say counts for anything.

FooBar

  • Posts: 94
  • Turrets: +9/-1
    • http://avalanche.server.googlepages.com
Security Breach -Biggest in Trem History?
« Reply #9 on: February 15, 2007, 10:54:42 pm »
Just out of curiosity, why does the website for Pol's server (s11.info) redirect to (or at least display a copy of) tremulous.tjw.org?  That seems a little odd.

vcxzet

  • Guest
Security Breach -Biggest in Trem History?
« Reply #10 on: February 15, 2007, 11:03:28 pm »
Quote from: "FooBar"
Just out of curiosity, why does the website for Pol's server (s11.info) redirect to (or at least display a copy of) tremulous.tjw.org?  That seems a little odd.

he is using tjw's stats php

DieFamilyGuy

  • Posts: 138
  • Turrets: +1/-0
Re: Security Breach -Biggest in Trem History?
« Reply #11 on: February 15, 2007, 11:30:44 pm »
Quote from: "bazuka_poo"
Quote from: Mario
As of Feb. 14, 2007 i've been informed that a Server Operator by the name of Pol (the one who controls the S11 Info server) has been !setleveling certain players with GUID's to gain access to their servers using their own GUID's. Because I was setleveled on his server, my GUID has been compromised and i've had no choice but to !setlevel myself to 0 for the time being. Servers across Tremulous have been attacked due to compromised GUID's of admins and operators. If you've been setleveled on his server then let me know immediately. I'll come back with more details soon to follow.



Pol has been stealing GUID's from who ever goes onto his server. My suggestion to you, Change your RCON, get a new GUID.

Note: The Dev's have been informed of this.





pol....hmm i recognize that name....yeah he used to come on beer garden, knew something was fishy about him
URL=http://imageshack.us][/URL]
-It takes no skill to use a chaingun. It takes plenty of skill to master it.

Stof

  • Posts: 1343
  • Turrets: +1/-1
Security Breach -Biggest in Trem History?
« Reply #12 on: February 15, 2007, 11:38:16 pm »
Don't worry about RCON, they cannot be directly compromised like that. No need to be (more) paranoïd than required.

Although the RCON password might be compromised if you gave it away to a hacker you though was a friend because he was using your friend GUID.
urphy's rules of combat
8 ) Teamwork is essential; it gives the enemy someone else to shoot at.
18 ) Make it too tough for the enemy to get in and you can't get out.

TinMan

  • Posts: 1019
  • Turrets: +49/-70
    • http://neonpulse.net
Security Breach -Biggest in Trem History?
« Reply #13 on: February 15, 2007, 11:51:37 pm »
For those of you who need a new GUID, go into your tremulous/base/ and delete your QKEY file, the next time you play tremulous a new one will be generated and you will then have a new GUID.
Code: [Select]
Linux: ~/.tremulous/base/
Mac: ~/Library/Application\ Support/Tremulous/base/
Windows: C:\Documents and Settings\username\Local Settings\Application Data\Tremulous\base\
NeonPulse
http://neonpulse.net/media/games/tremulous/base/autoexec.cfg

Caveman

  • Guest
Security Breach -Biggest in Trem History?
« Reply #14 on: February 15, 2007, 11:53:45 pm »
If Pol(ly) knew his stuff then he also has the passwords for priv-slots if the player did not unset it when they did not need it ...

Caveman

  • Guest
Security Breach -Biggest in Trem History?
« Reply #15 on: February 16, 2007, 06:30:16 am »
ok :)

pollywannacrkr

  • Posts: 1
  • Turrets: +0/-0
Security Breach -Biggest in Trem History?
« Reply #16 on: February 16, 2007, 06:34:38 am »
Quote from: "Caveman"
stop that


o dam caveman ur hired.
ttp://lewl2u.freehostia.com/pollywannacracker.txt

Caveman

  • Guest
Security Breach -Biggest in Trem History?
« Reply #17 on: February 16, 2007, 07:14:42 am »
Allways cite the source :P

FooBar

  • Posts: 94
  • Turrets: +9/-1
    • http://avalanche.server.googlepages.com
Security Breach -Biggest in Trem History?
« Reply #18 on: February 16, 2007, 08:32:38 am »
Not that I have any affection for Pol at all, but I want to be the first to suggest that the moderators take down this information.  This kind of harassment is not acceptable.

Stof

  • Posts: 1343
  • Turrets: +1/-1
Security Breach -Biggest in Trem History?
« Reply #19 on: February 16, 2007, 10:04:49 am »
Oh, was that harassement? It looked like spam so I kinda deleted it on sight :p

Don't go posting other users personal info here!
urphy's rules of combat
8 ) Teamwork is essential; it gives the enemy someone else to shoot at.
18 ) Make it too tough for the enemy to get in and you can't get out.

Caveman

  • Guest
Security Breach -Biggest in Trem History?
« Reply #20 on: February 16, 2007, 01:54:16 pm »
Information, freely available on Google, can't be harassment .) but if it's not wanted.... ok :)

FooBar

  • Posts: 94
  • Turrets: +9/-1
    • http://avalanche.server.googlepages.com
Security Breach -Biggest in Trem History?
« Reply #21 on: February 16, 2007, 02:51:46 pm »
Well, maybe not harassment, but perhaps it's incitement to harassment.  :)

vcxzet

  • Guest
Security Breach -Biggest in Trem History?
« Reply #22 on: February 16, 2007, 02:54:41 pm »
Quote from: "Stof"
Oh, was that harassement? It looked like spam so I kinda deleted it on sight :p

Don't go posting other users personal info here!

we should all stay as Unfunny Anonymous Cowards
as stated in Interwebs rule number 2

Stof

  • Posts: 1343
  • Turrets: +1/-1
Security Breach -Biggest in Trem History?
« Reply #23 on: February 16, 2007, 03:16:54 pm »
Quote from: "vcxzet"
Quote from: "Stof"
Oh, was that harassement? It looked like spam so I kinda deleted it on sight :p

Don't go posting other users personal info here!

we should all stay as Unfunny Anonymous Cowards
as stated in Interwebs rule number 2

Do you mean that you are "pollywannacrkr"?

Btw, that account is posting from http://hidemyass.com/ and I sure bet it has been created specialy for those posts.
urphy's rules of combat
8 ) Teamwork is essential; it gives the enemy someone else to shoot at.
18 ) Make it too tough for the enemy to get in and you can't get out.

khalsa

  • Administrator
  • Posts: 597
  • Turrets: +187/-132
    • http://www.mercenariesguild.net
Security Breach -Biggest in Trem History?
« Reply #24 on: February 16, 2007, 03:59:29 pm »
While I am opposed to the posting of polly's personal info here, I dont think ANYONE is going to feel sorry for you at this point.

Screw around with a tight-knit community - what do you think is going to happen? Especially when you have your whole life on google.

Pol: if your reading this i'd strongly suggest you stop whatever it is you're doing and apologize to those you've hurt. You may not realize, but people on the internet are crazy, and may do something "unfixable" to you.

A simple disagreement or misunderstanding (or ban for spamming) should not be grounds to permanently hurt someone.

Now basically everyone has your e-mail(s) so i'd simply suggest that if you have a problem wih you, to e-mail you or contact you otherwise to discuss these matters.

Lastly: I Strongly suggest that NO ONE go to the S11 server until everything is resolved, if even that.

Khalsa
}MG{ Mercenariesguild
ਮਨੁ ਜੀਤੇ ਜਗੁ ਜੀਤਿਆ

CU|CUdyin

  • Posts: 29
  • Turrets: +0/-0
    • http://www.cu-clan.net
Security Breach -Biggest in Trem History?
« Reply #25 on: February 16, 2007, 05:35:58 pm »
IMO, every person who is farming full GUIDs is even worse than every deconner, so he/she/it should get banned from the master-server, if the whole thing can be proved.

Nevertheless, I've been once on S11, so I already changed my GUID (at least temporary).

Pol

  • Guest
Security Breach -Biggest in Trem History?
« Reply #26 on: February 16, 2007, 07:43:03 pm »
Noob Thread -Biggest in Trem History?

NOPE! GUESS WHAT, I AM!

gareth

  • Posts: 710
  • Turrets: +38/-89
Security Breach -Biggest in Trem History?
« Reply #27 on: February 16, 2007, 07:57:32 pm »
Quote from: "Pol"
Noob Thread -Biggest in Trem History?

It is now.

FooBar

  • Posts: 94
  • Turrets: +9/-1
    • http://avalanche.server.googlepages.com
Security Breach -Biggest in Trem History?
« Reply #28 on: February 16, 2007, 09:12:17 pm »
Hey, Pol-- wondering when or whether you'd drop in here.

I'm curious, I'd like to know your side of the story.  I've seen a good amount of evidence from the other side suggesting that you basically took over another server by means of a stolen GUID.  I'm just wondering if you have another side to present: was it not you?  Was it someone totally different and you're the scapegoat?  Was it someone else with your IP or your computer?  Or have your actions been misrepresented?

Or did you do exactly what you were accused of, but for a legitimate reason?  I can't imagine a legitimate reason, but if you think you've got one I'd love to hear it.

Rather than throwing around bootless insults, why don't you enlighten us with your side of the story?

Pol

  • Guest
Security Breach -Biggest in Trem History?
« Reply #29 on: February 16, 2007, 09:42:51 pm »
My side of the story?

Basically, it's fully expressed in my last post.

If you want more than that:

My side of the story is that it wouldn't really matter if I say it was me, not me, you, raWr, or anybody else.  Who would ever know with 100% certainty ?

I'm the S11.Info operator.  I maintain this server for the entertainment of myself, and the individuals who choose to play there.

I am not rapt in acting maliciously against any of my server's guests, or those of another server, or other server admins.

Tremulous's current GUID / ip userinfo system is obviously flawed.  Even tjw's latest 'new guid per server' hack is hardly worthy of the effort.  It needs a complete re haul, so I'd suggest to however's pissy at me for whatever reason would best to redirect their angst at someone like tjw, timbo, or careless server operators/admins.

By the way, pumpkin seeds are apparently good for the prostate.