Author Topic: Rcon command without Rcon. Interesting.  (Read 4020 times)

BeerBastard

  • Posts: 276
  • Turrets: +25/-21
    • Home of [OPP]
Rcon command without Rcon. Interesting.
« on: February 27, 2007, 06:17:31 am »
Ok we had a griefer come into the game.  And set us past stage 3, meaning nothing can be built, no one can evolve and it says you have no eggs. I set us back after kicking the known griefer.

I thought the only way to do this is with rcon g_humanstage and g_alienstage
Which require you to know rcon password.  

How do you do this without rcon? We just changed our rcon password, and it happened again.  If its a bug, is there a fix? It happened again when the griefer came back the 2nd time.
Feeling Oppressed?
You Down with [OPP]?


-[OPP]Beerbastard

dodo1122

  • Posts: 160
  • Turrets: +0/-0
Rcon command without Rcon. Interesting.
« Reply #1 on: February 27, 2007, 09:25:49 am »
maybe he hax00r'd to the machine running your server and just looked in server.cfg? :P



dodo
nime & manga fan <3

Currently learning the fine art of programming in c++
Currently on holidays (will be back @ 24/08/07 )

DoorKnob

  • Posts: 88
  • Turrets: +0/-0
    • http://noobs4boobs.free.fr
Rcon command without Rcon. Interesting.
« Reply #2 on: February 27, 2007, 11:47:11 am »
i've also had this happen, he would come in, change all the server setttings thrn i'd kick him, but before i know that he was doing it, i was going crazy cause i'm the only with rcon, but he told me it was him and told me he uses leeches to hax my server.... Perm ban :P
roud Ex-Leader of the Mighty UVache!

Odin

  • Spam Killer
  • *
  • Posts: 1767
  • Turrets: +113/-204
    • My Website
Rcon command without Rcon. Interesting.
« Reply #3 on: February 27, 2007, 03:47:57 pm »
Maybe he knew the password?

Caveman

  • Guest
Rcon command without Rcon. Interesting.
« Reply #4 on: February 27, 2007, 04:05:40 pm »
Most server I've seen this happening on do offer maps via a webserver and link their /base in order to save some time in setting up, not realizing that they give read-access to their confs...

vcxzet

  • Guest
Rcon command without Rcon. Interesting.
« Reply #5 on: February 27, 2007, 04:20:55 pm »
type
/class level4
/name blah

DASPRiD

  • Administrator
  • Posts: 549
  • Turrets: +21/-2
    • http://www.dasprids.de
Rcon command without Rcon. Interesting.
« Reply #6 on: February 27, 2007, 04:54:15 pm »
Quote from: "Caveman"
Most server I've seen this happening on do offer maps via a webserver and link their /base in order to save some time in setting up, not realizing that they give read-access to their confs...


I did nearly the same. It's quite simple:

Code: [Select]

#Tremulous map download
<VirtualHost>
  ServerName tremulous.servers.dasprids.de
  DocumentRoot /srv/www/tremulous/

  AliasMatch ^/(.*)\.pk3$ /usr/local/games/tremulous/$1.pk3

  <directory>
    Allow from all
  </directory>

  <directory>
    Allow from all

    Options +Indexes
  </directory>
</VirtualHost>


-edit-
Gnaa, damn forum, here's the right paste:
http://pastebin.us/15387
url=https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=mail%40dasprids%2ede&item_name=DASPRiD%27s&no_shipping=0&no_note=1&tax=0&currency_code=EUR&lc=DE&bn=PP%2dDonationsBF&charset=UTF%2d8][/url]

BeerBastard

  • Posts: 276
  • Turrets: +25/-21
    • Home of [OPP]
Rcon command without Rcon. Interesting.
« Reply #7 on: February 27, 2007, 07:32:04 pm »
We used the mg mappack so we linked that from our forums, We didnt link our server base folder.
Feeling Oppressed?
You Down with [OPP]?


-[OPP]Beerbastard

beerbitch

  • Posts: 195
  • Turrets: +11/-19
Rcon command without Rcon. Interesting.
« Reply #8 on: February 27, 2007, 07:45:31 pm »
Quote from: "DoorKnob"
i've also had this happen, he would come in, change all the server setttings thrn i'd kick him, but before i know that he was doing it, i was going crazy cause i'm the only with rcon, but he told me it was him and told me he uses leeches to hax my server.... Perm ban :P


What do you mean by "leeches" ?? You mean the naruto downloaders that got the gnaa fake fansub ? Maybe they were trojaned, but I don't see how a denial of service attack on a q3 based engine server gives them rcon........


I want to know how somebody without rcon password, and without access to the files on the server can bump aliens to s4.
Beerbitch - "Some days you're the pigeon, other days you're the statue"