Author Topic: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED  (Read 7598 times)

Volt

  • Posts: 256
  • Turrets: +66/-54
IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« on: August 11, 2008, 10:12:10 am »
There is some one who's dosing tremulous servers rcon.
I first came across this problem when hibby(owner of aa) asked me to look into a non responsive rcon issue.
at first changing out the server.cfg worked but soon after rcon became unresponsive again.
Then from word of mouth i learned archangel was dosing aa servers rcon, contacted maverick(noghost) host of aa, he handled problem by calling isp ect.... all that good junk.

around 4am the same day a server i run 000000.> began getting this from my attached console.

Bad rcon from 201.233.109.48:1661:
Bad rcon from 201.233.109.48:1661:

This is just a warning to other server owners espically those who host and use web ftp and web rcon, if you're experiencing rcon failure it might be because of an attack on your server.
« Last Edit: August 11, 2008, 10:17:44 am by Volt »

NiTRoX

  • Posts: 1453
  • Turrets: +41/-200
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #1 on: August 11, 2008, 10:24:52 am »
I say ban,sue and fuck the motherfucker.

Archangel

  • Guest
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #2 on: August 12, 2008, 05:06:36 am »
There is some one who's dosing tremulous servers rcon.
I first came across this problem when hibby(owner of aa) asked me to look into a non responsive rcon issue.
at first changing out the server.cfg worked but soon after rcon became unresponsive again.
Then from word of mouth i learned archangel was dosing aa servers rcon, contacted maverick(noghost) host of aa, he handled problem by calling isp ect.... all that good junk.

around 4am the same day a server i run 000000.> began getting this from my attached console.

Bad rcon from 201.233.109.48:1661:
Bad rcon from 201.233.109.48:1661:

This is just a warning to other server owners espically those who host and use web ftp and web rcon, if you're experiencing rcon failure it might be because of an attack on your server.

Yeah, cause I totally live in South America.

plasma@ceylon ~ (55) %  host 201.233.109.48
48.109.233.201.in-addr.arpa domain name pointer cable201-233-109-48.epm.net.co.

duck-o-destruction

  • Posts: 176
  • Turrets: +12/-55
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #3 on: August 12, 2008, 12:48:39 pm »
i believe u have programs like q3u unban that give u static ip's.   Snake said something about a program that spammed said server w/ bots.  maybe net_socks?
:grenade:

David

  • Spam Killer
  • *
  • Posts: 3543
  • Turrets: +249/-273
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #4 on: August 12, 2008, 01:02:05 pm »
rcon source IP can be spoofed if you don't care about seeing the response, but any vaguely competent ISP would not let you do such things.
Playing with a spoof IP is impossible, as is bot spam or anything else.
Any maps not in the MG repo?  Email me or come to irc.freenode.net/#mg.
--
My words are mine and mine alone.  I can't speak for anyone else, and there is no one who can speak for me.  If I ever make a post that gives the opinions or positions of other users or groups, then they will be clearly labeled as such.
I'm disappointed that people's past actions have forced me to state what should be obvious.
I am not a dev.  Nothing I say counts for anything.

Archangel

  • Guest
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #5 on: August 13, 2008, 01:09:05 am »
i believe u have programs like q3u unban that give u static ip's.   Snake said something about a program that spammed said server w/ bots.  maybe net_socks?

net_socks is a cvar built into the Q3 engine -- it's available only on windows.

cactusfrog

  • Posts: 390
  • Turrets: +678/-176
    • tremulous fun server offical site
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #6 on: August 15, 2008, 09:57:01 am »
as soon as your rcon becomes responsive change it by typing /rcon ******** rconpassword ****

Death On Ice

  • Posts: 1287
  • Turrets: +126/-141
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #7 on: August 17, 2008, 06:20:16 pm »
as soon as your rcon becomes responsive change it by typing /rcon ******** rconpassword ****
That's not the point. Well, the person could be brute-forcing, but it seems to me that they're just trying to disable the rcon.

Also, I know rconip (or something) can be used to rcon into a server without being present, but does it avoid bans?

Zero

  • Posts: 129
  • Turrets: +5/-19
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #8 on: August 17, 2008, 06:52:42 pm »
Eh, you might as well use SubSeven to get into your computer and watch your screen until you type it in.

benmachine

  • Posts: 915
  • Turrets: +99/-76
    • ben's machinery
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #9 on: August 17, 2008, 08:59:35 pm »
Also, I know rconip (or something) can be used to rcon into a server without being present, but does it avoid bans?

Yes. rcon is handled by the server, which doesn't know about g_admin in most cases.
benmachine

David

  • Spam Killer
  • *
  • Posts: 3543
  • Turrets: +249/-273
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #10 on: August 17, 2008, 09:47:20 pm »
Also, ssh+screen makes rcon obsolete.
Any maps not in the MG repo?  Email me or come to irc.freenode.net/#mg.
--
My words are mine and mine alone.  I can't speak for anyone else, and there is no one who can speak for me.  If I ever make a post that gives the opinions or positions of other users or groups, then they will be clearly labeled as such.
I'm disappointed that people's past actions have forced me to state what should be obvious.
I am not a dev.  Nothing I say counts for anything.

Death On Ice

  • Posts: 1287
  • Turrets: +126/-141
Re: IMPORTANT NOTICE IF YOUR SERVER IS HOSTED
« Reply #11 on: August 18, 2008, 04:34:22 pm »
Also, ssh+screen makes rcon obsolete.

Well, obviously so. You're literally controlling the terminal the server is running, so you can see messages, errors, etc.
None of those are achievable with rcon.