View Full Version : Rcon Hacked from Server
Shakall
02-26-2010, 11:47 AM
Hello people.
I Have an cod2 server whit PAM Mode 2.03 but a problem.
Somebody hacking my Server over the rcon because they change the name of the server and all settings give he free.
I must change my rcon pass to make it better but after pair days its the same.
Is there an Exploit so that he can make it or how can i make it to stop him ?
Best Regards
Shakall
romeozor
02-26-2010, 12:58 PM
the mod's been out for ages and i haven't seen anything what you described. try changing mods (something different from pam) and see if it still happens.
Shakall
02-26-2010, 07:57 PM
Great where can i find the newer as 2.03 ?
hypepl
02-26-2010, 10:41 PM
PAM2.03 was updated to PAMD1.05 (latest).
I would be interested in knowing if the upgrade changes anything for you. I got a feeling someone might have access to the game control panel like TCADMIN rather then just the rcon.
NoBS|Evilgenius
02-28-2010, 12:54 AM
you dont have your server.cfg in the redirect for downloads do ya? i have found countless ones on google where people put the cfg in the redirect.
Shakall
03-01-2010, 01:06 AM
No i dont have it.
I have now changed to PAMD1.05 and for now its ok but i will say it to you all in pair Days.
Thanks for the help.
I hope this was it whit pam 2.03
Shakall
03-10-2010, 01:34 AM
The same Thing everytime.
I dont know what i must make because they change everytime my settings and name of my Server as they set a Password so that the people cant yoin intoit.
Please said me what can i do ?
Best Regards
P.S. I have a root access on the server also no TCAdmin or so.
Shakall
03-10-2010, 01:56 AM
I have look on my logs and find this :
Bad rcon from 91.150.120.135:28799:
status
Bad rcon from 91.150.120.135:28799:
dvarlist
Bad rcon from 91.150.120.135:28799:
fdir
I dont understant how he can make this commands because he dont have the rcon password.
NoBS|Evilgenius
03-10-2010, 08:19 PM
he isnt actually succeeding. he trys but thats why it says "bad rcon"
anyone can try to use rcon on any server. but that guy dont have the right rcon pw
theMechanic
03-10-2010, 10:50 PM
are you sure your the only one that has access to your FTP or gamepanel, or both?
try changing your passwords to those.
and make sure you only have game files loaded on there and nothing thats not supposed to be there.
Shakall
03-11-2010, 02:49 AM
I have only root access on that server.
NO FTP downloads and no WWW downloads are on.
There are only the standard maps and PB working not more.
I have changed my password many times and the password have only my cousine and me nobody else.
I have now put my password whit numbers and letters in it.
I hope now its better but how long :(
My friend have a COD4 Server and the same problem.
NoBS|Evilgenius
03-11-2010, 07:21 PM
Bad rcon from 91.150.120.135:28799:
bad rcon means he dont have the rcon passwords... unless there are tons of this in logs and he is trin to brute force it i wouldnt worry bout it
master0
04-28-2010, 07:59 PM
had the same problem but after some search i find out that if your server is allowing downloads by command sv_allowdownload 1 then they can download almost anything from server. so better turn it off and if you have some mods or maps just use redirect link. ;)
but now i am dealing with something new and i need some help. there are some console commands that a spectator is using with no rcon and can make server restart. i dont know if other commands can be executed but this is happening for real.
anyone have some info?
thanks
Shakall
04-29-2010, 01:09 AM
I have FOUND IT !
Rename your cfg file in whatelse.cfg
Put it in the start parameter and disable client console for the game.
That is it.
vBulletin® v3.8.7, Copyright ©2000-2012, vBulletin Solutions, Inc.