PDA

View Full Version : Delator 2 errors or just cheaters/hackers??


ParrotCA
02-06-2003, 01:56 PM
As suggested, I have copied this previous post to the Delator forum.


Here is a copy/paste of a thread I started at thecheatpolice.com

I hope that somebody else can either confirm what I have discovered. I am not a programmer, and I don't know much about how this software works, but below is an observation I have put together over the past few days.

Ok, ok. I know this isn't the mohaadmin forums for this, but it does relate directly to Delator 2 and detecting/stopping some cheaters.

Lately, I have been having somebody turn off or crash delator 2. I know this sounds strange, but I have noticed a positive correlation between several events.

The timers on D-2 stop.
I restart, and I get the "delator already running, do you wish...."
I click yes to start it
the first 8 spots on our server are reserved, and D-2 gets through those fine, but then later on, it will give me a "runtime error-subscript out of range" I keep an eye on which client # it gave me the error on.
So, I go to my other computer where I have all seeing eye running, and use the remote console in ASE to do a "STATUS" check. Then I remember what "client number" D-2 reached before giving me the "runtime error"
I manually do a dumpuser on that client through ASE. In this case, it was client # 10 that the D-2 stopped running.
I dumpuser client #10 first, and low and behold, his
r_lightmap "hacked"
r_novis "hacked"
r_farplane "hacked"
r_farplane_nofog "hacked"
cg_3rd_person "hacked"

all read "hacked"
So, I clientkick 10
he leaves, but before he does, I ban him on CK's Auto-kicker, just so I have a record of his IP addy and can manually add it to the D-2 banned list.
Guess what? D-2 starts running just fine once I get rid of this ass.

So, I beleive that some of the "runtime error-subscript out of range" messages that some users have been getting may not be an error with Delator 2 at all, but somebody using a D-2 counter measure.

Just thought I would share this with the [CP]comunity, and see if anybody else could test my theory. I am sure others running D-2 have noticed similar instances where they could not re-start D-2 until a server shutdown or certain clients leave. If these events prove to be sound, then maybe we could pass the info on to YoChoy and/or Crow King and Shockwave.

If you don't already have All Seeing Eye, you can grab it at All Seeing Eye http://www.udpsoft.com/eye/
when you right click on your server, a menu comes up. Go to server properties, and enter your Rcon password. From here, you can run ANY rcon command without having to be in the server. Great for monitoring team matches. You can sit back, run your dumpuser quietly as an observer, and make sure you get the names spelled right.

Hope this helps someone.


Parrot(CA)
Confederate Armada www.confederatearmada.com

Ruiner
02-06-2003, 02:47 PM
i think there was a post that described the warnings/kicks settings. IE: 3 warnings = a kick. But, if one person was breaking more than 3 rules, this would cause Delator to crash for some reason...or, maybe just by chance, this client had one of those large 10# - port numbers...just my guesses though

Sitting_Duck
02-06-2003, 02:47 PM
Well it sounds like we will have to go and find what ever they are using. We all know that the hacks have ways around the security our guys are making. But now to cause it to crash? The servers I admin on are constantly crashing. At first it was mainly related to the number of players in the server, (20). But this bit of news makes it a whole different ball game. The one thing that I wonder about is why this hack would allow his name to be scanned. It sounds like a n00b cheater, or was this in an AA server? If it was in SH and its a n00b that would mean they didn't know about the scan.....which means this counter measuser should be easy to get.

ParrotCA
02-07-2003, 03:57 PM
Ok,
It was MOH:AA, not SH.
It was not accumulated kicks. I don't have any warnings set. If somebody is caught, they are banned imediatley. There is zero tolerance on our server.

The only reason I can think relating him allowing his name to be scanned, is that he may have come in between scans. I set the scan to 60 seconds, and the patrol to 3 minutes, so there would have been time for them to come in and realize that D-2 just logged them in.

It wasn't a long IP addy. it was pretty normal.

Another thing, now that I am thinking about it, is the same thing happend when I had somebody shooting through the walls on Destroyed Village. It was one of the second floor windows that are blacked out. I was gettin raped as I spawn, and i look up after 3 or 4 times looking for the shooter, and a muzzle flash was coming out of the window. I go spectator mode, and sure enough, there is somebody firing through that window into the allies spawn room. (Screenshot available if anyone wants to see it) But, I digress.
The point is, that this group of 3 clanners also forced D-2 to stop running. Either that, or it was one heck of a "coincidence" that D-2 stopped when these ppl were shooting through "blocked windows"
When I questioned them about a wall-hack, they said "We can't cheat, we run PONTO you fu**ing moron"
Big deal, I don't have the software installed on our server. They must have thought they were bull-shitting somebody, cause as far as I know, ponto only works when it is running on the server AND client.