BAD RCON ATTEMPT -
BlowUP - 23.07.2015
[01:24:50] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] [part] loquenddero has left the server (15:1)
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] UPDATING : TICK: 1161478
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] [death] Conrad_Simon died 54
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:58] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:58] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:00] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:07] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:07] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] [kill] Andy_Smoke killed Xluke M4
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:09] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:09] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
how i can stop this ! im still under attack
Re: New Hack ! BAD RCON ATTEMPT -
StuartD - 23.07.2015
Try adding "rcon 0" to server.cfg.
Re: New Hack ! BAD RCON ATTEMPT -
stueycow - 23.07.2015
Create a system where several rcon attempts results in a kick or ban? For now IP ban that IP.
Also in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
Re: New Hack ! BAD RCON ATTEMPT -
BlowUP - 23.07.2015
Quote:
Originally Posted by stueycow
Create a system where several rcon attempts results in a kick or ban? For now IP ban that IP.
Also in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
|
thank you for replying
i banend that ip and the attack still on
EDIT: i cannot set rcon 0 in server.cfg Configuration because i couldnt find it in my host cp
and for some reasons im not allowed to edit server.cfg with ftp ( file zilla or smth)
Re: New Hack ! BAD RCON ATTEMPT -
Crayder - 23.07.2015
I'd make a script that only allows your IP to attempt RCON log ins. Only you should have RCON.
This will only allow you to have access. Just set YOUR_IP_HERE to your IP.
pawn Code:
public OnRconLoginAttempt(ip[], password[], success)
{
if(strcmp(ip, "YOUR_IP_HERE", true))
{
new pip[16];
foreach(new i: Player)
{
GetPlayerIp(i, pip, sizeof(pip));
if(!strcmp(ip, pip, true))
Kick(i); //Kick'em out.
}
}
return 1;
}
Re: New Hack ! BAD RCON ATTEMPT -
BlowUP - 23.07.2015
the problem is that OnRconLoginAttemp is not called !!!
i have this
pawn Code:
if(!success)
{
new playersIP[17], playerid;
for(; playerid < MAX_PLAYERS; playerid++)
{
GetPlayerIp(playerid, playersIP, 17);
if(!strcmp(ip, playersIP))
{
break;
}
}
rconAttempts[playerid]++;
if(rconAttempts[playerid] >= 2)
{
S_LOG("~r~BAD RCON:: %s(%d) Has Been Banned For Bad Rcon Password",GetName(playerid),playerid);
Ban(playerid);
}
}
Re: New Hack ! BAD RCON ATTEMPT -
Crayder - 23.07.2015
Quote:
Originally Posted by BlowUP
the problem is that OnRconLoginAttemp is not called !!!
i have this
pawn Code:
if(!success) { new playersIP[17], playerid;
for(; playerid < MAX_PLAYERS; playerid++) { GetPlayerIp(playerid, playersIP, 17); if(!strcmp(ip, playersIP)) { break; } }
rconAttempts[playerid]++;
if(rconAttempts[playerid] >= 2) { S_LOG("~r~BAD RCON:: %s(%d) Has Been Banned For Bad Rcon Password",GetName(playerid),playerid); Ban(playerid); } }
|
It's only called when the login command is used in-game. If someone is using an outside source then you'll need a new solution.
Re: New Hack ! BAD RCON ATTEMPT -
Florentin77 - 24.07.2015
Hi,
If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server
Flo'
Re: New Hack ! BAD RCON ATTEMPT -
Crayder - 24.07.2015
Quote:
Originally Posted by Florentin77
Hi,
If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server
Flo'
|
You must be blind, Flo'. His problem isn't an in game player trying to log in. It's an external brute force attempt.
Re: New Hack ! BAD RCON ATTEMPT -
n0minal - 24.07.2015
Quote:
Originally Posted by Florentin77
Hi,
If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server
Flo'
|
The account stuff has literally nothing to do with his issue seeing as the atack comes from server's outside.
Quote:
Originally Posted by stueycow
in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
|
Re: New Hack ! BAD RCON ATTEMPT -
BlowUP - 24.07.2015
i will set rcon 0 and restart when i have less players , thanks for helping
Re: New Hack ! BAD RCON ATTEMPT -
Abagail - 24.07.2015
You can try using YSF, see my include I made here:
https://sampforum.blast.hk/showthread.php?tid=568048
And the according tutorial:
https://sampforum.blast.hk/showthread.php?tid=568062
Re: New Hack ! BAD RCON ATTEMPT -
jamesbond007 - 24.07.2015
this is not new