Is that possible ? (Rcon password finder)
#8

Quote:
Originally Posted by NaS
View Post
But that already leaves a security hole. The RCON remote console. You can attempt to login through that as often as you like if the server doesn't temp. ban the IP (temporary range ban would be the best).
If that isn't done it can be brute forced from outside.
The server should detect login attempts, even from the remote console. That's why I did mention banning in case of a brute force.

Quote:
Originally Posted by NaS
View Post
Changing the RCON PW after a successful attempt is also useless as I'd already be logged in at that point (which allows me to change it myself, ban everyone on the server or crash it).
True, it's a really thin layer of security. Useful for situations when people get to have a look at what your password is (maybe a look over the shoulder or a keylogger).
That still leaves the rest of the measures, which if scripted properly, can render a brute force attack useless.
Reply


Messages In This Thread
Is that possible ? (Rcon password finder) - by SintaksTR - 26.11.2018, 09:48
Re: Is that possible ? (Rcon password finder) - by Kane - 26.11.2018, 09:50
Re: Is that possible ? (Rcon password finder) - by SintaksTR - 26.11.2018, 09:52
Re: Is that possible ? (Rcon password finder) - by Variable™ - 26.11.2018, 10:59
Re: Is that possible ? (Rcon password finder) - by cuber - 26.11.2018, 11:12
Re: Is that possible ? (Rcon password finder) - by HeLiOn_PrImE - 26.11.2018, 13:06
Re: Is that possible ? (Rcon password finder) - by NaS - 26.11.2018, 14:10
Re: Is that possible ? (Rcon password finder) - by HeLiOn_PrImE - 27.11.2018, 10:15
Re: Is that possible ? (Rcon password finder) - by Variable™ - 27.11.2018, 11:37

Forum Jump:


Users browsing this thread: 1 Guest(s)