[Help] Hackers are able to send commands from other players
#1

I have a problem. For some reasons hackers have the ability to send commands MY account through their account. For example: There is a double-xp enable command, and only admins can access it. The hacker somehow sends the command through MY account, which is an admin account, and it shows as if I enabled double xp. Is there any way to block it? I've never seen a thing like that.
Reply
#2

Theoretical they can't , only there is a bug into the cmd, only at that cmd happend? I was experiecing a similiar thing at ban cmd, where i forget to check if player is logged and they can ban players without been logged from admins accounts
Reply
#3

Its not possible until You have a bug in your script or He has "edited" your .amx file ._.(Yes,That would be hacking into ur computer).
Reply
#4

Quote:
Originally Posted by Gotham
Посмотреть сообщение
Its not possible until You have a bug in your script or He has "edited" your .amx file ._.(Yes,That would be hacking into ur computer).
You can't edit an .amx file.
Reply
#5

Quote:
Originally Posted by BurnZ
Посмотреть сообщение
You can't edit an .amx file.
Lol , can't you just compile a part of code and then put it in his script too? He might be a computer expert, :P
Anyways idc it was just an example!
Reply
#6

Quote:
Originally Posted by Gotham
Посмотреть сообщение
Lol , can't you just compile a part of code and then put it in his script too? He might be a computer expert, :P
Anyways idc it was just an example!
This place is not for kids, leave SA-MP kids, leave SA-MP. (sarcasm, since killing children is a sin and a crime and not allowed and.. and...)

You can't compile a part of a code and compile it into a pre-existing code, the .amx is uploaded on the server with the secured FTP as I guess, and how the person/ kid can get access to his host?, its probably a bug in his command, that he is not checking the player status and/or is using a weak rcon pass.
Whatever you said was shit and I haven't ever read this kind of stupid reply, ever before in my life.
Reply
#7

Are you sure it's not someone playing a prank on you? Do you have any fake chat commands or something similar that they could be using? As far as I'm aware, they cannot spoof callbacks with another player's ID, only their own. So I am going to assume you have something in your script that allows players to send commands on your behalf.
Reply
#8

Apparently a hacker breached into my FTP, uploaded a filterscript and he could call remote functions from my gamemode to his favor. Thank you for your help guys, I've blocked that asshole.
Reply
#9

How'd he/she get the details to FTP, though?
Reply
#10

Quote:
Originally Posted by SickAttack
Посмотреть сообщение
How'd he/she get the details to FTP, though?
There was a security hole in our UCP host which allowed them to download the UCP files and access them. The FTP details were there.
Reply


Forum Jump:


Users browsing this thread: 4 Guest(s)