BAD RCON ATTEMPT
#1

[01:24:50] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:51] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:52] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:53] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] [part] loquenddero has left the server (15:1)
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:54] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:55] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] UPDATING : TICK: 1161478
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:56] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:57] [death] Conrad_Simon died 54
[01:24:57] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:58] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:58] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:24:59] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:00] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:01] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:02] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:03] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:04] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:05] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:06] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:07] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:07] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:08] [kill] Andy_Smoke killed Xluke M4
[01:25:08] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:09] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:09] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:10] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:11] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9
[01:25:12] BAD RCON ATTEMPT BY: 181.164.183.9

how i can stop this ! im still under attack
Reply
#2

Try adding "rcon 0" to server.cfg.
Reply
#3

Create a system where several rcon attempts results in a kick or ban? For now IP ban that IP.

Also in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
Reply
#4

Quote:
Originally Posted by stueycow
View Post
Create a system where several rcon attempts results in a kick or ban? For now IP ban that IP.

Also in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
thank you for replying
i banend that ip and the attack still on
EDIT: i cannot set rcon 0 in server.cfg Configuration because i couldnt find it in my host cp
and for some reasons im not allowed to edit server.cfg with ftp ( file zilla or smth)
Reply
#5

I'd make a script that only allows your IP to attempt RCON log ins. Only you should have RCON.

This will only allow you to have access. Just set YOUR_IP_HERE to your IP.
pawn Code:
public OnRconLoginAttempt(ip[], password[], success)
{
    if(strcmp(ip, "YOUR_IP_HERE", true))
    {
        new pip[16];
        foreach(new i: Player)
        {
            GetPlayerIp(i, pip, sizeof(pip));
            if(!strcmp(ip, pip, true))
                Kick(i); //Kick'em out.
        }
    }
    return 1;
}
Reply
#6

the problem is that OnRconLoginAttemp is not called !!!

i have this
pawn Code:
if(!success)
    {
        new playersIP[17], playerid;

        for(; playerid < MAX_PLAYERS; playerid++)
        {
            GetPlayerIp(playerid, playersIP, 17);
            if(!strcmp(ip, playersIP))
            {
                break;
            }
        }

        rconAttempts[playerid]++;

        if(rconAttempts[playerid] >= 2)
        {
            S_LOG("~r~BAD RCON:: %s(%d) Has Been Banned For Bad Rcon Password",GetName(playerid),playerid);
            Ban(playerid);
        }
    }
Reply
#7

Quote:
Originally Posted by BlowUP
View Post
the problem is that OnRconLoginAttemp is not called !!!

i have this
pawn Code:
if(!success)
    {
        new playersIP[17], playerid;

        for(; playerid < MAX_PLAYERS; playerid++)
        {
            GetPlayerIp(playerid, playersIP, 17);
            if(!strcmp(ip, playersIP))
            {
                break;
            }
        }

        rconAttempts[playerid]++;

        if(rconAttempts[playerid] >= 2)
        {
            S_LOG("~r~BAD RCON:: %s(%d) Has Been Banned For Bad Rcon Password",GetName(playerid),playerid);
            Ban(playerid);
        }
    }
It's only called when the login command is used in-game. If someone is using an outside source then you'll need a new solution.
Reply
#8

Hi,

If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server

Flo'
Reply
#9

Quote:
Originally Posted by Florentin77
View Post
Hi,

If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server

Flo'
You must be blind, Flo'. His problem isn't an in game player trying to log in. It's an external brute force attempt.
Reply
#10

Quote:
Originally Posted by Florentin77
View Post
Hi,

If you have an account system, juste allow your account to login into RCON,
if someone try to login into RCON and it is not your account, he is banned (or kicked) from the server

Flo'
The account stuff has literally nothing to do with his issue seeing as the atack comes from server's outside.

Quote:
Originally Posted by stueycow
View Post
in server.cfg set 'rcon 0' insted of 'rcon 1' unless you need it
Reply
#11

i will set rcon 0 and restart when i have less players , thanks for helping
Reply
#12

You can try using YSF, see my include I made here:
https://sampforum.blast.hk/showthread.php?tid=568048

And the according tutorial:
https://sampforum.blast.hk/showthread.php?tid=568062
Reply
#13

this is not new
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)