Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 11:58

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 35 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: Jedi Knight hacking
PostPosted: 01 Feb 2009 21:59 

Joined: 30 Dec 2008 01:30
Posts: 17
Hey today were a guy with the name eVc on my Clan base server (Jedi Knight 3) and hacked the rcon password. I ask him how he do that and he says me that he has modifid his dll and other files and the dll files of the server, so he can download the server config and all other files. He means that works on all servers and he can hack the rcon password of servers with ja+ mod with only one script. He told me something about the Pandora Project. He say only 4 Players know these bugs there names are Toast, Deathspike, BobaFett and eVc. They all programed some hacks for this game. He says that he can download my cfg too. So my question is can any one tell me how to do this?


Top
 Profile  
 
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 00:01 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
for JA or JA+ specific bugs I think that evan knows better, so I bet he will have more ideas.

anyway exist at least 2 known vulnerabilities in the quake 3 engine (so problems which go to add the the possible bugs of JA and possibly to the JA+ mod) that give a certain level of access to the server and are the directory traversal which allows to download any file (included server.cfg) if the server has the downloads enabled.
the other is that one which allows to execute commands on the server through the callvote.

if you have the downloads enabled it's at 99% the first one.
other informations about your configurations (version of JA, version of JA+, if downloads are enabled and so on) could be useful.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 11:30 

Joined: 30 Dec 2008 01:30
Posts: 17
Okay the server have cl_download 0. The guy say that this work on all games based on the quake 3 engine and the server dont must have cl_download 1 to download the config and any other file. My Jka version is 1.01 the server runs on this version too. My Ja+ version is 1.43 beta the server is a base server so it dont have any mods install. Oh he say that he can crash the processor of the server there the jka server run.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 13:20 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
the cvar you must check is sv_allowdownload


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 13:29 

Joined: 30 Dec 2008 01:30
Posts: 17
No sv_allowdownload is not enabled


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 14:19 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
anyway there are a lot of inaccuracies in what you say like the fact that "he modifies the dll of his client" and "his server" (eh?!?), the fact that you talk about downloading the files and then about "hack the rcon password" which are 2 things that can be the same or just the opposite thing (the first is a method, the second an effect which can be caused even by the callvote bug and others), the fact that you don't know even the cvar which enables the downloads and so on... so for the moment there is nothing to do.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 20:24 

Joined: 27 May 2008 18:46
Posts: 3
That guy was a faker. I'm the real eVc and i retired from playing JK/Jka many months ago.

Edit: just read what you actually posted i can just say its lies. Why would he modify your server files just to download the server config? He would need access to the server via some exploit to alter the file, but why? if he has access/privs to change some files.. then he could directly pipe the config into some buffer or download the file directly. I think its some lamer who got lucky getting the rconpassword and is pretending to be people, imagining exploits to portray himself as elite.

My 2c..


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 22:13 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
uh, can this be a note for everyone who speaks of JK3/JK2 or any other game... PLEASE STATE THE VERSION...
i believe u are referring to jk3 1.01 because u have said something about "JA+ Mod", so i'm just going to go with that.

how can he be editing your server's .dll's, that is actually illegal hacking and u should investigate on that if it is true.
it sounds like some1 is using dirtrav on u if u have sv_allowdownloads on 1...
or if u have voting off, u should turn that off too
i spoke with BobaFett he said he didn't know what "pandora project" was...
i was going to speak with deathspike but he wasn't available at the time...
eVc i'm always trying to find the real one because people keep faking him or giving me false information to contact him
and who the eff is toasty?

but yeah this guy was just bluffing, he has probably just guessed ur password, actually downloaded the password, used callvote exploit or has asked 1 of the people of ur server who has rcon for it (or it is 1 of the people on ur server who has rcon)...

oh but are u really the evc? :P


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 22:18 

Joined: 27 May 2008 18:46
Posts: 3
Yea :), Deathspike can confirm it, as he was the one who brought this topic to my attention.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 02 Feb 2009 23:10 

Joined: 05 Oct 2007 01:20
Posts: 402
Location: Florida
oh really? lol.
i told bobafett about this post, then he said he would ask deathspike because he has more contact with eVc (you) incase you knew anything about it...
so after like a year and a half searching for the actual person, u end up on a forum... heh :P
can i get ur contact info for like future reasons? email/msn/aim/xfire ? :p


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 03 Feb 2009 19:54 

Joined: 03 Feb 2009 19:52
Posts: 36
Location: Switzerland
okay really now, i was the admin of this server and there was no sv_allowdownload 1 and there was no callvote before hacking:
983:37 sayteam: ^3eVc: dont kick everyone we just want ban westbam
983:37 sayteam: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: nice ;-P
983:45 sayteam: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: ok thats rly good
983:47 sayteam: ^3Bobafett: NEW RCON?
983:49 sayteam: ^3eVc: coz he flame me in mpc
sayteam: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: wie ist rcon? xD
983:09 sayteam: ^3Bobafett: Cor114577895512
say: ^3Bobafett: we are the anti westbam clan
^3DeathSpike: hahhaa
[QMM] NoCrash: Userid 9 has attempted to execute a command
^3Bobafett: cu
980:09 ClientBegin: 3
980:13 say: ^3eVc: k finaly westbam is banned
980:21 say: ^3Bobafett: jo
980:22 say: ^3eVc: now elts go ban him for other servers
say: ^3eVc: u know pp for powerplay?
989:18 say: ^3eVc: pw
989:23 say: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: intern or blue >.<
eVc: jim do u have any cool server for hack where we can ban westbam?
987:05 sayteam: ^3eVc: XD
987:34 say: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: hmm slaystation? bimonswarzone?
987:41 say: ^3Bobafett: bimons not working
987:42 say: ^3eVc: new pw for slaystation?
987:42 say: ^3Bobafett: i think
987:55 say: ^1a^7X^1iom^7'^1s^7}{^1e^7V^1il jim: uff dunno... 1337? leet?
987:58 say: ^3Bobafett: no
988:03 say: ^3Bobafett: ask duri whatever

i dont believe you guy's because they hacked known servers like axiom and powerplay etc, and they changed my rcon again! now i have password changed etc.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 04 Feb 2009 07:59 

Joined: 14 Nov 2008 16:37
Posts: 15
He could intercept packets xD


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 06 Feb 2009 08:27 

Joined: 24 Sep 2007 02:12
Posts: 1114
Location: http://sethioz.co.uk
sounds like bunch of bullshit to me. why change your game .dll files to get rcon ?
I can confirm that 99.9% of this kind of ppl who claim that they hacked something, are fakers. They either guess the pass or get it somewhere and then they play some wannabes.

I didn't say that its impossible to hack a game server, i've done it myself in AvP2, where i found a way to enter locked servers (password locked)..etc, but just this stuff he described sounds just stupid. actually it sounds more like some 'kid' is trying to look elite, like already mentioned in this topic.
I haven't messed around with Luigi's tools or Q3 engine or jedi knight at all, but wasn't there a tool to bruteforce rcon ? most likely he got the password by guessing or bruteforcing or just got it from somebody.

Eragon you say you was/are the admin of that server ?! what was your rcon when it got 'hacked' ? ofcourse you dont have to post the exact password, but give me an idea. like was it just one word in lower alpha (like "password") ? or was it something harder. like "pAssword1" style ?

Anle, as about the packets. Q3 engine uses "challenge response" so its not possible to 'hack' server rcon with a simple packet editor. if you know any tool like "tamper data" or "webscarab" which would work on games, then it would be quite possible, but as far as i know there's no such tools. Luigi's proxocket is the closest, but you can't edit data live in there.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 06 Feb 2009 12:20 

Joined: 14 Nov 2008 16:37
Posts: 15
My friend knows how to intercept packets. I don't know how he did. oO


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 06 Feb 2009 13:27 

Joined: 29 Dec 2007 13:54
Posts: 10
Quote:
983:47 sayteam: ^3Bobafett: NEW RCON?


That confirms it's not me, the F isnt capitalized, and the colors are wrong :P


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 06 Feb 2009 15:23 

Joined: 03 Feb 2009 19:52
Posts: 36
Location: Switzerland
Eragon wrote:
983:09 sayteam: ^3Bobafett: Cor114577895512

Well this is over 15 letters and numbers, big and small - i thought that rcon bruteing is not possible over 15 letters, and it will takes day's, with or without -d 100, to brute this. and the second hacked rconpassword was over 17 letters....

But i think now it was Callvote hacking, become rcon by calling a vote, i dont know how they've done this, but all other servers said that g_allowvote must be 0.
Now i changed allowVote to 0, and theres no hacking since i changed it...

But i dont want to keep that..... I search on a Solution for this callvote hack, i dont know how, so Peoples can you maybe help me...? Maybe Cvar hack playes a role on it.

any solutions?


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 08 Feb 2009 12:25 

Joined: 29 Dec 2007 13:54
Posts: 10
The only way to fix the callvote exploit is to either disable voting, or get the mod you're running to fix it.

As far as i'm aware, JA+ will have a new release soon with this exploit fixed, same for MB2, i'm not aware of the status for other mods though.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 08 Feb 2009 17:26 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
I have just released a beta fix for the Windows versions of the vulnerable games:
post5476.html#p5476


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 08 Feb 2009 17:58 

Joined: 24 Sep 2007 02:12
Posts: 1114
Location: http://sethioz.co.uk
Quote:
My friend knows how to intercept packets. I don't know how he did. oO

Well maybe you are so kind and ask your friend and then pm me about the tool. it goes lil bit out of topic i guess. if i can get my hands on a tool like "tamper data" or "webscarab" which would work on games...i would do miracles :) ..and i mean intercept, not just record them. ok well WPE Pro kind a works, but its not same as tamper data and/or webscarab. wpe pro can only make filters and automatically change it. what im looking for is a tool just like tamper data and webscarab which gives you popup window before data is sent.
Quote:
Well this is over 15 letters and numbers, big and small - i thought that rcon bruteing is not possible over 15 letters, and it will takes day's, with or without -d 100, to brute this. and the second hacked rconpassword was over 17 letters....


Everything is possible :) just depends how bad you want it. It is possible to run attack from multiple computers to speed it up, BUT days ? you must be kidding me.. bruteforcing a 15 letter password, which contains lower and upper alpha + numeric, would take over 1000 years. For example my PC can do like 7 million passes per second locally and it would still take 1000 years or even more. ..and bruteforcing remote password, it would be like 50 passes per second max..

so either somebody leaked it or it was really that vote exploit which allowed that 'hacker' to download the config.


Quote:
That confirms it's not me, the F isnt capitalized, and the colors are wrong :P

If you are known in some game or internet, then get used to it. there's always some dumb imposters...who are too retarded to actually use their own name (either real or not).


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 09 Feb 2009 07:31 

Joined: 19 May 2008 04:02
Posts: 3
Seems like some people are going around using the callvote exploit to enable SV_ALLOWDOWNLOAD on servers and downloading the configs.

I suppose thats 1 downside of releasing the exploit :/

By the way, I'm guessing this reference to the Pandora Project came from the ESL Forums? I'm guessing your the same guy who made the post there?

http://www.esl.eu/eu/jkja/forum/388/393 ... 1234156625

Also, you should release a completely patched up version of the dedicated server for people to download (linux/win). Including all the patch fixes from the past.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 09 Feb 2009 13:12 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
Quote:
Also, you should release a completely patched up version of the dedicated server for people to download (linux/win). Including all the patch fixes from the past.

uhmmm I hope you are not referring to me or you meant something else.

if there is something that you don't like feel free to pass your next years learning assembly, debugging and some other technical things and creating patches and work-arounds in your free time for games that you even don't know or have played before.
when you will have done this, release everything for free and open source for people that you don't know.
if this is still not enough make also a patch for any old and new version of a game and for any other game built on the same engine affected by a vulnerability.
oh naturally your patch must work on both the windows version of a game server and on the linux one, maybe bsd and macosx too where available.

when you will have done this you can return in this forum (hoping the world is not finished in the meantime) and you can have a little chance that I will "consider" a similar affirmation.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 09 Feb 2009 14:22 

Joined: 16 Oct 2007 18:47
Posts: 23
AMailer wrote:
Seems like some people are going around using the callvote exploit to enable SV_ALLOWDOWNLOAD on servers and downloading the configs.

I suppose thats 1 downside of releasing the exploit :/

By the way, I'm guessing this reference to the Pandora Project came from the ESL Forums? I'm guessing your the same guy who made the post there?

http://www.esl.eu/eu/jkja/forum/388/393 ... 1234156625

Also, you should release a completely patched up version of the dedicated server for people to download (linux/win). Including all the patch fixes from the past.

Maybe the just used another bug since there are still other vulnerabilites in those games....


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 09 Feb 2009 18:22 

Joined: 03 Feb 2009 19:52
Posts: 36
Location: Switzerland
hm... an ESL Topic posts a callvote bug Fix, but theres a slight damage different, said the poster... i'll test it, theres also a msgboom and forcestringfix in it.

http://esl-fr.verygames.net/jampgamei386.zip


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 09 Feb 2009 19:39 

Joined: 19 May 2008 04:02
Posts: 3
aluigi wrote:
uhmmm I hope you are not referring to me or you meant something else.


Oh wow; relax. I was only suggesting not forcing you to release one. I figured it would be "nice" (not necessary to do) to release a patched up version (I guess I was only thinking of JKA, since its the game I play(ed). Just run the lpatch of yours on the files, for all the different exploits and make a nice "patched up" package.

But its okay; was just a suggestion though :P Maybe I'll just run your patcher for the JKA dedicated servers and make a release.


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 17 Apr 2009 19:43 

Joined: 02 May 2008 15:37
Posts: 38
evan1715 wrote:
how can he be editing your server's .dll's, that is actually illegal hacking and u should investigate on that if it is true.


FAIL !! There's no illegal hacking !!!! xD Me likes this type of beaches how fck up the whole server system <3 I've been watching my frined how he hack JA+ server. I said him 1 random server (just only me and him inside) and he just need few minutes and BANG!! - I receive full force LOL !


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 18 Apr 2009 17:08 

Joined: 27 Jul 2008 09:23
Posts: 13
do that again and select a server with sv_allowdownload 0 and g_allowvote 0.
Let's see if he is still able to hack it^^


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 18 Apr 2009 18:15 

Joined: 02 May 2008 15:37
Posts: 38
hah do u think I'm so stupid - I was sure there's no allowdownload or callvote on . Aways there's a way to bypass someting


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 19 Apr 2009 00:48 

Joined: 11 Mar 2009 15:46
Posts: 20
Is your server patched against the buffer overflow crash? because you can run machine code on the server through that bug.
or it may just happen that you are dealing with a level 3 wizzard :O


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 25 Apr 2009 22:00 

Joined: 03 Feb 2009 19:52
Posts: 36
Location: Switzerland
there is no knowed way to hack a server without sv_allowdownload 1, or g_allowvote 1, or bruteing........


Top
 Profile  
 
 Post subject: Re: Jedi Knight hacking
PostPosted: 29 May 2009 14:18 

Joined: 03 Feb 2009 19:52
Posts: 36
Location: Switzerland
Well, now we have updatet our Writeconfig Script, and we saw that a possibly might exist, to write Files in a other folder.. if that would be possible, we Can Overwrite The Shadow and Passwd Files in the ../../../../etc folder, which are responsible for the FTP Login etc.. But we didn't find a Command yet. We Tried to write like that:
rcon path (for example)
/home/Username/.duel/base
Then:
rcon writeconfig ../../home/Username/.duel/test.cfg
But it gives an Error:

Code:
15:16:40 Writing ../../home/Username/.duel/test.cfg.
         WARNING: refusing to create relative path "/home/Username/.duel/base/../../home/Username/.duel/test.cfg"
         Couldn't write ../../home/Username/.duel/test.cfg.


anyone has an Idea?

Best Regards
Eragon


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 35 posts ]  Go to page 1, 2  Next

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: