Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 14:13

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 19 posts ] 
Author Message
 Post subject: multircon help
PostPosted: 26 Sep 2007 03:00 

Joined: 26 Sep 2007 02:55
Posts: 7
My server has been hacked many times this past week and I think it's from this tool, but i'm not sure. I read that it doesn't work to great with the quake 3 engine, but what about soldier of fortune II? I tried testing it on my server, by setting up a wordlist and setting the rconpassword to something that's in the wordlist but it does not find it? How else could this person be getting the rcon password? Thanks. :wink:


Top
 Profile  
 
 
 Post subject:
PostPosted: 26 Sep 2007 09:15 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
if your server has sv_allowdownload set to 1 the trick is explained:

http://www.securityfocus.com/archive/1/ ... 0/threaded

with the proof-of-concept q3dirtrav anyone can download any file from the disk on which the server is running.
The only way to avoid this type of attack is disabling the downloading of files in your server.


Top
 Profile  
 
 Post subject:
PostPosted: 27 Sep 2007 03:25 

Joined: 26 Sep 2007 02:55
Posts: 7
Thanks! That helps. One more thing. Someone has been changing the file size of our files on our server which corrupts them where all our settings are lost. Is there any way to fix this or do you know of such an xploit? Thanks!


Top
 Profile  
 
 Post subject:
PostPosted: 27 Sep 2007 10:18 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
Do you mean they have modified your configuration files or the game files (exe, dll, pk3 and so on)?
Anyway depends by how they have been corrupted, don't you have a backup of these files?


Top
 Profile  
 
 Post subject:
PostPosted: 27 Sep 2007 21:33 

Joined: 26 Sep 2007 02:55
Posts: 7
I mean the server files. I do have backups but is what someone is doing is corrupting all the files that are on the server. i.e server.cfg, osp.mapcycle, etc. They are somehow changing the file size which corrupts it and no longer allows it to work. Any idea? Thanks :wink:


Top
 Profile  
 
 Post subject:
PostPosted: 28 Sep 2007 10:15 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
Uhmmm as far as I know is not possible to modify the server's configuration files since there is no way for doing it (known bugs).
Is possible that these people still have your rcon password or have uploaded some new "files" which cause these problems... it can be anything.


Top
 Profile  
 
 Post subject:
PostPosted: 16 Jan 2008 16:27 

Joined: 10 Jan 2008 22:35
Posts: 4
What is the path to download the server.cfg from Enemy Territory? I used that q3dirt program which it will crash my enemy territory everytime and it will never download anything. So what command should i use to donwload the the files? I have tried /download et/etmain/server.cfg /download etmain/server.cfg /download base/server.cfg etc but nothing seems to work. i know my server is set to allow donwloads and it is vulnable but how can one get this file?


respectfully,

greenleaf


Top
 Profile  
 
 Post subject:
PostPosted: 16 Jan 2008 17:28 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
ET actually seems to be the only game not supported by q3dirtrav probably because uses a different clientConnection_t structure.
For the moment I don't know if I will work on a work-around for this game like I did for CoD


Top
 Profile  
 
 Post subject:
PostPosted: 16 Jan 2008 20:36 

Joined: 10 Jan 2008 22:35
Posts: 4
Oh ok makes sense why it dont work. But can you please work on a run around for this game? That would be so great and awesome!!!!!!! Also that pbmsgs, nothing happens when I use it for a server that is vulnable, i tired -l 100 server port and it will run .................. that forever. So i tell people to go to my server when i use it and that doesnt effect the server. Any ideas ?


Ci vediamo dopo!!!!!!

greenleaf


Top
 Profile  
 
 Post subject:
PostPosted: 18 Jan 2008 15:15 

Joined: 24 Sep 2007 02:12
Posts: 1114
Location: http://sethioz.co.uk
did you tried that only on your server ? and if yes .. does your server run in your pc ? ..usually you have to use 127.0.0.1 ip instead of public ip if you testing something on your own server...


Top
 Profile  
 
 Post subject:
PostPosted: 18 Jan 2008 23:07 

Joined: 10 Jan 2008 22:35
Posts: 4
Well yes my server and others. No my server is rented buy a company. It is not from my pc.


Top
 Profile  
 
 Post subject: Help
PostPosted: 09 Aug 2008 22:09 

Joined: 07 Aug 2008 06:01
Posts: 45
This may be off topic but when i exec multircon.exe in cmd line,i drag it and i do the ip + port but what option do i do?when i do -a it comes up with this....
StdOut:
Multi engine RCON tool and password guesser 0.2.3b
by Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org

- target 216.165.226.162 : 60948
- rcon type 0 "Quake 3 engine"
- insert password: - the following are the commands handled internally by this tool:
/rcon_help this help
/rcon_pass [PASS] for re-inserting the password
/rcon_host HOST[:PORT] for changing server and password
/rcon_port PORT for changing only the server's port
/rcon_type [NUM] for changing the type of rcon, use ? for list
/rcon_info query the server

Error: unable to create thread


StdErr:


Top
 Profile  
 
 Post subject:
PostPosted: 09 Aug 2008 22:58 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
the thread error is strange and unusual.
what operating system are you using and what exact version/service pack?


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 13 Sep 2008 23:31 

Joined: 07 Aug 2008 06:01
Posts: 45
I am using a mac osx lol, But i have a program to run the command line. ^^ it's all good,i know how to bruteforce, but i'm never succesful lol,even on my own server with the /rcon password ''a'' :C Is there a fast way to do it?


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 14 Sep 2008 00:29 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
if your rcon password is "a" the password guessing should be immediate, if doesn't happen means there is a compatibility problem in the tool or in the options you used


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 15 Sep 2008 15:21 

Joined: 01 Sep 2008 07:40
Posts: 31
Luigi, I recently tried this tool of yours out, it works perfectly well for each game supported except for Half-Life it seems. Which version of Half-Life should this work for, and should it work for current HL-based games such as Counter-Strike or even Source versions of these games? It always returns a "Error: socket timeout, no reply received" error for me.

Thank you.


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 15 Sep 2008 16:54 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
multircon is compatible with the non-steam version of HL, like HL 4.1.1.1e


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 15 Sep 2008 20:16 

Joined: 01 Sep 2008 07:40
Posts: 31
aluigi wrote:
multircon is compatible with the non-steam version of HL, like HL 4.1.1.1e

As I thought, thank you.


Top
 Profile  
 
 Post subject: Re: multircon help
PostPosted: 16 Sep 2008 11:45 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
if the format of the rcon of steam is enough simple and someone has some dumped packets I could add support for it


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 19 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
cron