Hacking

Page 1 of 2 12 LastLast
Results 1 to 25 of 28
  1. #1
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Hacking

    Hello everyone.

    I have a 2.2.3.2 rf server. I got all the protection which is needed. I got the dev-corp serverside protection to be exact. I have a player in my server that is probably using a WPE. Im not quite sure tho. But everytime I banned this guy, 3 to 4hrs later hes gonna come up with another char with all +7upgrade and all gm eles. This guy has been doing this for about a week now and all I do is banned him. I dunno if this guy has access to my SQL.


    Any advice that you guys csn give?

    I would appreciate your advice.


  2. #2
    Leech feeder. lifestream is offline
    Grand MasterRank
    Oct 2008 Join Date
    855Posts

    Re: Hacking

    vulnerable gamecp. So hes ether got admin access or sql injecting.

  3. #3
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by lifestream View Post
    vulnerable gamecp. So hes ether got admin access or sql injecting.
    how do I check if theyre doing sql injection?

  4. #4
    Leech feeder. lifestream is offline
    Grand MasterRank
    Oct 2008 Join Date
    855Posts

    Re: Hacking

    Well idk what gamecp you are using. u can start by changing the sql passwords and look at gamecp logs if any of the gm accounts is used to give items (leaked/shared info).

    ur best bet to catch injections is to run sql pro filer - but there will be loads of data to go through and find any unusual queries.

  5. #5
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by lifestream View Post
    vulnerable gamecp. So hes ether got admin access or sql injecting.
    Quote Originally Posted by foxzone33 View Post
    how do I check if theyre doing sql injection?
    I dont think they have admin acc
    Quote Originally Posted by lifestream View Post
    Well idk what gamecp you are using. u can start by changing the sql passwords and look at gamecp logs if any of the gm accounts is used to give items (leaked/shared info).

    ur best bet to catch injections is to run sql pro filer - but there will be loads of data to go through and find any unusual queries.
    im using intrepids game cp. i checked all my logs and I dont see no giving going on. So the best bet is SQL injection. do they have any tools that you can buy to filter the unwanted injections? does anyone offer those kind of security?

  6. #6
    Leech feeder. lifestream is offline
    Grand MasterRank
    Oct 2008 Join Date
    855Posts

    Re: Hacking

    also make sure al lthe ports are blocked, besides the updater,web and login/server. you may have controlserver access open.

  7. #7
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by lifestream View Post
    also make sure al lthe ports are blocked, besides the updater,web and login/server. you may have controlserver access open.
    what port is that?

  8. #8
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by lifestream View Post
    also make sure al lthe ports are blocked, besides the updater,web and login/server. you may have controlserver access open.
    do you know whos selling a filther for anti sql injection? life for example it will only takw commanda from a certain ip?

  9. #9
    Leech feeder. lifestream is offline
    Grand MasterRank
    Oct 2008 Join Date
    855Posts

    Re: Hacking

    10001, 27780 besides launcher 80/8080/10007 and rdp port are the only ones u really need to open.

  10. #10
    Newbe likertuban is online now
    ModeratorRank
    Apr 2012 Join Date
    2,337Posts

    Re: Hacking

    don't open port for control server,
    use it only on local...
    change sql, and .ini password...
    use different user and password for account, and zone server...
    block any unused port...
    check your firewall and port forwarding...
    and check for backdoor...

  11. #11
    Leech feeder. lifestream is offline
    Grand MasterRank
    Oct 2008 Join Date
    855Posts

    Re: Hacking

    and no.. anti sql ijnject software doesn't exist. Software that is coded as inject safe is the only solution.

  12. #12
    Sorcerer Supreme sadi is offline
    Member +Rank
    Oct 2012 Join Date
    251Posts

    Re: Hacking

    Change (% god hand)

  13. #13
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by sadi View Post
    Change (% god hand)
    I habe a custom gm commands.

  14. #14
    Newbe likertuban is online now
    ModeratorRank
    Apr 2012 Join Date
    2,337Posts

    Re: Hacking

    if you have custom GM command, then it's maybe SQL inject, or control server...

  15. #15
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by sadi View Post
    Change (% god hand)
    I habe a custom gm commands.
    Quote Originally Posted by likertuban View Post
    if you have custom GM command, then it's maybe SQL inject, or control server...
    so I have to clear the port? and what do you mean control server?

  16. #16
    Newbe likertuban is online now
    ModeratorRank
    Apr 2012 Join Date
    2,337Posts

    Re: Hacking

    Quote Originally Posted by foxzone33 View Post
    I habe a custom gm commands.

    so I have to clear the port? and what do you mean control server?
    i mean RF manage tool...
    don't used it, don't open port for manage tool,
    -clear port on firewall and port forwarding
    -use different account and privillage for RF_user and RF_World in sql also in *.ini (make custom account name, don't use 'sa')
    -make sure there's no sql injection

  17. #17
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by likertuban View Post
    i mean RF manage tool...
    don't used it, don't open port for manage tool,
    -clear port on firewall and port forwarding
    -use different account and privillage for RF_user and RF_World in sql also in *.ini (make custom account name, don't use 'sa')
    -make sure there's no sql injection
    what do you mean make sure no sql injection? that means once ita injected its always going to be injected?

  18. #18
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Quote Originally Posted by foxzone33 View Post
    what do you mean make sure no sql injection? that means once ita injected its always going to be injected?
    unless you clean it?

  19. #19
    Newbe likertuban is online now
    ModeratorRank
    Apr 2012 Join Date
    2,337Posts

    Re: Hacking

    no, sql injection usually change your query...
    but, it's possible to destroy your entire server, because someone can get full access on your sql database with sql injection
    and scan your server, make sure no backdoor...

  20. #20
    Elite Member foxzone33 is offline
    Member +Rank
    Jul 2010 Join Date
    PhilippinesLocation
    162Posts

    Re: Hacking

    Now it make sense to me. I have a lot of port that is not meant to be open. Probably thats how everything got started. i even have a port on msql that is also open -_______-

    BTW question do i need to use outbound as well? Or no outbound needed?

  21. #21
    no failure, no greget! dodojimbun is offline
    Grand MasterRank
    Jun 2012 Join Date
    IndonesiaLocation
    511Posts

    Re: Hacking

    1. block tcp and udp inbound and outbound for port

    1433, 61433 (depend which sql port u open)
    27000, 28000, 29000 (account server)
    27555, 27556 (unused port of zoneserver)

    *CMIIW

    2. make a whitelist for ur IP

    3. for make sure ur RDP is safe, change the port and dont forget whitelist it on firewall so u can connect, else u cant connect haha (find it @ google for how)

  22. #22
    Newbe likertuban is online now
    ModeratorRank
    Apr 2012 Join Date
    2,337Posts

    Re: Hacking

    i think sql port doesn't need to be opened? o.O
    people can still play without opening sql port right? o.O

  23. #23
    Sorcerer Supreme sadi is offline
    Member +Rank
    Oct 2012 Join Date
    251Posts

    Re: Hacking

    Quote Originally Posted by foxzone33 View Post
    I habe a custom gm commands.
    I think it takes a lot of work you want to enter from SQL
    I also think he did not need to start from your
    You should check the right GM
    All the commands have changed
    As long as you do even your GM account even if you can not work a success

    - - - Updated - - -

    There is also a
    The first change the default account ControlServer_GloD.exe
    Turn it off when not in use
    Or do not open world

  24. #24
    Member makatekamo is offline
    MemberRank
    Apr 2009 Join Date
    PhilippinesLocation
    46Posts

    Re: Hacking

    In my server i have a case like that , you must secure all your ports so the hacker will not be able to use injection.... And i guess you need to IP BANNED that hacker :)

  25. #25
    no failure, no greget! dodojimbun is offline
    Grand MasterRank
    Jun 2012 Join Date
    IndonesiaLocation
    511Posts

    Re: Hacking

    IP Banned? how bout usb internet user? hahaha or can use VPN :junglejane:



Page 1 of 2 12 LastLast

Advertisement