Ulysses

Ulysses Stuff => General Chat & Help and Support => Topic started by: JabbaTheWut on February 10, 2015, 07:26:42 PM

Title: How did this happen
Post by: JabbaTheWut on February 10, 2015, 07:26:42 PM
So I am running ULX and I got on my server and some I looked at the chat and it said "(Console) added =|TF|= TiggyTheTiger to group superadmin" Me and the other owner have no idea who he is. We have perma banned and removed him but, how did this happen. I didnt even know something like this is even possible. And how can I prevent it from happening in the future?
Title: Re: How did this happen
Post by: Megiddo on February 10, 2015, 07:35:31 PM
My guess would be your rcon password was easy to guess or was compromised. The message is telling you that the command was executed from the server console.

Back in the old days, you could exploit sv_cheats pretty easily to do this too, can't remember if Garry "patched" it or not.
Title: Re: How did this happen
Post by: Caustic Soda-Senpai on February 11, 2015, 11:51:03 AM
Make 100% sure your RCON Password is NOT in your server.cfg Put it in the Startup line of your server.
Title: Re: How did this happen
Post by: Bite That Apple on February 12, 2015, 12:16:22 AM
My suggestion is just not have a rcon password.
Title: Re: How did this happen
Post by: Caustic Soda-Senpai on February 12, 2015, 01:16:59 AM
My suggestion is just not have a rcon password.

Or that.
Title: Re: How did this happen
Post by: MrPresident on February 12, 2015, 07:18:44 PM
Depending on how you administer your server, that's not an acceptable suggestion.
I rely HEAVILY on HLSW which is an RCON application. I absolutely need RCON.

But yes, make sure you don't set your rcon password in your config file.
Some hosts don't let you change the command line, in which case you would have to set it in the config file, but do that at your own risk because there are plenty of exploits out there that grant users access to that file for viewing.
Title: Re: How did this happen
Post by: PwndKilled on February 12, 2015, 10:50:57 PM
You downloaded a backdoor leak for sure :D