Jump to content

How to stop this CHEAT - HACKED DEDI SERVER


Recommended Posts

  • Replies 445
  • Created
  • Last Reply

Top Posters In This Topic

Posted
Protection tested for GUNS'N'ROSES Arena server (SPC) and not hold out if we toppled over the weekend, it will make sense to declare the result.

 

Do you care to share how you protect your server?

There are only 10 types of people in the world: Those who understand binary, and those who don't.

Posted

are you sure some one didn't plug the wrong number, in the wrong place in a script, which multiplied the ai aircraft?? that's the way it looks to me... looks like someone went down a list of flights, wings, squads, and they, and plugged in numbers like 3,4,5, which in turn exponentially multiplied.

ASUS Strix Z790-H, i9-13900, WartHog HOTAS and MFG Crosswind

G.Skill 64 GB Ram, 2TB SSD

EVGA Nvidia RTX 2080-TI (trying to hang on for a bit longer)

55" Sony OLED TV, Oculus VR

 

Posted
are you sure some one didn't plug the wrong number, in the wrong place in a script, which multiplied the ai aircraft?? that's the way it looks to me... looks like someone went down a list of flights, wings, squads, and they, and plugged in numbers like 3,4,5, which in turn exponentially multiplied.

Ya I bet that's exactly what happened...

  • Like 1

[sIGPIC][/sIGPIC]

Posted

Ok gents, LETS FLY AGAIN!!!!!!!!!!! :pilotfly:

 

I`m start up server today (false =4c=SVFS server) and i had few series of attack in a 7 hours. In that time all servers are hacked few times but my server stay as a proud soldier who will not flinch. He (poor guy) is attack us but no successfuly. I can say to all: Our poor hacker can retire without honors!

 

My secret weapons is NetPeeker Firewall and Monitor

 

Server admins do this rules in your firewall:

1. Block ICMP protocol (all types) INBOUND CONNECTIONS: DENY all to ping you. He just ping servers with Ping of Death.

2. Block outgoing connections for windows process msfeedssync.exe - all the time when attack start this program ask to go out. If you permit it LOFC/BS will crash then. This is for case if we have trojan in system.

3. Block all (make a custom RULES) strange and crazy IP`s if you are not sure WHOIS. And step by step ALLOW people to join after filtering...

...watch attachment for more info

 

I know filtering is hard work and admins should spend to much time but on this way problem is solved and this is the only way for now. We will enjoy in our flights again. :thumbup:

 

Let`s fly! :)

rules.thumb.png.d984664a9cc30360c8e9945c0bd3ae98.png

  • Like 2
Quote

Немој ништа силом, узми већи чекић!

MSI Tomahawk MAX | Ryzen 7 3700x | 32GB DDR4 3200MHz | RX 5700 XT OC Red Dragon 8GB | VPC Throttle CM3 + VPC Constellation ALPHA on VPC WarBRD Base | HP Reverb G2

 Youtube Follow Me on TWITCH! 

Posted
Ok gents, LETS FLY AGAIN!!!!!!!!!!! :pilotfly:

 

I`m start up server today (false =4c=SVFS server) and i had few series of attack in a 7 hours. In that time all servers are hacked few times but my server stay as a proud soldier who will not flinch. He (poor guy) is attack us but no successfuly. I can say to all: Our poor hacker can retire without honors!

 

My secret weapons is NetPeeker Firewall and Monitor

 

Server admins do this rules in your firewall:

1. Block ICMP protocol (all types) INBOUND CONNECTIONS: DENY all to ping you. He just ping servers with Ping of Death.

2. Block outgoing connections for windows process msfeedssync.exe - all the time when attack start this program ask to go out. If you permit it LOFC/BS will crash then. This is for case if we have trojan in system.

3. Block all (make a custom RULES) strange and crazy IP`s if you are not sure WHOIS. And step by step ALLOW people to join after filtering...

...watch attachment for more info

 

I know filtering is hard work and admins should spend to much time but on this way problem is solved and this is the only way for now. We will enjoy in our flights again. :thumbup:

 

Let`s fly! :)

 

My hats off to you bud...nice stuff...:clap_2:

  • Like 1
Posted (edited)
Ok gents, LETS FLY AGAIN!!!!!!!!!!! :pilotfly:

 

I`m start up server today (false =4c=SVFS server) and i had few series of attack in a 7 hours. In that time all servers are hacked few times but my server stay as a proud soldier who will not flinch. He (poor guy) is attack us but no successfuly. I can say to all: Our poor hacker can retire without honors!

 

My secret weapons is NetPeeker Firewall and Monitor

 

Server admins do this rules in your firewall:

1. Block ICMP protocol (all types) INBOUND CONNECTIONS: DENY all to ping you. He just ping servers with Ping of Death.

2. Block outgoing connections for windows process msfeedssync.exe - all the time when attack start this program ask to go out. If you permit it LOFC/BS will crash then. This is for case if we have trojan in system.

3. Block all (make a custom RULES) strange and crazy IP`s if you are not sure WHOIS. And step by step ALLOW people to join after filtering...

...watch attachment for more info

 

I know filtering is hard work and admins should spend to much time but on this way problem is solved and this is the only way for now. We will enjoy in our flights again. :thumbup:

 

Let`s fly! :)

You are mistaken. it does not help.

To get started, simply block all the ip addresses of Tor, which will not allow an attacker to use them.But the difficulty lies in the fact that the list is dynamic, and it is necessary to continually update and contribute to the firewall. That's it really helps, at least for a while.

And if you make only the trusted list, the server will be closed on the way for new players.

Edited by Hellboy
  • Like 1
Posted
3. Block all (make a custom RULES) strange and crazy IP`s if you are not sure WHOIS. And step by step ALLOW people to join after filtering...

Unfortunatelly, public servers are no more public, if you apply whitelisting. And we are again at the beginning...

  • Like 1
Posted

Good job Falcon, that's what I suggested few days ago and it looks like it's working. Congrats bud.

There is nothing fancy in registering on the server's forums and asking for IP clearance. Best way is to get a static IP from your ISP.

Now if the bad guys still want to play, they'll have to register and use a regular IP, no more hiding behind proxies.

banner_discordBannerDimensions_500w.jpg

Situational Awareness: https://sa-sim.com/ | The Air Combat Dojo: https://discord.gg/Rz77eFj

Posted

Hope this works, but I'm sure he'll try to find a way around it.

i7-4820k @ 3.7, Windows 7 64-bit, 16GB 1866mhz EVGA GTX 970 2GB, 256GB SSD, 500GB WD, TM Warthog, TM Cougar MFD's, Saitek Combat Pedals, TrackIR 5, G15 keyboard, 55" 4K LED

 

Posted
...Best way is to get a static IP from your ISP...

Some ISPs charge you for single static-IP more, than for 100/100mbit flat connection. Others do not give you static-IP even if you'd pay it with pure gold (especially those who use private-IP & NAT for all customers)...

Posted
Some ISPs charge you for single static-IP more, than for 100/100mbit flat connection. Others do not give you static-IP even if you'd pay it with pure gold (especially those who use private-IP & NAT for all customers)...

 

Well, I guess people who are really interested in saving MP servers will be willing to do it. After all, those servers' admins have been paying from their own pockets for ages, and for the pleasure of the community.

A little cash sacrifice or ISP change from the other side would be fair enough IMO.

banner_discordBannerDimensions_500w.jpg

Situational Awareness: https://sa-sim.com/ | The Air Combat Dojo: https://discord.gg/Rz77eFj

Posted
Not work!:doh:

 

And your solution? Week-end's over.......Has it worked? :)

Novice or Veteran looking for an alternative MP career?

Click me to commence your Journey of Pillage and Plunder!

[sIGPIC][/sIGPIC]

'....And when I get to Heaven, to St Peter I will tell....

One more Soldier reporting Sir, I've served my time in Hell......'

Posted
You are mistaken. it does not help.

To get started, simply block all the ip addresses of Tor, which will not allow an attacker to use them.But the difficulty lies in the fact that the list is dynamic, and it is necessary to continually update and contribute to the firewall. That's it really helps, at least for a while.

And if you make only the trusted list, the server will be closed on the way for new players.

 

It helps very much. In this way he can not do anything because there is no connection to the server. Can only see how powerless he is. So much for his hacking skill.

 

Unfortunatelly, public servers are no more public, if you apply whitelisting. And we are again at the beginning...

 

Yes for now, but... Better than make server hiden or in LAN. Every player will see server, how many players there and if wanna join should ask and provide his IP. Server will be ''public'' very fast for many players. People who often hide behind another nickname, which connect through a proxy, which create problems on the server - does not deserve to enter the server in any case. Thus we do not care who they are, whether they connect from Mauritus or Zanzibar - they just can not connect. Filtered players will be able to play and finally to complete the mission. When the =4c= server decides that the players must be registered if they want to join - people are come and register. Also will come and say their IP address (static or dynamic, it does not matter). I know this is not an ideal solution, but what else to do.

 

Not work!:doh:

 

Please stop - IT WORK. Yesterday your server is hacked - MY NOT (server stay online more than 7 hours). I watched the attacks live while my friends enjoyed on my server. I watched and laughed.

  • Like 1
Quote

Немој ништа силом, узми већи чекић!

MSI Tomahawk MAX | Ryzen 7 3700x | 32GB DDR4 3200MHz | RX 5700 XT OC Red Dragon 8GB | VPC Throttle CM3 + VPC Constellation ALPHA on VPC WarBRD Base | HP Reverb G2

 Youtube Follow Me on TWITCH! 

Posted (edited)

Please stop - IT WORK. Yesterday your server is hacked - MY NOT (server stay online more than 7 hours). I watched the attacks live while my friends enjoyed on my server. I watched and laughed.

 

My server just worked too, but it was open to all users.See the difference?

Your option is suitable for flying friends and nothing more, and this task can be implemented completely by any firewall.You can leave the server in the list of available servers and cut off the only hacker to connect? I am sure it is not.

Edited by Hellboy
Posted
My server just worked too, but it was open to all users.See the difference?

I think it makes hell of difference, if it works of course. You say it did for you, so maybe you could enlighten us...

Posted (edited)
My server just worked too, but it was open to all users.See the difference?

 

So, lets talk about your solution - multiplayer are in cahos 2 monts.

 

Your option is suitable for flying friends and nothing more...

 

Friends are all good people in this comunity.

 

...and this task can be implemented completely by any firewall.

 

This firewall do complete job and keep this hacker in his dark room.

Edited by Falcon_S
Quote

Немој ништа силом, узми већи чекић!

MSI Tomahawk MAX | Ryzen 7 3700x | 32GB DDR4 3200MHz | RX 5700 XT OC Red Dragon 8GB | VPC Throttle CM3 + VPC Constellation ALPHA on VPC WarBRD Base | HP Reverb G2

 Youtube Follow Me on TWITCH! 

Posted
Well, I guess people who are really interested in saving MP servers will be willing to do it.

Yes, if it works. But I'm telling you right now: whitelisting based on IP will not work for long. Actually, it is very easy to circumvent such a protection. But I'm not going into details...

Posted

The goal is to make public server no-touch to this poor child. Hiding it or making whitelist of IP is not the solution, it makes good only for private servers for friends. Not for server, where 20-30 people could enter.

I hope this Hellboy's solution will make such thing working flawlessly.

Reminder: Fighter pilots make movies. Bomber pilots make... HISTORY! :D | Also to be remembered: FRENCH TANKS HAVE ONE GEAR FORWARD AND FIVE BACKWARD :D

ಠ_ಠ



Posted (edited)
Yes, if it works. But I'm telling you right now: whitelisting based on IP will not work for long. Actually, it is very easy to circumvent such a protection. But I'm not going into details...

 

Totally agree with you.

I think it should run a special forum with restricted access only for admins, where they could put the program itself and the documentation for it. I do not want to hacker broke on the second day of defense, after reading this forum for all mechanisms.

I will try to implement it.

Edited by Hellboy
Posted
I watched the attacks live while my friends enjoyed on my server. I watched and laughed.

 

LOL That made my day.

ED have been taking my money since 1995. :P

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...