• Any good anticheat addons?
    19 replies, posted
So last night someone got in-game access to my console... Im not sure how this happened, but I would like to see if there are any good anti-cheat addons out there, and also the best way of keeping hackers at bay! So, what do you all use to keep your servers safe? Thanks in advance! Not sure if KurruptRP is known for being hackers or what, but the spam message last night by console was: [I] This server is shit, join KurruptRP (Someip)[/I]
The only way somebody get's access to your server's console is through a backdoor/exploit in a script/addon you've downloaded or if you've shared your RCON password with others (or made it painfully obvious like '123').
[QUOTE=EvacX;42822451]The only way somebody get's access to your server's console is through a backdoor/exploit in a script/addon you've downloaded or if you've shared your RCON password with others (or made it painfully obvious like '123').[/QUOTE] Hm. Thats odd. The only thing I have is ULX.. Everything else was bought off coderhire..
Did you set the RCON pass in server.cfg?
[QUOTE=ms333;42822633]Did you set the RCON pass in server.cfg?[/QUOTE] Yes, its 16 random numbers/digits.
[QUOTE=GM_Wizard;42822658]Yes, its 16 random numbers/digits.[/QUOTE] Set it in your start-up line (a new pass) and remove it from the server.cfg.
[QUOTE=ms333;42822702]Set it in your start-up line (a new pass) and remove it from the server.cfg.[/QUOTE] Thanks, I did not think of that... Hope it works.
If you don't need RCON at all, it's best to completely disable it. Set an empty password for RCON and it's disabled automatically.
[QUOTE=danielga;42822899]If you don't need RCON at all, it's best to completely disable it. Set an empty password for RCON and it's disabled automatically.[/QUOTE] What kind of server admin wouldn't need RCON?
So if the only public addon you had installed was ULX, there might still be some ULX exploits are still floating around? What gamemode were you running?
[QUOTE=EvacX;42823019]What kind of server admin wouldn't need RCON?[/QUOTE] RCON is built into ULX allowing him to use that feature. He also has direct console access.
[url]http://coderhire.com/scripts/view/456[/url] shameless plug, but there is no other ac thats any good cept for hex's/private AC's [editline]11th November 2013[/editline] Also just disable rcon itself. It's not needed.
[QUOTE=GM_Wizard;42822616]Hm. Thats odd. The only thing I have is ULX.. Everything else was bought off coderhire..[/QUOTE] You might want to note that even coderhire scripts can be used to backdoor. We dealt with something like this only a few months ago. There was a widespread backdoor in many scripts downloaded off the workshop. Coderhire doesn't mean security. Be smart about what you put on your server.
[QUOTE=Jarva;42823147]RCON is built into ULX allowing him to use that feature. He also has direct console access.[/QUOTE] Doesn't ULX disable use of some commands like sv_cheats and probably some more I'm forgetting?
[QUOTE=Sm63;42826443]Doesn't ULX disable use of some commands like sv_cheats and probably some more I'm forgetting?[/QUOTE] Probably, just use direct console access then.
[QUOTE=zerothefallen;42823443][url]http://coderhire.com/scripts/view/456[/url] shameless plug, but there is no other ac thats any good cept for hex's/private AC's [editline]11th November 2013[/editline] Also just disable rcon itself. It's not needed.[/QUOTE] [quote]Detects Detours -- Something I've never seen an AC do before, this detects nearly every cheat.[/quote] You mean you didn't see ralle/Polly's, Yakahughes' or my anticheat 3 years ago; all 3 of which were publicly released? Oh and if you're looking to detect every cheat, checking for detours isn't the best way.
[QUOTE=Flapadar;42827993]You mean you didn't see ralle/Polly's, Yakahughes' or my anticheat 3 years ago; all 3 of which were publicly released? Oh and if you're looking to detect every cheat, checking for detours isn't the best way.[/QUOTE] When you release a cheat to the public you're asking for it to get detected. Let's not derail this one like the last one.
[QUOTE=bobbleheadbob;42831578]When you release a cheat to the public you're asking for it to get detected. Let's not derail this one like the last one.[/QUOTE] Obviously you have misunderstood what Flapadar said. To be honest, this is all around the subject of Anti-Cheats, not what I would call a derailment at least. It may indirectly lead us to a nifty conclusion. Oubliette released an Anti-Cheat not so long ago that should deal with most of the unwanted activities on your server. As for the rcon, you might want to do some more digging on how he gained access.
[QUOTE=Flapadar;42827993]You mean you didn't see ralle/Polly's, Yakahughes' or my anticheat 3 years ago; all 3 of which were publicly released? Oh and if you're looking to detect every cheat, checking for detours isn't the best way.[/QUOTE] i havent seen any ac do it before, exactly what mine says. plus it isnt the best way, doesnt mean it hurts? still detects pretty much every cheat that doesnt force load priority
[QUOTE=zerothefallen;42832232]i havent seen any ac do it before, exactly what mine says. plus it isnt the best way, doesnt mean it hurts? still detects pretty much every cheat that doesnt force load priority[/QUOTE] Even if the Cheat does prevent the Anti-Cheat from loading, you could just make a call back check once the Anti-Cheat is loaded, or otherwise kick the client. Obviously, it would be a cat and mouse game, but there will always be ways for a cheat to bypass an anti-cheat.
Sorry, you need to Log In to post a reply to this thread.