[mohaa] server hijacking

Steve Pirk orion at deathcon.com
Wed Aug 13 16:06:51 EDT 2003


Maybe do a:
user at host:/game/mohaa$ strings fgameded.so
and look for likely commands?

--
Steve (egrep)

On Wed, 13 Aug 2003, Shaun Green wrote:

> I dont know it either im trying to find out.
>
> ----- Original Message -----
> From: <MOH at digitalnines.com>
> To: <mohaa at icculus.org>
> Sent: Wednesday, August 13, 2003 2:48 PM
> Subject: Re: [mohaa] server hijacking
>
>
> > but what is the command?
> > if i knew what i was looking for it would make things a lot easier :)
> >
> >
> > BhAaD
> >
> > ----- Original Message -----
> > From: "Shaun Green" <greensha at rogers.com>
> > To: <mohaa at icculus.org>
> > Sent: Wednesday, August 13, 2003 2:25 PM
> > Subject: Re: [mohaa] server hijacking
> >
> >
> > > >From my understanding the command is built into the fgameded.so.  If
> you
> > > open this up with a hex editor and just change the name of the command
> to
> > > something else it works apparently.  Im just going by what I have been
> > told.
> > > Does it work?  Who knows?  But editing the gamex86.dll on win32 servers
> > has
> > > apparently cured the problem for those servers.  Do I have any clue at
> > what
> > > Im doing. Nope, but Im willing to try.  And I could be way off this,
> just
> > > going by info I have gathered from other admins.
> > >
> > > CDN
> > >
> > >
> > > ----- Original Message -----
> > > From: <MOH at digitalnines.com>
> > > To: <mohaa at icculus.org>
> > > Sent: Wednesday, August 13, 2003 2:10 PM
> > > Subject: Re: [mohaa] server hijacking
> > >
> > >
> > > > And how exactly do you plan to "edit the linux binaries"?
> > > >
> > > > ----- Original Message -----
> > > > From: "Shaun Green" <greensha at rogers.com>
> > > > To: <mohaa at icculus.org>
> > > > Sent: Wednesday, August 13, 2003 1:43 PM
> > > > Subject: Re: [mohaa] server hijacking
> > > >
> > > >
> > > > > Does anyone actually no the command that restarts the map?  I think
> > the
> > > > best
> > > > > way to fix this problem is edit the linux binaries and change the
> > > command
> > > > to
> > > > > something only you would know.  That way there wouldnt be any chance
> > of
> > > it
> > > > > being discovered.  I will have to investigate and find out what the
> > > actual
> > > > > command is.  If you know it please dont post it.
> > > > >
> > > > > CDN
> > > > > ----- Original Message -----
> > > > > From: "Bradley Caricofe" <Caricofe at Comcast.net>
> > > > > To: <mohaa at icculus.org>
> > > > > Sent: Tuesday, August 12, 2003 5:37 PM
> > > > > Subject: RE: [mohaa] server hijacking
> > > > >
> > > > >
> > > > > > If this is true then basically all MOHAA servers are rendered
> > > completely
> > > > > > worthless to the people running them.  I have a friend who runs a
> > very
> > > > > busy
> > > > > > MOH server, he recently put it on permanent passwd protection to
> > stop
> > > > the
> > > > > > cheaters and the crackers from getting in.  Sad...
> > > > > >
> > > > > > > -----Original Message-----
> > > > > > > From: Shaun Green [mailto:greensha at rogers.com]
> > > > > > > Sent: Tuesday, August 12, 2003 5:29 PM
> > > > > > > To: mohaa at icculus.org
> > > > > > > Subject: Re: [mohaa] server hijacking
> > > > > > >
> > > > > > >
> > > > > > > Apparently there is a simple client side command that allows the
> > > > > > > restarting
> > > > > > > of maps.   The experience I had today just really ticked me off.
> > 3
> > > or
> > > > 4
> > > > > > > peeps doing it and I had lost complete rcon control. (they never
> > had
> > > > > rcon
> > > > > > > control just the constant restarting seemed to jam the whole
> > > > > > > thing up)  Even
> > > > > > > ssh to the main console on the server was useless. Someone on
> > > > > mohadmin.com
> > > > > > > has a made a fix.  He hasnt posted it yet because anyone could
> > > > download
> > > > > it
> > > > > > > and get the new command. (he needs some guidance on hiding the
> > > > > > > command)  The
> > > > > > > win32 user made fix has been encoded to disguise the command.
> > > > > > > Lets hope we
> > > > > > > can get this fixed.
> > > > > > >
> > > > > > > CDN
> > > > > > >
> > > > > > > ----- Original Message -----
> > > > > > > From: "Salsich, Luke" <LJS at protectorgroup.com>
> > > > > > > To: <mohaa at icculus.org>
> > > > > > > Sent: Tuesday, August 12, 2003 4:43 PM
> > > > > > > Subject: RE: [mohaa] server hijacking
> > > > > > >
> > > > > > >
> > > > > > > What they do is bind a series of keys to certain actions (like
> > chat)
> > > > and
> > > > > > > this causes errors in the game that repeat endlessly -  This is
> > > > > > > what causes
> > > > > > > the lag and usually a game crash. I haven't worked on finding a
> > way
> > > to
> > > > > > > prevent it as they only did this once to my servers.
> > > > > > >
> > > > > > > Luke
> > > > > > >
> > > > > > >
> > > > > > >
> > > > > > > -----Original Message-----
> > > > > > > From: Anthony Quon [mailto:anthonyquon at hotmail.com]
> > > > > > > Sent: Tuesday, August 12, 2003 3:56 PM
> > > > > > > To: mohaa at icculus.org
> > > > > > > Subject: Re: [mohaa] server hijacking
> > > > > > >
> > > > > > >
> > > > > > >
> > > > > > > Yep there are 'hacking' clans that will come around and will
> > > initially
> > > > > > > wallhack/aimbot a server to get a rise out of the server admins.
> > > Once
> > > > > the
> > > > > > > admins try and kick these users, they will come back with
> taughts
> > > and
> > > > > msg
> > > > > > > floods with their group website and etc and will eventually
> crash
> > > the
> > > > > > > server. From what I hear, there are 10+ ways of crashing or
> > > restarting
> > > > a
> > > > > > > server...I'm not sure if they are just exagerating..but even if
> > > > > > > there aren't
> > > > > > > 10+ ways..there is at least one way since they are able to do
> it.
> > > > > > > I couldn't
> > > > > > > find any traces in any log files since I don't normally turn
> logs
> > > > > > > up because
> > > > > > > of the performance hit it causes....if anyone has any
> information,
> > > > that
> > > > > > > would be great.
> > > > > > >
> > > > > > >
> > > > > > > Also, in regards to the map changes and etc in the initial
> > > post...are
> > > > > you
> > > > > > > sure you disabled voting? This is definitely one way where they
> > can
> > > > vote
> > > > > > > their way into changing a map. I have turned off voting for all
> my
> > > > > servers
> > > > > > > since it's kinda useless anyway.
> > > > > > >
> > > > > > > Thanks,
> > > > > > > ANthony
> > > > > > >
> > > > > > >
> > > > > > > >From: <MOH at digitalnines.com>
> > > > > > > >Reply-To: mohaa at icculus.org
> > > > > > > >To: <mohaa at icculus.org>
> > > > > > > >Subject: Re: [mohaa] server hijacking
> > > > > > > >Date: Tue, 12 Aug 2003 12:44:39 -0400
> > > > > > > >
> > > > > > > >I've also had players come in crashing some of our clients
> > servers.
> > > > > They
> > > > > > > >spam some msg's and crash the servers and leave.  Last time we
> > got
> > > an
> > > > > ip
> > > > > > > >and ipchained him from the server.
> > > > > > > >They seem to be spamming msg's (such as their site) or what
> not.
> > > It
> > > > > > > >scrolls down and then the server crashes.
> > > > > > > >Any ideas ?
> > > > > > > >
> > > > > > > >   ----- Original Message -----
> > > > > > > >   From: Shaun Green
> > > > > > > >   To: mohaa at icculus.org
> > > > > > > >   Sent: Tuesday, August 12, 2003 7:11 AM
> > > > > > > >   Subject: [mohaa] server hijacking
> > > > > > > >
> > > > > > > >
> > > > > > > >   It has come to my attention that players on the server can
> > > > > continually
> > > > > > > >reload the map at will.  There is a command in the gamex86.dll
> > that
> > > > > will
> > > > > > > >allow anyplayer to restart the map. [without rcon]  As us linux
> > > > admins
> > > > > do
> > > > > > > >no use the gamex86.dll this needs patched on the linux ver.  A
> > > > > > > fix has been
> > > > > > > >made for Microshaft servers.  Please someone help as I had 3
> > > > different
> > > > > > > >people continually starting the map every 30 secs.
> > > > > > > >
> > > > > > > >   CDN
> > > > > > >
> > > > > > >
> _________________________________________________________________
> > > > > > > The new MSN 8: smart spam protection and 2 months FREE*
> > > > > > > http://join.msn.com/?page=features/junkmail
> > > > > > >
> > > > > >
> > > > >
> > > >
> > >
> >
>



More information about the Mohaa mailing list