Welcome to PBBans
![]() |
Welcome to PBBans, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information for you to signup. Be apart of PBBans by signing in or creating an account.
|
Manual Bans?Question
#1
?????????? дур 27, 2008 - 03:36
If evidence (server logs) can be provided clearly showing that a player is attempting to (and successfully did) hack a server, is that enough to place a manual PB ban on said player? Two Bunker servers were attacked on the 25th by the same guy, one which he crashed.
Is this a possibility, or out of the question?
#2
?????????? дур 27, 2008 - 03:53
#3
?????????? дур 27, 2008 - 05:15
#4
?????????? дур 27, 2008 - 05:59
#5
?????????? дур 28, 2008 - 03:05
We do run 2.6b (on all servers).
We are currently attempting to take legal action against them (talking to their ISP atm).
The attack they used has been posted here before: Connect with no GUID, and then generate lots of phony players (names like: SHD787SAK389WS) and attempt to hack the RCON attempting to crash the server. With a Shrubbot ban, everyone is banned (invalid ban entry - no GUID).
#6
?????????? дур 28, 2008 - 03:13
#7
?????????? дур 28, 2008 - 03:20
RoadWarrior, op Feb 28th 2008, 01:13 PM, zei:
He doesn't have the password, he's attempting to bruteforce it using numerous random accounts that he generates once he connects.
We went from 30/64 to 60/64 within minutes of him connecting, and once we were able to ban him via IP we were back to 30.
#8
?????????? дур 28, 2008 - 11:12
????????? ???? ???????? STA - DynoSauR: дур 28, 2008 - 11:13
#9
?????????? дур 29, 2008 - 04:14
Change your rcon password to one which has both upper and lower case characters, and preferably a number or two aswell. This means it'll take days for the program to obtain the password, and it's unlikely the hacker will wait for so long.
#10
?????????? дур 29, 2008 - 10:29
=BLACKWOLF=, op Feb 29th 2008, 01:14 AM, zei:
Change your rcon password to one which has both upper and lower case characters, and preferably a number or two aswell. This means it'll take days for the program to obtain the password, and it's unlikely the hacker will wait for so long.
Our rcon is long, has numbers, upper case, lower case, etc... Trust me, we stream every server to PB, have some very smart anti-cheat experts/programmers, etc...
The hack's effects: A player will connect with no GUID, and begin to generate numerous, false players with names composed of random numbers/letters. You can kick the false players as much as possible, but they keep regenerating. When you check the logs, you see that they are all attempting to brute-force RCON.
Only way to stop it for the short-term (that we've found) is to Ban via IP. The problem with that, any hacker smart enough to do this can easily fake/get a new IP...
Hence, is there anything PB and/or EB can do?
1 ????????????? ?????? ??? ????
0 ?????????????, 1 ??????, 0 ???????












