GREENWICH MEAN TIME is Currently: - 08:41 *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: We are now hosting a Capture The Flag Server RAW recruits CTF 31.132.2.124:25777
Advanced Search  
Pages: [1]
  Print  
Author Topic: russian hacker on our server  (Read 155 times)
Epsilon
RAW Member
*****
Posts: 2790


sad_epsilon@hotmail.com
Email
« on: February 03, 2012, 06:03:32 AM »

Ok maybe some of you know that there is this guy trying to connect to our server. Changing his name constantly.

Is there maybe a way, like in FEAR, to add an IP or guid to a file and then restart the server so he can't even try to connect anymore?

He is being really persistent, now with a different IP.


--------------------------copy from vnc

nickname
CONNECT OR BAN  / SPAM 7000 SVRS / 195.46.191.148
IF we can please IP ban "him", RCON doesnt work on him since he is always connecting - eps  

guid  0186505dd769c5e55d62ba8a0cbae139

195.46.191.148

[11:02:43 PM] dumpuser "195.46.191.148"
----------------------
userinfo
--------
cg_predictItems     1
cl_punkbuster       1
cl_voice            0
cl_wwwDownload      1
rate                25000
snaps               30
name                195.46.191.148
protocol            6
challenge           2105795170
qport               -27679

------------------------------------------------------------------------------


Same story, different IP now, and slightly different names.      He's being a smart ass now as well.. if you look at his nicks; so what else?, 100$ to remove, connect or ban, some weird russian letters, and his icq number..  : icq 426873513  

I cant get any more info unlike the other guy mentioned above, it said it cant find the guid or it's unknown.

 6     0 CNCT                                  so what else? :   12350 128.71.26.211:28966   -27679 25000


IP trace revealed it's coming from Russia, but that could be false. Im not sure.



195.46.191.148 IP address location & more:
IP address [?]:   195.46.191.148 [Whois] [Reverse IP]
IP country code:   RU
IP address country:   Russian Federation
IP address state:    n/a
IP address city:    n/a
IP address latitude:    60.0000
IP address longitude:    100.0000
ISP of this IP [?]:    VimpelCom
Organization:    VimpelCom
Host of this IP: [?]:    static-a148.Togliatti.golden.ru[Whois] [Trace]





195.46.191.148 Whois

Contact Email

Whois Data
NetRange: 195.0.0.0 - 195.255.255.255
CIDR: 195.0.0.0/8
OriginAS:
NetName: RIPE-CBLK3
NetHandle: NET-195-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 1996-03-25
Updated: 2009-03-25
Ref: http://whois.arin.net/rest/net/NET-195-0-0-0-1

OrgName: RIPE Network Coordination Centre
OrgId: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
RegDate:
Updated: 2011-09-24
Ref: http://whois.arin.net/rest/org/RIPE

ReferralServer: whois://whois.ripe.net:43

OrgTechHandle: RNO29-ARIN
OrgTechName: RIPE NCC Operations
OrgTechPhone: +31 20 535 4444
OrgTechEmail:  
OrgTechRef: http://whois.arin.net/rest/poc/RNO29-ARIN

OrgAbuseHandle: RNO29-ARIN
OrgAbuseName: RIPE NCC Operations
OrgAbusePhone: +31 20 535 4444
OrgAbuseEmail:  
OrgAbuseRef: http://whois.arin.net/rest/poc/RNO29-ARIN

RTechHandle: RIPE-NCC-ARIN
RTechName: RIPE NCC Hostmaster
RTechPhone: +31 20 535 4444
RTechEmail:  
RTechRef: http://whois.arin.net/rest/poc/RIPE-NCC-ARIN

 
195.46.191.148 Server Details

IP address: 195.46.191.148
Server Location: Russian Federation
ISP: VimpelCom

------------------------

HERE is his icq page (click on More about me)
http://www.icq.com/people/426873513/


I tried with pb on codrcontool, but he doesnt show up in the list. only when i ask for player info, but since he is not IN the server, the pb commands don't work. There is no way of getting rid of this dude it seems T_T (fucking lifeless piece of shit)
« Last Edit: February 03, 2012, 06:08:13 AM by Epsilon » Logged
mk'ers
Administrator
*****
Posts: 1727



Email
« Reply #1 on: February 03, 2012, 03:21:23 PM »

It's not just our server either.

I also looked up the IP address, it seems a COD4 server is running with the same address. Once you see it , it's obvious they're connected.

http://www.gametracker.com/server_info/195.46.191.148:28960/



* COD4spamserver.jpg (108.99 KB, 713x580 - viewed 14 times.)
Logged

When danger reared its ugly head, he bravely turned his tail and fled.
Epsilon
RAW Member
*****
Posts: 2790


sad_epsilon@hotmail.com
Email
« Reply #2 on: February 04, 2012, 02:33:39 AM »

yea and there are other victims as well if you look at the comment box.

hmm player stats are not tracked, and they went from rank 6000 to 1800...  lol


the other ip doesn't show up any servers in gt though. Seems like nothing we could really do about it..
Logged
Rebel
Administrator
*****
Posts: 4983


Ho Ho Ho

2638543
WWW Email
« Reply #3 on: February 28, 2012, 05:29:32 AM »

Problem now identified and fixed. Alpha networks received a complaint about one of our servers hacking into another machine, it was someone using a "get status" bug on our server.

Have downloaded a couple of dll's (wsock32 & myproxocket) into COD's root directory and restarted the server, this may help our other games too as without the get status bug, less traffic may be going to our server, thanks to Dan the Man for this one.
Logged

GODS HAS DONE WHAT!!!  
mk'ers
Administrator
*****
Posts: 1727



Email
« Reply #4 on: February 29, 2012, 10:35:54 AM »

Using our server to 'hack' others eh, swine. Cheers for the info.
Logged

When danger reared its ugly head, he bravely turned his tail and fled.
Pages: [1]
  Print  
 
Jump to: