Past weeks, hundred and hundred webs around the world got Defaced by some Arab teams... commanded by a guy named "SiR Abdou" (personally i think "defaced work" is so lame, thats cant be called "HACKED"
anyways.... past days a group of kids has exploited /injected some Cs. 1.6 servers, and i think those kids wanting some attention, are using "SiR" nicks trying everyone think cs servers got hacked by same Arab Team...
i just think that was by Russians...
Ok. i was looking into BsK and AG VDS finding any kinda evidence to trace those intrusions, i found just few evidence, because those kids disable servers logs to protect his identity...
1- Since we cant Update our Dproto servers, we are at risk to being attacked so easy, we have nothing againts this.... BUT WE GONNA DO OUR BEST TO PROTECT ALL OUR TEAM.
2- The only thing i saw, was a kinda Metamod inject / xploit
This what i saw:
create/download a file named Client.jar this file is backdoored (i will decompile this next days) in this root: /gameroot/cstrike
![[Image: troyan.png]](http://img221.imageshack.us/img221/6726/troyan.png)
then create a exec file in /gameroot/cstrike/addons/metamod
![[Image: execa.png]](http://img12.imageshack.us/img12/5403/execa.png)
inside this exec.cfg file:
![[Image: exec2.png]](http://img811.imageshack.us/img811/8961/exec2.png)
a folder named "maps" is created in /gameroot/cstrike/addons/amxmodx/configs
inside that folder are all those map configs
![[Image: maps.png]](http://img5.imageshack.us/img5/1064/maps.png)
inside each map.cfg are all stupid edited cvars, so as everyone knows, that map folders is autimatic readed each server restart, so cvars keep loading after each map change
![[Image: configsd.png]](http://img189.imageshack.us/img189/7046/configsd.png)
So, now everyone know rcon and nick passwords to enjoy all "hacked servers"
there are few thing that i will do in BsK servers, to protect us..
1- motd.txt will be read-only
2- we gonna disable pause/unpause plugin
3- added those steam, nicks to amxbanlist also servers banlist
4- make read-only "maps" folder
5- make read-only user.ini file to avoid those kids added as admin
6- thinking add some rcon protect plugins (changing name to avoid those kids can disabled
7 "log off" and "mp_logfile 0" always wil be ON
I decide post this, because i think that info can be readed and used by other clans to protect his owns VDS...
if anyone have any idea or suggestion about this, please let us know!
anyways.... past days a group of kids has exploited /injected some Cs. 1.6 servers, and i think those kids wanting some attention, are using "SiR" nicks trying everyone think cs servers got hacked by same Arab Team...
i just think that was by Russians...
Ok. i was looking into BsK and AG VDS finding any kinda evidence to trace those intrusions, i found just few evidence, because those kids disable servers logs to protect his identity...
1- Since we cant Update our Dproto servers, we are at risk to being attacked so easy, we have nothing againts this.... BUT WE GONNA DO OUR BEST TO PROTECT ALL OUR TEAM.
2- The only thing i saw, was a kinda Metamod inject / xploit
This what i saw:
create/download a file named Client.jar this file is backdoored (i will decompile this next days) in this root: /gameroot/cstrike
![[Image: troyan.png]](http://img221.imageshack.us/img221/6726/troyan.png)
then create a exec file in /gameroot/cstrike/addons/metamod
![[Image: execa.png]](http://img12.imageshack.us/img12/5403/execa.png)
inside this exec.cfg file:
![[Image: exec2.png]](http://img811.imageshack.us/img811/8961/exec2.png)
a folder named "maps" is created in /gameroot/cstrike/addons/amxmodx/configs
inside that folder are all those map configs
![[Image: maps.png]](http://img5.imageshack.us/img5/1064/maps.png)
inside each map.cfg are all stupid edited cvars, so as everyone knows, that map folders is autimatic readed each server restart, so cvars keep loading after each map change
![[Image: configsd.png]](http://img189.imageshack.us/img189/7046/configsd.png)
So, now everyone know rcon and nick passwords to enjoy all "hacked servers"
there are few thing that i will do in BsK servers, to protect us..
1- motd.txt will be read-only
2- we gonna disable pause/unpause plugin
3- added those steam, nicks to amxbanlist also servers banlist
4- make read-only "maps" folder
5- make read-only user.ini file to avoid those kids added as admin
6- thinking add some rcon protect plugins (changing name to avoid those kids can disabled
7 "log off" and "mp_logfile 0" always wil be ON
I decide post this, because i think that info can be readed and used by other clans to protect his owns VDS...
if anyone have any idea or suggestion about this, please let us know!
![[Image: giphy.gif]](https://media.giphy.com/media/LrLaeFiAWqmyuFcA53/giphy.gif)