Author Topic: Security Breach at Tasty?  (Read 3643 times)

Offline IrOn448

  • Newbie
  • *
  • Posts: 12
  • MY NEW TATTOO
    • View Profile
  • Rated:
Security Breach at Tasty?
« on: January 10, 2010, 03:51:38 AM »
Hi Console, I have been seeing a lot of this in the logs?

[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:60704[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:60954[WallFly[BZZZ]]: kick 3
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:49722[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:52491[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:46169[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:53570[WallFly[BZZZ]]: status

Why kick 3, does somebody have my rcon password? just wanted to pass this along.
Do  I need to change my rcon password. Please let me know what to do?
« Last Edit: January 11, 2010, 12:56:13 PM by Admin »
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline X7

  • Sr. Member
  • ****
  • Posts: 447
  • Quake II
    • View Profile
  • Rated:
Re: Security Breach at Tasty?
« Reply #1 on: January 10, 2010, 05:49:17 AM »
Hi Console, I have been seeing a lot of this in the logs?

[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:60704[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:60954[WallFly[BZZZ]]: kick 3
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:49722[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:52491[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:46169[WallFly[BZZZ]]: status
[2010-01-09 18:33] Rcon from 74.52.xxx.xxx:53570[WallFly[BZZZ]]: status

Why kick 3, does somebody have my rcon password? just wanted to pass this along.
Do  I need to change my rcon password. Please let me know what to do?

one of the TS admins, did a status
then kick player 3



X7
« Last Edit: January 11, 2010, 12:56:30 PM by Admin »
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
Quake II

Offline console

  • Brobdingnagian Member
  • ***
  • Posts: 4518
  • "Man, this is the way to travel," said my attorney
    • View Profile
    • tastyspleen.net
  • Rated:
Re: Security Breach at Tasty?
« Reply #2 on: January 10, 2010, 12:12:09 PM »
one of the TS admins, did a status
then kick player 3

Not quite.  It was an auto-kick by wallfly, based on the active banlist.

  20:14:33 CONNECT:     [3]  "Buckwheat"
  20:14:33 wallfly: enforce_bans: name(Buckwheat) clnum(3) ip(24.21.xxx.xxx)
  20:14:33 wallfly: rcon kick 3
  Dropping Buckwheat, console kick issued.

Buckwheat contacted me yesterday, and I've already added an exception for him so he can bypass the subnet ban.


Note: Assuming the server IrOn448 is referring to is KILLERPINGS, the ts admins don't have access to that rcon password at all.

But wallfly does use the global banlist by default.


Regards,

quadz

« Last Edit: January 10, 2010, 12:13:44 PM by console »
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline yahoo

  • Opulent Member
  • *
  • Posts: 2290
  • Quake II | Powered by SMF 1.0.9.
    • View Profile
  • Rated:
Re: Security Breach at Tasty?
« Reply #3 on: January 10, 2010, 03:47:23 PM »
I was wondering , (global banlist) does it mean that the ban applies on all servers seen at goto?
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
Quake II | Powered by SMF 1.0.9.
© 2001-2005, Lewis Media. All Rights Reserved.

Offline console

  • Brobdingnagian Member
  • ***
  • Posts: 4518
  • "Man, this is the way to travel," said my attorney
    • View Profile
    • tastyspleen.net
  • Rated:
Re: Security Breach at Tasty?
« Reply #4 on: January 10, 2010, 05:45:08 PM »
I was wondering , (global banlist) does it mean that the ban applies on all servers seen at goto?

Sort of.

The AIR* and TG* servers in UK and Italy are each on their own WallFly network, and have their own separate ban lists for their networks.

Most of the INDEPENDENT ZONE servers do share tastyspleen's ban list.  A few don't.  It's not mandatory for independent servers to share the ts ban list, BUT if a server participates in the invite! system, the only way I currently have to prevent someone from abusing invite! is to ban or mute them.

Some jerk from socal.res.rr.com was abusing invite! on KILLERPINGS and WHALE last week.  They were spoofing DonKeyballs-CRU's name and using both WHALE and KILLERPINGS to spam obnoxious invite messages.  So I added a mute for this player on all servers which participate in the invite! system.


Regards,

quadz


  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline yahoo

  • Opulent Member
  • *
  • Posts: 2290
  • Quake II | Powered by SMF 1.0.9.
    • View Profile
  • Rated:
Re: Security Breach at Tasty?
« Reply #5 on: January 10, 2010, 06:14:43 PM »
The AIR* and TG* servers in UK and Italy are each on their own WallFly network, and have their own separate ban lists for their networks.

Most of the INDEPENDENT ZONE servers do share tastyspleen's ban list.  A few don't.  It's not mandatory for independent servers to share the ts ban list, BUT if a server participates in the invite! system, the only way I currently have to prevent someone from abusing invite! is to ban or mute them.


Ahh.. so maybe thats why when i was on an AIR server, i used goto and there were some servers that showed empty even if there were players


Some jerk from socal.res.rr.com was abusing invite! on KILLERPINGS and WHALE last week.  They were spoofing DonKeyballs-CRU's name and using both WHALE and KILLERPINGS to spam obnoxious invite messages.  So I added a mute for this player on all servers which participate in the invite! system.


Regards,

quadz



I think I saw that.. Thanks.
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
Quake II | Powered by SMF 1.0.9.
© 2001-2005, Lewis Media. All Rights Reserved.

 

El Box de Shoutamente

Last 10 Shouts:

 

RyU

September 03, 2024, 05:15:49 PM
And wow Derrick is still playing lol
 

RyU

September 03, 2024, 05:15:15 PM
Just know yesterday is gone and soon tomorrow will be gone too  :)
 

Lejionator

August 08, 2024, 07:28:01 PM
It's tiem to QuakeCon!!!  ;)

https://www.youtube.com/watch?v=ThQd_UJaTys
 

ImperiusDamian

July 26, 2024, 09:34:53 PM
In nomine Quake II et Id Software et Spiritus John Carmack, Amen.
 

QuakeDuke

July 26, 2024, 05:10:30 PM
Hey, shout, summertime blues
Jump up and down in you blue suede shoes
Hey, did you rock and roll? Rock on!!  ...QD
 

Yotematoi

July 24, 2024, 01:31:20 PM
Ayer me mato 5 veces para robarme en la vida real hará lo mismo? [img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid0wXU2VgS7atesBcSoMz5BWMJCJajeZFVT6GzSU6TtpJGddN9kLTvWNgcZaskkbKFQl&amp;show_text=true&amp;width=500
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid0wXU2VgS7atesBcSoMz5BWMJCJajeZFVT6GzSU6TtpJGddN9kLTvWNgcZaskkbKFQl&show_text=true&width=500" width="500"
 

Yotematoi

July 24, 2024, 01:25:59 PM
hi ya está la basura de Martin, se cambió el nombre es un ladron estupido, asi llegó a 10000[img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&amp;show_text
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&show_text
 

Yotematoi

July 24, 2024, 01:25:59 PM
hi ya está la basura de Martin, se cambió el nombre es un ladron estupido, asi llegó a 10000[img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&amp;show_text
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&show_text
 

-Unh0ly-

July 05, 2024, 05:20:36 AM

Show 50 latest
Welcome, Guest. Please login or register.
September 20, 2024, 04:36:12 AM

Login with username, password and session length