Hacker on the loose on the MS

Status
Not open for further replies.

Autosaver

Member
I was making a server. Somewhat 5 minutes into the game. We started going through walls, getting crushed, moving everywhere, jumping/death frames forever. I was playing tag.

I've run into to this like 5 times. And eventually got sigsevd. Did I get hacked?
 
Ok, what wad you was playing/was you playing wad at all? Did you have ability to move anyway? Tell please more info about it, so I can (erm, others too)get it what was that, and why that happened. You said, that your server is hacked, what CAN be possible, but tell me what happened in end of that chaos.

Edit: This is getting interesting :]
 
Well, I just started a tag. And I was IT. I could see VERY far away, underground a dead me. The next second I just jumping and getting stuck to the floor. I pressed jump and suddenly I'm stuck in the wall. And then a second later, everyone is in the pool.

I was like WTF? I tried to record it, but once I started Fraps it stopped.

Oh, no wads added.
 
Autosaver said:
Well, I just started a tag. And I was IT. I could see VERY far away, underground a dead me. The next second I just jumping and getting stuck to the floor. I pressed jump and suddenly I'm stuck in the wall. And then a second later, everyone is in the pool.

I was like WTF? I tried to record it, but once I started Fraps it stopped.

Oh, no wads added.

Um, did you lagged/your server lagged? And, which srb2 you was playing, AND, If you played the new one, the problem should be there. They can contain BUGS. And lag can bong you far away, ofc the lag stage saw's in your ping.

If you was playing again the old srb2; Lag, I think. Hacking can be possible.

Hint: Virus scan ur computer :), and plus, what means for getting Sigsev'd?
 
I was in a server, and in GFZ1, the host was saying he/she was always getting 'teleported' back to the start instantaneously. In NAGZ, he also complained that his camera was always messing up (turning in random directions, involuntarily), causing him to fall into a pit; he was also forced to hit the ceiling at random times (as if gravity was modified, but there was no admin), which likewise made him fall into the pit. He kicked a certain player, and then everything calmed down. When that player rejoined, however, things started to mess up again.
 
^SAME EXACT thing. A certain user joined. He wasn't ingame. He just goes by the name "Player (number)"

And they are usually green sonics.
 
IPs would be nice, you know, they show on join (and through nodes) when you're admin.
 
And I think you can show the log, too. I seriously want to see what happened - And I think the Ip are in the log, too :]
 
I'll show log the next time it happens. Because I obviously havn't waited to get my answer.(New game...)

Though, I think I posted a EIP in the bug report topic.
 
I think this video will be worth watching. But I am not entirely sure if it would help with this.

Video Link (log #2 goes with this one)

Log Files:
Log #1
Log #2


Hacker IP from log: 173.54.93.199
Port: 5029

I had a hacker join my server today a couple of times, and he played match and CTF in a very funny way. The first time he joined - actually his name was "sonic" that time, taking a video wasn't at all in my mind (log overwritten accidentally). I saw him cheat, and I kicked him from the server (just gave him a chance to rejoin, so I can see his reactions). He rejoined, same IP, but named himself "cyan," and then after a few seconds the server remotely shut down. The second time he joined, it was just the hacker and me, so I didn't get to see exactly how he played (spectate) because he complained. However I managed to see how he was fighting against me from my view, and I used startmovie command to take a video, but apparently what I got was an extremely large PNG file - around 1GB, because it was long - and I can't view it (see log #1). The third time he joined I took the liberty of recording the session with HyperCam 2. It was great there were other players in the server, so I just spectated Cyan the whole time (see log #2 and video link).

More information below, see the video and/or log #2 for everything:

Video Description on YouTube said:
This is a network game in Sonic Robo Blast 2: http://srb2.org

Sorry for lack of sound... recording and saving a video with sound in it would take up far too much space for my hard drive to contain.

Wednesday, August 05, 2009, at around 1:10 AM UTC-7, a hacker, by the name of Cyan, had joined my server (servername: symf). I've seen him a couple of times before, but I managed to take a video of his actions in this game.

Log of the incident here (start at highlighted lines, when he joined, contains IP address): http://srb2.pastebin.com/f1f403f8d

Known actions:
-He verified himself spontaneously without entering a password or notifying me
-Teleporting randomly in normal ring, special ring, or emerald respawn points for quick and easy collection
-Also teleporting to a player's respawn point when the player died
-In addition, teleporting fairly close to another player to surprisingly shoot him or her, and then doing the same thing to another player - again at RAPID rates
-Weird way of following players when Super, to hurt on contact?
-Remotely shutting down the server from his computer - not under my control

Only when I used the NODES command, and only when I actually paid a closer look to what came up, did I see that Cyan was a verified admin. I did NOT verify anyone in the server before seeing that. I then verified Daniel Zenkai Alpha (node 1), and after a few seconds, he got kicked from the server. I later verified myself (node 0) so that nobody would be an administrator, and then suddenly all these UNKNOWN NET COMMAND messages flooded the console, along with some few other "say" messages from unknown player, "~P" and "~SERVER" and myself. Finally the server shut down (see log for reference).

As the UNKNOWN NET COMMAND messages were flooding the console, and as random messages came up from an unknown player, I tried putting on mute, but the game crashed too soon for me to do so.

Video recorded using HyperCam 2 (free version).

Just tell me if I'm missing anything...
 
That doesn't sound good. I hope this Hacker guy gets banned soon, otherwise we'll have to be careful while hosting.
 
I didn't want to ban him while making the video just yet. I wanted to see how he would react if I took away his server powers, which he somehow got himself. And I didn't have any password set.

And again, anyone smart enough can change his or her IP, causing some hosts to still ban each time he joins. Why not just ban a range of IPs of the hacker, preventing him from joining any servers hosted on the Master Server?

In the game of Log #1, he also was doing very similar things as shown in the video, but I was his only opponent, and it was CTF. It was very impossible for me to even score one point because he always comes from nowhere to touch me so I can drop the flag. He was super too, so I wasn't able to lay a finger on him.
 
First off, welcome back Reunite.

I forgot to say that when I saw your 1st post after you've returned.

Well, I agreed with you so I edited my post above. ;-)
 
Have something to say too : today, I've got a hacker (not a bug), he was able to kick everyone, even me (result of a server shutdown). He came few times and that was boring. After i used the ban command, but he came back few minutes later. He also activated the cheats himself.

Next, I dont know if it's a hack or not, but theses things happened too :
- found monsters in tag mode (verified, not a hack, forget it).
- some values were changed (nparam, and others, dont remember)
- the console said a file was tried to be add, but because I didnt have it, the server has shutdown.

That's all, for me.
 
Totaya17 said:
Have something to say too : today, I've got a hacker (not a bug), he was able to kick everyone, even me (result of a server shutdown). He came few times and that was boring. After i used the ban command, but he came back few minutes later. He also activated the cheats himself.

Next, I dont know if it's a hack or not, but theses things happened too :
- found monsters in tag mode
- some values were changed (nparam, and others, dont remember)
- the console said a file was tried to be add, but because I didnt have it, the server has shutdown.

That's all, for me.

A note: Files like "V!"
 
Status
Not open for further replies.

Who is viewing this thread (Total: 1, Members: 0, Guests: 1)

Back
Top