Remote Attack!
Hello, My Server Is Tunare Reborn I Put This Warning On The Forums For ANY Other Server Owners, Someone Remotly Attacked My Server Computer And Added Himself As GM Level 255 In My DB Also Removed My Servers Maps Folder, What He Planned To Accomplish By This I Dont Know.
Tho I Don't Know Who He Is Being He Made Like 50 Players ALL Rank 255 Lucky For Me I Always Keep Backups Of My Files So Shove It Hacker! |
did you took a note of his account name/ip of anything of sort?
also, if he could do it once... he may come back... |
Yeah, best start locking down accounts/changing passwords.
|
And share whatever LS accounts he's on, so other server operators can be aware.
|
I Couldnt Get His Acct Info Or IP Cause He Made Like 50 People On My Server Admins So i Dont know whitch one he is
|
Well, depending on how he compromised your server, there might be some evidence.
|
i looked, he made sure no to leave ANY evidence behind
|
Quote:
Forgive me if you have already done this, but I assume that since your server was compromised in the first place, that you didn't know this before. Also, I'm assuming you're running a linux server if your's is a dedicated server. There's a few things you can do to lock it down:
I'll also add that I'm not a professional server admin, it's just a hobby, so I know there are at least a few more things you can do to secure it, I just don't know how to do it (ie chroot). |
sshd is pretty safe as long as passwords are disabled, so it only uses public-key encryption, and as long as you have decent passphrases, and the machine you login from has no keylogger on it. ssh with passwords is asking for trouble.
|
Quote:
|
My Server Computer Uses Windows 7 64 Bit 8 GB RAM Intel Quad Core and how he did it was he used navicat to get access to the DB i have it set up so all u have to do is open navicat and ur in the DB
|
So what your saying is, the problem lies between the chair and the keyboard.
|
http://www.securityfocus.com/infocus/1726
Yeah, i'm not even sure how you set up your mysql user accounts, but it's pretty obvious you didn't 1) disable the ability of users to remotely access your database, 2) using a generic easy to guess password. Navicat is just a MySQL query tool, your problem lies within how you configured MySQL, not in any program. May want to read up security practices in MySQL to understand your folly, and review all your configurations. Then top it off with reading how to disable other means of connection except for what you use (remote desktop, etc) But did you seriously think you WOULDN'T GET remotely attacked when you simply connect to navicat and you have full access to your SQL database? :o /scared As Rogean said, user error. :x |
This sounds like a layer 8 problem for sure. I advise you use the OSI Model to solve this issue.
Quote:
|
Expertise
Some people have certain expertise in different areas. I'm almost positive at least on of us is capable of tracking a hacker as long as they had access to your database and log files. I suggest using a phone and a screen sharing program. I'll bet a phone and a screen sharing program would help lots of people with lots of different problems. The more people we get using EQEmu the more community-rich our servers can become.
|
All times are GMT -4. The time now is 11:50 AM. |
Powered by vBulletin®, Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.