Jump to content
Sign in to follow this  
Barabus

Server config file script

Recommended Posts

There is a nasty script floating out there that allows the script access to the content of you server config files. It should be pretty obvious how damaging this can be. A script kid posted the admin password to a friend's server and other information that you really don't want made public. My advice, if you suspect a hacker on your server, change your admin password and anything else quickly.

Share this post


Link to post
Share on other sites

The script / bypass to download the server config and RCon config of any server you are playing on has been made semi-public (this means it has been made public to all those script-kiddies running bypasses)

You know what that means?

Any script running person that logs on to your server can leech the server config and the BEserver config. The server config will contain the ingame admin password and the BEserver config contains the password to connect to your server through RCon / BeRcon. This gives anyone who has it more or less control over your server.

Oh, and apparently this issue has been known for over a year (ARMA 2 thingie) and easily avoidable. Still the serverhosters out there (Vilayer for one) use the default paths and filenames for every single slotted server they rent out!

dev-heaven.net/issues/20994

forums.bistudio.com/showthread.php?121438-How-to-secure-Your-server-Read-here!/page3&p=1974973#post1974973

So not only do hackers run the show ingame, prepare your slotted gameserver to be taken over.

Edited by tickle_me_jesus
  • Like 1

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×