View unanswered posts | View active topics It is currently Sat Apr 25, 2026 4:51 pm



Reply to topic  [ 23 posts ]  Go to page Previous  1, 2
 Attention Sysops hacker Alert!! 
Author Message
Veteran Op
User avatar

Joined: Thu Jun 02, 2005 2:00 am
Posts: 5558
Location: USA
Unread post 
513 is a standard rlogin port. While neither twxproxy nor swath do this by default, some telnet programs like zoc and putty will change the port if you select "rlogin" as the method by accident.

My point isn't that these guys did a typo, I'm sure that's not the case here. What I'm saying is... just because someone hits your admin port don't assume it's a hack attempt, it could just be an accident. It's important to determine the intent of things.

_________________
May the unholy fires of corbomite ignite deep within the depths of your soul...

1. TWGS server @ twgs.navhaz.com
2. The NavHaz Junction - Tradewars 2002 Scripts, Resources and Downloads
3. Open IRC chat @ irc.freenode.net:6667 #twchan
4. Parrothead wrote: Jesus wouldn't Subspace Crawl.

*** SG memorial donations via paypal to: dpocky68@booinc.com
Image


Wed May 30, 2007 9:09 pm
Profile ICQ WWW
Gameop
User avatar

Joined: Sun Oct 08, 2006 2:00 am
Posts: 991
Unread post 
I understand where you are coming from. But, I am not willing to put forth the effort or take the time to find out their intent.  Its not as if I were making money or they are a paying customer. I deal with security issues everyday, its the social engineering part of finding out the user's intent that makes the whole thing too dangerous to deal with.

Cerne

_________________
"All warfare is based on deception..." - Art of War
"Time will tell all tales" - SG
Any advanced tactic in TW is indistinguishable from cheating.


Wed May 30, 2007 10:40 pm
Profile ICQ
Veteran Op
User avatar

Joined: Thu Jun 02, 2005 2:00 am
Posts: 5558
Location: USA
Unread post 
Well, of course if you don't you're opening yourself up to some nastiness by posting IPs here. If someone just randomly connects and you jump at the "omfghax0r!" paranoia you're going to be blaming a lot of innocent people.

You don't need to talk to them to demonstrate intent. If they go in to tedit and screw with stuff, that's pretty solid. If they go thru a process of trying to enter potential usernames and passwords, that's pretty solid too. If they go thru your ports hitting from 1 to 65535 then that's pretty solid as well. But if they just randomly connect to your rlogin port and then disconnect... that's not exactly a hack attempt.

Ail made a very good point tho, with a NAT router you only need to NOT port forward your admin ports to eliminate the problem all together.

If you really wanted to get fun you could setup an SSH server on a non-standard port, block the admin port access from the outside but allow the SSH port, then if you needed remote admin capability you'd route thru the SSH to the admin port from within the network. Something like that could even out a lot of potential admin area flaws that might exist. Am I the only one that wonders if there's a potential overflow in there somewhere?

_________________
May the unholy fires of corbomite ignite deep within the depths of your soul...

1. TWGS server @ twgs.navhaz.com
2. The NavHaz Junction - Tradewars 2002 Scripts, Resources and Downloads
3. Open IRC chat @ irc.freenode.net:6667 #twchan
4. Parrothead wrote: Jesus wouldn't Subspace Crawl.

*** SG memorial donations via paypal to: dpocky68@booinc.com
Image


Thu May 31, 2007 5:40 am
Profile ICQ WWW
Gameop
User avatar

Joined: Sun Oct 08, 2006 2:00 am
Posts: 991
Unread post 
This is getting a little off the subject I posted about. My point was that I could care less what someone's intent is if they try to access my admin port. I just ban their IP and the problem is solved. The perp can go play elsewhere. Since there is no way to prove intent, either good or bad, it is a total waste of time and energy to bother with it.

Cerne

_________________
"All warfare is based on deception..." - Art of War
"Time will tell all tales" - SG
Any advanced tactic in TW is indistinguishable from cheating.


Thu May 31, 2007 8:12 am
Profile ICQ
Gameop
User avatar

Joined: Thu Mar 08, 2001 3:00 am
Posts: 886
Location: USA
Unread post 
Space Ghost wrote:
Ok i can understand checking the admin port (i guess) ( kinda like A Bank Robber getting caught and saying he wanted to see how secure his money was before he deposited it) However you stated

"I noticed a unknown user log to my twgs, so i spyed on the node and almost instantly saw this unknown user enter the editor and start running active player info. i instantly banned this user "

So i guess if he was just checking to see if it was secure WHY pray tell, Would he be running active player info??? there is NO excuse for that is there?
Please id this guy to the rest of the sysops and game ops.



dude hehe. 'running active player info' is hitting # at the main twgs menu. i hit that unconciously whenever i log into a twgs manually, admin or otherwise. zen doesn't say that he was checking the player info in tedit.

edit: ok maybe he says 'enter the editor' but i think zen should clarify.

_________________
twgs : telnet://twgs.thereverend.org:5023
web : http://www.thereverend.org
games : http://www.thestardock.com/twgssearch/i ... verend.org
helper : http://svn.thereverend.org:8080/revhelper/


Thu May 31, 2007 11:46 am
Profile
Commander

Joined: Wed Apr 14, 2004 2:00 am
Posts: 1324
Location: USA
Unread post 
By active player info I'm under the assumption that he is looking at their passwords, sectors, etc. All the things found in the user editor.

_________________
Infecting others with a Polymorphic Virus since 1975.

Curing ignorance and terminal stupidity since 1999.

Questioning the intellectual abilities of three digit annual salary earners since 2015.


Thu May 31, 2007 6:54 pm
Profile WWW
Veteran Op
User avatar

Joined: Thu Jun 02, 2005 2:00 am
Posts: 5558
Location: USA
Unread post 
Quote:
This is getting a little off the subject I posted about. My point was that I could care less what someone's intent is if they try to access my admin port. I just ban their IP and the problem is solved. The perp can go play elsewhere. Since there is no way to prove intent, either good or bad, it is a total waste of time and energy to bother with it.


Uh yea you can prove intent, I just gave you atleast 3 ways to do so. Just touching a port doesn't make you a "perp" ... I do it all the time. It's hardly criminal, and your admin port is on a standard port number so any number of things could try to access it. Intentionally or otherwise, it's a standard rlogin port.

If you want to ban them fine, but going onto a forum and posting their IP as part of an unofficial blacklist and labeling them a criminal equals libel plain and simple. Hobby or no, it's just dumb to open yourself up to stuff like that... and the admins here could very end up on the chopping block as well. Dumb++;

That's why there needs to be rules about what gets posted, and what kind of evidence is needed beforehand. Accusations should be supported, and people have a right to face their accusor.

_________________
May the unholy fires of corbomite ignite deep within the depths of your soul...

1. TWGS server @ twgs.navhaz.com
2. The NavHaz Junction - Tradewars 2002 Scripts, Resources and Downloads
3. Open IRC chat @ irc.freenode.net:6667 #twchan
4. Parrothead wrote: Jesus wouldn't Subspace Crawl.

*** SG memorial donations via paypal to: dpocky68@booinc.com
Image


Thu May 31, 2007 9:37 pm
Profile ICQ WWW
Gameop
User avatar

Joined: Mon Aug 30, 2004 2:00 am
Posts: 96
Location: Canada
Unread post 
Will IP logging be part of a future upgrade?

_________________
_________________
Team Ultimate TW Administrator
And Proud Member Of The Ultimate TW Community!
Come Join The Crowd


Mon Jun 25, 2007 4:33 am
Profile ICQ WWW
Display posts from previous:  Sort by  
Reply to topic   [ 23 posts ]  Go to page Previous  1, 2

Who is online

Users browsing this forum: No registered users and 90 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by wSTSoftware.