Quoting [EMAIL PROTECTED]:
> Hold up yo, As far as Ive tested my server bans myself everytime I try to
Brute Force iT! The Brute FOrce can be exicuted through console, in game, and
even with joint effort from 3rd party apps like hlsw. Everytime I do it my
server bans my IP and i have to remote into another box so I can remove my other
box's banned Ip address.
This little ditty helps you secure your rcon "sv_rcon_maxfailures 10" put it
in your server.cfg or game.cfg for css. Also having a strong password is a good
start cause the load and time it would take to break a 14 character password
would be noticed by my IDS anyway. 6 Years now, and no one has ever taken out
my rcon.
My complaint is i just took down my CZ server cause it was such a beat ass
release and a waiste of my money. So I get CSS going and like maps like
scoutzknivez have missing textures and screw ups, steam had to be updated like
twice a day for 3 days and random crap like rcon not functing would happen, then
they fix and screw something else up. I hate buying what looks like such a good
game from Valve then
playing it only to find out the game is still only 95% done, after who know how
many years they had to finish it. I also love how steam can eat up 30+ MB of
memory to due absolutely nothing, Ive seen this even in offline mode with hl2.
Anyway CSS is pretty hot that is if your pushing at least an AMD 2.2GHZ system
with a 9800 pro. I used to play cs 1.5 on some dual voodoo 2's and a Pentium
Pro 200 and get 80fps!! back in the day. Gotta love the pre steam days and im
dead serious about it.
Heres my other main problem. My retail install of HL2 and CSS will not start
unless I have my HL2 CD 1 in the drive. Everyone who did the internet install
does not have this problem. Ok we all know that Yes I can crack Your friggen
game Valve, yes there are people playing CSS for free, get over it. People buy
the games they like, which is why I am not going to crack my copy I rather get a
legit update from yourselves to fix it right.
O Ya Another BIG PROBLEM!!!!!! How about huge memory leaks in CSS the server
turns to absolute shit after 5 days. Now to break it down for ya, it mainly
happens on 3rd party maps like scoutzknivez, retail maps still arent great
though, after 2 days of aztec my server was using a little over 700MB of memory.
Stats 14 people on scoutzknivez everyone alive and going nuts. The memory also
never completely fills and swap is never touched but still this seems a little
to sloppy to me.
P4 1.8GhZ 1GB RDRAM 800
Slackware 9.1 on 2.6Kernel
Vanilla CSS except for the map.
00:15:46 up 5 days, 19:09, 1 user, load average: 0.06, 0.17, 0.16
25 processes: 24 sleeping, 1 running, 0 zombie, 0 stopped
CPU states: 10.2% user 0.4% system 0.0% nice 0.0% iowait 89.3% idle
Mem: 1037660k av, 1032440k used, 5220k free, 0k shrd, 99028k buff
346872k active, 559164k inactive
Swap: 2097136k av, 0k used, 2097136k free 757004k cached
PID USER PRI NI SIZE RSS SHARE STAT %CPU %MEM TIME CPU COMMAND
1677 cs 15 0 558M 54M 19820 S 10.9 5.3 821:33 0 ./srcds_i686
-noipx -heapsize 512000 -pingboost 1
All in all the server runs pretty damm fast for most people, but i do notice a
slight studder now and then even though the ping will be good. I think a lot of
studder issues could be from excessive memory usage and or plain old sloppy
linux porting
of an already sloppy windows based game.
Benchmarks on my Desktop connected to my Server are while standing still on huge
map are 80fps @ 1024x768 6xA 16xAA dropping to 45fps with huge firefights and
what not. Small maps ex scoutzknivez I can run at 1600x1200 2xA 16xAA and still
hit 230fps dropping to 80-150 under heaving action. This is on a nforce 2 with
AMD 3000+ clocked at 2.3GHZ 1GB ram and a 9800 pro stock, XP sp2. Also the game
looks like crap at any resolution without AA on. Even at 1600x1200 with no AA
the game still looks bad. Running at 1024x768 with 16X AA really makes the game
look good.
Fix the bugs in this game, and it will become and Olympic Event.
NgR2000 67.100.173.234:27015
>
> Send hlds_linux mailing list submissions to
> [EMAIL PROTECTED]
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> or, via email, send a message with subject or body 'help' to
> [EMAIL PROTECTED]
>
> You can reach the person managing the list at
> [EMAIL PROTECTED]
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of hlds_linux digest..."
>
>
> Today's Topics:
>
> 1. css server lags with more than 6 players, CPU usage and Ping ok
> (Theo)
> 2. RE: HLSW alternatives, (e.g. Kcontrol, but what else?) (Chris
> Adams)
> 3. Is this an RCON hole that needs to be patched? ([EMAIL PROTECTED])
> 4. Re: Is this an RCON hole that needs to be patched? (Andy Shinn)
> 5. Re: Is this an RCON hole that needs to be patched? (m0gely)
> 6. Re: Is this an RCON hole that needs to be patched? (Gilly
> Cottle)
> 7. Re: Is this an RCON hole that needs to be patched? (John)
> 8. RE: Is this an RCON hole that needs to be patched? (Peter
> Holcroft)
>
> --__--__--
>
> Message: 1
> From: "Theo" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Date: Sat, 4 Dec 2004 16:00:25 +0100
> Subject: [hlds_linux] css server lags with more than 6 players, CPU
> usage and Ping ok
> Reply-To: [EMAIL PROTECTED]
>
> This is a multi-part message in MIME format.
> --
> [ Picked text/plain from multipart/alternative ]
> Hi,
>
> I host one css server, but if there are more than 6 players on the
> server its impossible to play. Ping is ok (30-50 ms), but the server
> seem to lag. CPU usage is only 20-30%!!
> The Box is a Athlon XP 2800, 512 Ram, 80 Gig HD, Suse Linux, Kernel:
> 2.4.21-215-athlon, glibc version: 2.3.X, 100 Mbit @ 6,4 GBit Backbone
> (tracert is ok).
>
> Any ideas?
>
> Theo
> --
>
>
>
>
> --__--__--
>
> Message: 2
> From: "Chris Adams" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: RE: [hlds_linux] HLSW alternatives, (e.g. Kcontrol, but what
> else?)
> Date: Sat, 4 Dec 2004 19:14:09 -0000
> Reply-To: [EMAIL PROTECTED]
>
> AFAIK Kcontrol isn't coming out. Kris released the source on his
> homepage (www.kquery.com) for all to use as he doesn't have time for
> it.
>
> ---------------------------------------
> Chris Adams
> Fragzzhost
>
> T (07005) 964 855
> F (07005) 964 857
> www.fragzzhost.com
>
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of List
> Keeper
> Sent: 04 December 2004 07:14
> To: [EMAIL PROTECTED]; [EMAIL PROTECTED]
> Subject: [hlds_linux] HLSW alternatives, (e.g. Kcontrol, but what
> else?)
>
>
> In light of HLSW not updating fast enough for my liking, would anyone
> know of other alternative programs that have similar functionality
> over
> controlling servers via RCON?
>
>
>
> I remember one such alternative program had a GUI that looked just
> like
> Steam does, would anyone happen to know which one it is? I've tried
> guessing many different names and word combinations without any luck
> except for coming across Kcontrol which is "coming soon".
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
>
>
>
>
>
> --__--__--
>
> Message: 3
> From: [EMAIL PROTECTED]
> To: [EMAIL PROTECTED]
> Date: Sat, 04 Dec 2004 19:49:44 -0400
> Subject: [hlds_linux] Is this an RCON hole that needs to be patched?
> Reply-To: [EMAIL PROTECTED]
>
> [ Converted text/html to text/plain ]
>
> Just a quick question.
>
> I've confirmed that you are able to bring down the console and use the
> rcon_address and rcon_password commands to communicate to a server via
> rcon
> WITHOUT being logged into the server. Doesn't that present a hole
> which
> allows multiple password attacks? In the past some admins have used
> sv_rcon_minfailures to protect against this, but if you don't need to
> be
> logged in, then this can't protect you anymore right? You don't get to
> se=
> e
> the responses of your rcon commands when in the window, but all they
> would
> need is a logged in player to look for a sample " rcon say hello "
> command =
> to
> know they've cracked the password.
>
>
>
> Snewo
> --
>
> _______________________________________________
> The coolest e-mail address on the web and it=92s FREE! Sign-up[1] today
> for=
> Beer
> Mail @ beer.com.
>
> =3D=3D=3DReferences:=3D=3D=3D
> 1. http://webmail.beer.com
>
>
> --__--__--
>
> Message: 4
> Date: Sat, 04 Dec 2004 16:11:18 -0800
> From: Andy Shinn <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Re: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> Reply-To: [EMAIL PROTECTED]
>
> Is it possible to exploit root from rcon or execute code locally from
> rcon? If not then I don't see why an attacker would want to brute
> force
> a game server anyways.
>
> [EMAIL PROTECTED] wrote:
>
> >[ Converted text/html to text/plain ]
> >
> >Just a quick question.
> >
> >I've confirmed that you are able to bring down the console and use
> the
> >rcon_address and rcon_password commands to communicate to a server via
> rco=
> n
> >WITHOUT being logged into the server. Doesn't that present a hole
> which
> >allows multiple password attacks? In the past some admins have used
> >sv_rcon_minfailures to protect against this, but if you don't need to
> be
> >logged in, then this can't protect you anymore right? You don't get
> to s=
> ee
> >the responses of your rcon commands when in the window, but all they
> would
> >need is a logged in player to look for a sample " rcon say hello "
> command=
> to
> >know they've cracked the password.
> >
> >
> >
> >Snewo
> >--
> >
> >_______________________________________________
> >The coolest e-mail address on the web and it=92s FREE! Sign-up[1] today
> fo=
> r Beer
> >Mail @ beer.com.
> >
> >=3D=3D=3DReferences:=3D=3D=3D
> > 1. http://webmail.beer.com
> >
> >_______________________________________________
> >To unsubscribe, edit your list preferences, or view the list archives,
> ple=
> ase visit:
> >http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
> >
> >
> >
> >
>
>
>
> --__--__--
>
> Message: 5
> Date: Sat, 04 Dec 2004 16:30:49 -0800
> From: m0gely <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Re: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> Reply-To: [EMAIL PROTECTED]
>
> Andy Shinn wrote:
>
> > Is it possible to exploit root from rcon or execute code locally
> from
> > rcon? If not then I don't see why an attacker would want to brute
> force
> > a game server anyways.
>
> Because when the past root exploits came out it was only possible if
> you
> had rcon. And who cares, people shouldn't be screwing with other
> peoples services.
>
> --
> - m0gely
> http://quake2.telestream.com/
> Q2 | Q3A | Counter-strike
>
>
> --__--__--
>
> Message: 6
> Date: Sat, 4 Dec 2004 17:12:47 -0800
> From: Gilly Cottle <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Re: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> Reply-To: [EMAIL PROTECTED]
>
> You've always been able to use rcon from outside the server. Ever
> heard of HLSW?
>
>
> On Sat, 04 Dec 2004 16:30:49 -0800, m0gely <[EMAIL PROTECTED]>
> wrote:
> > Andy Shinn wrote:
> >
> > > Is it possible to exploit root from rcon or execute code locally
> from
> > > rcon? If not then I don't see why an attacker would want to brute
> force
> > > a game server anyways.
> >
> > Because when the past root exploits came out it was only possible if
> you
> > had rcon. And who cares, people shouldn't be screwing with other
> > peoples services.
> >
> > --
> > - m0gely
> > http://quake2.telestream.com/
> > Q2 | Q3A | Counter-strike
> >
> >
> >
> > _______________________________________________
> > To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
>
>
> --
> Gilly Cottle
>
>
> --__--__--
>
> Message: 7
> Date: Sat, 4 Dec 2004 20:55:48 -0500
> From: John <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: Re: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> Reply-To: [EMAIL PROTECTED]
>
> HLSW, Phprcon, allseeingeye, hrmm the list goes on.
>
>
> On Sat, 4 Dec 2004 17:12:47 -0800, Gilly Cottle <[EMAIL PROTECTED]>
> wrote:
> > You've always been able to use rcon from outside the server. Ever
> > heard of HLSW?
> >
> >
> >
> >
> > On Sat, 04 Dec 2004 16:30:49 -0800, m0gely <[EMAIL PROTECTED]>
> wrote:
> > > Andy Shinn wrote:
> > >
> > > > Is it possible to exploit root from rcon or execute code locally
> from
> > > > rcon? If not then I don't see why an attacker would want to brute
> force
> > > > a game server anyways.
> > >
> > > Because when the past root exploits came out it was only possible if
> you
> > > had rcon. And who cares, people shouldn't be screwing with other
> > > peoples services.
> > >
> > > --
> > > - m0gely
> > > http://quake2.telestream.com/
> > > Q2 | Q3A | Counter-strike
> > >
> > >
> > >
> > > _______________________________________________
> > > To unsubscribe, edit your list preferences, or view the list
> archives, please visit:
> > > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > >
> >
> >
> > --
> > Gilly Cottle
> >
> >
> >
> > _______________________________________________
> > To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> >
>
>
> --
>
> - John
>
>
> --__--__--
>
> Message: 8
> From: "Peter Holcroft" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Subject: RE: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> Date: Sun, 5 Dec 2004 10:24:44 -0000
> Reply-To: [EMAIL PROTECTED]
>
> It bans you by IP, not your steam ID if you use the wrong password too
> many
> times. That's why it doesn't matter why you are logged in.
>
> Pete.
>
> > -----Original Message-----
> > From: [EMAIL PROTECTED] [mailto:hlds_linux-
> > [EMAIL PROTECTED] On Behalf Of John
> > Sent: 05 December 2004 01:56
> > To: [EMAIL PROTECTED]
> > Subject: Re: [hlds_linux] Is this an RCON hole that needs to be
> patched?
> >
> > HLSW, Phprcon, allseeingeye, hrmm the list goes on.
> >
> >
> > On Sat, 4 Dec 2004 17:12:47 -0800, Gilly Cottle <[EMAIL PROTECTED]>
> wrote:
> > > You've always been able to use rcon from outside the server. Ever
> > > heard of HLSW?
> > >
> > >
> > >
> > >
> > > On Sat, 04 Dec 2004 16:30:49 -0800, m0gely <[EMAIL PROTECTED]>
> > wrote:
> > > > Andy Shinn wrote:
> > > >
> > > > > Is it possible to exploit root from rcon or execute code
> locally
> > from
> > > > > rcon? If not then I don't see why an attacker would want to
> brute
> > force
> > > > > a game server anyways.
> > > >
> > > > Because when the past root exploits came out it was only possible
> if
> > you
> > > > had rcon. And who cares, people shouldn't be screwing with
> other
> > > > peoples services.
> > > >
> > > > --
> > > > - m0gely
> > > > http://quake2.telestream.com/
> > > > Q2 | Q3A | Counter-strike
> > > >
> > > >
> > > >
> > > > _______________________________________________
> > > > To unsubscribe, edit your list preferences, or view the list
> archives,
> > please visit:
> > > > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > > >
> > >
> > >
> > > --
> > > Gilly Cottle
> > >
> > >
> > >
> > > _______________________________________________
> > > To unsubscribe, edit your list preferences, or view the list
> archives,
> > please visit:
> > > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
> > >
> >
> >
> > --
> >
> > - John
> >
> > _______________________________________________
> > To unsubscribe, edit your list preferences, or view the list
> archives,
> > please visit:
> > http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
>
>
>
>
> --__--__--
>
> _______________________________________________
> To unsubscribe, edit your list preferences, or view the list archives,
> please visit:
> http://list.valvesoftware.com/mailman/listinfo/hlds_linux
>
>
>
> End of hlds_linux Digest
>
_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds_linux