Results 1 to 15 of 15
Like Tree10Likes
  • 1 Post By nickos3
  • 1 Post By Vincents
  • 8 Post By Vincents

Server owners, be aware.

This is a discussion on Server owners, be aware. within the Private Servers forums, part of the Knight Online (ko4life.com) category; Besides the Game Server sockets flood that's going on for the last couple of months and it's daily noticed on ...
Page: 1


  1. #1
    www.professionalko.com Senior Member nickos3's Avatar
    Join Date
    Sep 2010
    Posts
    2,618

    Default Server owners, be aware.

    Besides the Game Server sockets flood that's going on for the last couple of months and it's daily noticed on ProfessionalKO, there's also a MS-SQL Server attack taking place that started 1 month ago.

    The attacker is using more than one VPS (or, there are more than one attacker) with proxy services and the machine is using Linux OS.
    They use NMAP to retreive the server information and then they start attacking through MSSQL_Login with a simple file they have, which is a full list of generated names/passwords (Brute-force attack).

    Our block list already counts more than 1000+ blocked IPs, that means, everything they do is automatic, including the IP changes.

    Why am I creating this topic on G4L ? Because there's no development forum in english anymore to post in there AND because they managed to find our MS-SQL Admin name/password two weeks ago. The bad news; they placed a PHP Backdoor Shell on our Web-Server. The good news; they couldn't harm us as every sql user including admin are having restricted power on our Game Database and the malware was detected and deleted right away from our Anti-Virus that's active 24/7.

    I should create this topic two weeks ago, when this happened, but I felt this could be unnecessary because there aren't many known and old servers to be taken down or hacked anyways. But, since they're still trying to brute-force our passwords 30 days after they started, I feel that now it's necessary for others to know.

    There's a suspect who's -luckily to us- detected (either a proxy IP change 'bug' or his own-manual mistake) but since we're attacked from more than one VPS at the same time and since there's no proof that could be used publicly, I can't name people.

    To the point of this topic:

    1. Use multiple SQL and Windows users with restricted power, for everything you're running (Web-Server, SQL Server, Game Files).
    2. Install a premium Anti-Virus.
    3. Keep changing your information, often.
    4. Keep monitoring your web, sql, windows and game logs at least once in a day.

    Pretty much, whatever allows you to change/restrict it, do it. And not to think "I'll leave this as it is, who's going to harm me ? and why me?" even if your game is low-populated. If you don't know how to ? Google & Firewalls, folks.



    Smooth likes this.

  2. #2
    Senior Member
    Join Date
    Dec 2009
    Posts
    1,805

    Default

    And only allow specific services (as absolutely necessary) access to the outside world?
    Why can people even connect to MSSQL from the outside?

  3. #3
    Little archer Senior Member
    Join Date
    Dec 2007
    Location
    nowhere
    Posts
    8,270

    Default

    Willing to bet that grobar is somehow involved. Always seems to be the case in all of these server hazard topics lol.

  4. #4
    BANNED FOR SCAMMING! Regular Member
    Join Date
    Jun 2015
    Posts
    71

  5. #5
    www.professionalko.com Senior Member nickos3's Avatar
    Join Date
    Sep 2010
    Posts
    2,618

    Default

    Quote Originally Posted by twostars View Post
    And only allow specific services (as absolutely necessary) access to the outside world?
    Why can people even connect to MSSQL from the outside?
    Due to router issues, if you're connected via RDP shit and you're disconnected from internet, everything's going to freeze.

  6. #6
    Senior Member Vincents's Avatar
    Join Date
    Apr 2010
    Posts
    577

    Default

    shame .

  7. #7
    Senior Member Vincents's Avatar
    Join Date
    Apr 2010
    Posts
    577

    Default

    Quote Originally Posted by twostars View Post
    And only allow specific services (as absolutely necessary) access to the outside world?
    Why can people even connect to MSSQL from the outside?
    Don't be stupid, everyone knows players need to connect to the SQL SERVER!

    In other news, nice to see you're alive, on the count of

    [6:49:02 AM] Bijit Chakraborty: bro you know twostar news ? why he close snoxd
    [6:49:12 AM] Bijit Chakraborty: some one told me he is dead in car accdent
    razor likes this.

  8. #8
    www.professionalko.com Senior Member nickos3's Avatar
    Join Date
    Sep 2010
    Posts
    2,618

    Default

    Quote Originally Posted by Vincents View Post
    shame .
    Oh, hai Vincents!.

  9. #9
    Senior Member Vincents's Avatar
    Join Date
    Apr 2010
    Posts
    577

    Default

    Quote Originally Posted by nickos3 View Post
    Oh, hai Vincents!.
    What's up!

    Nice to see my security guide prevented some damage to your server, keep up the good work!

  10. #10
    Banned Senior Member
    Join Date
    Aug 2012
    Posts
    1,090

    Default

    RIP Twostars.

  11. #11
    Senior Member Vincents's Avatar
    Join Date
    Apr 2010
    Posts
    577

    Default

    Quote Originally Posted by ReesesPieces View Post
    RIP Twostars.

  12. #12
    Senior Member
    Join Date
    Jul 2014
    Posts
    78

    Default

    lol... that's not so funny.

  13. #13
    Senior Member
    Join Date
    Oct 2012
    Posts
    948

    Default

    why not lock the SA account or any other with a high level of privileges, logins based on x amout of failed login attempts, say 30 minutes? that really puts a limit on brute forcing passwords.

  14. #14
    Senior Member Vincents's Avatar
    Join Date
    Apr 2010
    Posts
    577

    Default

    Quote Originally Posted by Sephiroth View Post
    why not lock the SA account or any other with a high level of privileges, logins based on x amout of failed login attempts, say 30 minutes? that really puts a limit on brute forcing passwords.
    or rename it all together

  15. #15
    Senior Member
    Join Date
    Oct 2012
    Posts
    948

    Default

    Quote Originally Posted by Vincents View Post
    or rename it all together
    looks like hes done that "could not find the login matching the name provided." they could be guessing for years lol

Similar Threads

  1. [Speech] Message to Server Owners
    By Former08 in forum Private Servers
    Replies: 98
    Last Post: 08-22-2013, 01:26 PM
  2. A letter to server owners.
    By ilterates in forum Private Servers
    Replies: 16
    Last Post: 10-04-2012, 08:51 PM
  3. ATTN: All server owners.
    By twostars in forum Private Servers
    Replies: 210
    Last Post: 09-29-2011, 08:22 AM
  4. Server owners - please read.
    By twostars in forum Private Servers
    Replies: 47
    Last Post: 08-28-2011, 05:15 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •