Server rentals :: NFOservers.com

Forums

All times are UTC - 8 hours



Author Message
PostPosted: Sun Feb 03, 2013 12:23 am 
Offline
A semi-regular
A semi-regular
User avatar

Joined: Tue Apr 24, 2012 4:39 am
Posts: 18
This is not provider specific. One person we know that got hit was NFO hosted but for example we host our own so this can happen to anyone since its Admin fault.

Someone will come into your server with a high ranking admins name and (Phone) in the name. They will ask in text for their usergroup to be assigned until someone finally does. Once you do that they have a script to yank everyones usergroup and change some permissions to max values. Change the password and delete the channels before leaving.

Thankfully for us since we host our own its a quick database swap and back in action.

[Content removed at original poster's request.]

Anyways while the one name seems to stick all of that is not important its the MO. Keep an eye out always verify your TS permission having admins by voice before reassigning them a group.


Top
 Profile  
 
PostPosted: Sun Feb 03, 2013 1:28 am 
Online
Staff
Staff
User avatar

Joined: Fri Sep 17, 2010 9:06 am
Posts: 2020
Location: California
Oddly enough, I've seen several users here who have had there servers hurt my "Kobra". This seems to be an exploit in the last TS3 version.

Unfortunately no on seems to have reported this to the TS3 guys since there is nothing on there forums about it.

_________________
<@TimeX-NFo> Hey, we used to have to carry our packets to the servers.
<@TimeX-NFo> And it was upstream, both ways.

<@TimeX-NFo|away> You're asking the old dude for help?????
<@Kraze^NFo> Yes


Top
 Profile  
 
PostPosted: Sun Feb 03, 2013 2:04 am 
Offline
A semi-regular
A semi-regular
User avatar

Joined: Tue Apr 24, 2012 4:39 am
Posts: 18
Interesting.

We had no founders and almost no head admins on until around the time this occured. They were on the server most of the day on and off but 2 of those names were around from the time I was at work till the time I went home.

Nothing seems to happen until they get a decent amount of permissions. Our setup is a bit flawed where HA's can switch to Founder but never cared too much because there is almost no difference in our permissions. But I intend to go ahead and restructure anyways so that HA's have a bit less permissions and put a TS Admin group way ahead of it all. Won't prevent everything especially with an exploit. But should prevent some accidents.

THE MOMENT they got permissions it was only a few seconds before the bomb finished exploding. I mean it was all scripted no one can right click as fast as these commands were going through.

I just say keep the admin out of their hands so far that keeps them at bay.


Top
 Profile  
 
PostPosted: Sun Feb 03, 2013 6:22 am 
Offline
This is my homepage
This is my homepage

Joined: Sun Jun 26, 2011 8:03 am
Posts: 1127
At least TS folks look into these reports and investigate them so to resolve the security issues.

Ventrilo is extremely easy to hijack admin and when I posted on their site to talk to them in private about how it''s dome, they deleted the post about the security issue and banned me from posting. Even tried a new account and no go. Guess my ip was banned from posting, but could only view the forum.

Couldn't believe they would ignore such an issue.

_________________
Visit gspreviews.com And Rate & Review Your Old & Current GSP's
Procon Hosting $2.50/month - aaquacks.com
Find Your GSP Coupons at gspreviews.com/coupons/
Make Money Using Url Shortners at w1z.it


Top
 Profile  
 
PostPosted: Thu Feb 07, 2013 3:23 pm 
Offline
This is my homepage
This is my homepage

Joined: Thu Aug 10, 2006 9:41 pm
Posts: 966
.=QUACK=.Major.Pain wrote:
At least TS folks look into these reports and investigate them so to resolve the security issues.

Ventrilo is extremely easy to hijack admin and when I posted on their site to talk to them in private about how it''s dome, they deleted the post about the security issue and banned me from posting. Even tried a new account and no go. Guess my ip was banned from posting, but could only view the forum.

Couldn't believe they would ignore such an issue.


We plan to eventually move off from ventrilo to TS3 soon.

_________________
Image
Image

http://www.47r-squad.com


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
It is currently Mon May 20, 2013 11:28 am
Powered by phpBB® Forum Software © phpBB Group