malicious hackers on the server

User avatar
BrunoMine
Member
 
Posts: 902
Joined: Thu Apr 25, 2013 17:29
GitHub: BrunoMine

malicious hackers on the server

by BrunoMine » Thu Sep 12, 2013 19:38

I saw a player get into my server and fly. Even without the privileges. Checked twice but he could fly, run and do everything.
That worried me a lot.
They told me minetest could not be hacked.
My small square universe under construction ... Minemacro
Comunidade Minetest Brasil
www.minetestbrasil.com
 

User avatar
Menche
Member
 
Posts: 994
Joined: Sat Jul 02, 2011 00:43

by Menche » Thu Sep 12, 2013 19:51

Some players have modified the client to disable client side collision detection, allowing flying and noclip without privs. Setting 'disable_anticheat = false' may help.
Last edited by Menche on Fri Sep 13, 2013 07:49, edited 1 time in total.
An innocent kitten dies every time you top-post.
I am on the Voxelands Forums more often than here.
Try Voxelands (forked from Minetest 0.3) by darkrose
 

User avatar
BrandonReese
Member
 
Posts: 836
Joined: Wed Sep 12, 2012 00:44
GitHub: bremaweb
IRC: BrandonReese
In-game: BrandonReese

by BrandonReese » Thu Sep 12, 2013 20:09

Get their IP address and ban them at the computer's firewall, that's what I do :-) I potentially ban thousands of other people (that most likely aren't playing Minetest) but it hasn't caused a problem yet.
 

User avatar
sfan5
Member
 
Posts: 3636
Joined: Wed Aug 24, 2011 09:44
GitHub: sfan5
IRC: sfan5

by sfan5 » Fri Sep 13, 2013 05:15

Menche wrote:There's a cracked client going around

There is?
Mods: Mesecons | WorldEdit | Nuke
Minetest builds for Windows (32-bit & 64-bit)
 

User avatar
Menche
Member
 
Posts: 994
Joined: Sat Jul 02, 2011 00:43

by Menche » Fri Sep 13, 2013 07:53

sfan5 wrote:
Menche wrote:There's a cracked client going around

There is?

lol, I worded that horribly. edited.
An innocent kitten dies every time you top-post.
I am on the Voxelands Forums more often than here.
Try Voxelands (forked from Minetest 0.3) by darkrose
 

User avatar
rubenwardy
Member
 
Posts: 4500
Joined: Tue Jun 12, 2012 18:11
GitHub: rubenwardy
IRC: rubenwardy
In-game: rubenwardy

by rubenwardy » Fri Sep 13, 2013 10:09

It is hardly difficult to hack the client, any cpp programmer could work it out, and it can not be counted as "malicious": it does no harm. It is not really hacking.

To fly and no-clip without privileges, all you need to do is remove the privilege check on the client that checks for fly privileges and no-clip privileges. The reason this is possible is because the player movement is handled by the client, and not the server. Dont worry, they can not give them self give, ban, admin, etc privs without hacking the server (which is very hard for the average MT player)

disable_anticheat = false will not help at all.

To prevent this, you need a mod or code that:
  • detects where the player is (ie: are they 5m away from any blocks)
  • not are moving correctly (ie: falling)
  • and have no fly privs

if these are true, then ban the player.

Malicious is stuff like DDoS'ing the server, or blocking/banning other players, or griefing, or stealling, etc. NOT FLYING
Last edited by rubenwardy on Fri Sep 13, 2013 13:57, edited 1 time in total.
 

User avatar
sfan5
Member
 
Posts: 3636
Joined: Wed Aug 24, 2011 09:44
GitHub: sfan5
IRC: sfan5

by sfan5 » Fri Sep 13, 2013 13:28

Hybrid Dog wrote:
sfan5 wrote:
Menche wrote:There's a cracked client going around

There is?
more than one

Really? Where?
Mods: Mesecons | WorldEdit | Nuke
Minetest builds for Windows (32-bit & 64-bit)
 

User avatar
jojoa1997
Member
 
Posts: 2890
Joined: Thu Dec 13, 2012 05:11

by jojoa1997 » Fri Sep 13, 2013 13:29

sfan5 wrote:
Hybrid Dog wrote:
sfan5 wrote:There is?
more than one

Really? Where?
rarkenin made me one. 0.4.4 I think but all it did was bugly make everything light out.
Coding;
1X coding
3X debugging
12X tweaking to be just right
 

User avatar
rubenwardy
Member
 
Posts: 4500
Joined: Tue Jun 12, 2012 18:11
GitHub: rubenwardy
IRC: rubenwardy
In-game: rubenwardy

by rubenwardy » Fri Sep 13, 2013 13:57

jojoa1997 wrote:
sfan5 wrote:
Hybrid Dog wrote:more than one

Really? Where?
rarkenin made me one. 0.4.4 I think but all it did was bugly make everything light out.


As I said, It is really easy to crack since it is open source.
 

User avatar
BrunoMine
Member
 
Posts: 902
Joined: Thu Apr 25, 2013 17:29
GitHub: BrunoMine

by BrunoMine » Fri Sep 13, 2013 15:04

So I think this can disturb me much. In my server players can not fly. What do I do? disable no_clip?
My small square universe under construction ... Minemacro
Comunidade Minetest Brasil
www.minetestbrasil.com
 


Return to Minetest Problems

Who is online

Users browsing this forum: No registered users and 10 guests

cron