Jump to content


Photo
- - - - -
Declined

Hacker bypassed tf2center password and joined the server without being into the lobby



  • Please log in to reply
1 reply to this topic

#1 StefanB

StefanB

    Newbie

  • Users
  • Pip
  • 3 posts

Posted 24 July 2015 - 12:23 PM

TF2C Profile: StefanB
Region: EU

Browser: Google Chrome
Critical plugins: * Adblock Plus
OS: Windows
Connection type: * WiFi* Router

Bug type: Lobby creation
Lobby ID: #475525
Date & Time: Jul 24 3:09 PM

Good day, gentelman.

This guy: nigghero http://steamcommunit...561198194678417hacked the password of the tf2center lobby and join the server after that he said the pass into the chat, then other players join in too. I don't remember all their names but one of them was [ß3] 80sBigMan http://steamcommunit...561198004290837 causing the lobby players from my team and from the other to quit the game. I didn't told the tf2center password to anybody, how did he managed to access? Is there a leak into your security?

[attachment=543:Untitled.png]

In the end I managed to kick the guys mentioned above using the "rcon_password" & "rcon kick " commands.
I'm looking forward for your reply and future instructions. I don't know what happend and I don't want to happen this to me again.
  • mariPr, Williamsext, nataPr and 4 others like this

#2 ninjaMooCow

ninjaMooCow

    Former TF2C staff

  • Members
  • PipPipPipPipPip
  • 2225 posts
  • LocationOhio

Posted 24 July 2015 - 10:51 PM

This player is not a "hacker."

The lobby password is set when a lobby is created.

The game server password is "random" and assigned to the server upon the setting up of a lobby.

After a lobby begins, the lobby page refreshes and has a link that will allow you to join the tf2 game server.  This link also shows the "connect string" so that players can manually join if the auto-launch somehow fails.  The connect string reveals the server name (or IP address), server port, and the server's randomly assigned password.

 

The guy telling the game server password did not know that password until AFTER your lobby launched. 

 

My conclusion is that there was no hacking.

 

An interesting thing that you may not have known is that once a lobby launches, tf2c will monitor who is in the game.  If you are not supposed to be in the game server due to properly joining or else joining as a sub, you will be swiftly kicked off of the server.

 

I didn't look at the server logs. But I bet that everyone in your game on your game server was authorized to be there by joining properly.  Otherwise, I would expect them to be auto-kicked.







Also tagged with one or more of these keywords: Declined