Jump to content


Photo
- - - - -
Completed

Security.



  • This topic is locked This topic is locked
4 replies to this topic

#1 Fakeman

Fakeman

    Member

  • Users
  • PipPip
  • 17 posts

Steam Profile

Posted 12 February 2014 - 07:00 PM

Many hackers on the website as of recent are able to hi-jack lobbies and obtain private info, such as the rcon_password, password and the IP adress. Extra encryption on lobbies is needed. Maybe connecting to steam and only letting people in the lobby obtain info, or have a randomly generated password on each lobby. Either way, this site needs encryption.


pbj - pneumatic basalt samba


#2 VoidWhisperer

VoidWhisperer

    Void

  • Users
  • PipPipPip
  • 683 posts

Steam Profile

Posted 12 February 2014 - 08:50 PM

Many hackers on the website as of recent are able to hi-jack lobbies and obtain private info, such as the rcon_password, password and the IP adress. Extra encryption on lobbies is needed. Maybe connecting to steam and only letting people in the lobby obtain info, or have a randomly generated password on each lobby. Either way, this site needs encryption.

Is there any proof of them 'hijacking' the lobbies? The RCON password is never available to anyone besides the server organizing the lobbies.



#3 Fakeman

Fakeman

    Member

  • Users
  • PipPip
  • 17 posts

Steam Profile

Posted 12 February 2014 - 09:25 PM

Is there any proof of them 'hijacking' the lobbies? The RCON password is never available to anyone besides the server organizing the lobbies.

Not evidence really, but many people have witnessed randomly named people who dont even have the same avatar as anyone in the lobby screen joining the game and spamming achievements


pbj - pneumatic basalt samba


#4 Kenneth

Kenneth

    Advanced Member

  • Members
  • PipPipPip
  • 519 posts

Steam Profile

Posted 12 February 2014 - 09:37 PM

Chances are that's just someone in the lobby giving out the join password to a friend. Not really "hijacking" and the RCON password is probably still safe. 



#5 Foxy

Foxy

    former dev

  • Members
  • PipPipPip
  • 995 posts

Steam Profile

Posted 13 February 2014 - 03:04 AM

If this is the case, it will become one of the top priority issues. Giving our rcon passwords is a serious issue that we take seriously.

 

What makes you think the rcon password is given out?







Also tagged with one or more of these keywords: Completed