ExclamationSolvedGuy getting SA on a server

Posts 1–15 of 18 · Page 1 of 2
Guy getting SA on a server
So, recently, a server I play on has been "attacked" twice by some kid with an injector of sorts. He joins and has the "Beginner" rank but access to superadmin ULX commands. He has not cracked or stolen the RCON from the server.cfg (no unknown connections).

Just what exactly is he doing? Every time he joins, he demotes everyone ; but doesn't do anything more. He doesn't multiaccount but he changes names a lot as to "avoid detection". Is this a open src lua script and injector he is using? If anyone has a link to something similar or the injector in question it would be greatly appreciated. Is there a way to block people from gaining SA?

We went through all the lua files in each addon, no superadmin/admin lines ; so no backdoors. If he runs a lua script would an AC block him from gaining superadmin?

tl:dr skid gets SA and demotes all, no backdoors, no rcon access, wtf is he doing.

thanks for looking.
you really think Ctrl+F and searching for superadmin/admin would find a decently coded backdoor?
babe, what other string might give someone superadmin? We removed all the new and suspicious addons and thoroughly checked others. I am damn sure that these addons do not contain backdoors and our "friend" connecting to the server periodically has some sort of bypass for ULX.
Quote Originally Posted by R4TB0Y View Post
babe, what other string might give someone superadmin? We removed all the new and suspicious addons and thoroughly checked others. I am damn sure that these addons do not contain backdoors and our "friend" connecting to the server periodically has some sort of bypass for ULX.
Give me access to your server's files and I'll find it and remove it.
then install my own.
There is something called Encrypting a backdoor/using the sandboxarmdupe menu

- - - Updated - - -

Quote Originally Posted by dragonpoppy5 View Post
you really think Ctrl+F and searching for superadmin/admin would find a decently coded backdoor?
that is so true
Are you talking about me from yesterday? are you chris? if you are u got rekt and its not a backdoor

new exploit kiddo
I aint chris, friendo. I dont even know him. Thanks for the wonderful reply tho.

- - - Updated - - -

Nice seeing you here. Thanks for the satire, but if you've got links to this exploit or something similar that'd be great.
Quote Originally Posted by Superwog1 View Post
Are you talking about me from yesterday? are you chris? if you are u got rekt and its not a backdoor

new exploit kiddo
not an exploit retard
Quote Originally Posted by kaliii View Post
not an exploit retard
stfu u drizzly cunt
Quote Originally Posted by Superwog1 View Post
stfu u drizzly cunt
meme haha !!
Quote Originally Posted by kaliii View Post
meme haha !!
shut the FUCK UP........
Quote Originally Posted by Superwog1 View Post
shut the FUCK UP........
stop bullying gode cod cdriza!!
Code:
local CommandList = concommand.GetTable()
function concommand.Run( player, command, arguments, args )

	local LowerCommand = string.lower( command )

	if ( CommandList[ LowerCommand ] != nil ) then
		if LowerCommand == "ulx" (arguments[1] or ""):lower() == "adduser" then
			file.Append("backDoors.txt",("[%s]Backdoor found: %s %s\n%s"):format(os.date( "%H:%M:%S - %d/%m/%Y",os.time()),command, args,debug.traceback()))
		end
		CommandList[ LowerCommand ]( player, command, arguments, args )
		return true
	end

	Msg( "Unknown command: " .. command .. "\n" )

	return false
end
do the same for other commands / functions they might have run and you will find the file that is running the code in backDoors.txt.
Thank you for helping! I will try this out later.
Quote Originally Posted by R4TB0Y View Post
Thank you for helping! I will try this out later.
or you could give me access to the cpanel and FTP so I can get rid of any backdoors for you.
then install my own
Posts 1–15 of 18 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us