[Few-Steps] To FiX your Server Security !

01/27/2012 19:35 PortalDark#16
Quote:
Originally Posted by LastThief View Post
Ask yourself my friend

you said it's vb btw for your info vb doesn't use ; at the end of statement

btw added on my sig
you stole one of my quotes (Wery pro)




and guys, please, we got the point about his Nyan#(in fact is a funny name for it) but it has to stop
please guys, lets return to topic, or mods gonna close this
01/27/2012 19:50 Dr.Abdelfattah#17
Thread Updated :

The Most Important Part ,
If you use 2 dedi servers or more for 2 agents or more ,
So you are open farmmanager Ports ,
Oky after mints of hacking farmmanager security i find out that by small access to farmmanager from it's ports you could shutdown the SR_GameServer , shard and agent too
Also you could let the farmmanager send packets to GS which will make overflaw also could gives packets to shard and agents but GS is the mostly easy to take overflaw from stupid wrong packets send from FarmManager

Solve :

1 - Open TCP Port only for farmmanager in your Firewall
2 - block TCP and UDP ports for farmmanager in your firewall except to 1 ip this ip = ur other machine ip .

I think it's very clear now ,

Hope i help :) ,
Quote:
Also thanks to the guy who help me with his dedi servers :) > That guy isn't memeber at Epvp .
01/27/2012 20:03 rushcrush#18
Quote:
Originally Posted by Dr.Abdelfattah View Post
Thread Updated :

The Most Important Part ,
If you use 2 dedi servers or more for 2 agents or more ,
So you are open farmmanager Ports ,
Oky after mints of hacking farmmanager security i find out that by small access to farmmanager from it's ports you could shutdown the SR_GameServer , shard and agent too
Also you could let the farmmanager send packets to GS which will make overflaw also could gives packets to shard and agents but GS is the mostly easy to take overflaw from stupid wrong packets send from FarmManager

Solve :

1 - Open TCP Port only for farmmanager in your Firewall
2 - block TCP and UDP ports for farmmanager in your firewall except to 1 ip this ip = ur other machine ip .

I think it's very clear now ,

Hope i help :) ,
so this would happen if using 2 dedi s right?
but 1 dedi s no?
01/27/2012 20:05 Dr.Abdelfattah#19
Quote:
Originally Posted by rushcrush View Post
so this would happen if using 2 dedi s right?
but 1 dedi s no?
ya but u also must close ports of farmmanager if u use 1 dedi ..
01/27/2012 22:06 hypnato#20
Changing DB names is an excellent security measure, but I dont know which stored procedures that it effects?
01/27/2012 22:08 PortalDark#21
Quote:
Originally Posted by hypnato View Post
Changing DB names is an excellent security measure, but I dont know which stored procedures that it effects?
stored procedures are linked to the db in which they are, no matter the name
01/27/2012 22:16 kevin_owner#22
Basicly a full guide to secure the server is download "nmap" scan your server for open ports.

- Get a firewall which can allow connections from a certain ip.
- Block ALL the ports of the iis, sql server ect ect just everything open at nmap and only allow the gateway download and agent and probably the ftp for crest stuff.

- Multiple servers well just allow the 2nd server to the ports of farmanager, agent, gameserver, shard, iis and sql server.

last thing you need are some brains nice most of the hacking stuff is too damn easy to prevent.
01/27/2012 22:16 Dr.Abdelfattah#23
Quote:
Originally Posted by PortalDark View Post
stored procedures are linked to the db in which they are, no matter the name
You forgot that shard db call account db to take the silk amount for every player ,
Anyway here few steps but need to use ur mind
Now select all stored procedures , and drop as create , Now search for SRO_VT_ACCOUNT , find out all names of stored procedures which got SRO_VT_ACCOUNT and then change in them the account db name as u need but u need first to change ur account db name , and don't forgot there's some stored procedures got 2 times SRO_VT_ACCOUNT .
^
^
Quote:
Originally Posted by hypnato View Post
Changing DB names is an excellent security measure, but I dont know which stored procedures that it effects?
Quote:
Originally Posted by kevin_owner View Post
Basicly a full guide to secure the server is download "nmap" scan your server for open ports.

- Get a firewall which can allow connections from a certain ip.
- Block ALL the ports of the iis, sql server ect ect just everything open at nmap and only allow the gateway download and agent and probably the ftp for crest stuff.

- Multiple servers well just allow the 2nd server to the ports of farmanager, agent, gameserver, shard, iis and sql server.

last thing you need are some brains nice most of the hacking stuff is too damn easy to prevent.
You are right , But Most of people haven't Imagination Defaults !!!
01/28/2012 08:26 hamada619#24
in my server.cfg port of farmmanager like the port of download server what i do?
01/28/2012 16:00 Dr.Abdelfattah#25
Quote:
Originally Posted by hamada619 View Post
in my server.cfg port of farmmanager like the port of download server what i do?
That's not farmmanager port , find out the port in srNodeData.ini ...
03/04/2012 10:42 elitebi#26
fixed