Jump to content
  • 0

Server got hacked


ubeyou

Question


  • Group:  Members
  • Topic Count:  5
  • Topics Per Day:  0.00
  • Content Count:  13
  • Reputation:   0
  • Joined:  09/04/12
  • Last Seen:  

Hi, is there any ways to prevent server got hacked/ sql injected? 

 

Surprisingly the hacker only know how to delete the char table, and luckily i got perform daily backup.

 

Server: rAthena 17000+

CP: Flux CP

Edited by ubeyou
Link to comment
Share on other sites

9 answers to this question

Recommended Posts

  • 0

  • Group:  Members
  • Topic Count:  39
  • Topics Per Day:  0.01
  • Content Count:  175
  • Reputation:   7
  • Joined:  09/13/12
  • Last Seen:  

purchase a SSL certificate and make your server cp secured. plus, seeing a https:// in your website wil make your players feel secured too and wil have confidence in you for keeping their data secured.

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  94
  • Topics Per Day:  0.02
  • Content Count:  2192
  • Reputation:   252
  • Joined:  11/11/11
  • Last Seen:  

Use a better secured password? Use multiple different passwords for different databases? No other way to really prevent something like that unless there is a security flaw inside your control panel or your passwords and usernames are easily guessable. 

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  5
  • Topics Per Day:  0.00
  • Content Count:  13
  • Reputation:   0
  • Joined:  09/04/12
  • Last Seen:  

but the problem is he only able to delete all the char data in the server. this is not the first time.

 

I checked the control panel & there is no login detected.

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  4
  • Topics Per Day:  0.00
  • Content Count:  54
  • Reputation:   24
  • Joined:  11/22/11
  • Last Seen:  

I got a solution:

 

Get rid of the server

Move on

????

Win

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  5
  • Topics Per Day:  0.00
  • Content Count:  13
  • Reputation:   0
  • Joined:  09/04/12
  • Last Seen:  

That's not a solution haha. Actually the char deletion brings no harm to my server as I implemented a special backup system.

I just wanted to figure out a way to make the server more stable & immune to this char table deletion.

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  25
  • Topics Per Day:  0.01
  • Content Count:  509
  • Reputation:   80
  • Joined:  11/20/11
  • Last Seen:  

change database & password

close ur CP for a while

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  9
  • Topics Per Day:  0.00
  • Content Count:  379
  • Reputation:   304
  • Joined:  11/10/11
  • Last Seen:  

purchase a SSL certificate and make your server cp secured. plus, seeing a https:// in your website wil make your players feel secured too and wil have confidence in you for keeping their data secured.

Feel secured doesn't mean be secured.

Https don't protect from SQL injection and some hacks methods.

Surprisingly the hacker only know how to delete the char table, and luckily i got perform daily backup.

Maybe because he doesn't want to cheat but just want to annoyed your server.

As everyone said, it can come from any tool you add to your CP (forum, control panel, bug tracker) or in game npc (check for query_sql) or even from the hoster or your own team.

  • Upvote 1
Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  96
  • Topics Per Day:  0.02
  • Content Count:  554
  • Reputation:   14
  • Joined:  09/24/12
  • Last Seen:  

Find any malicious code in you server or winscp..
There should be some backdoor ^ ^

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  34
  • Topics Per Day:  0.01
  • Content Count:  188
  • Reputation:   16
  • Joined:  06/12/12
  • Last Seen:  

Hi, is there any ways to prevent server got hacked/ sql injected? 

 

Surprisingly the hacker only know how to delete the char table, and luckily i got perform daily backup.

 

Server: rAthena 17000+

CP: Flux CP

well you can have security measures, firstly , are you using

phpmyadmin >?? if yes then might be your phpmyadmin version is low ,

check your php version first , by command

php -v

IF its below 5.2 , you MUST update php and hence phpmyadmin. As the before versions were vulnerable.

Next

is your database user/passowords , I recommend passwords generated

automatically, they are more secure than any of the other.

If 

you are using eAthena  , i would suggest you to move on to rathena .

But if you want to use eathena mobs and items and other things , just

copy paste them here to der, DONT DO THAT WITH SRC.

rAthena is way too much secure than eAthena and is advanced.

At

last is your flux, The flux for eathena have a Loop hole, I would never

use old flux if i were you, Rather switch to Calcium Kid's CP or

Xantara's CP.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...