Results 1 to 12 of 12
Thread: 2.0.24.1 server hack by Monster*
-
27-05-2009, 08:43 #1
-= TeamSpeak User =-
- Join Date
- May 2009
- Location
- Munich
- Posts
- 5
2.0.24.1 server hack by Monster*
Hello everybody,
I found at least one thread about Monster* hack, but its completely in german, which is not my native language. Decided to open a new thread:
Well, in my scope of responsibilities are different things, one is Teamspeak server administration. First started in 2006 on Windows machine, later on my TS was moved to Linux base. Everything was fine until 24.05.2009. One guy, with nickname Monster*, got SA rights and deleted all the channels. He left a link in default channel description. Look at this: http://www.youtube.com/garksmstemm
He says he is 19 years old, german. I'm not familiar with German law, but currently I'm on a business trip in Munich. I'd appreciate if someone can advice on what can be done officially with this issue. I mean involving police, interpol, I don't know if this helps. At least we know his icq#245362824 and IP from log. I believe if escalated in a proper way we can do something.
Now a little bit technical details to developers. Guys, wake up. Look at video, what Monster* does and think what kind of exploit was used. Video shows some kind of a hacking tool, looks like brut force.
My TS is running on Linux, not under root account. version 2.0.24.1, behind router.
Port 8757 is the only one mapped outside, web interface is open for administering purposes, but mapped on the other port then default and has IP restriction applied. TCP query port is not mapped outside, but is available internally.
From the thread: http://forum.teamspeak.com/showthread.php?t=23726 all thing were applied long time ago (before hack).
From the server log I see next:
Hacker connect as user, then as SA, then with nickname Monster and SA but nothing is in LoginName.
24-05-09 22:43:04,ALL,Info,AccessLog, SID: 1 client connected [IP:92.72.116.92, Nick: Guest, LoginName: GIGA, DBID: 2952, Version:2.0.32.60]
24-05-09 22:43:04,ALL,Info,SALog, SID: 1 serveradmin connected [IP:
92.72.116.92, Nick: Guest, LoginName: GIGA]
24-05-09 22:47:15,ALL,Info,SALog, SID: 1 serveradmin connected [IP:
92.72.116.92, Nick: Monster, LoginName: ]
Following the link I posted above: http://www.youtube.com/garksmstemm
There is a video, named owned, so, you will see there my TS, which is already hacked (no channels, Hellbound.ge logo).
I'd ask developers investigate possible ways to fix the issue. Quick patch is highly appreciated. From my side I can provide any additional info required.
Also, if anyone knows, how to deal with police regarding hacking fact, I'd escalate the issue until I'm in Munich (till 30.05.2009).
Look forward to your replies.
Best Regards
SSEliteLast edited by SSElite; 27-05-2009 at 09:05.
-
29-05-2009, 05:20 #2
-= TeamSpeak Addict =-
- Join Date
- Jun 2003
- Posts
- 246
how strong is your SSA password?
-
29-05-2009, 05:33 #3
-= TeamSpeak Fanatic =-
- Join Date
- Jul 2006
- Posts
- 1,573
it is not possible to "hack" teamspeak unless you post full evidence of what has happened.
you maybe have to considers some other things that caused your teamspeak server to be hacked, for example weak passwords
-
29-05-2009, 10:44 #4
-= TeamSpeak User =-
- Join Date
- May 2009
- Location
- Munich
- Posts
- 5
-
29-05-2009, 10:50 #5
-= TeamSpeak User =-
- Join Date
- May 2009
- Location
- Munich
- Posts
- 5
-
29-05-2009, 14:24 #6
-= TeamSpeak Fanatic =-
- Join Date
- Jul 2006
- Posts
- 1,573
http://it.truveo.com/warheit-%C3%BCb.../id/3172467922
Weil das erste YouTube Video in deutscher Sprache war, hab ich mir gedacht, dass ich das mal kurz zeigen wollte; habe ich gefunden auf der Suche nach diesem Programm.
In dem Video wird erklärt, dass es kein solches Programm gibt bzw. nur ein "Fake" gespickt mit Trojanern ist.Last edited by maxi1990; 29-05-2009 at 15:43.
-
31-05-2009, 13:26 #7
-= TeamSpeak User =-
- Join Date
- May 2009
- Location
- Munich
- Posts
- 5
I managed to translate your post, but please remember, we are in English server thread and unfortunately I don't understand German.
Well, man on this video, as you say, speaks about "fake" program.
But Monstrer* got SA rights somehow, right?
He logged on to my TS and deleted all the channels.
Thanks for research you done, maxi1990.
I'm still waiting for TeamSpeak developer team answer.
The way Monster* got SA rights and more than strange server logs should be investigated.
Particularly, I'm interesting in next thing: how come the server log SA login string does not contain login name. (see log message in my first post)
-
31-05-2009, 18:24 #8
-= TeamSpeak Fanatic =-
- Join Date
- Nov 2008
- Location
- United States
- Posts
- 1,791
There are 'internet police' people. In the long run you'll have to fork out some money for the court and lawyers and it'll probably be awhile before anything ever comes from it. I'd say it's not worth fighting over for your loss of channels. You can google search for it and i'm sure you'll find more information. It's up to you though.
Usually they are used for 'hacking' against a corporation and causing them money in investigation and prosecution and so forth. In the states, it's a felony but i'm not sure how it works in the cyber world. If he's in america, but 'hacks' something in germany, not sure under which country he's charged under.
In all reality, he's a script kiddie. You can laugh in his face for not actually being able to 'hack' and gloating himself like he can. That would be satisfaction enough for me. Seriously, i doubt it's worth the fight over your channels. Just brush it off and continue on.Last edited by ZeroTKA; 31-05-2009 at 18:34.
-
05-06-2009, 08:05 #9
-= TeamSpeak User =-
- Join Date
- May 2009
- Location
- Munich
- Posts
- 5
-
05-06-2009, 08:32 #10
-= TeamSpeak Fanatic =-
- Join Date
- May 2006
- Location
- Europe/Czech Rep.
- Posts
- 1,299
Last edited by Tomas; 05-06-2009 at 19:11.
-
05-06-2009, 08:37 #11
-= TeamSpeak Addict =-
- Join Date
- Aug 2008
- Location
- Whois
- Posts
- 597
unnecessary discussion hydra gives it for a long time and functions…
-
12-06-2009, 00:01 #12
-= Undercover TeamSpeak Fanatic =-
- Join Date
- Jan 2007
- Location
- LA
- Posts
- 4,700
There was more than one SA on the server. Is your tcp query port open?
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Router problems
By bigteam0385 in forum [TeamSpeak 2] Server SupportReplies: 4Last Post: 24-05-2011, 10:53 -
Cannot connect to server by LAN or WAN
By Basti504 in forum [TeamSpeak 2] Server SupportReplies: 5Last Post: 25-11-2007, 22:30 -
Server start-up issues.
By AzureGod in forum [TeamSpeak 2] Client SupportReplies: 5Last Post: 08-06-2007, 10:37 -
Server Issue's When PC Reboots
By gokub27 in forum [TeamSpeak 2] Client SupportReplies: 3Last Post: 14-09-2006, 21:32 -
Server
By lars-andre-petersen in forum [TeamSpeak 2] Server SupportReplies: 70Last Post: 26-09-2005, 11:54


Reply With Quote
