1. I'm sorry, I write with the help of Google translator.
    One unknown player as that removes totems, doors, some things, cars and so on. It removes all as if he admin.
    How is this possible?
    Could this be due for rcon?
    Could it have come from the fact that I set SteamCMD on behalf of the anonymous.
    Could this be due for qweryport 12872.
    Please help! OHE DOES NOT PLAY!
     
  2. Wulf

    Wulf Community Admin

    The only "RCON" that Hurtworld has right now is via the in-game F1 console. There is no remote access aside from that. The query port is just for Steam to query information from the server, which is used for things such as the in-game server list. If a player is removing things as admin, he likely is either added as admin (check your startup/autoexec.cfg) or you have a plugin installed that is allowing it.
     
  3. Maybe it via substitution SteamID (Administrators are online)?
     
  4. Wulf

    Wulf Community Admin

    Please use English when posting. Your message above has been translated.

    I'm not aware of any exploits such as this, but I'd recommend checking your configs and logs.
     
  5. Plugin list:
    AdminTools, CustomDeathMessages, Help, InventoryManager, Kits, Location, NoClone, NoSuicide, Ping, PlayersList, PrivateMessage, Reporting, Reserved, SpawnConfig, Teleportation, TimedExecute

    Hurtworld -batchmode -nographics -exec "host 12871;queryport 12871;maxplayers 60;servername SurvON Adventure; creativemode 0; enforceeac 0

    oxide.groups.data

    admin‘
    teleportation.adminteleportation.tprteleportation.homenosuicide.excludedadmintools.allinventorymanager.admininventorymanager.clear.selfinventorymanager.clear.othersinventorymanager.copyinventorymanager.give.selfinventorymanager.give.othersinventorymanager.viewinventorymanager.searchinventorymanager.size.selfinventorymanager.size.othersinventorymanager.update"admin
    >
    moderator1
    admintools.kickadmintools.mute" moderator
    `
    defaultU
    teleportation.tprteleportation.homeping.bypassnosuicide.excluded"default


    autoexec.cfg
    quit 86400
    loadbalancerframebudget 100
    addadmin 765***01208******
    addadmin 765***991112******


    Maybe a mistake here ?
     
    Last edited by a moderator: Jan 11, 2016
  6. Wulf

    Wulf Community Admin

    I don't see much wrong there, side from ping.bypass and suicide.excluded being granted to the default group, making it pointless to have those plugins installed. Your server's query port and main port shouldn't be the same either.
     
  7. I changed queryport on the other because I was advised not to give anyone.
    Someone said to me that it was because of him I hacked.
    queryport 12871 ---> 12872 (this port is now installed)
     
  8. Hello everybody!
    Generally the problem is very critical.
    On my server somehow give themselves administrative privileges and can do everything.
    Including the destruction of all the buildings.

    How do I get around?
    Now it is a problem for many.
    I put the logs.
    The cracker is the nickname Etrim

    Code:
    Player Connected - Etrim:88.147.153.151
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DJckote</color><color=white>:</color> <color=white>я сундуки</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] DJckote: я сундуки
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>UnnamedPlayer)</color><color=white>:</color> <color=white>с выстрела</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] UnnamedPlayer): с выстрела
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DimaWegas</color><color=white>:</color> <color=white>есть там?</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] DimaWegas: есть там?
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DEADPOOL</color><color=white>:</color> <color=white>ага</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] DEADPOOL: ага
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>UnnamedPlayer)</color><color=white>:</color> <color=white>всё равно у мя ценного нету</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] UnnamedPlayer): всё равно у мя ценного нету
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>saimon4724</color><color=white>:</color> <color=white>Где вы живёте??? И где РТ лутаете???</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:51 PM [Info] [Better Chat] [Игрок] saimon4724: Где вы живёте??? И где РТ лутаете???
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Must be connect to a server
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 92 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 123 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 28 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 11 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 24 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 31 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DJckote</color><color=white>:</color> <color=white>раньше в рт корпусы были</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:52 PM [Info] [Better Chat] [Игрок] DJckote: раньше в рт корпусы были
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DimaWegas</color><color=white>:</color> <color=white>ага</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:52 PM [Info] [Better Chat] [Игрок] DimaWegas: ага
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 1 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 38 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>UnnamedPlayer)</color><color=white>:</color> <color=white>эээм ват??</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:52 PM [Info] [Better Chat] [Игрок] UnnamedPlayer): эээм ват??
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Destroyed 54 objects
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Starting game save to file autosave_DiemensLand
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Finished writing containers for save, waiting on save thread
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)Writing to disk completed from background thread
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DimaWegas</color><color=white>:</color> <color=white>что!?</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:53 PM [Info] [Better Chat] [Игрок] DimaWegas: что!?
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Broadcast] <color=#C4FF00>[Игрок]</color> <color=#DCFF66>DimaWegas</color><color=white>:</color> <color=white>блять дом пропал</color>
    (Filename: C:/buildslave/unity/build/artifacts/generated/common/runtime/UnityEngineDebugBindings.gen.cpp Line: 65)[Oxide] 1:53 PM [Info] [Better Chat] [Игрок] DimaWegas: блять дом пропал
    [DOUBLEPOST=1452692996][/DOUBLEPOST]I find it First Hurtworld Exploit Bounty - Gaining Admin Rights • /r/hurtworld

    Hello, i have this problem.
    Queryport=12950
    Game port=12940
     
    Last edited by a moderator: Jan 13, 2016
  9. Wulf

    Wulf Community Admin

    The query port is not private info, but you shouldn't be able to do anything via that port.

    Are you using the Livemap.io extension?
     
  10. Wulf

    Wulf Community Admin

    Yes, Spencer and I are discussing it right now. It's also on Reddit:

    So far I haven't been able to find anything from Oxide that would be allowing it.
     
    Last edited: Jan 13, 2016
  11. Hi Skeleton 2 - one of the Hurtworld devs here. Would you be able to provide a SteamID for Etrim? Please don't post it publicly, just PM me.
     
  12. Okay ^)
     
  13. We have not solved this problem?
     
  14. PROBLEM still relevant !
     
  15. Hey guys. This appears to only be an issue with non-Steam servers that bypass Steam authentication. Are you running a non-Steam server?

    Edit: Considering this thread, I'm going to assume yes. We don't support non-Steam servers. Can't break the security and then complain about the security being broken.
     
    Last edited by a moderator: Feb 4, 2016