Thread: Hacked by a player with no ID

    Hacked by a player with no ID


    My server has been hacked by some little knob with no player ID and he somehow managed to inject a .vdf file inside of my A3 directory.

    One of our regular players reported that a new message was displayed on joining the server, The message reads
    Thank you BIS for making my hacking life so much easier. This BIS_fnc_MP command is just what i need to screw people up. Why don't you go bitch on the forums about it? Hmmm ... it's not exactly hacking anymore, now that it's a feature ...
    Screen shot of the message >

    There was also another error message that i hadn't seen before
    Cannot open object a3\air_f\gbu12fly.p3d
    After checking my A3 installation i noticed a file had been injected in my A3 directory, The file name was installscript.vdf
    I still have the file but i won't post it's contents publically, If a moderator or someone from BE wants it i'll send it

    The player had no game ID, I can't ban someone with no ID
    All i have is
    16:10:43 STSu*EroMusha uses modified data file
    16:10:43 Player STSu*EroMusha connecting.
    16:10:44 Player STSu*EroMusha kicked off - too big custom file 'face.jpg' (83659 B > 10 B).
    16:10:44 Player STSu*EroMusha disconnected.
    It had to be him/her as nobody else was online and the previous player i can vouch for.

    I have VerifySignatures = 2; in my server.cfg so what else can i do ?
    No doubt the little knob will be waiting for this post to get their lulz

    Any help would be great to stop this or detect it
    Last edited by Dwarden; Apr 24 2013 at 04:03. Reason: there is no file injected ... installscript.vdf is part of install

    nothing unexpected
    the BIS_fnc_MP
    is evolution of TOH's replacement
    of A2/OA old MPF (multiplayer framework)

    as Alpha has no security yet, cheating or exploiting ingame scripting and functions is bound to happen

    * Removed after being informed installscript.vdf is a valid file *
    Last edited by Richie; Apr 23 2013 at 18:24.

    Are you sure that this "installscript.vdf" file was put there by a hacker / wasn't there before? According to Google, it seems to be a pretty standard Steam file that can be created in a Steam game's directory.

    EDIT: I just checked my test server (which has only been used by me so far) and it also has an installscript.vdf file in the Arma3 directory. Not sure when that got there, but it certainly wasn't put there by a hacker. False alarm, I dare say.

    I don't know if it was there or not before the hack but it had been modified today, all other files and folders had an older date on but the installscript.vdf was the only recently modified file.
    Removing it hasn't changed anything and my server is running again.

    Can you send me a copy of your installscropt.vdf and i'll compare it to the one i have ?

    I got one from someone else, It is a normal file but it was modified today and the time was around the same as the hack.

    Sent. Btw. mine wasn't the newest file in the directory, but only a day older than the newest one.

    installscript oddly holds the install script.

    Aka the steps that you must complete before starting the game..

    DirectX,registry stuff.

    Nothing wrong with it.
    Thanks for the help so far

    So i now know VerifySignatures = 2; is pointless, It also causes lots of random lag.
    Scripters can't be banned because they can join without a player ID, anyone know a way to kick/block a player without an ID ?

    hi, Richie
    Same issue with our servers can you send me private message, we have 2 servers, using console.log and we had the same user connected to the servers.
    it was the last one and each time, the hack was deployed.
    So i would like to compare if this could be the same guy.

    I don't think there's much we can do in that regard until the actual security measures are implemented. As Dwarden keeps repeating, security (including ID checks AFAIK) is currently nonexistent.

    Hopefully, the situation will improve once the dedi server is out. (Some time next week, if the latest SITREP is to be believed.)

