PtokaX forum

Development Section => Your Developing Problems => Topic started by: vipernef on 17 December, 2004, 12:48:13

Title: Security problems
Post by: vipernef on 17 December, 2004, 12:48:13
Hello
I am having some problems in my hub. someone is using a program that makes my hub strat loosing users , users start droping and cant get back in, other probles is redirecting someone that is not an operator manages to redirect users and even using ptoka on is pc redirect my ip to his ptoka
How can I protect from this
Kind regards
Title:
Post by: [NL]Pur on 17 December, 2004, 13:10:07
do you have an firewall installed on your computer, and are you sure , he didn't hacked your windows ?
Title:
Post by: bastya_elvtars on 17 December, 2004, 13:13:57
QuoteOriginally posted by vipernef
Hello
I am having some problems in my hub. someone is using a program that makes my hub strat loosing users , users start droping and cant get back in, other probles is redirecting someone that is not an operator manages to redirect users and even using ptoka on is pc redirect my ip to his ptoka
How can I protect from this
Kind regards

i found a f***ing backdoor that installs with Radmin

do you use radmin?
Title:
Post by: vipernef on 17 December, 2004, 14:37:09
I use ptoka x  4034 and I use sygate firewall and a router with a firewall as well
My bigest problem are teh redirects and the user droping they can redirect and kick my users
Title:
Post by: blackwings on 17 December, 2004, 15:34:36
or do you use a script that you haven't got from this site? because then there might be some nasty things in it, like redirecting users with a certain tag, or haveing a function that counts connecting users and sends  like every 20 users to a different IP.

These scary function that you can find on other places then this site (like wares servers on p2p networks), they can be like just a very few lines that has been mixed up with the rest of the code of the original script.
Title:
Post by: [_XStaTiC_] on 17 December, 2004, 16:37:00
Hi,

I think you have to check your Profile Manager.
Maybe you have turned on the redirect and dropping for RegUsers.
Title:
Post by: plop on 17 December, 2004, 20:44:11
QuoteOriginally posted by vipernef
I use ptoka x  4034
????????????????????????????????????
that 1 doesn't excist.

plop
Title:
Post by: Herodes on 17 December, 2004, 22:09:50
QuoteOriginally posted by plop
QuoteOriginally posted by vipernef
I use ptoka x  4034
????????????????????????????????????
that 1 doesn't excist.

plop
prolly 4043 refers to DC++ v0.4034 and 'ptokax x' == 'accessing ptokax with' ..:/
Title:
Post by: vipernef on 18 December, 2004, 00:09:48
sorry its 0.3.3.0 the version I put befiore was  from revconnect LOL
Title:
Post by: plop on 18 December, 2004, 14:51:31
QuoteOriginally posted by bastya_elvtars i found a f***ing backdoor that installs with Radmin

do you use radmin?
radmin is a backdoor, a backdoor 2 manage a computer over a network.
so you didn't find anything bad.

plop
Title:
Post by: bastya_elvtars on 18 December, 2004, 17:04:53
QuoteOriginally posted by plop
QuoteOriginally posted by bastya_elvtars i found a f***ing backdoor that installs with Radmin

do you use radmin?
radmin is a backdoor, a backdoor 2 manage a computer over a network.
so you didn't find anything bad.

plop

i bet IT company do know this... why did 2 spy checkers report it then?
Title:
Post by: [NL]Pur on 18 December, 2004, 19:50:18
maby to notify you that radmin is installed on your computer.

It might be that someone else installs radmin on your comp and gains access thru it without you knowing that radmin is installed.

I can imagine that some users don't even know what radmin is.
Title:
Post by: bastya_elvtars on 18 December, 2004, 21:17:49
QuoteOriginally posted by [NL]Pur
maby to notify you that radmin is installed on your computer.

It might be that someone else installs radmin on your comp and gains access thru it without you knowing that radmin is installed.

I can imagine that some users don't even know what radmin is.

i uninstalled it for safety... maybe i will install 2.1 once, but we are running ptokax, not yhub, and ptokax does not crash ;p
Title:
Post by: [NL]Pur on 18 December, 2004, 23:24:04
exactly , we only use radmin to see how nicely ptokax runs ;)
Title:
Post by: plop on 19 December, 2004, 00:04:44
QuoteOriginally posted by [NL]Pur
maby to notify you that radmin is installed on your computer.

It might be that someone else installs radmin on your comp and gains access thru it without you knowing that radmin is installed.

I can imagine that some users don't even know what radmin is.
indeed, you can install radmin and disable the tray icon.
now you can abuse it as a trojan horse giving you full acces.

plop
Title:
Post by: [PT]CableGuy on 19 December, 2004, 05:44:04
Radmin is not a trojan !!! There are some vulnerabilities though...
But...why use Radmin and be forced to install the application ?
If you need "remote desktop systems" , take a look at UltraVNC (http://ultravnc.sourceforge.net/) !!!
It gives you:

Quote* File Transfer with intuitive Graphical User Interface
* Optional Video Driver for high speed and low CPU  (W2000/XP/2003), Ddi hooking (Win 9.x)
* NT Domain and Active Directory based security
* High speed and performances over LAN connections.
* Very good responsivness over slow connections (cable, modem)
* Embedded Client/Server Text Chat
* Optional Data Stream Enrcryption Plugin
* Viewer with Auto Configuration, Quick Options and Auto Scaling
* Standard Win32 Viewer and JavaViewer connections over TCP/IP
* Supported Operating Systems: Win9x/NT4/Win2000/XP/2003
* Viewer Toolbar and Hot keys
* View Modes: Full-Screen, Scaled and Windowed
* Viewer Status Window
* Dynamic Single Window/Full Desktop view switching
* Backward Compatible with others VNC flavors.
* Support for 32/24/16/8 bits colors
* Server's Desktop dynamic resolution switching
* Server Screen Blanking/mouse locking from viewer side
* Bandwidth Saving technologies : Bitmap Cache management, server screen scaling
* Possibility to send Ctrl-Alt-Del to the remote server
Sincerely , the best and fastest , remote desktop system i've ever used...and you don't need to install nothing !!
Give it a try. ;)
Title: thank you
Post by: vipernef on 20 December, 2004, 12:42:22
the problem continues .... its really anoying lol
but I know the guy that is doing it I think I am going to take more "real" measures hehehe

thank you all for your help
Title:
Post by: plop on 21 December, 2004, 00:13:46
QuoteOriginally posted by vipernef
the problem continues .... its really anoying lol
but I know the guy that is doing it I think I am going to take more "real" measures hehehe

thank you all for your help
if your behind a router you should check the settings.
look for default server and DMZ, if those are enabled you found a huge leak.
but open up the given ip fully 2 the internet, here you need a firewall on your computer 2 protect yourself.
a router has NAT inside it, which hides your computer.
but as a result you need 2 forward some ports for dc and the hub, but then the firewall only needs 2 protect those ports.

plop