Bug My server has been hacked, twice.

  • The FTB Forum is now read-only, and is here as an archive. To participate in our community discussions, please join our Discord! https://ftb.team/discord

john01dav

Active Member
Nov 30, 2013
93
2
33
Hello,

Semi-recently a/some player(s) by the name of "Dragnyl," "Animised_Fox," and perhaps "sk8rrchik" (I do not know if these are the same person with alternate accounts or multiple hackers who found some hacked client that found a flaw in FTB -- their IP addresses are all different) have come on my server and wreaked significant havoc.

The first attack consisted of Dragnyl joining, offering creative items, and threatening players. He followed through with these threats by killing players with nukes all over the world. The logs show nothing special in this case, except RebornCore talking about how long explosions took. This player is not in ops.json and they have no data in LuckPerms (other players who have the default rank do have data in LuckPerms). After Dragnyl was banned (which seems to have worked), another account called Animised_Fox joined and wreaked similar havoc.

Now, just today, a player called "sk8rrchik" joined and shortly after everyone online was teleported outside the server's world border to very high coordinates. These very high coordinates caused server crashes when some players joined, and internal server errors when others did. I was able to repair these issues by teleporting these players back to spawn as they joined. It should be noted, however, that sk8rrchick only joined just before this teleportation happened -- they may have nothing to do with it.

Has anyone else experienced similar issues? If so, what did you do? If not, can you recommend anything?

Also, if you need any extra information please let me know, I am quite at a loss for what to do.

Extra information:
  • I am using SpongeForge with FTB Beyond
  • FTB Beyond is entirely default except for the removal of FTB Utilities and RFTools dimensions
  • The additional mods/Sponge plugins are: Dynmap, FlexibleLogin, Nucleus, GriefPrevention, Nuvotifier, LuckPerms, Prism, and MinecraftMarket.
  • The server is running on Ubuntu Server 16.04 LTS x64 with key-only SSH with a key only I have being the only way to access the server.
 
Last edited:
E

eobie

Guest
Hello,

Semi-recently a/some player(s) by the name of "Dragnyl," "Animised_Fox," and perhaps "sk8rrchik" (I do not know if these are the same person with alternate accounts or multiple hackers who found some hacked client that found a flaw in FTB -- their IP addresses are all different) have come on my server and wreaked significant havoc.

The first attack consisted of Dragnyl joining, offering creative items, and threatening players. He followed through with these threats by killing players with nukes all over the world. The logs show nothing special in this case, except RebornCore talking about how long explosions took. This player is not in ops.json and they have no data in LuckPerms (other players who have the default rank do have data in LuckPerms). After Dragnyl was banned (which seems to have worked), another account called Animised_Fox joined and wreaked similar havoc.

Now, just today, a player called "sk8rrchik" joined and shortly after everyone online was teleported outside the server's world border to very high coordinates. These very high coordinates caused server crashes when some players joined, and internal server errors when others did. I was able to repair these issues by teleporting these players back to spawn as they joined. It should be noted, however, that sk8rrchick only joined just before this teleportation happened -- they may have nothing to do with it.

Has anyone else experienced similar issues? If so, what did you do? If not, can you recommend anything?

Also, if you need any extra information please let me know, I am quite at a loss for what to do.

Extra information:
  • I am using SpongeForge with FTB Beyond
  • FTB Beyond is entirely default except for the removal of FTB Utilities and RFTools dimensions
  • The additional mods/Sponge plugins are: Dynmap, FlexibleLogin, Nucleus, GriefPrevention, Nuvotifier, LuckPerms, Prism, and MinecraftMarket.
  • The server is running on Ubuntu Server 16.04 LTS x64 with key-only SSH with a key only I have being the only way to access the server.


Is the server running in offline mode?
 

john01dav

Active Member
Nov 30, 2013
93
2
33
@eobie Sorry for the slow response, no it is not in offline mode. Additionally, any accounts that would have access to do something like this are setup with two factor authentication.

Here's the server.properties file:
Code:
spawn-protection=0
max-tick-time=60000
generator-settings=
force-gamemode=false
allow-nether=true
gamemode=0
broadcast-console-to-ops=true
enable-query=false
player-idle-timeout=0
difficulty=1
spawn-monsters=true
op-permission-level=4
announce-player-achievements=true
pvp=true
snooper-enabled=true
level-type=DEFAULT
hardcore=false
enable-command-block=false
max-players=24
network-compression-threshold=256
resource-pack-sha1=
max-world-size=29999984
server-port=25566
server-ip=
spawn-npcs=true
allow-flight=true
level-name=world
view-distance=10
resource-pack=
spawn-animals=true
white-list=false
generate-structures=true
online-mode=true
max-build-height=256
level-seed=
use-native-transport=true
enable-rcon=false