Network: WoW Gold | WoW Accounts | MPS Games | FPSowned
MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides
Homepage »      Register »      FAQ »      Members »      Advertise »      Marketplace »
 
Sign up



Do you like this excellent information? Then Donate HERE to remove ads and support the MMOwned community.


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > WoW Emulator Server > Emulator Server Guides

Emulator Server Guides Guides for working with World of Warcraft Emulator servers. Learn how to create a WoW Server here.
[NO QUESTIONS HERE]

Reply
 
LinkBack Thread Tools
  #1  
Old 07-29-2007
WoWLegend's Avatar
WoWLegend is offline.
Contributor

 
Join Date: Aug 2006
Location: mah house
Posts: 878
Rep Power: 4
Reputation: 265
The Risks of hosting a public server, and how you can protect yourself [Guide]

Hello everyone,
recently my world of warcraft private server was hacked by a SQL junkie who banned all the GMs and took over the server, i had to temporarily shut it down. So this doesn't happen again I would like to create this Guide on how to protect your private server from these 12 year olds that got nothing better to do.

This guide will be based on personal experiences so if you want something added to the guide you are weary about. post the topic and i will add it.

Public Server General Risks

So you have created a public server, and your first few customers are flocking in. You do not know these people, but at this stage, your just happy having them here, that is what blinds you from this point i would like to make.

Those people have an established connection to your computer. They are allowed through the router, and now you are close to being completely vunerable to attack, if one was a hacker. You may be thinking to yourself, "oh crap im screwed" , this shouldnt be the case, because some handy tools can help keep your players, your server, and most importantly, YOU safe from harm.

Password Inspection and Changing

If you are using antrix or MaNGOS, make your MySQL password something no one would guess, including numbers and letters, and atleast 9 characters long. That should ensure temporary safety to brute force attacks. Also, you should change the password often. (once a week) This also goes for your username and password on your router and Computer.

Firewall and Antivirus

These two things will be your primary tools to defending your computer. You are foolish to be without both of them. But only some are recommendable for this occasion.

Firewalls are your last resort before a hacker can get into your computer and corrupt and change your data. Make sure you have one with limitation options preferably options that allow you to block an IP and protect open ports.

Some recommended Firewalls are:

ZoneAlarm - [Only registered and activated users can see links. ]

Norton Personal Firewall - [Only registered and activated users can see links. ]

McAfee Firewall - [Only registered and activated users can see links. ]

An Antivirus is your clean up tool. If your hacker gets in and implants his programs to do his bidding, this is your only way to clean up what he has dumped on your harddrive.

Some recommended Anti-virus's are:

Norton Internet security - [Only registered and activated users can see links. ]

AVG - [Only registered and activated users can see links. ]

Nod32 - [Only registered and activated users can see links. ]

Kaspersky - [Only registered and activated users can see links. ]

These are great for picking up known viruses, i suggest using more than one.

With these tools you should be well armed for battle against a hacker. But if you want a little more protection, i suggest looking into a router.

Router Protection - The Ultimate Firewall

A router is a supreme solution to keeping your computer safe from malicious attacks. The main reason they are near bulletproof. Nothing can get through without ports being open.

On routers their are a few default ports that are always open. for example port 80 for internet browsing. but if you want people to connect to your computer. Lets say play on your private server, you will have to open more ports (3 to be exact) for them to be able to connect. This leaves those ports vunerable for attack. but thats 3 ports out of 99999. So the hacker would have to know what hes hacking before he could get inside (or he would do a port scan which is what piggy told me earlier).

So there, this limits the hackers possibilities to virtually none if he wasnt attacking your private server. But in this thread we will pretend he is, and at this point in the game. You would be hijacked. So lets continue to find out what we can do to keep those people out.

How To Respond To an Attack, and What You Should Do.

So lets say this hacker got through, made it into your mySQL database, banned all your GMs, made himself one, and enlisted a few more to help his cause. You would be just about ready to give up, rolling on the floor sucking your thumb knowing your computers going down slowly. Dont panic, this is what you can do to protect yourself.

Using Antivirus and Firewall protection, as well as the command prompt. We can find the person connected to your computer's IP, Block it from your computer, delete his virus he probably left to get back in, and in the end save your computer!

Here is the battle plan.

The Battle Plan - A Defensive Alternative

So the hacker because GM on your server and probably banned you and took away your powers. Dont fear, you won't forget, you have GUI control over the mySQL database. when you see him enter your realm. quickly make a GM account. get on the server, and before he kicks and bans you, do a .playerinfo. at the bottom of the blue message, it will display his IP. write it down, this part is vital.

With that IP in hand you are now ready to launch your defensive manuaver. Bring up your firewall, and pray it can block IP's. if it can, put in his IP, if it requires a network LAN IP, open up command prompt (start > Run >CMD) and type in ipconfig, your lan IP will be the Ip address shown, then either wait for him to DC from your server, or kill the connection with a .killbyaccount command. now he will be barred from your system without any means of getting back in. His IP is blocked (Be careful, this only works with STATIC IPs).

The hacker, however, could of deployed a few viruses for him to gain entry again. (examples include backdoor.trojan or a RAT program). use a few antiVirus's to scan for them. use more than one however, most antivirus's dont pick up everything.

When your done the clean up. You are now safe from the hacker. For now. And I guarantee he will try to attack again, just remain smart, remember the battle plan. and know how to use your tools effectively to get that low life back out of your computer.


Note: your computer is never going to be 100% safe. so make a public server at your own expense. Thank you for reading my guide, I hope it has given you an Idea on how to protect yourself.

If you see an error in the guide please point it out and I will fix it the best I can (please dont flame)

FAQ and reader concerns and personal issues

This is a section to help readers with there personal experiences and concerns. I will try to give the best answer I can so i can keep the MMOwned members safe.

Q: Will Blizzard ban me?
A: Probably, if they ever find out, but I highly doubt they will while doing legal things.

Q: Can you teach me how to make a private server plz?
A: No, this guide merely points out the risk of running one, and how to protect yourself.

Becareful and have fun on your servers!

Special thanks to Marlo, Flying Piggy and Alkhara Majere
__________________
The Unofficial MMOwned Radio Station! [Only registered and activated users can see links. ]

Last edited by WoWLegend; 07-29-2007 at 11:08 PM. Reason: had to give thanks!
Reply With Quote
  #2  
Old 07-29-2007
Alkhara Majere's Avatar
Alkhara Majere is offline.
Looks down, whispers no.
Legendary User
 
Join Date: Jul 2006
Location: Canada
Posts: 2,595
Rep Power: 10
Reputation: 943
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Zomg sticky?
__________________

Reply With Quote
  #3  
Old 07-29-2007
Errage's Avatar
Errage is offline.
HWHUT?!
 
Join Date: Jan 2007
Location: Canada
Posts: 2,280
Rep Power: 8
Reputation: 666
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

<GM> Errage from Wowlegend's server (Long story about MMOwned account, etc) and I have seen this all happening, a player named 'Illidari' joined and caused complete chaos. I had been helping Wowlegend101 to my best, but it resulted in Illidari perma-locking my account. Please keep an eye out for anybody that goes by this name, although he probably won't use the same name. Wowlegend did suggest a little plan while you're getting ready to slap your hacker back out of your computer. Most often, as was mentioned, the hacker is a rather young person. Young hackers often just LOVE to hack you in order to see your reaction, so what you might want to do, is instead of trying to ban them, etc. or spam .kick on them (They might just get mad and kill your computer) ignore them, and be as casual as you can. Try to fix any errors they cause, etc.

, Wowlegend
__________________

Errage / Eija - Tortheldrin US (Horde)
La La La La La La La La Lie, Lie, Lie

Last edited by Errage; 09-18-2008 at 06:57 PM.
Reply With Quote
  #4  
Old 07-29-2007
Zokmag's Avatar
Zokmag is offline.
Commander
 
Join Date: Apr 2007
Location: Sweden! ^^
Posts: 930
Rep Power: 3
Reputation: 28
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

++++++++REP!!!!!! YOU OWN!! Right Errage i play on Illidari too so it's hacked thats why it's down??
Reply With Quote
  #5  
Old 07-29-2007
WoWLegend's Avatar
WoWLegend is offline.
Contributor

 
Join Date: Aug 2006
Location: mah house
Posts: 878
Rep Power: 4
Reputation: 265
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

yes thats why its down
__________________
The Unofficial MMOwned Radio Station! [Only registered and activated users can see links. ]
Reply With Quote
  #6  
Old 07-29-2007
Errage's Avatar
Errage is offline.
HWHUT?!
 
Join Date: Jan 2007
Location: Canada
Posts: 2,280
Rep Power: 8
Reputation: 666
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Quote:
Originally Posted by Zokmag View Post
++++++++REP!!!!!! YOU OWN!! Right Errage i play on Illidari too so it's hacked thats why it's down??
You mean you play on Wowlegend's server o.o

Yes, that's why it's down. Illidari is being dealt with, and the server must be down for a bit for the sake of Wowlegend's computer.
__________________

Errage / Eija - Tortheldrin US (Horde)
La La La La La La La La Lie, Lie, Lie

Last edited by Errage; 09-15-2007 at 11:30 PM.
Reply With Quote
  #7  
Old 07-30-2007
Ryuk's Avatar
Ryuk is offline.
Sergeant Major
 
Join Date: Oct 2006
Location: Shinigami World
Posts: 136
Rep Power: 3
Reputation: 18
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

+rep that sure helps a lot wowlegend...
__________________
Reply With Quote
  #8  
Old 07-30-2007
adonis912 is offline.
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
 
Join Date: May 2007
Posts: 22
Rep Power: 3
Reputation: 1
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

I back up my entire database everyday, only takes about 60 seconds. If something goes wrong I can wipe it and reinstall it in about 10 minutes.
Reply With Quote
  #9  
Old 07-30-2007
WontonMan7's Avatar
WontonMan7 is offline.
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
 
Join Date: May 2007
Location: Pimpville
Posts: 24
Rep Power: 3
Reputation: 1
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

What if your server isnt hosted from your comp? My server is a Windows Virtual server
Reply With Quote
  #10  
Old 07-30-2007
j9sjam3's Avatar
j9sjam3 is offline.
Knight
 
Join Date: Mar 2007
Location: Wales, UK
Posts: 190
Rep Power: 3
Reputation: 14
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Dude.... I LOVE YOU!!!
__________________
[Only registered and activated users can see links. ] <--- please click.

*working on a decent siggy*
Reply With Quote
  #11  
Old 07-30-2007
WoWLegend's Avatar
WoWLegend is offline.
Contributor

 
Join Date: Aug 2006
Location: mah house
Posts: 878
Rep Power: 4
Reputation: 265
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Quote:
Originally Posted by adonis912 View Post
I back up my entire database everyday, only takes about 60 seconds. If something goes wrong I can wipe it and reinstall it in about 10 minutes.
Still doesn't mean a hacker cant get in and make himself a GM.

Quote:
Originally Posted by Wontonman7 View Post
What if your server isnt hosted from your comp? My server is a Windows Virtual server
Make sure your server provider is fitted with maximum protection, and make sure they know what to do if their servers are under attack.
__________________
The Unofficial MMOwned Radio Station! [Only registered and activated users can see links. ]
Reply With Quote
  #12  
Old 08-01-2007
Zokmag's Avatar
Zokmag is offline.
Commander
 
Join Date: Apr 2007
Location: Sweden! ^^
Posts: 930
Rep Power: 3
Reputation: 28
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Some of u guys know if one of this firewalls have a free edition (already got avg free edition)
EDIT: ILLIDARI SERVER PWN ALL SERVERS!! Right the server maby need more gm's or gm's online more all are yelling in LFG GM! GM!!
__________________
Swedan teh capital of europez?
Vikings ftw!

Last edited by Zokmag; 08-01-2007 at 04:08 AM.
Reply With Quote
  #13  
Old 08-01-2007
WoWLegend's Avatar
WoWLegend is offline.
Contributor

 
Join Date: Aug 2006
Location: mah house
Posts: 878
Rep Power: 4
Reputation: 265
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

the server doesnt belong to illidari, it is not called illidari, it is now down permanently cause illidari deleted my DB when i tried to put it back online

RIP warcraftmax
__________________
The Unofficial MMOwned Radio Station! [Only registered and activated users can see links. ]
Reply With Quote
  #14  
Old 08-01-2007
Errage's Avatar
Errage is offline.
HWHUT?!
 
Join Date: Jan 2007
Location: Canada
Posts: 2,280
Rep Power: 8
Reputation: 666
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

Quote:
Originally Posted by WoWLegend View Post
the server doesnt belong to illidari, it is not called illidari, it is now down permanently cause illidari deleted my DB when i tried to put it back online

RIP warcraftmax
The server shall be missed dearly.
__________________

Errage / Eija - Tortheldrin US (Horde)
La La La La La La La La Lie, Lie, Lie

Last edited by Errage; 09-15-2007 at 11:31 PM.
Reply With Quote
  #15  
Old 08-01-2007
snowfox is offline.
Private
 
Join Date: Jul 2007
Posts: 1
Rep Power: 0
Reputation: 1
Re: The Risks of hosting a public server, and how you can protect yourself [Guide]

i love the guid
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -4. The time now is 11:53 AM.




Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439