1

I got hacked [AND I GOT SCREENSHOTS!]

EmpathyHeals's Avatar EmpathyHeals3/29/14 9:39 pm
1 emeralds 234 9
3/30/2014 2:04 pm
DtigerCSK's Avatar DtigerCSK
Help me find this cretin so I can ban them, folks.

My server has been peaceful so far but we've finally drawn the attention of a hacker . They spammed my server with rude messages (see screenshots, bad language warning ) and put in other player's names as well, so that messed with milestones.

Any clue how to find out a) who did it and b) how to prevent someone from highjacking VoteRoulette again in the future?

Thank you!
Emp

http://empathyheals.enjin.com/forum/m/21228992/viewthread/11916459-our-first-attack
Posted by EmpathyHeals's Avatar
EmpathyHeals
Level 42 : Master Zombie
120

Create an account or sign in to comment.

9

1
03/30/2014 1:37 pm
Level 11 : Journeyman Artist
Vermon122
Vermon122's Avatar
Hello Empathy, I'll take a look at the website, You can change your public key by removing the Votifier Folder and .jar from your server and re-downloading it. Unfortunatly doing so you'll have to change it for all Server Listings. If I can help you in anyway please add me on skype: Nick.Carpenter52


Thanks!

~Vermon


Alright After looking around on that website, I neither know how to remove it, Considering they are still in beta they probably don't have it implemented. When I hosted my server for the short amount of time, I used them aswell. I had no issues except claiming the server was mine. I do recommend makng a forum post, to aware others to NOT post there server on that site, unless they get a good ~100 players

Thanks Again,
- Vermon
1
03/30/2014 4:12 am
Level 42 : Master Zombie
EmpathyHeals
EmpathyHeals's Avatar
He advertized his site on Planet Minecraft and then did that; do you think I should report him?
1
03/30/2014 2:04 pm
Level 34 : Artisan Pokemon
DtigerCSK
DtigerCSK's Avatar
Yes definitely, this is a type of phishing(-ish), and it is against the rules to advertise other server lists as well.
1
03/30/2014 3:54 am
Level 11 : Journeyman Artist
Vermon122
Vermon122's Avatar
Hello Empathy, I assume you can remove your server by going to the 'User Profile'. and going under a tab called My Servers or even Dashboard. There is many different layouts for MC Server Listings. I hope everything ended up ok, If you would like any help on your server I do Plugin and Building Management for cheap amounts of cash.(sometimes free) but that's besides the point. I hope everything is okay, and I would highly recommend uses a different email for server things. Therefore people don't go too far with their dumb tricks.


Thanks!

~ Vermon
1
03/30/2014 4:07 am
Level 42 : Master Zombie
EmpathyHeals
EmpathyHeals's Avatar
Thank you Vermon, but I cannot figure out how to remove a server neither from

http://theminecraftserverlist.com/

which is the site I got spammed from (which in the end I don't want to remove my server, but change the password and public key, however, I do have ANOTHER server on this site that I do want removed and I can't find an option)

nor from the site I signed up my server on that happens to have the crook of an owner who stole my password, logged into http://theminecraftserverlist.com/, and stole my votifier public key.

I could use help removing my severs from both those sites.
Thank you.

PS. The site of the crook isn't here because I don't want to get in trouble by talking badly about a site, so it's in my post here: http://empathyheals.enjin.com/forum/m/21228992/viewthread/11916459-our-first-attack/page/1/post/last
1
03/30/2014 3:45 am
Level 42 : Master Zombie
EmpathyHeals
EmpathyHeals's Avatar
I FIGURED IT OUT so learn a lesson from my experience, everyone.

Do NOT sign your server up for sites that you do not research well or do not have an established reputation!!!

What happened is that some dude posted his site on PMC and I fell for it, so I signed up my server at his site.

Go to my forum post to find out what site it was; I'm afraid if I post it here I'll be disciplined for talking badly about another site or something; I have the same post as here there except I include the dude's name and email in there:

http://empathyheals.enjin.com/forum/m/21228992/viewthread/11916459-our-first-attack/page/1/post/last

I soon got a newbie that logged into my server, asked if racism was allowed after reading the rules which clearly state BE RESPECTFUL, so when I decided to ban instead of educate, he wasn't happy. He wrote me an email "innocently" stating he was just asking a simple question *eyeroll* and would I please unban him. When I did not I guess he decided to retaliate.

I noticed his email address domain was the same as the domain I signed up my server on, and at the bottom is his username that I banned, so what seems to have happened is that he owns the site and STOLE MY PASSWORD, logged into another votifier enabled site, and SPAMMED ME.

My fault, now I will have to change my public key, all my passwords... so learn a lesson from me everyone: do not sign up on new sites that haven't been tested or earned a good reputation, do not use the same password on different sites, also.

/kicks self.
Emp

PS. Any idea how to remove my server from that site? I don't feel like asking the owner...
1
03/30/2014 1:28 am
Level 42 : Master Zombie
EmpathyHeals
EmpathyHeals's Avatar
Okay BEFORE I change the public key (sigh, I got 11 sites and I just did that already because I switched hosts), is there any way they could have only done it on that site for some reason? I did not give anyone access to my host, I did a search on the forum and although I pasted some log files from the host (I will be more careful about that) the public key does not show up anywhere. I did not email it to anyone or provide anyone the config file, and I did install all my plugins through BukGet from Multicraft (not any link somebody sends me). If I don't see it in BukGet I don't get it no matter how much anybody tells me it's a safe plugin. I do notice they only used one site to spam from; I disabled votifier ON THAT SITE; could that alone take care of it? I turned off milestones for now so even if it happens again people will just get potions and stuff and not money, but I would like to turn milestones back on. Thanks for any input! *grumble*
Emp
1
03/30/2014 12:04 am
Level 34 : Artisan Pokemon
DtigerCSK
DtigerCSK's Avatar
Votifier is next to impossible to hack, the only way an user could have done this would have been by knowing your votifier key and port, or with malicious plugins. Try deleting your public.key file, then let it create a new one. You will, however, have to change the key to the new one on the server lists you have posted your server to.
As for malicious plugins, make sure you don't download plugins from places other than BukkitDev, as downloading plugins could have code harmful to your server.

You won't be able to find out the user who is doing this, as there's no way of knowing who voted on a server list, provided that they didn't use their username.

Prevention would just be making sure you download plugins only from BukkitDev, and changing your votifier key.
You might want to just disable Votifier if this continues.
1
03/29/2014 10:30 pm
Level 42 : Master Zombie
EmpathyHeals
EmpathyHeals's Avatar
Anybody? I tried voting at that site myself again and I couldn't; so how could they vote so many times in a row? Is it just this site they can bypass that requirement for or all of them? http://theminecraftserverlist.com/vote/ ... 63.5:25745
Planet Minecraft

Website

© 2010 - 2024
www.planetminecraft.com

Welcome