<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.cubers.net/a/h/Server_security?feed=atom</id>
		<title>Server security - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.cubers.net/a/h/Server_security?feed=atom"/>
		<link rel="alternate" type="text/html" href="https://wiki.cubers.net/a/h/Server_security"/>
		<updated>2026-05-16T02:20:19Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.30.2</generator>

	<entry>
		<id>https://wiki.cubers.net/index.php?title=Server_security&amp;diff=5449&amp;oldid=prev</id>
		<title>X-Ray Dog at 18:16, 22 April 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.cubers.net/index.php?title=Server_security&amp;diff=5449&amp;oldid=prev"/>
				<updated>2012-04-22T18:16:28Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr style=&quot;vertical-align: top;&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 18:16, 22 April 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==General==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==General==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is easy to set up a minimal server, however if you plan to host a server over a long time you should consider some security aspects. General goals:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is easy to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Server_setup|&lt;/ins&gt;set up a minimal server&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]]&lt;/ins&gt;, however if you plan to host a server over a long time you should consider some security aspects. General goals:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Run the server with an underprivileged user account. This reduces the applications access to local system resources such as the filesystem&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Run the server with an underprivileged user account. This reduces the applications access to local system resources such as the filesystem&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>X-Ray Dog</name></author>	</entry>

	<entry>
		<id>https://wiki.cubers.net/index.php?title=Server_security&amp;diff=619&amp;oldid=prev</id>
		<title>Apollo at 06:28, 24 June 2010</title>
		<link rel="alternate" type="text/html" href="https://wiki.cubers.net/index.php?title=Server_security&amp;diff=619&amp;oldid=prev"/>
				<updated>2010-06-24T06:28:54Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr style=&quot;vertical-align: top;&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 06:28, 24 June 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{ Language | pagename=Server security }}&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==General==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==General==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is easy to set up a minimal server, however if you plan to host a server over a long time you should consider some security aspects. General goals:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is easy to set up a minimal server, however if you plan to host a server over a long time you should consider some security aspects. General goals:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Apollo</name></author>	</entry>

	<entry>
		<id>https://wiki.cubers.net/index.php?title=Server_security&amp;diff=365&amp;oldid=prev</id>
		<title>Flowtron: import from previous wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.cubers.net/index.php?title=Server_security&amp;diff=365&amp;oldid=prev"/>
				<updated>2010-06-20T13:36:53Z</updated>
		
		<summary type="html">&lt;p&gt;import from previous wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{ Language | pagename=Server security }}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==General==&lt;br /&gt;
It is easy to set up a minimal server, however if you plan to host a server over a long time you should consider some security aspects. General goals:&lt;br /&gt;
&lt;br /&gt;
# Run the server with an underprivileged user account. This reduces the applications access to local system resources such as the filesystem&lt;br /&gt;
# Run the server in a way that does not require an interactive session. This ensures that the server keeps running independent of any user session.&lt;br /&gt;
# Run the server in a sandbox. Isolate the server process to minimize its ability to affect the local system&lt;br /&gt;
&lt;br /&gt;
The following sections describe these measurements on different platforms. It is presumed that the reader knows how to perform basic administrative tasks such as creating new user accounts.&lt;br /&gt;
&lt;br /&gt;
==Microsoft Windows==&lt;br /&gt;
This section covers the following Windows platforms:&lt;br /&gt;
&lt;br /&gt;
* Windows Server 2000&lt;br /&gt;
* Windows Server 2003&lt;br /&gt;
* Windows XP Professional Edition&lt;br /&gt;
* Windows XP Professional x64 Edition&lt;br /&gt;
* Windows XP Media Center Edition 2005&lt;br /&gt;
&lt;br /&gt;
Unfortunately, Windows XP Home Edition is missing some necessary features, so you will be unable to run a server as a service if you are running XP Home.&lt;br /&gt;
&lt;br /&gt;
===Running the AC server as a service===&lt;br /&gt;
Creating an own service for the AC server is a good way to achieve the goals 1. and 2. : It runs the AC server using a configurable user credential and keeps it running independent of any user session.&lt;br /&gt;
&lt;br /&gt;
Start &amp;gt; Run &amp;gt; ''lusrmgr.msc'' to access ''Local Users and Groups''.&lt;br /&gt;
[[Image:New-ac-user.gif|thumbnail|right|The newly created ''ACserver'' account listed in the ''Local Users and Groups'' window, on Windows XP Professional]]&lt;br /&gt;
# Create a new user account for the AC server, e.g. a local user account named ''ACserver''.&lt;br /&gt;
# Remove the account from the ''Users'' group.&lt;br /&gt;
# Create a new group for game servers, e.g. ''Gameservers'' and add the ''ACserver'' account to it.&lt;br /&gt;
# Set the correct filesystem permissions, as described below. To enable the ''Security'' tab on folder properties, go to My Computer &amp;gt; Tools &amp;gt; Folder Options... &amp;gt; View and '''uncheck''' ''Use simple file sharing (Recommended)''.&lt;br /&gt;
## Deny write permission on the system drive (C:\)&lt;br /&gt;
## Grant execute permission on the ''\bin_win32'' folder&lt;br /&gt;
## Grant execute permission on the ''\assaultcube_server.bat'' file&lt;br /&gt;
## Grant Read permission on the ''\config\maprot.cfg'' file&lt;br /&gt;
&lt;br /&gt;
==Linux/Unix==&lt;br /&gt;
For maximum security - on a machine you have root access to - you should create a dedicated user with no group memberships (except it's own group, of course).&lt;br /&gt;
If you can and think it safer you might consider using some form of [http://en.wikipedia.org/wiki/Chroot chroot].&lt;br /&gt;
'''chown''' and '''chmod''' the files appropriately .. either accessible only for the user as owner and group ''chown -R acs:acs *'' (if your user is '''acs''') or maybe you ''do'' trust your staff/admins - but be careful with any logfiles and extra careful ('''chmod 600''') with config/serverpwd.cfg.&lt;br /&gt;
Run the server inside a [http://en.wikipedia.org/wiki/GNU_Screen screen-session].&lt;br /&gt;
There are also a number of ways to keep a server alive in case it crashes without having to manually interact with the machine.&lt;br /&gt;
One of the most straight-forward methods is to have some script like the following run periodically via something like [http://en.wikipedia.org/wiki/Cron cron].&lt;br /&gt;
 #!/bin/sh&lt;br /&gt;
 &lt;br /&gt;
 ACdir=&amp;quot;/usr/local/games/AC&amp;quot;&lt;br /&gt;
 ACpsi=`ps aux | grep &amp;quot;bin_unix.\+_server&amp;quot; | grep -v grep | awk '{print $2,$3,$4,$8,$11}'`&lt;br /&gt;
 ACpid=`echo &amp;quot;$ACpsi&amp;quot;|awk '{print $1}'`&lt;br /&gt;
 ACstat=`echo &amp;quot;$ACpsi&amp;quot;|awk '{print $4}'`&lt;br /&gt;
 # you might even want to check $ACstat doesn't contain &amp;quot;Z&amp;quot; .. as in zombie&lt;br /&gt;
 &lt;br /&gt;
 if [ -z &amp;quot;$ACpid&amp;quot; ]; then&lt;br /&gt;
 &lt;br /&gt;
   echo &amp;quot;Couldn't find AC server running, restarting it.&amp;quot;&lt;br /&gt;
   cd &amp;quot;$ACdir&amp;quot;&lt;br /&gt;
   # run the screen session:&lt;br /&gt;
   /usr/local/bin/my_screen_session_for_an_AC_server&lt;br /&gt;
   # or just try this:&lt;br /&gt;
   #nohup ./server.sh &amp;amp;&lt;br /&gt;
   echo &amp;quot;&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 fi&lt;br /&gt;
&lt;br /&gt;
Very advanced users may even poll the infoport to check for responsiveness and/or gamestate sanity - we leave that as an exercise to you ;-)&lt;br /&gt;
&lt;br /&gt;
[[Category:English]]&lt;br /&gt;
[[Category:Server]]&lt;br /&gt;
[[Category:Configuration]]&lt;/div&gt;</summary>
		<author><name>Flowtron</name></author>	</entry>

	</feed>