Eventscripts - Creating Windows Account
Lane Wrote:Hi Guys,

I wanted to shoot out an email to everyone in regards to an exploit we have
come across today for those who are running Eventscripts & windows based

Apparently a user is able to upload "corelib.pyc" to the game server without
using the common FTP/Control panel and via the game server itself. In turn,
using eventscripts he is able to execute his script, create an administrator
with full remote desktop access and finally remove all his files once his
account is created.

Our security caught it before it was able to cause us any issues, however
this may be an issue for people who have lesser amount of security in place
and especially if you do not have a anti-virus/firewall running on the

We have also found there is multiple variations of this file, so you may
want to be sure you do a full look at your machines.

With that being said, the files are coming from a free web hosting account
over at - So if your machines have seen any connections in/out bound
to that host in the past 48 hours, I would highly suggest you check your

Now on to the hosts on this list, we also found this in his scripts:


So he was testing this somewhere else, someone else who is running TCAdmin -
If this is yours, I would start checking your boxes.

Attached is a decrypted copy of the corelib.pyc.



If you run TCAdmin you should aways run the services as a second account, with out admin rights! Big Grin

