molfar_audit / Rules / CFG005

CFG005 rcon_password is set

warning Server config

RCON is enabled.

Why it matters

RCON sends the password in plain text over UDP and is a common attack target.

How to fix

Remove rcon_password and manage the server through txAdmin.

Not a problem in your case?

Add -- molfar-audit-ignore CFG005 on the reported line (or the line above it), or ignore it in config.json: "ignore": [{ "rule": "CFG005", "resource": "your_resource" }].