Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   PlayerWorlds Main Forum (https://forums.graalonline.com/forums/forumdisplay.php?f=15)
-   -   Stefan-Hacking Solution (https://forums.graalonline.com/forums/showthread.php?t=19883)

royce 12-29-2001 12:51 PM

Stefan-Hacking Solution
 
Here is a solution to our troubles. Each Pw owner makes a list of what the password changes are going to be every month. They email Stefan the passwords for the next 4 months. Every month Stefan changes the passwords. This would help a bit.

iniquitus 12-29-2001 01:09 PM

What Graal needs is* 1024bit Tripple MDS Encryption! :D

Urizen

LiquidIce00 12-29-2001 01:18 PM

actually it would be nice if it was like restricted 5 diff ip's or something ^_^

Python523 12-29-2001 01:19 PM

How bout every week? A brute-forcer could probably figure out a password in a mounth

royce 12-29-2001 01:24 PM

How bout a Randomer....Like the owner picks 5 passwords a month, then he can send to stefan the different ways to get in. Think of it as directories. the last directory is the access. The directory path can switch around up to 3 ways. And a Simple note to the owner even says that which Swich is taking place.

iniquitus 12-29-2001 01:30 PM

That would be alot of work, MD5 password encryption would be eaiser :p

iniquitus 12-29-2001 01:56 PM

Afterthought* :D

What ever happened to good ol'fashion server backups? :)

Urizen

Faheria_LAT1 12-29-2001 01:57 PM

Quote:

Originally posted by iniquitus
Afterthought* :D

What ever happened to good ol'fashion server backups? :)

Urizen

Mithica's NPC Admin fought against the File deleting ***** for more then 3 hrs, reuploading again and again..

Falcor 12-29-2001 02:03 PM

Dont bother, Graal is dieing anyhow.

iniquitus 12-29-2001 02:03 PM

Maybe seting up a Firewalling system and making the FTP daemon only accept connections from certain IP's (This would work well if all owners had static's) Maybe change the port number of the FTP server every month or something would help too. (Make sure you have portsentry or something on the server to detect portscaners!)

Urizen

***EDITED:


There's the ticket! Setup a Firewall with a VPN to access the FTP server, and give owners the VPN clients and the Private Key. NetScreen has a nice off the shelf product to do this if you don't want to brave it manualy (www.netscreen.com I think) it offers 2 layer 1024bit 3DES encryption and MD5 password shadowing etc etc.. very nice product. I just installed one at work.

JubeiSaotomeX 12-29-2001 09:59 PM

or howabout only the owner gets ftp, problem solved

kp_p2p 12-30-2001 12:00 AM

=/
 
Quote:

Originally posted by JubeiSaotomeX
or howabout only the owner gets ftp, problem solved
but the you see... the owner isnt there all the time. what if they go on vacation? the server doesn't get updated until they return?

zell12 12-30-2001 12:22 AM

Yes, well... with my server only Me, other Owner, and GM will have FTP access... this was only three people have it, The GM (or Owners) will take the work from the other admins and upload it...
Also, if you incrypt it, its just as easy to get the pass, because ya just use BruitForce, then use a decrypter yo decode it... So what ya should use is a Firewall, with a random ip changer for the server... (not sure they will like this, but anywho).
Btw, what if they have 56K or something, ya can't make a ip lock for ftp then

Shard_IceFire 12-30-2001 01:51 AM

On Divided Kingdoms I think someone hacked the FTP pass...I never gave it to anyone so i don't know how they'd get it.

DarkPyro_2001 12-30-2001 11:55 PM

You know, if you only looked at the topic of the thread, you'd almost think that Stefan was the hacker.. HMM. :cool:

Shard_IceFire 12-31-2001 12:43 AM

Quote:

Originally posted by DarkPyro_2001
You know, if you only looked at the topic of the thread, you'd almost think that Stefan was the hacker.. HMM. :cool:
lol! Y'know, you're right.

Admins 12-31-2001 04:33 AM

The solution would probably be to add
ftp upload to RC, I already made concepts for
it but haven't got time to implement it
(the owner can say what files in which folders you
can change, then via RC you can upload and
download those files, can be simple for the start)

James 12-31-2001 05:05 AM

Quote:

Originally posted by Stefan
The solution would probably be to add
ftp upload to RC, I already made concepts for
it but haven't got time to implement it
(the owner can say what files in which folders you
can change, then via RC you can upload and
download those files, can be simple for the start)


Excellent idea, that would help a lot.

Andor_Admin1 12-31-2001 05:17 AM

That would be a great way to do things. If I could restrict what directories/files people could change, it would solve any problems that occur with FTP. For example, if somebody quits, it will be nice to not have to change the FTP pass just to keep them out of the FTP (In a perfect world, people would just leave it alone if they left, but, sadly, this is not a perfect world.)

LiquidIce00 12-31-2001 02:21 PM

oo.. that would be awesome .. like rights and stuff.. and since you can protect RC's by IP it will be much safer..
and u can have an actual guild manager who only can do guilds , or some1 who can only do certain things o.o
btw: ipgps.txt is still in use.. isnt it supposed to be gone and read ips from the rights??

Mustang1988 01-01-2002 01:27 PM

Quote:

Originally posted by Stefan
The solution would probably be to add
ftp upload to RC, I already made concepts for
it but haven't got time to implement it
(the owner can say what files in which folders you
can change, then via RC you can upload and
download those files, can be simple for the start)

Whoa.. Stefan is thuper thmart! And it can keep a log of who downloads/uploads stuff so you can keep track if you have a hacker on someone's account or a corrupt LAT (With IPs ;p)

LiquidIce00 01-01-2002 01:41 PM

Quote:

Originally posted by Mustang1988


Whoa.. Stefan is thuper thmart! And it can keep a log of who downloads/uploads stuff so you can keep track if you have a hacker on someone's account or a corrupt LAT (With IPs ;p)

omfg l33t idea

Torankusu 01-01-2002 05:49 PM

no way is safe.

they could still get onto the account if there is no secure IP.

iniquitus 01-02-2002 12:35 AM

And IP addresses are eaisly spoofed, Windows XP actualy makes it very easy to do this too (People at microsoft are idoits.) In a few months script-kiddies will be able to find some websites titled "How to Spoof you IP with Windows XP in 3 easy steps!"

Giving out Key's over an encrypted tunnel might be the most secure method.

"This Stefan-Hacking Problem is a real threat! We MUST find a way to stop Stefan from distributing his massive Trojan Worm to every child on this planet... I don't know how we'll get the word out in time, he's alredy fooled hundreds, and this "Graal" gains popularity every day... God help us."

hehe

TDO2000 01-03-2002 12:19 AM

Quote:

Originally posted by Stefan
The solution would probably be to add
ftp upload to RC, I already made concepts for
it but haven't got time to implement it
(the owner can say what files in which folders you
can change, then via RC you can upload and
download those files, can be simple for the start)

That makes no sense...
normally no normal user is supposed to have FTP Pass or user account so if they got it this time they will get it if u use your RC-System no difference :rolleyes:

grim_squeaker_x 01-03-2002 12:25 AM

Quote:

Originally posted by TDO2000


That makes no sense...
normally no normal user is supposed to have FTP Pass or user account so if they got it this time they will get it if u use your RC-System no difference :rolleyes:

Actually there would be a difference, RC accounts have a registered IP on the FTP, the FTP server itself, currently, however only has password security

btedji 01-03-2002 12:36 AM

Re: =/
 
Quote:

Originally posted by kp_p2p
but the you see... the owner isnt there all the time. what if they go on vacation? the server doesn't get updated until they return?
I know lots of servers where the owner barely does anything

Jinx 01-03-2002 03:01 AM

Why not have a 2 part thing?

In order for someone to log on FTP, they need to have the right on their RC, and the password.

For example, I could give someone on RC the right to FTP, then when he presses the "FTP" button on RC, it would ask him for the FTP password.

That way if someone were to hack onto an RC or something, they would then have to figure out the FTP password too.


And why doesn't stefan just randomly generate passwords for FTP? Dont let the owner's do it, Stefan should just throw together a big long line of letters and numbers and give it to the owner.

-Jinx

zell12 01-03-2002 04:13 AM

What stefan is talking is already made, its called bullet proof FTP you dl the server, and set it up ( You create all the accounts and such) passwords are ready made and never the same, there all encrypted and the Owner can specify what files staff have access too... go to www.google.com and search fr it, im too lazy to find the address, but if I do i'll post it... did I mention its free for one month ;)

btedji 01-03-2002 05:23 AM

Quote:

Originally posted by zell12
What stefan is talking is already made, its called bullet proof FTP you dl the server, and set it up ( You create all the accounts and such) passwords are ready made and never the same, there all encrypted and the Owner can specify what files staff have access too... go to www.google.com and search fr it, im too lazy to find the address, but if I do i'll post it... did I mention its free for one month ;)
www.bpftp.com
www.bpftpserver.com

LiquidIce00 01-03-2002 11:32 PM

Quote:

Originally posted by Torankusu
no way is safe.

they could still get onto the account if there is no secure IP.

w/ Stefans way?
It be good cuz even if some guy hax0red a guy thru sub7 and got RC acct he would get rc acct but the guy might not have power to delete levels or to do this or that and he wouldnt be able to mess up the server half as bad. also to get rid of the guy would be a 5 minute thing instead of having to email/pm stefan saying "we got haxored change ftp plz"

Nishoku 01-03-2002 11:41 PM

I heard about that Liquid. Dark Warlock came to me first I told him to get the RC logs and stay calm.


All times are GMT +2. The time now is 06:48 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.