![]() |
Stefan-Hacking Solution
Here is a solution to our troubles. Each Pw owner makes a list of what the password changes are going to be every month. They email Stefan the passwords for the next 4 months. Every month Stefan changes the passwords. This would help a bit.
|
What Graal needs is* 1024bit Tripple MDS Encryption! :D
Urizen |
actually it would be nice if it was like restricted 5 diff ip's or something ^_^
|
How bout every week? A brute-forcer could probably figure out a password in a mounth
|
How bout a Randomer....Like the owner picks 5 passwords a month, then he can send to stefan the different ways to get in. Think of it as directories. the last directory is the access. The directory path can switch around up to 3 ways. And a Simple note to the owner even says that which Swich is taking place.
|
That would be alot of work, MD5 password encryption would be eaiser :p
|
Afterthought* :D
What ever happened to good ol'fashion server backups? :) Urizen |
Quote:
|
Dont bother, Graal is dieing anyhow.
|
Maybe seting up a Firewalling system and making the FTP daemon only accept connections from certain IP's (This would work well if all owners had static's) Maybe change the port number of the FTP server every month or something would help too. (Make sure you have portsentry or something on the server to detect portscaners!)
Urizen ***EDITED: There's the ticket! Setup a Firewall with a VPN to access the FTP server, and give owners the VPN clients and the Private Key. NetScreen has a nice off the shelf product to do this if you don't want to brave it manualy (www.netscreen.com I think) it offers 2 layer 1024bit 3DES encryption and MD5 password shadowing etc etc.. very nice product. I just installed one at work. |
or howabout only the owner gets ftp, problem solved
|
=/
Quote:
|
Yes, well... with my server only Me, other Owner, and GM will have FTP access... this was only three people have it, The GM (or Owners) will take the work from the other admins and upload it...
Also, if you incrypt it, its just as easy to get the pass, because ya just use BruitForce, then use a decrypter yo decode it... So what ya should use is a Firewall, with a random ip changer for the server... (not sure they will like this, but anywho). Btw, what if they have 56K or something, ya can't make a ip lock for ftp then |
On Divided Kingdoms I think someone hacked the FTP pass...I never gave it to anyone so i don't know how they'd get it.
|
You know, if you only looked at the topic of the thread, you'd almost think that Stefan was the hacker.. HMM. :cool:
|
Quote:
|
The solution would probably be to add
ftp upload to RC, I already made concepts for it but haven't got time to implement it (the owner can say what files in which folders you can change, then via RC you can upload and download those files, can be simple for the start) |
Quote:
Excellent idea, that would help a lot. |
That would be a great way to do things. If I could restrict what directories/files people could change, it would solve any problems that occur with FTP. For example, if somebody quits, it will be nice to not have to change the FTP pass just to keep them out of the FTP (In a perfect world, people would just leave it alone if they left, but, sadly, this is not a perfect world.)
|
oo.. that would be awesome .. like rights and stuff.. and since you can protect RC's by IP it will be much safer..
and u can have an actual guild manager who only can do guilds , or some1 who can only do certain things o.o btw: ipgps.txt is still in use.. isnt it supposed to be gone and read ips from the rights?? |
Quote:
|
Quote:
|
no way is safe.
they could still get onto the account if there is no secure IP. |
And IP addresses are eaisly spoofed, Windows XP actualy makes it very easy to do this too (People at microsoft are idoits.) In a few months script-kiddies will be able to find some websites titled "How to Spoof you IP with Windows XP in 3 easy steps!"
Giving out Key's over an encrypted tunnel might be the most secure method. "This Stefan-Hacking Problem is a real threat! We MUST find a way to stop Stefan from distributing his massive Trojan Worm to every child on this planet... I don't know how we'll get the word out in time, he's alredy fooled hundreds, and this "Graal" gains popularity every day... God help us." hehe |
Quote:
normally no normal user is supposed to have FTP Pass or user account so if they got it this time they will get it if u use your RC-System no difference :rolleyes: |
Quote:
|
Re: =/
Quote:
|
Why not have a 2 part thing?
In order for someone to log on FTP, they need to have the right on their RC, and the password. For example, I could give someone on RC the right to FTP, then when he presses the "FTP" button on RC, it would ask him for the FTP password. That way if someone were to hack onto an RC or something, they would then have to figure out the FTP password too. And why doesn't stefan just randomly generate passwords for FTP? Dont let the owner's do it, Stefan should just throw together a big long line of letters and numbers and give it to the owner. -Jinx |
What stefan is talking is already made, its called bullet proof FTP you dl the server, and set it up ( You create all the accounts and such) passwords are ready made and never the same, there all encrypted and the Owner can specify what files staff have access too... go to www.google.com and search fr it, im too lazy to find the address, but if I do i'll post it... did I mention its free for one month ;)
|
Quote:
www.bpftpserver.com |
Quote:
It be good cuz even if some guy hax0red a guy thru sub7 and got RC acct he would get rc acct but the guy might not have power to delete levels or to do this or that and he wouldnt be able to mess up the server half as bad. also to get rid of the guy would be a 5 minute thing instead of having to email/pm stefan saying "we got haxored change ftp plz" |
I heard about that Liquid. Dark Warlock came to me first I told him to get the RC logs and stay calm.
|
| All times are GMT +2. The time now is 06:48 AM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.