Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Future Improvements (https://forums.graalonline.com/forums/forumdisplay.php?f=10)
-   -   new PW type (https://forums.graalonline.com/forums/showthread.php?t=22162)

LiquidIce00 01-27-2002 12:17 AM

new PW type
 
If you have not noticed everyone who steals passwords from other people is simply thru the register. They go and take the register then paste on theirs and done.

If there is a new way to save these passwords so people can not hack them would be way better.
Perhaps it could log the computer name w/ the password and if it doesnt not match it then it does not display.. or log a certain date and if the registry was created on a diff date then the one in the encryption it wont work.. well you get my point ;)

Oladahn 01-28-2002 04:07 PM

there has to be some better way. I've had accounts screwed up before, and it wasn't fun.

Kasuagi 01-29-2002 04:42 AM

hmm, how about IP restriction?

bah, everyone hacks the servers through registry. it's kind of hard to prevent though

Faheria_GP2 01-29-2002 05:33 AM

IP restriction wouldn't work too well, my old ISP did weird **** because you could dial 1 of 4 numbers (chances are 3 weren't working) and on one day it would be 205.119.93.84 and the next it would be something like 207.105.73.70, so I had to give *.*.*.* as my IP range, luckily now I am on cable :D

Tyhm 01-29-2002 11:09 AM

Base it off the windows key, a secret registry value unique to every installation that international law prohibits internet transmission of (or we'd be able to crack down on sooo many hackers...). Each character is binary xor'd of the windows key when it's saved and binary xor'd again when it's loaded - unless you have the windows key, you'll never be able to crack it, not in a million years.

Works too. 4 xor 5 is 1, 1 xor 5 is 4...

Kaimetsu 01-29-2002 11:28 AM

Quote:

Originally posted by Tyhm
Base it off the windows key, a secret registry value unique to every installation that international law prohibits internet transmission of (or we'd be able to crack down on sooo many hackers...). Each character is binary xor'd of the windows key when it's saved and binary xor'd again when it's loaded - unless you have the windows key, you'll never be able to crack it, not in a million years.

Works too. 4 xor 5 is 1, 1 xor 5 is 4...

Kick me if I'm being stupid, but if they could access the password from the registry then what's to stop them accessing this windows key too?

Tyhm 01-29-2002 11:42 AM

Well yeah, they could. Except the windows registry is huge and they probably wouldn't even know what they're looking for, plus any algorythm applied to the windows key to encrypt the password would make it hard...I mean, say you use Xor. A hacker would have to know Graal uses Xor encryption, know it's applied to the windows key, know where to find the windows key, and then do a decryption on the stolen registry. If it doesn't in fact use Xor, they can go to all that trouble and wind up with nothing.

Falcor 01-29-2002 12:01 PM

just steal the encrypted password and decode it in other types then :confused:

Kaimetsu 01-29-2002 12:03 PM

Quote:

Originally posted by Falcor
just steal the encrypted password and decode it in other types then :confused:
Well, that's not necessarily very easy.

konidias 01-30-2002 04:50 AM

At the moment it's very easy to steal someones pass.. just make a program that grabs the registry info from Graal and have that info sent to an email address.. then you can just put that info into your own registry using regedit.

Then if you get one of those encrypted pass decoders they can uncover the "******" in the Graal password box, so you can get the real pass instead of the encoded one.

There need's to be a different form of password security though, I agree.

LiquidIce00 01-31-2002 12:26 AM

If its possible to check on the date which a registry key was created, then like have the key log the date in which each thing was made, and if that date is different then the date in which it was created, it would not work and delete itself.

For example,
my password is boohoo1.
I go and I type in boohoo1 and my acct name, it will encode boohoo1 and write to the registry along with the date
so for example it could have like
boohoo1-1/30/02 and encode that.
If a person steals and put that in the registry, if you can check which date the registry key was created, then for example if tomorrow they stole my key, it would mess up because the date would be different.

But , if a person kept changing dates till they found out the right one, then it be different. I think there can be some way. Windows key would be nice. Or perhaps by computer name or something.
Or maybe Graal can assign a different key to itself every time its installed into a new machine ( i dunno )


All times are GMT +2. The time now is 12:52 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.