Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   PlayerWorlds Main Forum (https://forums.graalonline.com/forums/forumdisplay.php?f=15)
-   -   Server Owners Read (https://forums.graalonline.com/forums/showthread.php?t=45900)

protagonist 07-02-2003 11:48 PM

Server Owners Read
 
Hello.


You may notice the nickname m1nt popping up on your playerlist. If you didn't know, he is part of "Team Intelligence", the guys who make trainers. I recommend that you do not ban the account, as I have verified that the account he used on UN is not his in any way, shape or form. Disconnecting him until he does not come back online is the most efficient way to get rid of him, IP banning probably will not work because I daresay he does not have a concrete IP address. I would assume he stole the accounts from people who downloaded his trainer somehow, so anyone who has recently had a trainer running (e.g they were given Graalshop.exe and it was a trainer) should delete the file, scan their computer and check their win.ini to make sure the file didn't extract a second hidden file.

Neonight 07-02-2003 11:51 PM

Re: Server Owners Read
 
Quote:

Originally posted by protagonist
Hello.


You may notice the nickname m1nt popping up on your playerlist. If you didn't know, he is part of "Team Intelligence", the guys who make trainers. I recommend that you do not ban the account, as I have verified that the account he used on UN is not his in any way, shape or form. Disconnecting him until he does not come back online is the most efficient way to get rid of him, IP banning probably will not work because I daresay he does not have a concrete IP address. I would assume he stole the accounts from people who downloaded his trainer somehow, so anyone who has recently had a trainer running (e.g they were given Graalshop.exe and it was a trainer) should delete the file, scan their computer and check their win.ini to make sure the file didn't extract a second hidden file.

I have no idea why people would randomly message a trainer-maker and ask them for Graalshop. The idea in itself seems rather *****ic.

Dude6252000 07-02-2003 11:52 PM

M1nt's pesky. o_o You think we would have gotten rid of him and all the other anti-graal people a long time ago. M1nt and friends seem to devote most of their life to being anti-graal, and still are coming back to pester us every so often. Hopefully we can stop him soon, so we don't have another RC hacking incident.

protagonist 07-02-2003 11:56 PM

Re: Re: Server Owners Read
 
Quote:

Originally posted by Neonight


I have no idea why people would randomly message a trainer-maker and ask them for Graalshop. The idea in itself seems rather *****ic.


Dude, it isn't always done that way. Alot of the password crackers of the modern age use brute force (e.g aaaaaa,aaaaab,aaaaac and so on) to grab passwords. If they have enough patience and the right way to save progress, it can only take a matter of hours to crack a password (they have to restart or the crack will burn out their processor). I've never used one myself, but I would assume that is how one would operate.

Neonight 07-02-2003 11:59 PM

Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by protagonist



Dude, it isn't always done that way. Alot of the password crackers of the modern age use brute force (e.g aaaaaa,aaaaab,aaaaac and so on) to grab passwords. If they have enough patience and the right way to save progress, it can only take a matter of hours to crack a password (they have to restart or the crack will burn out their processor). I've never used one myself, but I would assume that is how one would operate.

Brute Force hacks FTP and such. It doesn't hack Graal passwords. Not to my knowledge, anyway. ;\ And Brute Force won't burn out the processor. Where did you get that idea?

Soul-Blade 07-02-2003 11:59 PM

Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by protagonist



Dude, it isn't always done that way. Alot of the password crackers of the modern age use brute force (e.g aaaaaa,aaaaab,aaaaac and so on) to grab passwords. If they have enough patience and the right way to save progress, it can only take a matter of hours to crack a password (they have to restart or the crack will burn out their processor). I've never used one myself, but I would assume that is how one would operate.

A matter of days, or weeks actually with brute force ;)

davidpsy 07-03-2003 12:00 AM

Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by protagonist



Dude, it isn't always done that way. Alot of the password crackers of the modern age use brute force (e.g aaaaaa,aaaaab,aaaaac and so on) to grab passwords. If they have enough patience and the right way to save progress, it can only take a matter of hours to crack a password (they have to restart or the crack will burn out their processor). I've never used one myself, but I would assume that is how one would operate.

So they are just gonna keep trying untill they get my password?!?

Soul-Blade 07-03-2003 12:04 AM

Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by davidpsy


So they are just gonna keep trying untill they get my password?!?


For the graal passwords it would take days, if not weeks to grab just one. Millions of combinations are possible, possibly even billions. It would take eternity to get a single password, trust me...even with a T3 line.

Neonight 07-03-2003 12:09 AM

Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Soul-Blade



For the graal passwords it would take days, if not weeks to grab just one. Millions of combinations are possible, possibly even billions. It would take eternity to get a single password, trust me...even with a T3 line.

The internet connection doesn't really matter. Each try takes less than 1 KB of information. Someone with a modem could get a password just as easily as someone with broadband could.

Soul-Blade 07-03-2003 12:15 AM

Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Neonight


The internet connection doesn't really matter. Each try takes less than 1 KB of information. Someone with a modem could get a password just as easily as someone with broadband could.


Incorrect. The cpu can process that much data nearly instantaneously, but sent through a internet connection there is about a 1 second delay. With a T3 line, I would guess around a .01 second delay...then again, it could be even longer because you send the data, the you must wait until the Graal servers respond. Graal servers are sending data to many users at once almost constantly, so not much bandwidth to spare. So there is a huge delay - if there was no delay, it would probably be a matter of hours to get any password, maybe less. Because it is over the internet, it does not process billions of bytes of data a second, because it can only do 1 at a time...do you get what I am saying?

Neonight 07-03-2003 12:22 AM

Re: Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Soul-Blade



Incorrect. The cpu can process that much data nearly instantaneously, but sent through a internet connection there is about a 1 second delay. With a T3 line, I would guess around a .01 second delay...then again, it could be even longer because you send the data, the you must wait until the Graal servers respond. Graal servers are sending data to many users at once almost constantly, so not much bandwidth to spare. So there is a huge delay - if there was no delay, it would probably be a matter of hours to get any password, maybe less. Because it is over the internet, it does not process billions of bytes of data a second, because it can only do 1 at a time...do you get what I am saying?

That's pretty funny, because in about 1 second, Brute Force can try about 50 passwords. I lost my password for a website a while back and I had to use Brute Force to find it. >_>

And Brute Force directly connects. It doesn't open and close the connection with each try.

G_yoshi 07-03-2003 01:07 AM

Re: Re: Server Owners Read
 
Quote:

Originally posted by Neonight


I have no idea why people would randomly message a trainer-maker and ask them for Graalshop. The idea in itself seems rather *****ic.

Sub7. A very old trojan. Most Anti-Virus software spot it instantly. Of course, I have heard there are ways to make it undetected :x

The point is not to download trainers and those that do deserve what happens to them.

Soul-Blade 07-03-2003 01:17 AM

Re: Re: Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Neonight


That's pretty funny, because in about 1 second, Brute Force can try about 50 passwords. I lost my password for a website a while back and I had to use Brute Force to find it. >_>

And Brute Force directly connects. It doesn't open and close the connection with each try.

As far as I am aware, most secure sites do not allow that, and I am assuming Graal has a secure server xx

protagonist 07-03-2003 01:22 AM

It's also fully possible that more than one person is trying, which makes it take 1/x the time. It also *could* be trying on the graal site where you can log in to see your status.

G_yoshi 07-03-2003 01:50 AM

Re: Re: Re: Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Soul-Blade


As far as I am aware, most secure sites do not allow that, and I am assuming Graal has a secure server xx

Trust me on this. Do not underestimate the perserverance of the Anti-Graal cult. For thier own inane reasons they seek to destroy Graal. I believe they think they are freeing people or some such rubbish like that. I think they are delusional people that didn't get thier way. So they do what most people do: throw a tanturm and make it so no one gets it.

Malignant users suck :(

zell12 07-03-2003 01:54 AM

How do you go about brute forcing a Graal password? You can't. =/

Neonight 07-03-2003 01:54 AM

Re: Re: Re: Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Soul-Blade


As far as I am aware, most secure sites do not allow that, and I am assuming Graal has a secure server xx

Brute Force acts the same way as logging into your account does. If it's the wrong password, it simply does not let you in. It will keep trying until the correct password is found.


And G_Yoshi:

I am well-aware of what Sub7 is. If people would scan the files before they open them, their Anti-Virus program(s) would catch the file and quarantine it.

Neonight 07-03-2003 01:56 AM

Quote:

Originally posted by zell12
How do you go about brute forcing a Graal password? You can't. =/
You believe there isn't a file that lists all of the accounts and passwords on them? How else does the server know what to allow and what to block?

G_yoshi 07-03-2003 02:05 AM

Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Server Owners Read
 
Quote:

Originally posted by Neonight

And G_Yoshi:

I am well-aware of what Sub7 is. If people would scan the files before they open them, their Anti-Virus program(s) would catch the file and quarantine it.

Um, most Anti-Virus software scans incoming files to my knowledge. I'm not 100% positive, but I think you can setup Norton or McAffee to scan downloads.

Androk 07-03-2003 02:50 AM

And this is why kids you should have 13 letter password like my self =P Let me see them crack that!

I also would like Players to set IP Range for their accounts or something *goes to make another thread*

protagonist 07-03-2003 02:55 AM

I would like it so that you could put in like, different fonted passwords and such. Or maybe make ascci passwords like this:

aÇ3¿1â€*x

Dude6252000 07-03-2003 03:02 AM

Quote:

Originally posted by protagonist
I would like it so that you could put in like, different fonted passwords and such. Or maybe make ascci passwords like this:

aÇ3¿1â€*x

That would be hard to type. People would probably have a text file of their password that they'll use to copy and paste in their password at times. ;x

protagonist 07-03-2003 03:12 AM

Quote:

Originally posted by Dude6252000

That would be hard to type. People would probably have a text file of their password that they'll use to copy and paste in their password at times. ;x


That's what I do, I don't let Graal save my password. Because you never know.

But it would be an extra security option, not a necessity.

thesaiyan 07-03-2003 03:16 AM

Funny how all you people know about stealing passwords. :(

*cough* hackers *cough*

Lyndzey 07-03-2003 03:35 AM

Quote:

Originally posted by Dude6252000
M1nt's pesky. o_o You think we would have gotten rid of him and all the other anti-graal people a long time ago. M1nt and friends seem to devote most of their life to being anti-graal, and still are coming back to pester us every so often. Hopefully we can stop him soon, so we don't have another RC hacking incident.
M1nt's actually one of the not so bad anti-Graal people. I talk to some Graal hackers (M1nt included) and he doesn't even really care about Graal anymore.

I don't plan on banning those accounts because they aren't his. Since no one believes his whole Nemesis thing, I doubt he will continue to send out the links.

I think M1nt did this out of hate for Nemesis rather than hate for Graal.

Neonight 07-03-2003 03:44 AM

Quote:

Originally posted by thesaiyan
*cough* hackers *cough*
You say that like it's a bad thing.

I've done my fair share of hacking, but not Graal hacking. Just messing with friends' websites and such. And their computers. ^_^

Soul-Blade 07-03-2003 05:44 AM

Quote:

Originally posted by thesaiyan
Funny how all you people know about stealing passwords. :(

*cough* hackers *cough*

Umm, do you even know the real meaning of the term "hacker"? A hacker is a brilliant programmer who challenges himself in order to improve his skills by trying to break into the most secure systems...A person out to harm someones system is better defined as a Cracker, and a person who simply uses programs (such as brute force - unless it was programmed by you, then you are still a cracker) is a mere script kiddie-cracker ;)

Deek2 07-03-2003 06:42 AM

Quote:

Originally posted by Soul-Blade


Umm, do you even know the real meaning of the term "hacker"? A hacker is a brilliant programmer who challenges himself in order to improve his skills by trying to break into the most secure systems...A person out to harm someones system is better defined as a Cracker, and a person who simply uses programs (such as brute force - unless it was programmed by you, then you are still a cracker) is a mere script kiddie-cracker ;)

Rabble! :)

G_yoshi 07-03-2003 07:08 AM

Quote:

Originally posted by protagonist



That's what I do, I don't let Graal save my password. Because you never know.

But it would be an extra security option, not a necessity.

Graal still encrypts the passwords you have it save :p It holds them in the registry. That's really how they obtain the password is by decrypting the password stored in the resigtry.

It wouldn't be too bad of an idea, I think, if Stefan added some extra personal measures for accounts such as requiring not only the password but particular things. Kind of like how sites like Paypal have you give them something only you would know like mother's maiden name or whatever. Answer that question and you get your password. But in the case of Graal, the questions are asked before you log on and they cannot be saved in the registry. The questions should be rather obscure but hold a personal value so that it won't be forgotten. Perhaps a different question each time? Use this feature for nearly everything that involves the input of the account password so that if someone gets the password, its useless without knowledge of the vitcim's personal memories.

Loriel 07-03-2003 02:08 PM

Quote:

Originally posted by Androk
And this is why kids you should have 13 letter password like my self =P Let me see them crack that!
Sorry, but only the first 8 characters are checked. :P

Quote:

Originally posted by protagonist
Or maybe make ascci passwords like this:
aÇ3¿1�x

I seriously doubt that � is an ascii character. Opposed to (most) letters and numbers, which are.
What I would like are unicode passwords :)

Quote:

Originally posted by Soul-Blade
A hacker is a brilliant programmer who challenges himself in order to improve his skills by trying to break into the most secure systems..
Green = Hacker, Red = Cracker :)

Quote:

Originally posted by G_yoshi
Answer that question and you get your password.
I would not want to set one up as that seems far less secure than a password: You need to give a real word as an answer, opposed to a mostly random string of characters, and it is real information someone who knows you could find out.

Zurkiba 07-03-2003 05:14 PM

Ban the accounts. If they're not m1nts then they downloaded trainers anyway.

protagonist 07-03-2003 05:17 PM

Not necessarily, it could have been entirely innocent. For example, the Graalshop trick people are doing.


All times are GMT +2. The time now is 08:35 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.