![]() |
Security increase for Administration of Playerworlds
Here is the way I see it, I said it before last year:
The accounts with level 4 rights (Manager Accounts) have an option added to them so that if they try to change the server options, folder configuration, rights of other accounts(default rights, manager can add more), etc... This should add better security incase someone with a ip mask gets ahold of your account. :) When you click the server options buttion, as an example, you can edit whatever you like. When you click apply/ok, it asks you for your password. If you enter an invaild password, it ask syou again. 3 bad passwords will result in your account being disabled, and mabey even an email sent to the pwa or one of the other managers. ;) |
That would be extremely annoying.
|
It's a nice idea in theory but not really practical..
|
It is practical with some amendments. And it would be a bugger, yes, but would you rather lose everything because someone found your account information? A 64/128-bit encryption password should be enough to protect someone on a game like "graal" ;)
|
Quote:
|
The ips, even hostnames (changed to an ip) can be spoofed, or masked, by programs. So you are only safe really, if they don't have your password.
|
Unless the password it asks for when changing the stuff is different from the account password, it's not really going to do any good. If somebody got hold of your account and got on RC with it, theres a 90% chance they'll know your account password.
|
I know that, I was just hoping you guys would too. :rolleyes:
|
Quote:
|
If somebody was really going to go to the trouble to spoof their IP address, i think getting your account password would be pretty easy. IP ranges are very VERY good protection against people who have gotten your password, but if they can bypass it then it's not like it's a top secret project you're working on.
Make regular back-ups as always and set your IP range as strictly as possible and you'll be fine. |
Well, ip ranges are not as secure as you think. It is like buying a lock from the dollar store, putting it on a PollyPocket chest, and stuffing a $1000 in it and leaving it on the side of a street.
|
Quote:
Unless you had access to the computer the actual IP address is assigned to, you can't do it with TCP. |
Jagen, people send you a trojan, they get your pass. Someone spoofs your ip, they have your account.
|
Quote:
|
I'll explain this later, because Fl1p did it on Mithica. :/
|
'Fl1p' more likely used a proxy or something like that. Jagen is right, you cannot use spoofed IPs to an advantage.
|
You can change your ip to anything you want. How hard is that to understand?
|
Quote:
Quote:
|
Quote:
Quote:
|
Quote:
To put it simply mr Zell, think of the TCP connection as a physical pipe running from one tank to another. If you sent a request with a spoofed ip saying HEY GIVE ME A PIPE, its going to think said address requested it, and try to make the connection with that address, instead of you. Even if it was a successful connection, you would be outside that pipe. unless you actually owned an ip with the needed range or proxied it (ie found some server with that range willing to route your packets), it IS impossible. And in my opinion, anyone who pays for a server and puts it at such a stupid risk by letting a lvl 4 rc be owned without the password/ip being really protected is a fool, and it would be a tough lesson that they need. Its not graalonlines responisbly to make up for your lack of responsibility. |
| All times are GMT +2. The time now is 12:59 PM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.