Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   PlayerWorlds Main Forum (https://forums.graalonline.com/forums/forumdisplay.php?f=15)
-   -   Playerworld Security Report (Summer '04) *Please Read* (https://forums.graalonline.com/forums/showthread.php?t=54047)

Spark910 07-26-2004 07:48 PM

Playerworld Security Report (Summer '04) *Please Read*
 
Well here are some interesting statistics about how secure… or should I say insecure Graal is, due to people not setting IP ranges.

Every time in the past from a server attack I think ‘how the hell’, because I was under the impression people wanted their servers secure, and not deleted. But when you log onto a server and find around 25 level4RCs, and 14 of which with an IP range of: *.*.*.* - you no longer begin to question how, but instead wonder why.

So over the past few weeks I have been server hoping removing any RC with an IP range of *.*.*.* and adding notes about other IPs that could be more secure.

I found a lot of servers had people in the staff= without any rights, which is not a good thing. If they are not staff, then they should not be in the staff = serveroption.

The Stats:
How many servers actually had all IPs set?
28/124 (22% of the online playerworlds were secure)


How many RCs actually had an IP range of *.*.*.*?
339 RCs were found in the staff= server option with an IP range of *.*.*.*

What level RCs were in the staff= server option with an IP of *.*.*.*?
Level4 RCs: 95/339 (28%)
Level3 RCs: 58/339 (17%)
Level2 RCs: 37/339 (11%)
Level1 RCs: 82/339 (24%)
Level0 RCs: 67/339 (20%)


Which playerworlds were 100% secure?
Classic Tab Playerworlds: 3/10 (30%)*
Hosted Tab Playerworlds: 2/6 (30%)*
Hidden Hosted Playerworlds: 23/108 (21%)
*Most Classic/Hosted tab playerworlds had one RC that had *.*.*.*, most of which were level 1/0.

Conclusion:
Graalonline playerworlds are very insecure. I am happy to see however that Classic/Hosted playerworlds are taking it serious with most of them with only 1 or two level1/0 RCs unprotected.

However this needs to change. Not setting an IP range is a security risk. Doing so is also against the playerworld rules. Any playerworld found with staff with an IP range of *.*.*.* that has been picked out this time, and is found next time, will be suspended for a period of time and removed from public if it is a Classic/Hosted playerworld.

What do we need to do now?
Well, as you will have seen if your playerworld was a problem I left a message in your serveroptions saying that you should not add the RCs back until an IP range is set. If you do this then you will be fine, but people need to keep checking these things.

--If you are a manager:
*Check IP ranges every month, to make sure they are all set.
*Never add anyone to the staff= serveroption without an IP range, make them give you them first, this was the common way of playerworlds getting attacked recently.
*Don’t add ‘temp’ or ‘guest’ RCs and if this is needed they shouldn’t be left in the staff= serveroptions, or with rights on their account.
*Do not give high rights to new staff, get to know you can trust them first.

--If you are a staff member with RC:
*Check your IP range on all your RCs, and make sure they are set.
*Frequently check if your IP range can be more secure that it currently is.

A few rule reminders/points:
So that’s all basically, but I would like to remind you of rules which are being broken on almost all playerworlds.

Quote:

Originally Posted by IPs
ALL RCs need an IP range or lock. This should be no less than two numbers. It should contain 2 numbers in the IP range. e.g:
#.#.*.* =2 numbers

Everyone should get a #.#.*.* IP range, even the AOL users, it may just need updating a lot at first.

Quote:

Originally Posted by RC Levels
No playerworld should have more than 3 level4 RCs. If you want to use a 3rd then you must keep the level 4 RC on the admin-playerworld## account. Those playerworlds that were not setup by means of payment can give this RC to another account

No playerworld should have more than three other high levelled RCs (level3), as rights are not needed and people can ask for things instead of performing actions their selves.

This is important, as people override each others decisions, and if they get annoyed they may delete the server, just because they can.

Quote:

Originally Posted by Admin-Playerworld Accounts
If you are not using this log onto it and disable it by saying:
/openacc Admin-Playerworld### and checking [ ] Banned
Then click apply.

Note also: Admin-Playerworld accounts with NO rights, when they connect, automatically get a level4 RC. So to stop this set some rights, such as ‘View Attributes’, then it will not get level4 when it connects.

Don’t Forget: I can update IP ranges and things, so there is no need for a ‘back-door RC’ just incase.

Thankyou for reading, that’s about it. While I would like everyone with IPs set, I realize that is an impossible request, however everyone should set IPs now, and check them all.

Next IP Range check Targets:
*80 % + of playerworlds secure
*ALL Classic and Hosted Playerworlds with ALL staff= RCs secured.

Thank you.

--Playerworld Administration Team

matt8891 07-26-2004 07:52 PM

I agree....However im still not understanding how to set someones IP when it changes everytime they log on....Meaning they have dial-up obviously.

Spark910 07-26-2004 07:53 PM

Quote:

Originally Posted by matt8891
I agree....However im still not understanding how to set someones IP when it changes everytime they log on.

I have seen some RCs with 20-30 IPs set, the 172.#.*.* people, and apparently they havent needed to update it in about 2-3weeks, so it's nearly done.

Malinko 07-26-2004 07:55 PM

Spark getting pretty with graphics now.

Slash-P2P 07-26-2004 07:55 PM

I secured Bravo.

xManiamaNx 07-26-2004 07:58 PM

Level4 RCs: 95/339 (28%)

Thats pathetic. What kind of idiots are running servers these days?

matt8891 07-26-2004 07:58 PM

I only have 2 Level4 RC's on my server.....Myself and my Manager.
I think that ALL people with RC's should have their IP set.....If not their RC would automatically disconnect because of their insecure IP range. Maybe someone could script that into RC file download.....And if this is impossible i think the RC's with an insecure IP range should have their RC removed...But i think thats already being done.

Spark910 07-26-2004 07:59 PM

Quote:

Originally Posted by Slash-P2P
I secured Bravo.

Bravo was already secure, I guess people wont mind me saying the secure playerworlds:

#gscript
Angels Server
Arena
Atlantis
Bravo Evolved
Bravo Evolved Dev
Condor Plains
Dark Nations
Endless Saga
Era
Era Development
Graal2001
Graal X
Graal3000
Hartland
Kantarian Empires
Nefarious
Nolavario
Oracle
Phantaria
RP Kingdoms
Sango
Sympothy
Tenebris
The Last Battle
Uerb
Unholy Nation
Zone

Note: Some were offline at the time, so weren't included.
And I don't know if it's possible but I would like to reward those who could follow the rules, but I don't know how yet.

Quote:

Originally Posted by matt8891
And if this is impossible i think the RC's with an insecure IP range should have their RC removed...But i think thats already being done.

Well I am asking Stefan for a *.*.*.* no-go pysical stop, which would be good I think. And yes, I have removed all *.*.*.* from staff= and it says not to add them until an IP is set, so basically thats a warning and next time comes the punishements.

matt8891 07-26-2004 08:05 PM

From my experience with working on playerworlds....Most administrators/managers dont know how to set an IP that changes after every login...So they leave it to default x.x (*.*.*.*)

LordMatt 07-26-2004 08:05 PM

you never logged onto Cynical to check it.

matt8891 07-26-2004 08:08 PM

Quote:

Originally Posted by LordMatt
you never logged onto Cynical to check it.


You dont know that...You might just have not been on at the time Mr. "Stefan,Unixmad and i went to go see Harry Potter"

LordMatt 07-26-2004 08:10 PM

Quote:

Originally Posted by matt8891
You dont know that...You might just have not been on at the time Mr. "Stefan,Unixmad and i went to go see Harry Potter"

I wasn't talking to you, and yes I do know. There are such things as logs. I was on at the time when he sent, "***global msg Spark910@graal2002: It is me on the account Spark_Admin, I am checking IP ranges. Thankyou." to the time he sent his last global message. I even double checked myself to make SURE I did not miss him. He never logged on today.

Spark910 07-26-2004 08:24 PM

Quote:

Originally Posted by LordMatt
I wasn't talking to you, and yes I do know. There are such things as logs. I was on at the time when he sent, "***global msg Spark910@graal2002: It is me on the account Spark_Admin, I am checking IP ranges. Thankyou." to the time he sent his last global message. I even double checked myself to make SURE I did not miss him. He never logged on today.

I've been doing it over the last few weeks, I only need playerworlds with names beginning with the letters H-N today, I had already done the rest. But I did do it, it's on the list.

TESTRETIS 07-26-2004 08:30 PM

The IP Range cap needs to be extended..it only allows like 5 numbers..can it be changed so more numbers can be added?

LordMatt 07-26-2004 08:31 PM

Quote:

Originally Posted by Spark910
I've been doing it over the last few weeks, I only need playerworlds with names beginning with the letters H-N today, I had already done the rest. But I did do it, it's on the list.

Ok, thank you for clearing that up.

jake13jake 07-26-2004 08:52 PM

How many times have I lectured Master Storm on issues of security, and he doesn't pass...

When PsychoRaymond set my hearts to 0 I couldn't prove it because PsychoRaymond had rw access to the logs/* (which you will probably find problems with too, spark, if you plan on looking after the IP range issues). No, rclog.txt does not record itself being uploaded. If it did you might have less problems with security, although not much. Write access to the logs folder should only be given to the manager and the owner. There is no reason for anybody to change logs.

Another thing... backup folders. Only the people creating the backups need to have write access to any backup folders. If you needed to get a script from a backup folder or you needed to see if somebody abused their rights in rclog.txt you can give them rights to read-only. Such sadness came to me when Lone told me he deleted the backup folder on Classic Dev that contained the 2 1/2 years of work and the over 1000 files I had converted in my contribution....

The IP issue is more easily fixed than the folder rights issue. If you put "rw */*" you're giving them access to everything. if you put "rw levels/*" you're leaving out classes, weapons, all the other folders etc.
NPC Code:

rw CLASSES/*
rw NPCS/*
rw WEAPONS/*


That would give you access to all the classes, weapons, and NPCs (on the NPC list, where Control-NPC is). The rest of the directories would be listed simply in the RCs file browser, and if you don't want it to be a huge hassle, keep your folder configs simple. When will people ever learn?

Spark910 07-26-2004 08:59 PM

Quote:

Originally Posted by TESTRETIS
The IP Range cap needs to be extended..it only allows like 5 numbers..can it be changed so more numbers can be added?

hmm.. some people had very long IP ranges that I saw x_x

konidias 07-26-2004 09:23 PM

Ehh... I honestly don't see how you feel having an ip range should be mandatory. These people paid to rent these servers. If they don't want to set an ip range for someone, they shouldn't have to. You should be warning them that they are at risk if they don't. Not removing their staff and telling them they have to.

If your IP changes frequently it's extremely annoying not being able to log on RC. I think it's a hassle. I'm already protecting my computer with firewalls and trojan detectors, and common sense. I don't feel like going through the trouble of having to ask PWA to change my IP range and not getting a response for weeks.

It's not convenient. That is why people don't set them. It's not like they are out to get you and are purposely breaking your rule to make you mad. Again, I say let people take the risk. You can't protect all playerworlds. A playerworld could have all their RC ip ranges set, and then one of their higher staff accepts some level with hidden destructive scripts in it, and then what? Your security was for nothing.

URBANLEGEND 07-26-2004 09:50 PM

Quote:

Originally Posted by Spark910
Nefarious

Yay me for making a PW safe.

Crono 07-26-2004 09:58 PM

1) I want to laugh at Valikorlia for not being on the secure list.

2) Most of these insecure servers are those "UC" servers that will never make it and are run by idiots "wo tlk liek dis ppl??"

3) Hey Koni posted! :D :D :D

brock128 07-26-2004 10:12 PM

Sup koni. <3<3

I think that if people want to be stupid, let them. Just make it a requirement that if you want to be un-hidden you need to remove your *.*.*.* IPs.

VeX_RaT_Boy 07-26-2004 10:44 PM

Quote:

Originally Posted by Spark910
Bravo was already secure, I guess people wont mind me saying the secure playerworlds:

#gscript
Angels Server
...
Nefarious
Nolavario
Oracle
...
Zone

Note: Some were offline at the time, so weren't included.
And I don't know if it's possible but I would like to reward those who could follow the rules, but I don't know how yet.



Well I am asking Stefan for a *.*.*.* no-go pysical stop, which would be good I think. And yes, I have removed all *.*.*.* from staff= and it says not to add them until an IP is set, so basically thats a warning and next time comes the punishements.

<3 :cool:

I think that playerworlds without IP ranges gives a LOT of extra work to the globals, and that is why there is such a rule.

brock128 07-26-2004 10:59 PM

Quote:

Originally Posted by VeX_RaT_Boy
<3 :cool:

I think that playerworlds without IP ranges gives a LOT of extra work to the globals, and that is why there is such a rule.

That is why I am now proposing the anti-***** rule.

If they lose their playerworld because of this, say "tough." (Not exactly, but to that extent.)

EDIT: Assuming the playerworld is still usable. If it's hacked beyond repair or something, reboot it. Or whatever.

jake13jake 07-26-2004 11:37 PM

Quote:

Originally Posted by konidias
Ehh... I honestly don't see how you feel having an ip range should be mandatory. These people paid to rent these servers. If they don't want to set an ip range for someone, they shouldn't have to. You should be warning them that they are at risk if they don't. Not removing their staff and telling them they have to.

If your IP changes frequently it's extremely annoying not being able to log on RC. I think it's a hassle. I'm already protecting my computer with firewalls and trojan detectors, and common sense. I don't feel like going through the trouble of having to ask PWA to change my IP range and not getting a response for weeks.

It's not convenient. That is why people don't set them. It's not like they are out to get you and are purposely breaking your rule to make you mad. Again, I say let people take the risk. You can't protect all playerworlds. A playerworld could have all their RC ip ranges set, and then one of their higher staff accepts some level with hidden destructive scripts in it, and then what? Your security was for nothing.

Insecurity on one server may result as a generalization of Graal being insecure as a whole, especially by those who don't understand how Graal works. Only secure servers should be shown on the tabs in my opinion.

MysticalDragonP2P 07-26-2004 11:38 PM

Quote:

Originally Posted by jake13jake
How many times have I lectured Master Storm on issues of security, and he doesn't pass...

When PsychoRaymond set my hearts to 0 I couldn't prove it because PsychoRaymond had rw access to the logs/* (which you will probably find problems with too, spark, if you plan on looking after the IP range issues). No, rclog.txt does not record itself being uploaded. If it did you might have less problems with security, although not much. Write access to the logs folder should only be given to the manager and the owner. There is no reason for anybody to change logs.



Thats not true,i tested your theory severeal times and everytime i deleted the logs it would create a new log with who deleted it in the previous logs.I also tested if you would of overwritten the rc log file with another file,it also showed the logs beeing overwritten.So maybe your problem was just ignored?

jake13jake 07-27-2004 12:18 AM

Quote:

Originally Posted by MysticalDragonP2P
Thats not true,i tested your theory severeal times and everytime i deleted the logs it would create a new log with who deleted it in the previous logs.I also tested if you would of overwritten the rc log file with another file,it also showed the logs beeing overwritten.So maybe your problem was just ignored?

I tested it and it didn't record the file being overwritten. Maybe you looked at the accountname loaded from logs/ instead?

What happened when I tested it:
jake13jake loaded file(s) from staffdocs/
jake13jake (removed a line for testing)Time: Fri Jul 23 21:20:10 2004
jake13jake loaded file(s) from logs/
Time: Fri Jul 23 21:24:35 2004
jake13jake changed the rights of jake13jake
removed file right: rw */*

The line removed was from loading the rclog.txt.

Darlene159 07-27-2004 12:22 AM

Some of you arent understanding that not being secure allows hackers to get on RC, and do things like overload the hard drive so all the pw's are screwed....not being secure affects Graal alot of times, not just that one PW

Spark910 07-27-2004 01:02 AM

Quote:

Originally Posted by konidias
POST[/COLOR]

It lowers the problems that happen on playerworlds, an extra level of security.
When /allservers spammed servers offline, it was a result of no IP ranges.
When playerworlds get *** pornography uploaded to them, it's a result of no IP ranges.
When playerworlds get deleted, it's commonly due to a result of no IP ranges.
When a playerworld script is made to loop in a log to create big logs, it's a results of no IP ranges.

Sure, anyone WITH an IP range set can do this, but then it's the playerworld managers fault for giving so many rights, or it's unavoidable. But with an IP range we can not only ban the user, but look at the IP which was used and if it was static we can block future accounts made by that person in random searches, of if it's not static then we can look at the IP realted to other accounts in a small time-frame.

The purpose of IP ranges is an extra level of security, and to make sure that the account owner is the only person who is on the account on RCs.

And I belive Stefan will possibly be making it so *.*.*.* aren't allowed, period. Which I support and am trying to get him to do.

jake13jake 07-27-2004 01:17 AM

Quote:

Originally Posted by Spark910
And I belive Stefan will possibly be making it so *.*.*.* aren't allowed, period. Which I support and am trying to get him to do.

yay... and here are some extra letters for the 10 character rule :D!!!

Scott 07-27-2004 02:05 AM

Quote:

Originally Posted by Spark910

Sympothy

... :frown:

brock128 07-27-2004 02:11 AM

Quote:

Originally Posted by Darlene159
Some of you arent understanding that not being secure allows hackers to get on RC, and do things like overload the hard drive so all the pw's are screwed....not being secure affects Graal alot of times, not just that one PW

If such a problem exists then maybe graal IS insecure as a whole for not physically blocking *.*.*.* IPs.

LittleBiiru 07-27-2004 03:39 AM

Thats extremely embarassing.

Spark910 07-27-2004 11:55 AM

Quote:

Originally Posted by brock128
If such a problem exists then maybe graal IS insecure as a whole for not physically blocking *.*.*.* IPs.

I agree, it does make sense to block it. The warning message isn't working as well as it should.

GoZelda 07-27-2004 12:37 PM

Mh. For a short while, I worked on one of Scott's UC playerworlds, vanguard, with *osrs. Anyway, my IP changed a lot too. I'm not sure, but could it be that multiple IP's can be set to one account? This would solve some of those IP-changing business.

Darlene159 07-27-2004 02:43 PM

Quote:

Originally Posted by GoZelda
Mh. For a short while, I worked on one of Scott's UC playerworlds, vanguard, with *osrs. Anyway, my IP changed a lot too. I'm not sure, but could it be that multiple IP's can be set to one account? This would solve some of those IP-changing business.

yes, more than one IP can be set

matt8891 07-27-2004 07:00 PM

Quote:

Originally Posted by Darlene159
yes, more than one IP can be set

How??

By doing (ex. 12.13.33.12,23,11,21,65,45)??Just separate with comma's?

haunter 07-27-2004 07:38 PM

Quote:

Originally Posted by matt8891
How??

By doing (ex. 12.13.33.12,23,11,21,65,45)??Just separate with comma's?

Yeah, except 23 isn't an IP range, neither is 65, or 21 for that matter... IP numbers have four sets of numbers seperated by periods.

Crono 07-27-2004 08:43 PM

Quote:

Originally Posted by Darlene159
Some of you arent understanding that not being secure allows hackers to get on RC, and do things like overload the hard drive so all the pw's are screwed....not being secure affects Graal alot of times, not just that one PW

Dude, they're not HACKERS. They're people who create keylogs then send it to other people :/

Either that or you just have some kind of virus. Its easy for virus makers to get info from your registry you know? :o

Darlene159 07-28-2004 12:07 AM

Quote:

Originally Posted by matt8891
How??

By doing (ex. 12.13.33.12,23,11,21,65,45)??Just separate with comma's?

Example: 12.12.12.12,9.9.9.9
and so on...

Quote:

Dude, they're not HACKERS. They're people who create keylogs then send it to other people :/
Point noted, but the end results are still the same

jake13jake 07-28-2004 12:18 AM

Quote:

Originally Posted by Darlene159
Some of you arent understanding that not being secure allows hackers to get on RC, and do things like overload the hard drive so all the pw's are screwed....not being secure affects Graal alot of times, not just that one PW

good point!


All times are GMT +2. The time now is 12:42 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.