![]() |
Playerworld Security Report (Summer '04) *Please Read*
Well here are some interesting statistics about how secure… or should I say insecure Graal is, due to people not setting IP ranges.
Every time in the past from a server attack I think ‘how the hell’, because I was under the impression people wanted their servers secure, and not deleted. But when you log onto a server and find around 25 level4RCs, and 14 of which with an IP range of: *.*.*.* - you no longer begin to question how, but instead wonder why. So over the past few weeks I have been server hoping removing any RC with an IP range of *.*.*.* and adding notes about other IPs that could be more secure. I found a lot of servers had people in the staff= without any rights, which is not a good thing. If they are not staff, then they should not be in the staff = serveroption. The Stats: How many servers actually had all IPs set? 28/124 (22% of the online playerworlds were secure) How many RCs actually had an IP range of *.*.*.*? 339 RCs were found in the staff= server option with an IP range of *.*.*.* What level RCs were in the staff= server option with an IP of *.*.*.*? Level4 RCs: 95/339 (28%) Level3 RCs: 58/339 (17%) Level2 RCs: 37/339 (11%) Level1 RCs: 82/339 (24%) Level0 RCs: 67/339 (20%) Which playerworlds were 100% secure? Classic Tab Playerworlds: 3/10 (30%)* Hosted Tab Playerworlds: 2/6 (30%)* Hidden Hosted Playerworlds: 23/108 (21%) *Most Classic/Hosted tab playerworlds had one RC that had *.*.*.*, most of which were level 1/0. Conclusion: Graalonline playerworlds are very insecure. I am happy to see however that Classic/Hosted playerworlds are taking it serious with most of them with only 1 or two level1/0 RCs unprotected. However this needs to change. Not setting an IP range is a security risk. Doing so is also against the playerworld rules. Any playerworld found with staff with an IP range of *.*.*.* that has been picked out this time, and is found next time, will be suspended for a period of time and removed from public if it is a Classic/Hosted playerworld. What do we need to do now? Well, as you will have seen if your playerworld was a problem I left a message in your serveroptions saying that you should not add the RCs back until an IP range is set. If you do this then you will be fine, but people need to keep checking these things. --If you are a manager: *Check IP ranges every month, to make sure they are all set. *Never add anyone to the staff= serveroption without an IP range, make them give you them first, this was the common way of playerworlds getting attacked recently. *Don’t add ‘temp’ or ‘guest’ RCs and if this is needed they shouldn’t be left in the staff= serveroptions, or with rights on their account. *Do not give high rights to new staff, get to know you can trust them first. --If you are a staff member with RC: *Check your IP range on all your RCs, and make sure they are set. *Frequently check if your IP range can be more secure that it currently is. A few rule reminders/points: So that’s all basically, but I would like to remind you of rules which are being broken on almost all playerworlds. Quote:
Quote:
Quote:
Don’t Forget: I can update IP ranges and things, so there is no need for a ‘back-door RC’ just incase. Thankyou for reading, that’s about it. While I would like everyone with IPs set, I realize that is an impossible request, however everyone should set IPs now, and check them all. Next IP Range check Targets: *80 % + of playerworlds secure *ALL Classic and Hosted Playerworlds with ALL staff= RCs secured. Thank you. --Playerworld Administration Team |
I agree....However im still not understanding how to set someones IP when it changes everytime they log on....Meaning they have dial-up obviously.
|
Quote:
|
Spark getting pretty with graphics now.
|
I secured Bravo.
|
Level4 RCs: 95/339 (28%)
Thats pathetic. What kind of idiots are running servers these days? |
I only have 2 Level4 RC's on my server.....Myself and my Manager.
I think that ALL people with RC's should have their IP set.....If not their RC would automatically disconnect because of their insecure IP range. Maybe someone could script that into RC file download.....And if this is impossible i think the RC's with an insecure IP range should have their RC removed...But i think thats already being done. |
Quote:
#gscript Angels Server Arena Atlantis Bravo Evolved Bravo Evolved Dev Condor Plains Dark Nations Endless Saga Era Era Development Graal2001 Graal X Graal3000 Hartland Kantarian Empires Nefarious Nolavario Oracle Phantaria RP Kingdoms Sango Sympothy Tenebris The Last Battle Uerb Unholy Nation Zone Note: Some were offline at the time, so weren't included. And I don't know if it's possible but I would like to reward those who could follow the rules, but I don't know how yet. Quote:
|
From my experience with working on playerworlds....Most administrators/managers dont know how to set an IP that changes after every login...So they leave it to default x.x (*.*.*.*)
|
you never logged onto Cynical to check it.
|
Quote:
You dont know that...You might just have not been on at the time Mr. "Stefan,Unixmad and i went to go see Harry Potter" |
Quote:
|
Quote:
|
The IP Range cap needs to be extended..it only allows like 5 numbers..can it be changed so more numbers can be added?
|
Quote:
|
How many times have I lectured Master Storm on issues of security, and he doesn't pass...
When PsychoRaymond set my hearts to 0 I couldn't prove it because PsychoRaymond had rw access to the logs/* (which you will probably find problems with too, spark, if you plan on looking after the IP range issues). No, rclog.txt does not record itself being uploaded. If it did you might have less problems with security, although not much. Write access to the logs folder should only be given to the manager and the owner. There is no reason for anybody to change logs. Another thing... backup folders. Only the people creating the backups need to have write access to any backup folders. If you needed to get a script from a backup folder or you needed to see if somebody abused their rights in rclog.txt you can give them rights to read-only. Such sadness came to me when Lone told me he deleted the backup folder on Classic Dev that contained the 2 1/2 years of work and the over 1000 files I had converted in my contribution.... The IP issue is more easily fixed than the folder rights issue. If you put "rw */*" you're giving them access to everything. if you put "rw levels/*" you're leaving out classes, weapons, all the other folders etc. NPC Code: That would give you access to all the classes, weapons, and NPCs (on the NPC list, where Control-NPC is). The rest of the directories would be listed simply in the RCs file browser, and if you don't want it to be a huge hassle, keep your folder configs simple. When will people ever learn? |
Quote:
|
Ehh... I honestly don't see how you feel having an ip range should be mandatory. These people paid to rent these servers. If they don't want to set an ip range for someone, they shouldn't have to. You should be warning them that they are at risk if they don't. Not removing their staff and telling them they have to.
If your IP changes frequently it's extremely annoying not being able to log on RC. I think it's a hassle. I'm already protecting my computer with firewalls and trojan detectors, and common sense. I don't feel like going through the trouble of having to ask PWA to change my IP range and not getting a response for weeks. It's not convenient. That is why people don't set them. It's not like they are out to get you and are purposely breaking your rule to make you mad. Again, I say let people take the risk. You can't protect all playerworlds. A playerworld could have all their RC ip ranges set, and then one of their higher staff accepts some level with hidden destructive scripts in it, and then what? Your security was for nothing. |
Quote:
|
1) I want to laugh at Valikorlia for not being on the secure list.
2) Most of these insecure servers are those "UC" servers that will never make it and are run by idiots "wo tlk liek dis ppl??" 3) Hey Koni posted! :D :D :D |
Sup koni. <3<3
I think that if people want to be stupid, let them. Just make it a requirement that if you want to be un-hidden you need to remove your *.*.*.* IPs. |
Quote:
I think that playerworlds without IP ranges gives a LOT of extra work to the globals, and that is why there is such a rule. |
Quote:
If they lose their playerworld because of this, say "tough." (Not exactly, but to that extent.) EDIT: Assuming the playerworld is still usable. If it's hacked beyond repair or something, reboot it. Or whatever. |
Quote:
|
Quote:
Thats not true,i tested your theory severeal times and everytime i deleted the logs it would create a new log with who deleted it in the previous logs.I also tested if you would of overwritten the rc log file with another file,it also showed the logs beeing overwritten.So maybe your problem was just ignored? |
Quote:
What happened when I tested it: jake13jake loaded file(s) from staffdocs/ jake13jake (removed a line for testing)Time: Fri Jul 23 21:20:10 2004 jake13jake loaded file(s) from logs/ Time: Fri Jul 23 21:24:35 2004 jake13jake changed the rights of jake13jake removed file right: rw */* The line removed was from loading the rclog.txt. |
Some of you arent understanding that not being secure allows hackers to get on RC, and do things like overload the hard drive so all the pw's are screwed....not being secure affects Graal alot of times, not just that one PW
|
Quote:
When /allservers spammed servers offline, it was a result of no IP ranges. When playerworlds get *** pornography uploaded to them, it's a result of no IP ranges. When playerworlds get deleted, it's commonly due to a result of no IP ranges. When a playerworld script is made to loop in a log to create big logs, it's a results of no IP ranges. Sure, anyone WITH an IP range set can do this, but then it's the playerworld managers fault for giving so many rights, or it's unavoidable. But with an IP range we can not only ban the user, but look at the IP which was used and if it was static we can block future accounts made by that person in random searches, of if it's not static then we can look at the IP realted to other accounts in a small time-frame. The purpose of IP ranges is an extra level of security, and to make sure that the account owner is the only person who is on the account on RCs. And I belive Stefan will possibly be making it so *.*.*.* aren't allowed, period. Which I support and am trying to get him to do. |
Quote:
|
Quote:
|
Quote:
|
Thats extremely embarassing.
|
Quote:
|
Mh. For a short while, I worked on one of Scott's UC playerworlds, vanguard, with *osrs. Anyway, my IP changed a lot too. I'm not sure, but could it be that multiple IP's can be set to one account? This would solve some of those IP-changing business.
|
Quote:
|
Quote:
By doing (ex. 12.13.33.12,23,11,21,65,45)??Just separate with comma's? |
Quote:
|
Quote:
Either that or you just have some kind of virus. Its easy for virus makers to get info from your registry you know? :o |
Quote:
and so on... Quote:
|
Quote:
|
| All times are GMT +2. The time now is 12:42 PM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.