Go Back   Champions of Regnum > English > General discussion

General discussion Topics related to various aspects of Champions of Regnum

View Poll Results: ??
Very secure... 9 30.00%
Not secure at all 21 70.00%
Voters: 30. You may not vote on this poll

Reply
 
Thread Tools Display Modes
Old 01-19-2008, 05:10 AM   #1
DemonMonger
Marquis
 
DemonMonger's Avatar
 
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
DemonMonger is on a distinguished road
Default How secure do you feel regnum is?

I suggest that you use a new account for forums so people do not see your login name..... I said this when regnum was still in beta... but im saying it again, because someone I know got hacked... and lost their account..

Last edited by DemonMonger; 01-19-2008 at 12:36 PM.
DemonMonger no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 06:11 AM   #2
putkonen
Banned
 
putkonen's Avatar
 
Join Date: Jan 2007
Location: Helsinki, Finland
Posts: 221
putkonen can only hope to improve
Default

I dont really understand this question but i guess regnum is pretty secure
putkonen no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 06:21 AM   #3
amade
Baron
 
amade's Avatar
 
Join Date: Jun 2007
Location: Kelana Jaya
Posts: 920
amade is on a distinguished road
Default

Regnum is never secure as long as DM is running around in it
__________________
*end.transmission - amade*

FoV Clan Inventory Listing
amade no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 07:57 AM   #4
ArcticWolf
Duke
 
ArcticWolf's Avatar
 
Join Date: Nov 2006
Location: 0x00CAFE
Posts: 3,366
ArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of light
Default

No secure at all... Packages aren't ciphered, for instance.
__________________
I don't have a solution, but I admire the problem.
ArcticWolf no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 09:09 AM   #5
DkySven
Marquis
 
DkySven's Avatar
 
Join Date: Jul 2007
Location: The Netherlands
Posts: 2,076
DkySven has a spectacular aura aboutDkySven has a spectacular aura about
Default

Not secure I think, but why would somebody hack Regnum?
__________________
Dky Sven, level 54 knight (Ra) Valhalla
Dky the Goat, level 35 conjurer(Ra)
Dky Sven, level 51 knight(Horus) Something
DkySven no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 09:17 AM   #6
Nikor
Initiate
 
Join Date: Jun 2007
Posts: 159
Nikor is on a distinguished road
Default

Quote:
Originally Posted by Xephandor
No secure at all... Packages aren't ciphered, for instance.
What would be the use of that? As far as I can see, the client verifies the local installation every time you start. I guess it computes some kind of hash value for the every file and compares that to the values stored on the server. If there are differences, it downloads the files again, now problem here.

If you think about signing the installation package (windows only, linux users just download the launcher) with some kind of certificate, I never really understood why this would help. I mean, how many people really do think twice if windows says "This file is not signed, it may not be safe" or whatever the real text is, and click on "Run anyway"? And publishing hash values of the installer on the web site doesn't help because if you are able the redirect the download to a site of your own, you can surely adjust the values accordingly. And you wouldn't get past the check/download procedure mentioned above anyway.

Going back to the original question, I think think the only real security issue Regum has is the same that all account-based application/games/web sites have: social engineering. That means getting other people to tell you your account data including the password. This is why there is a bold red text every time you start the game that tells you not to give your password to anyone.

Edit: added a few more thoughts
__________________
Ra: Lucinda {Silverbow,Wintersun,Ironfist}
Horus: Laleja - Conjurer (42)
Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr

Last edited by Nikor; 01-19-2008 at 09:29 AM.
Nikor no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 09:36 AM   #7
Nikor
Initiate
 
Join Date: Jun 2007
Posts: 159
Nikor is on a distinguished road
Default

Quote:
Originally Posted by asdfghs
Not secure I think, but why would somebody hack Regnum?
For the same reasons people hack other stuff. To gain an advantage, to make money or just for the fun of it. The last reason is actually a very good one as those people tend to report what they found to the developers so they can fix them.
__________________
Ra: Lucinda {Silverbow,Wintersun,Ironfist}
Horus: Laleja - Conjurer (42)
Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr
Nikor no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 12:37 PM   #8
DemonMonger
Marquis
 
DemonMonger's Avatar
 
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
DemonMonger is on a distinguished road
Default

Quote:
Originally Posted by amade
Regnum is never secure as long as DM is running around in it
wrong im your best friend..... I suggest that you use a new account for forums so people do not see yoru login name..... I said this when regnum was still in beta... but im saying it again, because someone I know got hacked... and lost their account..
DemonMonger no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 02:47 PM   #9
Drah
Initiate
 
Join Date: Jul 2007
Posts: 101
Drah is on a distinguished road
Default

DM, was their password a word that could be found in a dictionary list?

NGD, the forum has a 15 minute lockout if you fail the password 5 times - does the main website (and the game server) have anything to stop a dictionary-list or brute-force attack in a similar way to this?

I've tried SQL injection against my own account but couldn't force my way in through the main site or via the client app's login system.

To me, the biggest risk is with someone releasing a 0-day hack for vBulletin and for someone to leech all the passwords, converting the hash back to the original password using an MD5 string database (for example) - mainly because I've known sites that have had this happen to them.

Last edited by Drah; 01-19-2008 at 03:02 PM.
Drah no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 03:54 PM   #10
Stefan1200
Initiate
 
Join Date: Jul 2007
Location: Germany
Posts: 197
Stefan1200 is on a distinguished road
Default

Quote:
Originally Posted by Nikor
I guess it computes some kind of hash value for the every file and compares that to the values stored on the server. If there are differences, it downloads the files again, now problem here.
Yes, Regnum find changed files very good. But if you write protect the changed file, Regnum shows an error message and start with the changed file without problem. So you can hack files and use them!
Stefan1200 no ha iniciado sesión   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:06 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
NGD Studios 2002-2024 © All rights reserved