Go Back   Champions of Regnum > English > General discussion

General discussion Topics related to various aspects of Champions of Regnum

View Poll Results: ??
Very secure... 9 30.00%
Not secure at all 21 70.00%
Voters: 30. You may not vote on this poll

Thread Tools Display Modes
Old 01-19-2008, 07:42 PM   #11
ArcticWolf's Avatar
Join Date: Nov 2006
Location: 0x00CAFE
Posts: 3,366
ArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of light

Originally Posted by Nikor
What would be the use of that? As far as I can see, the client verifies the local installation every time you start. I guess it computes some kind of hash value for the every file and compares that to the values stored on the server. If there are differences, it downloads the files again, now problem here.
Uhm... Now that I read my reply I made a mistake... Packages were the Packets the client sends to the server to communicate. They're in plain text AFAIK. Ciphered packets would help to make the game more secure.

Sorry, I confused packages with packets (translation to Spanish would be: enpaquetados with paquetes ). My fault.

Originally Posted by Nikor
Going back to the original question, I think think the only real security issue Regum has is the same that all account-based application/games/web sites have: social engineering. That means getting other people to tell you your account data including the password. This is why there is a bold red text every time you start the game that tells you not to give your password to anyone.

Edit: added a few more thoughts
Nowadays, it's almost impossible to break security in most of the cases, but there's always a way and it's social engineering. I could get my school's wi-fi lan passkey which was secured with wpa-psk just asking some questions to my teachers. Of course it has nothing to do (and I used it to send some mails ), but you can do the exact same thing to retrive the user and pass from anyone in the game. Unfortunately, this will keep happening because there's a large number of innocent-minded players that trust everyone.
I don't have a solution, but I admire the problem.
ArcticWolf no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 07:44 PM   #12
Snoid's Avatar
Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
Snoid will become famous soon enoughSnoid will become famous soon enough

Originally Posted by DemonMonger
I suggest that you use a new account for forums so people do not see your login name..... I said this when regnum was still in beta... but im saying it again, because someone I know got hacked... and lost their account..
I suggest that you make anonymous polls.

EDIT: my fault. my bad english...

SuraK: encrypt SOMETHING
I'm an outsider, outside of everything...

Elegida Miss Ignis 2009 por votación popular
Snoid no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 09:24 PM   #13
DemonMonger's Avatar
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
DemonMonger is on a distinguished road

Originally Posted by Stefan1200
Yes, Regnum find changed files very good. But if you write protect the changed file, Regnum shows an error message and start with the changed file without problem. So you can hack files and use them!
right... or you can use old update in new version/new version for exp server in normal server
DemonMonger no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 04:11 AM   #14
Join Date: Jun 2007
Posts: 159
Nikor is on a distinguished road

Originally Posted by Xephandor
Uhm... Now that I read my reply I made a mistake... Packages were the Packets the client sends to the server to communicate. They're in plain text AFAIK. Ciphered packets would help to make the game more secure.
Ok, that makes a lot more sense and I agree with it. You can see a lot of information when running packet analyzers like wireshark while playing. It's not all plain text, but what is not would be easy to figure out if you have enough time to spare.

But what I ask myself here is: "Is this a security issue?" I do not think so. It possibly makes life easier for cheaters, but it does not compromise anyone's account data (username/password combination).

One more thought on security: It's not an on/off or black/white thing. You have to define what you want to secure and against what. This is always a compromise between cost of implementation and cost of not implementating.

This is why I do not vote here as there is not thing as "very secure" or "not secure at all". Security is always something in-between. Unless you define what you want to secure and against what, you can't really give a reasonable answer.
Ra: Lucinda {Silverbow,Wintersun,Ironfist}
Horus: Laleja - Conjurer (42)
Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr
Nikor no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 12:23 PM   #15
Join Date: Apr 2007
Posts: 309
tak is on a distinguished road

God you guys sure are anal about security. Who cares, its a game.
Choose a good password, thats enough and totally up to you.
If you get hacked, who could use your account anyways? You'd lose your stuff, and be completely at fault yourself if you choose a lame password.
tak no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 10:52 PM   #16
NightTwix's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 1,655
NightTwix is on a distinguished road

Originally Posted by tak
God you guys sure are anal about security. Who cares, its a game.
Choose a good password, thats enough and totally up to you.
If you get hacked, who could use your account anyways? You'd lose your stuff, and be completely at fault yourself if you choose a lame password.
uhm start the game and run a 'ps auxww' or similar (im sure windows is affected too)
the game is launched with the username and the hashed password as commandline switches.

So any other user on your system or any other running application can grab your login.

Then the unencrypted network traffic and packages could be a problem too but i havent looked into it.

For some reason i also doubt the coding quality when it comes to buffer overflows and similar methods of remote code execution.
I can imagine there arises a lot of trouble when someone does some security-auditing
NightTwix no ha iniciado sesión   Reply With Quote
Old 01-29-2008, 01:24 PM   #17
Rockwolf_'s Avatar
Join Date: Jan 2008
Location: ~/gam/regnum
Posts: 88
Rockwolf_ is on a distinguished road

This poll needs a third option, because your accountname is indeed visible, but this only means you can get "hacked" if your password is too easy. All the pressure is on the password. The stronger the password, the safer you are. But I see no reason a real hacker would steal someones account? Those people usually have more interesting things to do
Rockwolf_ no ha iniciado sesión   Reply With Quote
Old 01-29-2008, 02:42 PM   #18
Miraculix's Avatar
Join Date: Nov 2007
Location: Infinite Improbability Drive
Posts: 1,287
Miraculix will become famous soon enough

well that's the issue here, 2 words come to mind: script kiddies
Hit me, nail me, make me God.
Panoramix :: Half Elf Hunter ## Miraculix :: Half Elf Marksman ## Aspirinix :: Wood Elf Conjurer
Syrtis :: Horus :: Antartes
Miraculix no ha iniciado sesión   Reply With Quote
Old 02-01-2008, 03:15 AM   #19
Join Date: Aug 2007
Posts: 13
meldarion is on a distinguished road

The simplest way to stop password de-hashing using a db is to do something like MD5(username + password) or MD5(username + MD5(password)).

It will add a few magnitudes of difficulty to the process of getting at the password.

The network stuff is scarily scant....
meldarion no ha iniciado sesión   Reply With Quote
Old 02-01-2008, 03:26 AM   #20
GIGO305's Avatar
Join Date: Aug 2007
Location: with ur mom
Posts: 939
GIGO305 has a little shameless behaviour in the past
Post hackers

hakers r every where these days this 1 in youtube tried to hack but he got a bunch of viruses illigal defence mailed him a virus 4 pay back the only sucureness we get from our user name is that we dont use it game but hackers will look 4 us a forums and u can gues passes 4 ever so i goood hacking program can hack anyone in 5mins at most i know this from playing runescape a game in wich hacking is everysingle god danm day and if ur not with them they are aginst u but im not like that p.s some idiot made a tread asking for a hack for regnum morons like him are just BS real hackers use sht like him so ppl ignore wahts coming becareful in youtube look in my favorites i think i got an anty hacker thing if they send u a keylogger they get constant spam and my password is the same for everything because its alt codes i sugjest more ppl use this
GIGO305 no ha iniciado sesión   Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT. The time now is 11:10 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
NGD Studios 2002-2024 © All rights reserved