Go Back   Champions of Regnum > English > General discussion

General discussion Topics related to various aspects of Champions of Regnum

View Poll Results: ??
Very secure... 9 30.00%
Not secure at all 21 70.00%
Voters: 30. You may not vote on this poll

Reply
 
Thread Tools Display Modes
Old 01-19-2008, 07:42 PM   #11
ArcticWolf
Duke
 
ArcticWolf's Avatar
 
Join Date: Nov 2006
Location: 0x00CAFE
Posts: 3,366
ArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of lightArcticWolf is a glorious beacon of light
Default

Quote:
Originally Posted by Nikor
What would be the use of that? As far as I can see, the client verifies the local installation every time you start. I guess it computes some kind of hash value for the every file and compares that to the values stored on the server. If there are differences, it downloads the files again, now problem here.
Uhm... Now that I read my reply I made a mistake... Packages were the Packets the client sends to the server to communicate. They're in plain text AFAIK. Ciphered packets would help to make the game more secure.

Sorry, I confused packages with packets (translation to Spanish would be: enpaquetados with paquetes ). My fault.

Quote:
Originally Posted by Nikor
Going back to the original question, I think think the only real security issue Regum has is the same that all account-based application/games/web sites have: social engineering. That means getting other people to tell you your account data including the password. This is why there is a bold red text every time you start the game that tells you not to give your password to anyone.

Edit: added a few more thoughts
Nowadays, it's almost impossible to break security in most of the cases, but there's always a way and it's social engineering. I could get my school's wi-fi lan passkey which was secured with wpa-psk just asking some questions to my teachers. Of course it has nothing to do (and I used it to send some mails ), but you can do the exact same thing to retrive the user and pass from anyone in the game. Unfortunately, this will keep happening because there's a large number of innocent-minded players that trust everyone.
__________________
I don't have a solution, but I admire the problem.
ArcticWolf no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 07:44 PM   #12
Snoid
Master
 
Snoid's Avatar
 
Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
Snoid will become famous soon enoughSnoid will become famous soon enough
Default

Quote:
Originally Posted by DemonMonger
I suggest that you use a new account for forums so people do not see your login name..... I said this when regnum was still in beta... but im saying it again, because someone I know got hacked... and lost their account..
I suggest that you make anonymous polls.

EDIT: my fault. my bad english...

SuraK: encrypt SOMETHING
__________________
I'm an outsider, outside of everything...
RAMNA

Elegida Miss Ignis 2009 por votación popular
Snoid no ha iniciado sesión   Reply With Quote
Old 01-19-2008, 09:24 PM   #13
DemonMonger
Marquis
 
DemonMonger's Avatar
 
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
DemonMonger is on a distinguished road
Default

Quote:
Originally Posted by Stefan1200
Yes, Regnum find changed files very good. But if you write protect the changed file, Regnum shows an error message and start with the changed file without problem. So you can hack files and use them!
right... or you can use old update in new version/new version for exp server in normal server
DemonMonger no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 04:11 AM   #14
Nikor
Initiate
 
Join Date: Jun 2007
Posts: 159
Nikor is on a distinguished road
Default

Quote:
Originally Posted by Xephandor
Uhm... Now that I read my reply I made a mistake... Packages were the Packets the client sends to the server to communicate. They're in plain text AFAIK. Ciphered packets would help to make the game more secure.
Ok, that makes a lot more sense and I agree with it. You can see a lot of information when running packet analyzers like wireshark while playing. It's not all plain text, but what is not would be easy to figure out if you have enough time to spare.

But what I ask myself here is: "Is this a security issue?" I do not think so. It possibly makes life easier for cheaters, but it does not compromise anyone's account data (username/password combination).

One more thought on security: It's not an on/off or black/white thing. You have to define what you want to secure and against what. This is always a compromise between cost of implementation and cost of not implementating.

This is why I do not vote here as there is not thing as "very secure" or "not secure at all". Security is always something in-between. Unless you define what you want to secure and against what, you can't really give a reasonable answer.
__________________
Ra: Lucinda {Silverbow,Wintersun,Ironfist}
Horus: Laleja - Conjurer (42)
Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr
Nikor no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 12:23 PM   #15
tak
Banned
 
Join Date: Apr 2007
Posts: 309
tak is on a distinguished road
Default

God you guys sure are anal about security. Who cares, its a game.
Choose a good password, thats enough and totally up to you.
If you get hacked, who could use your account anyways? You'd lose your stuff, and be completely at fault yourself if you choose a lame password.
tak no ha iniciado sesión   Reply With Quote
Old 01-20-2008, 10:52 PM   #16
NightTwix
Count
 
NightTwix's Avatar
 
Join Date: Dec 2006
Location: Germany
Posts: 1,655
NightTwix is on a distinguished road
Default

Quote:
Originally Posted by tak
God you guys sure are anal about security. Who cares, its a game.
Choose a good password, thats enough and totally up to you.
If you get hacked, who could use your account anyways? You'd lose your stuff, and be completely at fault yourself if you choose a lame password.
uhm start the game and run a 'ps auxww' or similar (im sure windows is affected too)
the game is launched with the username and the hashed password as commandline switches.

So any other user on your system or any other running application can grab your login.

Then the unencrypted network traffic and packages could be a problem too but i havent looked into it.

For some reason i also doubt the coding quality when it comes to buffer overflows and similar methods of remote code execution.
I can imagine there arises a lot of trouble when someone does some security-auditing
NightTwix no ha iniciado sesión   Reply With Quote
Old 01-29-2008, 01:24 PM   #17
Rockwolf_
Apprentice
 
Rockwolf_'s Avatar
 
Join Date: Jan 2008
Location: ~/gam/regnum
Posts: 88
Rockwolf_ is on a distinguished road
Default

This poll needs a third option, because your accountname is indeed visible, but this only means you can get "hacked" if your password is too easy. All the pressure is on the password. The stronger the password, the safer you are. But I see no reason a real hacker would steal someones account? Those people usually have more interesting things to do
Rockwolf_ no ha iniciado sesión   Reply With Quote
Old 01-29-2008, 02:42 PM   #18
Miraculix
Count
 
Miraculix's Avatar
 
Join Date: Nov 2007
Location: Infinite Improbability Drive
Posts: 1,287
Miraculix will become famous soon enough
Default

well that's the issue here, 2 words come to mind: script kiddies
__________________
Hit me, nail me, make me God.
Panoramix :: Half Elf Hunter ## Miraculix :: Half Elf Marksman ## Aspirinix :: Wood Elf Conjurer
Syrtis :: Horus :: Antartes
Miraculix no ha iniciado sesión   Reply With Quote
Old 02-01-2008, 03:15 AM   #19
meldarion
Pledge
 
Join Date: Aug 2007
Posts: 13
meldarion is on a distinguished road
Default

The simplest way to stop password de-hashing using a db is to do something like MD5(username + password) or MD5(username + MD5(password)).

It will add a few magnitudes of difficulty to the process of getting at the password.

The network stuff is scarily scant....
meldarion no ha iniciado sesión   Reply With Quote
Old 02-01-2008, 03:26 AM   #20
GIGO305
Banned
 
GIGO305's Avatar
 
Join Date: Aug 2007
Location: with ur mom
Posts: 939
GIGO305 has a little shameless behaviour in the past
Post hackers

hakers r every where these days this 1 in youtube tried to hack but he got a bunch of viruses illigal defence mailed him a virus 4 pay back the only sucureness we get from our user name is that we dont use it game but hackers will look 4 us a forums and u can gues passes 4 ever so i goood hacking program can hack anyone in 5mins at most i know this from playing runescape a game in wich hacking is everysingle god danm day and if ur not with them they are aginst u but im not like that p.s some idiot made a tread asking for a hack for regnum morons like him are just BS real hackers use sht like him so ppl ignore wahts coming becareful in youtube look in my favorites i think i got an anty hacker thing if they send u a keylogger they get constant spam and my password is the same for everything because its alt codes i sugjest more ppl use this
GIGO305 no ha iniciado sesión   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:03 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
NGD Studios 2002-2024 © All rights reserved