Page 1 of 2 12 LastLast
Results 1 to 15 of 22
  1. #1
    L̋̾̈́͑ͥͨͨ͞Ò̴ͫͪ͛͋̉͛Lͥ̔̓ ͨ͛ͬ ͩ̀͢
    Premium Member
    C453's Avatar
    Join Date
    Jul 2012
    Gender
    male
    Location
    /dev/null
    Posts
    574
    Reputation
    44
    Thanks
    2,535
    My Mood
    Aggressive

    Be careful about registering for private servers!

    Recently, @RotMGnub has tricked many into using his MulepackageV1.

    I've always noticed this issue, but didn't want to mention it until this event occurred.


    This is a Warning!
    DO NOT USE YOUR PROD EMAIL AND PASSWORD ON ANY PRIVATE SERVER!

    EVEN IF THEY ARE "TRUSTED"



    For Players:
    I recommend changing your password/email if you are using your credentials for production.

    For Server Owners:
    I recommend changing the 'email' in the registration to 'Username' instead and avoid using emails.




    @nilly Sticky Thread Please
    BE CAREFUL WHEN REGISTERING INTO A SKILLY SOURCE SINCE IT HAS BEEN CONFIRMED THAT IT TRACKS YOUR PASSWORD.

    IT CAN BE USED TO STEAL YOUR REALM OF THE MAD GOD PRODUCTION INFORMATION AND INFORMATION OF OTHER PRIVATE SERVERS.

    DO NOT USE YOUR REALM EMAIL/REAL EMAIL AND DO NOT USE YOUR REALM PASSWORD/EMAIL PASSWORD.
    Last edited by Danny; 05-22-2016 at 05:35 PM. Reason: nice format luis
    cant have shit in detroit

  2. The Following 17 Users Say Thank You to C453 For This Useful Post:

    ADTwo (08-18-2013),[MPGH]Ahl (01-02-2014),Botmaker (08-02-2013),crastotal (08-07-2013),CursedRiot (09-22-2014),Daemonmann (11-19-2015),Daniel:D (09-30-2017),derickfls (04-16-2015),hSRhaeheahaehaerheadhyehr (02-08-2015),lkdjnfoskjednfblksjdfn (12-10-2015),Lxys (07-05-2014),Mewkus (06-22-2016),Nanaki7 (12-06-2016),nilly (08-02-2013),plokijjikolp (02-12-2016),RaymondW (08-02-2013),Royce (08-08-2013)

  3. #2
    Botmaker's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Location
    England
    Posts
    1,360
    Reputation
    89
    Thanks
    7,597
    My Mood
    Amused
    I agree with everything you’ve said

    People can also use the information, like the email and in game name
    As a way for phishing for real rotmg account credentials, granted they don’t know the password and wouldn’t be able to hack the account immediately. However there are many possible ways to gain access to the account with just the email and combined with there in game name allows a hacker to target and attack individuals accounts.

  4. The Following 2 Users Say Thank You to Botmaker For This Useful Post:

    [MPGH]Ahl (01-02-2014),C453 (08-02-2013)

  5. #3
    Threadstarter
    L̋̾̈́͑ͥͨͨ͞Ò̴ͫͪ͛͋̉͛Lͥ̔̓ ͨ͛ͬ ͩ̀͢
    Premium Member
    C453's Avatar
    Join Date
    Jul 2012
    Gender
    male
    Location
    /dev/null
    Posts
    574
    Reputation
    44
    Thanks
    2,535
    My Mood
    Aggressive
    Quote Originally Posted by Botmaker View Post
    I agree with everything you’ve said

    People can also use the information, like the email and in game name
    As a way for phishing for real rotmg account credentials, granted they don’t know the password and wouldn’t be able to hack the account immediately. However there are many possible ways to gain access to the account with just the email and combined with there in game name allows a hacker to target and attack individuals accounts.
    Yes, however, even though MySQL "Hashes" passwords, (I'm not going to say how) it is very easy to match hashes and obtain a password in plain text
    cant have shit in detroit

  6. #4
    Botmaker's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Location
    England
    Posts
    1,360
    Reputation
    89
    Thanks
    7,597
    My Mood
    Amused
    Quote Originally Posted by C453 View Post
    Yes, however, even though MySQL "Hashes" passwords, (I'm not going to say how) it is very easy to match hashes and obtain a password in plain text
    It’s really easy to switch off the hashing and have them stored as plain text, The email and password are sent to the world server using RSA, also the client sends the account details to the account server unencrypted because it only use http post and not https like the official client, however you are right.

  7. The Following 2 Users Say Thank You to Botmaker For This Useful Post:

    [MPGH]Ahl (01-02-2014),C453 (08-02-2013)

  8. #5
    RaymondW's Avatar
    Join Date
    Oct 2012
    Gender
    male
    Location
    Michigan
    Posts
    132
    Reputation
    10
    Thanks
    470
    My Mood
    Cynical
    Will take this into consideration!

  9. #6
    nilly's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    2,652
    Reputation
    155
    Thanks
    13,983
    My Mood
    Angelic
    How does the auto login to last used account feature of the client fit into the picture here? I'm guessing if you forgot to log out before exiting that your account information will be sent to the server even if you didn't want it to?
    Be careful, stray too far from the pack and you'll get lost.

  10. The Following 3 Users Say Thank You to nilly For This Useful Post:

    [MPGH]Ahl (01-02-2014),Botmaker (08-03-2013),hSRhaeheahaehaerheadhyehr (02-08-2015)

  11. #7
    Threadstarter
    L̋̾̈́͑ͥͨͨ͞Ò̴ͫͪ͛͋̉͛Lͥ̔̓ ͨ͛ͬ ͩ̀͢
    Premium Member
    C453's Avatar
    Join Date
    Jul 2012
    Gender
    male
    Location
    /dev/null
    Posts
    574
    Reputation
    44
    Thanks
    2,535
    My Mood
    Aggressive
    Quote Originally Posted by nilly View Post
    How does the auto login to last used account feature of the client fit into the picture here? I'm guessing if you forgot to log out before exiting that your account information will be sent to the server even if you didn't want it to?
    The account won't be sent to the SQL database, however, I bet you can analyse the request from the client with the credentials
    cant have shit in detroit

  12. The Following 2 Users Say Thank You to C453 For This Useful Post:

    [MPGH]Ahl (01-02-2014),Botmaker (08-03-2013)

  13. #8
    Botmaker's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Location
    England
    Posts
    1,360
    Reputation
    89
    Thanks
    7,597
    My Mood
    Amused
    Salts also combat the use of rainbow tables for cracking passwords

    maybe someone could add a salt to the c# server
    Salt (cryptography) - Wikipedia, the free encyclopedia

    DEFCON 17: Cracking 400,000 Passwords, or How to Explain to Your Roommate why Power Bill is a High - YouTube

  14. #9
    whiteworld's Avatar
    Join Date
    May 2013
    Gender
    male
    Posts
    25
    Reputation
    10
    Thanks
    97
    Ok thanks for letting us know this even though it should be common sense :P just like you dont use your gmail password for a viagra pill site :P

  15. The Following User Says Thank You to whiteworld For This Useful Post:

    BlackRayquaza (02-09-2015)

  16. #10
    ImperiDK's Avatar
    Join Date
    Dec 2013
    Gender
    male
    Location
    Havel's Dungeon
    Posts
    70
    Reputation
    10
    Thanks
    1
    My Mood
    Sleepy
    Thanks for information

  17. #11
    Stellar Spark's Avatar
    Join Date
    Jun 2013
    Gender
    female
    Posts
    724
    Reputation
    35
    Thanks
    799
    As a little update to the discussion, it is becoming more of a concern that some server owners may want to use emails in logins for the purpose of verification and to combat certain vandalism attempts such as account flooding, especially nowadays where people in general have more knowledge on the server scene and coding. For those willing to go that path, it's good practice to make sure users are reminded on registration about this issue.

  18. The Following 2 Users Say Thank You to Stellar Spark For This Useful Post:

    BlackRayquaza (02-09-2015),Prince Zuko (02-10-2015)

  19. #12
    Voula's Avatar
    Join Date
    Sep 2012
    Gender
    male
    Posts
    30
    Reputation
    16
    Thanks
    17
    Thanks so much

  20. #13
    SevenH's Avatar
    Join Date
    Dec 2015
    Gender
    male
    Posts
    5
    Reputation
    10
    Thanks
    1
    Register with a random email that you dont even have, y/n

  21. #14
    DimitriSavage's Avatar
    Join Date
    Dec 2015
    Gender
    female
    Location
    With the Devil
    Posts
    462
    Reputation
    27
    Thanks
    130
    My Mood
    Devilish
    BE CAREFUL WHEN REGISTERING INTO A SKILLY SOURCE SINCE IT HAS BEEN CONFIRMED THAT IT TRACKS YOUR PASSWORD.

    IT CAN BE USED TO STEAL YOUR REALM OF THE MAD GOD PRODUCTION INFORMATION AND INFORMATION OF OTHER PRIVATE SERVERS.

    DO NOT USE YOUR REALM EMAIL/REAL EMAIL AND DO NOT USE YOUR REALM PASSWORD/EMAIL PASSWORD.

    @Luis @Joe Please add this into it to warn all players to be extra careful when registering into a Skilly Source server.
     
    Look Below

    "One should not seek to know and understand the meaning of life"...for the meaning of life will be presented...
    when we all perish
    "Life greatest questions can only be answered in a man that believes not in god...but in himself and his abilities so understand the Universe"
    "The most important moment of your life is and will always be the way you lived it to the moment you died"
    "My methods may be harsh in contrast to my true intentions"... you may fight, cry, beg, and deny but at the end you will truly see why I done such a thing
     

    Visual Studio by Microsoft
    Xamarin Studio by Xamarin
    SharpDevelop by IcSharpCode Team
    Notepad++ by Don Ho
    AutoHotKey by Chris Mallet & Steve Gray
    Cheat Engine by Eric Heijen
    Java Development Kit by Oracle Corp.
    Blender by Blender Foundation
    Unity by Unity Tech.
    Unreal Engine by Epic Games


  22. #15
    Luis's Avatar
    Join Date
    Aug 2013
    Gender
    male
    Posts
    2,801
    Reputation
    348
    Thanks
    1,846
    My Mood
    Psychedelic
    Quote Originally Posted by DimitriSavage View Post
    BE CAREFUL WHEN REGISTERING INTO A SKILLY SOURCE SINCE IT HAS BEEN CONFIRMED THAT IT TRACKS YOUR PASSWORD.

    IT CAN BE USED TO STEAL YOUR REALM OF THE MAD GOD PRODUCTION INFORMATION AND INFORMATION OF OTHER PRIVATE SERVERS.

    DO NOT USE YOUR REALM EMAIL/REAL EMAIL AND DO NOT USE YOUR REALM PASSWORD/EMAIL PASSWORD.

    @Luis @Joe Please add this into it to warn all players to be extra careful when registering into a Skilly Source server.
    Guess it couldn't hurt.
    /edited.

Page 1 of 2 12 LastLast

Similar Threads

  1. [Discussion] Mod/Hack For Private Server's
    By deanking in forum Call of Duty Modern Warfare 3 Private Server Hacks
    Replies: 1
    Last Post: 10-03-2012, 10:13 AM
  2. [Release] fmo.dll and Trainer NDLL for Private Server
    By miki08 in forum Gunz Hacks
    Replies: 9
    Last Post: 09-03-2010, 09:34 AM
  3. [Request] Request for private server tut
    By omghacker in forum Runescape Hacks / Bots
    Replies: 4
    Last Post: 08-03-2010, 12:17 AM
  4. Hoster for private server.
    By Shocking in forum MapleStory Discussions
    Replies: 22
    Last Post: 02-18-2010, 10:51 PM
  5. Download + Register To Private Servers off gunz
    By Redbull in forum Gunz General
    Replies: 0
    Last Post: 07-04-2007, 01:36 PM