Skilly Realms v2 Source Warning

Posts 16–30 of 42 · Page 2 of 3
Quote Originally Posted by Riigged View Post
Hes away for 2 weeks, and shank is busy with college, unfortunately the only active minions at the moment are the new ones.
might just tell the global mods to remove the source until patched since this is a bigger problem then usual

apparently disabling the # was smart
//sarcasm


The download of the source got removed but from now on anyone using the source will be notified by me and anyone else who cares to join me that the source can potentially steal your production account information so do not use your real email and use with caution.
Quote Originally Posted by DimitriSavage View Post


might just tell the global mods to remove the source until patched since this is a bigger problem then usual

apparently disabling the # was smart
//sarcasm
the source is already removed
Thanks for removing it, you didn't have too but it's appreciated.
Quote Originally Posted by Riigged View Post
Im not going to publicly say how to re-add the encryption because then its self explanatory how to remove it as well for other sources people may want to use.
But hey, if he changes it on github. then people will know what he changed to add back encryption and they can just remove it again?

Seriously... It's a fuckin' forum dedicated to hacking and modifying games and things relating to it...

If the mods WOULDN'T let people get hacked, they might as well rebrand to MPGH - Game Modding Forums
@Kithio
So basically he should just never touch it because he will teach people how to remove it?

I mean his source is basically the worst source an owner can use...since they might get blamed for account stealing/hacking and possibly* their server removed from MPGH so it wouldn't matter
Erh..

I'm thinking seriously about something on this forum again. It's time to stop using #shitgrammar.

Anyways, the SHA1 encryption DOES actually help, because when you consider that the majority of people who use these sources are kids who don't know how to do simple research, it is encryption. It's really low-power encryption and can be undone by anyone WITH a brain, but remember that not everyone here has one.

Quote Originally Posted by DimitriSavage View Post
since they might get blamed for account stealing/hacking and possibly* their server removed from MPGH so it wouldn't matter
It's a guideline of general Internet security to not use your same passwords for different online accounts under your name. The fact that it's a guideline and not a rule defers the responsibility to the end user, who has to take their own steps to secure what they have.

All online accounts are property of the host body (MPGH accounts belong to MPGH, not their users). By registering an account under a host body like DarkSwagXDRelm, you defer a username and a password string to the host body to create and moderate an account under your name, which you are allowed to interact with their systems in a personalized way with these accounts.

If NoobServerOwner sees your password on their server and tries it on MPGH and somehow gets into your account, that's on YOU. It is NOT something that the admins of MPGH are able to enforce against besides locking/deleting threads and banning users. Only under large-volume account security violations would the admins take special action against something like that.

tl;dr
non-encrypted passwords on servers is not a huge issue
Never was a good idea to use your Prod password on Private Servers anyways...
Good to know how fucking bored everyone is to discuss this shit on a hacking forum
Quote Originally Posted by DimitriSavage View Post
@Kithio
So basically he should just never touch it because he will teach people how to remove it?

I mean his source is basically the worst source an owner can use...since they might get blamed for account stealing/hacking and possibly* their server removed from MPGH so it wouldn't matter
Idc about people removing it, I could make a whole thread about that, its 6 letters you remove lol, its super simple to both add it and remove it, removing SHA1 was done to help people with forgotten passwords, its been stated 100 times that you should never use the same password on private servers as you do on prod, if you do, its your own fault, you say, he will teach people how to remove it, this whole thread teaches them both how to remove it, decrypt it and add it.

- - - Updated - - -

Quote Originally Posted by cxydsaewq View Post
Good to know how fucking bored everyone is to discuss this shit on a hacking forum
dont call me a forum kid
Yeah, it's just common knowledge to not register with your fucking prod details...
I get cancer from this
Just Use different passwords on pservers and you're good
We have a sticky, don't get how this is a huge issue.
Even with the current algorithm, it's still pretty much in plaintext since it's so easy to crack.
Quote Originally Posted by Kushala Daora View Post
Even with the current algorithm, it's still pretty much in plaintext since it's so easy to crack.
Sorry if you didn't get the memo but this discussion is over, I added a warning in the sticky(LINK) at the P'Server main section and from now on I will add a warning in the comments of every skilly source to not use their real email and password since the owner may steal your account information at any time...to be honest Owners shouldn't use skilly source since now this is public, their servers will have less players due to this fact even tho anyone else can do it people will feel insecure and they will have to remember another whole new password just to be able to play on 1 messily server.
Quote Originally Posted by DimitriSavage View Post


Sorry if you didn't get the memo but this discussion is over, I added a warning in the sticky(LINK) at the P'Server main section and from now on I will add a warning in the comments of every skilly source to not use their real email and password since the owner may steal your account information at any time...to be honest Owners shouldn't use skilly source since now this is public, their servers will have less players due to this fact even tho anyone else can do it people will feel insecure and they will have to remember another whole new password just to be able to play on 1 messily server.
Thing is, you never know if a server owner removes the encryption.

I know several servers have their encryption removed, some for bad reasons while some for good like retrieving a user's password. There should be a tutorial on how to add it back in but honestly, it cannot be enforced. Best you can do is lock the file which the encryption can be removed in before releasing the source
Posts 16–30 of 42 · Page 2 of 3

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?