Register for your free account! | Forgot your password?

Go Back   elitepvpers > General Gaming > Early Access Games
You last visited: Today at 02:49

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[PSA] MULegend Account Security Risk

Discussion on [PSA] MULegend Account Security Risk within the Early Access Games forum part of the General Gaming category.

Reply
 
Old   #1
 
killzone's Avatar
 
elite*gold: 100
Join Date: Mar 2006
Posts: 1,819
Received Thanks: 425
Exclamation [PSA] MULegend Account Security Risk

Ok, not really but it is still risky.
Anyone who can get the right Authentication Key after you login can LOGIN any account without knowing the Exact Username & Password of that account.

How is that possible?
Simple because the Launcher from you are logging in store your Data in a encrypted string and pass it to the Client as the Parameter.

Example:
Mulegend.exe <YOUR ENCRYPTED DATA>

With that, MULegend.exe will validate it if the account is correct or not. But since there is already a validation from the Launcher. The Data being passed to the MULegend.exe is 100% Correct and it will just logged in that account.

How is this a risk to you?
A malicious programmer can create an application that gathers MULegend's Encrypted Data and save it or perhaps mail it back to him.

Once he has the data, he can login to any account according to the data he has gathered.

Since the Client (MULegend.exe) has no 2nd security authentication in game ANYONE CAN LOGIN ANY ACCOUNT AS LONG AS THE DATA IS CORRECT.

Ive included as simple app in this post to gather your AuthKey.
Instructions are in #README#.txt

I've included an example account (encrypted data) in Start Game.bat. For you to test.

Just a note, I have not tested this outside my network.



Edit:
Upon further observation, it appears there's also a SessionKey included. This sessionkey expires within certain amount of time. It may not be much but still risky if the malicious user gets your AuthKey and login as soon as possible.
Attached Files
File Type: zip AuthKey Grab.zip (11.4 KB, 6 views)
killzone is offline  
Thanks
1 User
Reply


Similar Threads Similar Threads
[Selling] WTS Game Private server [ Vps - Security Proxy - Security ddos] Files
06/10/2016 - Web Host / Server Trading - 2 Replies
Want To Sell My Vps Ram 8 Giga have time with security have time have all files you need you only setup
[Ad]MULegend - Full Season 8 Ep 2 - Return of the King
09/15/2014 - Private Server - 2 Replies
Server Location: USA http://warbeast.boards.net/ Website: Under Construction Ingame Registration - Please do not make accounts you don't want to use. Version: Season 8 Episode 2 Long term server. No wipe out. Servers: 1. x30 - Server 1, 30x Exp, No Resets PvP & x30 Non PvP 2. x50 - Server 2, x50 Exp, Unlimited Resets, PvP
FOR PEOPLE THAT DON'T LIKE TO RISK THEIR PRECIOUS ACCOUNT
01/16/2013 - Cabal Guides & Templates - 0 Replies
I PLAY CABAL NA (THIS WILL BE ALSO SUITABLE FOR other Cabal that are in EPISODE 9) Many people have been complaining of getting banned and blaming it to the creator of the Cheat......... Guys if you really want to use hack do it in Dungeon purpose only!!!!! And also use a DECOY account as in other account to be expected to be banned soon..... I've been a billionaire now Creating new accounts (I've created about 10 accounts already and all got banned except for the Account I have...
Diablo 3 Account For 10 Euro lVl 60 DH (this game is Sh.. Buy at own risk)
08/23/2012 - Diablo 3 Trading - 2 Replies
Hello i wanna Sell Account to this Crap And Boring Game Called Diablo 3 On Account : lvl 60 DH with 400 k Gold and 82 k DPS Price : 10 Euro Why that cheap ? Because This Game ISnt Worth Any Penny More
[Release] processor.php protection for potential security risk
08/24/2010 - Shaiya PServer Guides & Releases - 6 Replies
if you are useing the processor.php script, you need to know that is potentially attackable with code ijections. Here is a little solution that may help ya to fix SQL code injection, put this code at the beginning of your processor.php function sql_quote( $value ) { if( get_magic_quotes_gpc() ) { $value = stripslashes( $value ); }



All times are GMT +2. The time now is 02:49.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.