Erm, not to start/restart the war things :D, but salted hashed passwords have only 2 ways to be retrieved - 1st is to have the hash key and use brute force/compare crypted strings (the easy way) and 2nd is to use a brute force on both key and DB, which (is a suicide and) would eventually a hundred thousand hours/years, especially if (they're not but let's imagine this picture) usernames are also encrypted.Quote:
The passwords in 9D are hashed+salted both for forums and game, why would he waste his time cracking salted hashes when he can use a session fixation exploit on epvp?
Personally I've nothing against anyone and I respect the guys, who brought 9D back. It's more than anyone else have done before about 9D, right? So good persons or not, respect their effort. Yes, it has bugs and so, but I think everything will be back in order soon enough. If I had a chance, I'd help about that with whatever possible. After all I also enjoy 9D. Btw I've basic idea why do these bugs happen (I mean pty and band), but I've to look around some more AND will need the client source as from the link that Play9D posted, it can't be downloaded :(