Register for your free account! | Forgot your password?

Go Back   elitepvpers > Other Online Games > Browsergames > DarkOrbit
You last visited: Today at 01:19

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Security issue regarding sid and normal login

Discussion on Security issue regarding sid and normal login within the DarkOrbit forum part of the Browsergames category.

Reply
 
Old   #1
 
skeith_sk8's Avatar
 
elite*gold: 0
Join Date: May 2012
Posts: 3,053
Received Thanks: 2,658
Security issue regarding sid and normal login

Hi guys,
After a while waiting for BP to fix this i have decided to share this in order to avoid that you guys have troubles while sharing accounts. I hope that after this thread it also gets fixed.

As we all know, when someone enter on our account using password, we get a 99 error in the backpage as the SID changes and if someone enters on our account and goes to the spacemap we get a connection lost error. However, even if the SID is different if you press reconnect you will be able to recover the connection.

In other words, imagine that you share your account using password or sid, it does not matter, with a friend. If your friend does not close the spacemap window he will keep access to the spacemap forever even if the SID changes or you change password or whatever. This can cause a huge variety of issues, such as billions of dishonor == bye bye account, all ammo gone, kill people that shouldn't be killed, say on global chat "i am a bot user", pushing, etc etc.

So be careful guys with who get access to your account, and don't be that confident with SID, as even if it changes the other player can keep connection.

Regards
skeith
PS: You guys can test it just by openning 2 browser. Just connect with browser 1 to the spacemap. Then go browser 2 and enter on spacemap. You will have connection lost on browser 1. Press reconnect and you will recover the connection even if the SID is gone. Sometimes you can get a infinite trying to connect. The other user can just create 5-6 tabs with the spacemap and if 1 get stuck just close and press reconnect in the other one.
skeith_sk8 is offline  
Thanks
19 Users
Old 06/20/2017, 11:14   #2


 
linksus's Avatar
 
elite*gold: 60
Join Date: Apr 2011
Posts: 7,894
Received Thanks: 3,067
Thanks for info
linksus is offline  
Thanks
1 User
Old 06/20/2017, 20:33   #3

 
~Demetrio~'s Avatar
 
elite*gold: 93
Join Date: Oct 2012
Posts: 1,234
Received Thanks: 1,116
Quote:
Originally Posted by skeith_sk8 View Post
Hi guys,
After a while waiting for BP to fix this i have decided to share this in order to avoid that you guys have troubles while sharing accounts. I hope that after this thread it also gets fixed.

As we....
This is a know bug ! sometimes it doesn't connect to spacemap sometimes it does after a user login into the account!

But anyway, BP don't care the players! Even if there are hacked users BP will be happy to earn money from them! [no bot users].
~Demetrio~ is offline  
Old 06/20/2017, 20:53   #4
 
skeith_sk8's Avatar
 
elite*gold: 0
Join Date: May 2012
Posts: 3,053
Received Thanks: 2,658
Quote:
Originally Posted by ~Demetrio~ View Post
This is a know bug ! sometimes it doesn't connect to spacemap sometimes it does after a user login into the account!

But anyway, BP don't care the players! Even if there are hacked users BP will be happy to earn money from them! [no bot users].
It always connect actually (unless the screen gets bugged)
skeith_sk8 is offline  
Old 06/20/2017, 21:52   #5
 
elite*gold: 0
Join Date: May 2017
Posts: 9
Received Thanks: 0
thx
shiroe98 is offline  
Old 06/20/2017, 22:04   #6
 
elite*gold: 0
Join Date: Mar 2017
Posts: 356
Received Thanks: 171
First of all say thanks because they remove sid from game page url )
Sydno is offline  
Old 06/21/2017, 15:34   #7
 
somalia_'s Avatar
 
elite*gold: 0
Join Date: Jul 2011
Posts: 166
Received Thanks: 128
I thought that was a feature rather than a bug.. That's too bad. :/
somalia_ is offline  
Old 06/21/2017, 23:52   #8
 
:thonking:'s Avatar
 
elite*gold: 85
Join Date: Oct 2012
Posts: 319
Received Thanks: 158
This was an actual method how I saved my account about 4 years ago when the account hacking was easy(?). I could keep the account online at spacemap and it was always a mark that if my ship was moving, I knew someone was on my account. So fast login to backpage and changing the password and all was good.

However nowadays it's:

1. Impossible(?) to get into your account without knowing the username and password or sid (point: unable(?) to crack).
2. Even if it happens, the infinite connection bug might **** up your chances to save your account.

Just don't know should I laugh or cry, maybe just be neutral as the game sucks and idc if someone steals my acc. xD
:thonking: is offline  
Thanks
2 Users
Old 04/17/2018, 12:01   #9
 
skeith_sk8's Avatar
 
elite*gold: 0
Join Date: May 2012
Posts: 3,053
Received Thanks: 2,658
As a little update on this thread i can say that they finally patched this issue (partially). Since some days/weeks you can only keep the connection till the next server restart. After that, the client windows will not longer provide you the access to the account.
skeith_sk8 is offline  
Thanks
3 Users
Old 04/18/2018, 15:10   #10
 
elite*gold: 0
Join Date: Nov 2011
Posts: 53
Received Thanks: 6
so there is possibility to connect to an account with only SID?
grimreaper13 is offline  
Old 04/18/2018, 23:19   #11


 
PNTX's Avatar
 
elite*gold: 43
Join Date: May 2012
Posts: 1,562
Received Thanks: 729
Quote:
Originally Posted by grimreaper13 View Post
so there is possibility to connect to an account with only SID?
there is. and always was.
PNTX is offline  
Old 04/19/2018, 00:32   #12
 
elite*gold: 0
Join Date: Nov 2011
Posts: 53
Received Thanks: 6
Quote:
Originally Posted by PNTX View Post
there is. and always was.
how is that even possible? :O
grimreaper13 is offline  
Old 04/19/2018, 07:35   #13
 
skeith_sk8's Avatar
 
elite*gold: 0
Join Date: May 2012
Posts: 3,053
Received Thanks: 2,658
Quote:
Originally Posted by grimreaper13 View Post
how is that even possible? :O
skeith_sk8 is offline  
Thanks
1 User
Old 04/19/2018, 17:45   #14
 
manulaiko3.0's Avatar
 
elite*gold: 0
Join Date: May 2014
Posts: 663
Received Thanks: 1,154
Quote:
Originally Posted by grimreaper13 View Post
how is that even possible? :O
The Session ID is a unique 32char hex identifier that is randomly generated with each login. It's not any kind of security vulnerability, in fact is used everywhere you can login, it's just how the internet works.
manulaiko3.0 is offline  
Reply


Similar Threads Similar Threads
Response from Gm regarding ts1 and the situation regarding ts2
11/14/2014 - 12Sky2 - 7 Replies
Hungames is an independent company as it seems, ts2.5 is the latest korean version of the game and alt1 agreed to make a version for us as well, and here is the key part of the gms response hi there, sorry for the late reply. "1. TS1, we can open it, but now it's not a good time. when Hun TS2 bacome more stabilized we'll try to wrok on it. 2. 2.5 is actually a newest Korean version. and they have more contents that other servers dont have. and yes, also we will work on our own contents...
Gen Sid v0.3 =Darkorbit SID Generator=
10/08/2011 - DarkOrbit - 14 Replies
Removed by Limited™
[Remote Login Issue] Expired Security certificate
01/07/2011 - Shaiya Private Server - 0 Replies
Hi guys, i am having a small (and newly developed) issue with 1 of 4 computers and cant seem to figure why. Comp #1 Windows 98 SE 16 bit FAT Comp #2 Windows XP Pro 32bit NTFS Comp #3 Vista Premium 64bit NTFS Comp #4 Windows 7 MC 32bit NTFS Before NYE all where able to connect remotely to the server, when i returned from 2 days break Comp #3 will no longer connect and displays a warning that the certificate has expired. And as luck would have it, the #3 Comp is the newest/most...
was die SID?whats the SID?
11/07/2010 - Browsergames - 3 Replies
Hallo beim Ibot muss mann ja SID angeben was ist die und wo finde ich diese? bitte um hilfe Hello at the Ibot I musst do give on an SID whats that and where is it? sorry für das schlechte englisch xD/Sorry for the bad english xD



All times are GMT +1. The time now is 01:20.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.