Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Shaiya > Shaiya Private Server
You last visited: Today at 22:24

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[REQUEST]{URGENT}

Discussion on [REQUEST]{URGENT} within the Shaiya Private Server forum part of the Shaiya category.

Reply
 
Old   #1
 
Danco1990's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 348
Received Thanks: 260
Exclamation [REQUEST]{URGENT}

It seems the databases are stored in plaintext. abrasive Proved me it is easy to hack the normal databases. Therefor im requesting a way how to secure it by md5 or whatever is neccesary to make sure people can't read out data OR write in the db (apart from regpage and reading the pvp ranks).

Does anyone know how to succeed in securing a DB like stated and willing to share the information?
Danco1990 is offline  
Old 08/26/2010, 01:19   #2
 
[GM]Father's Avatar
 
elite*gold: 0
Join Date: Aug 2010
Posts: 136
Received Thanks: 343
Better test these changes on a private server before you take it live. Otherwise your 99% uptime is going to be greatly affected.
[GM]Father is offline  
Old 08/26/2010, 01:20   #3
 
Danco1990's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 348
Received Thanks: 260
Got 2 testservers running, im striving to make sure all my promises are kept, so i need a fix quick .
Danco1990 is offline  
Old 08/26/2010, 01:31   #4
 
nXu's Avatar
 
elite*gold: 0
Join Date: Oct 2009
Posts: 208
Received Thanks: 40
Well... since the login is using the plaintext password, i'm not sure if it's possible...
But its just my oppinion
nXu is offline  
Old 08/26/2010, 04:04   #5
 
elite*gold: 0
Join Date: Aug 2010
Posts: 4
Received Thanks: 0
It is possible mine uses a one way md5 hash but i had to edit both the registration forms and the executables to do it.

I thought you said you knew all about securing servers?

Quote:
Originally Posted by Danco1990 View Post
I know how to secure servers, thats why i made a guide about it, but i also know how to get in, even IF your server is secured in every possible way... Not a tread, just a warning.
TheShaiyaSyndicate is offline  
Old 08/26/2010, 04:40   #6
 
Danco1990's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 348
Received Thanks: 260
Yup, i do know some ways, but this way i have never seen before, the path to your goal can lead in different roads you see. This kind of problem i haven't seen before. I'm working on it as we speak, should be done soon.
Danco1990 is offline  
Old 08/26/2010, 05:22   #7
 
ProfNerwosol's Avatar
 
elite*gold: 0
Join Date: Oct 2009
Posts: 449
Received Thanks: 647
Quote:
Originally Posted by Danco1990 View Post
It seems the databases are stored in plaintext. abrasive Proved me it is easy to hack the normal databases. Therefor im requesting a way how to secure it by md5 or whatever is neccesary to make sure people can't read out data OR write in the db (apart from regpage and reading the pvp ranks).

Does anyone know how to succeed in securing a DB like stated and willing to share the information?
What do you mean? Securing database? If it's your computer you are running it on just lock the ports and disable external IP for connecting to the server. If not leave it for the provider to deal with security or do you mean how to secure the scripts on website with login and password for database? Just put there httpaccess thingie and it will prevent anyone from reading that directory. It's best to keep such information in a separate file and include it when needed. There's also another thing you can do if that's on your PC. Place the file with database login outside of httpd directory. No one can access anything above httpd from the internet, but from inside the script you can.
ProfNerwosol is offline  
Thanks
1 User
Old 08/26/2010, 05:48   #8
 
Danco1990's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 348
Received Thanks: 260
I host the reg page and pvp page local, so cant put it above the public folder im afraid. The ports are all blocked out, it seemed that there is a problem with the reg scripts, im getting some help atm to get that sorted. As far as i heard, only 2 servers running now are protected from this inject. I had 2 people proving me this now. I will put up a htaccess, since that will greatly improve the security, if i put this in, this means noone can see or get a password in the processor.php if i put another one in? If this is so, i can open my port for SQL again and i can work outside my IP range.

When i figure out how to proper secure the processor script against sql injects, i MIGHT release it.
Danco1990 is offline  
Reply


Similar Threads Similar Threads
[HELP][Request][URGENT!] i need help PHP i wanna do this cool thing
05/25/2010 - CO2 Private Server - 0 Replies
i was wondering how i can do something like to make people able to change there passwords and stuff. delete there char and account if they want. when they register it'l save there email and ip addresses for account security and stuff like that and then i want to add a top player list like most PKP and stuff GW winers that would be cool can some one help me? im using a 5165 flat file aka: FF, thank you in advance!:rtfm: i know lol but i dont have one lol
[request] URGENT!!
06/27/2009 - CO2 Private Server - 6 Replies
i need the id for cpbag and cpbackpack plz :D
Urgent..
05/03/2009 - Grand Chase - 13 Replies
Mga pare .. our days may be counted .. :pimp: Board Message http://gcboards.levelupgames.ph/index.php?showtop ic=15405 read the post..:rtfm: me nagmalinis na pinoy sa Forums.. amf.. ingat nLNg mga toL.. malaki chances na sa elite to.. kahit sa google search mo Grand chase hacks lalabas kagad to.. kea kanya kanyang bantay nLng ng sariling account.. ingat guyz Peace ya'll :mofo: kea paminsan ayoko magLeech.. meron Lng talaga mahilig maglinis ng sarili neang baho... :handsdown:
URGENT! ALL SPEEDHACKERS URGENT!
04/25/2007 - Eudemons Online - 9 Replies
Hi everyone. I am an avid player of Eudemons Online and the first time i discovered AndyX's speedhack i was so happy beyond describing. About 2 weeks ago, i got caught but i got off without paying. Then 1 week ago, i was caught for the second time and i tried pretending innocent so i didnt have to pay the fee of 2760 eps to get out but this time the gm told me i was speedhacking and the location+time. all the speedhackers are slowly starting to be botjailed and this is a warning to every1....



All times are GMT +1. The time now is 22:25.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.