Register for your free account! | Forgot your password?

You last visited: Today at 04:31

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Guide] All Devs Read!

Discussion on [Guide] All Devs Read! within the Shaiya PServer Guides & Releases forum part of the Shaiya Private Server category.

Reply
 
Old   #1
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
Exclamation [Guide] All Devs Read!

I have spent some time thinking about this...I relized fully that if i were to post it, it would do 2 things.

1. Owners that were active to E*pvpers would get tighter security for there server.
2. n00bs would be n00bs with the information...

I came to the conclusion last night that it was time i relised this. If people would want to lern how to hack AND WERE SERIOUS ABOUT IT!! the bits and piceaces i am going to post here would'nt be enough. So here it is Banes latest guide. Preventing hackers.

Ok, remeber when we all lived in the age were we thought hacking was just like in The Matrix?? a black program that only pros had and serious hackers could obtain. Well now we are somewhat more enlightend but some of us still don't know what they use...
Programs like: SQLping, Cain and Able, and Brute forcing devices are what they truley use. Now before you go Google crazy and relize these are all OPEN SOURCE programs (free ware) also know prevention of them are Open source aswell.
Ok first lets lean to know our enemy. Ok i am going to take a Paragraph that best discribes hackers from The Hacker Pragidem by Rich Christen
"hacker population is predominantly made up of adolescent males. This is often the image portrayed throughout the media. However, there seems to be more and more of an increase in self described female hackers as well. Since hacking is a relatively new element of society, many of the young adolescent hackers from years ago are now older and still claim to be hackers in some sense, whether it be a System Administrator with a hacker background, a Computer Security Expert, or even a programmer. Perhaps if the stereotype of hackers were to be less restrictive, such as not being all adolescent males, the hacker community would then gain many more new "hackers" and new perspectives and thus giving the media another focus." (full essay here )

Now let us start with the most common Hacker target Passwords: Now i also want to note that the is acctualy more dricted to you're website password. BUT don't think that you are secure even if you have a long password....you might not be. Also rember you're site is the MOST vital part of you're server. only because it provides the information of upcoming news.

Now here is what you DON'T want to do with you're password Easy to guess.
Seldom changed. Reused for many security points. (IE you use the password for alot of diffrent sites.

Also do not use programs that keep you're password in a memory file. or weaks file encriptions.

Dictionary attacks

Now before you imagine a hacker sitting there with a dictionary putting every singel word in the space...that's not what this is. A dictinaory attack is used by a program that breaks a few line's of the website and trys hundreds (to hundreds of thosands) of common passwords and dictionary passwords. Also some of these dictonary can contain multiple launguge passwords and leet speak passwords.. IE p@$$w0rd.

to stop this simpley make sure you'r password is long NUMERICL valude password IE 29976432Gl123 (feel free to write this down and lock it in a closet or something till you memirize it.)

Brute force attacks.

brute force attacks are programs that take well..infenitly generate passwords and atempt a login with it. probleme is they take days to work so the smart solution to not getting a brute force hacked is changing every month (use 3 passwords and alter)

Keystorke logger

This is by far the easyest way to "crack" a password. All hackers have to do is send you a file with a logger on it and it records you're history and keystrokes. simple solution hear though. ALWAYS SCAN FILES!

Next portion: Network hacking.

Before you even think you are secure rember you're network must be secure too. this means: you're host, VPN, firewall, and ETC.

Scanning

The fatal first step hackers will take is scanning. If you're network was weak and the scan was right then the hacker now know all they need to to bring you're server down. After a common scan they will know: provider, ports, System, and in some cases back doors to ******* you'r server.

According "How to hack for dummies" these are the most common scaned and hacked ports

7 Echo TCP, UDP
19 Chargen TCP, UDP
20 FTP data (File Transfer Protocol) TCP
21 FTP control TCP
22 SSH TCP
23 Telnet TCP
25 SMTP (Simple Mail Transfer Protocol) TCP
37 Daytime TCP, UDP
53 DNS (Domain Name System) UDP
69 TFTP (Trivial File Transfer Protocol) UDP
79 Finger TCP, UDP
80 HTTP (Hypertext Transfer Protocol) TCP
110 POP3 (Post Office Protocol version 3) TCP
111 SUN RPC (remote procedure calls) TCP, UDP
135 RPC/DCE (end point mapper) for Microsoft
networks
TCP, UDP
137, 138, 139, 445 NetBIOS over TCP/IP TCP, UDP
161 SNMP (Simple Network Management
Protocol)
TCP, UDP
443 HTTPS (HTTP over SSL) TCP
512, 513, 514 Berkeley r-services and r-commands (such
as rsh, rexec, and rlogin)
TCP
1433 Microsoft SQL Server (ms-sql-s) TCP, UDP
1434 Microsoft SQL Monitor (ms-sql-m) TCP, UDP
1723 Microsoft PPTP VPN TCP
3389 Windows Terminal Server TCP
5631, 5632 pcAnywhere TCP
8080 HTTP proxy TCP

So to prevent simpaly secure these ports.

DDOS

No matter who you are you will always be a possible target for Denial of Service attacks.

Now if we were running a real game or a inportent website we COULD have the risk of getting a 50K zombie comp attack. Fortunately all we relay have to worry about is 10-100 attacks (the largest attack being on evo and it was assumed it was a paied attack)

Ok, one attack choice hackers have is the SYN attack. In a SYN Flood, the attack works by overwhelming the protocol handshake that has to happen between two Internet-aware applications. How can we stop this. We don't need a high power application just a firewall that scans trafic and blocks bad internal IPs.

Next up is some good applecations that stop a DDOS 1 good application is (notice some are not very cost effecient but are 2 as stronge)

Last is staying up to date with DDOS breakthroughs and the tools they use. I highly recomend checking this website once a day as it updates periodically with new DDOS and the tools they use.

APR poisoning

Now there is soo much on Network hacking i just can't cover it. But i will cover the most dealdy APR posion. ARP poisoning can be hazardous to your network’s hardware and health,
causing downtime and more. So be careful! To prevent.

Never go to a driect IP hosted domain.
Never go to site that look odd or strange.
Never open a Tiny URL link from someone you do not know.


Next is what is most inportent to us pserver devs. The Database hacks.

Run your databases on different machines.
Check the underlying operating systems for security vulnerabilities.
Ensure that your databases fall within the scope of patching and system
hardening.
Require strong passwords on every database system.
Use appropriate file and share permissions to keep prying eyes away.
De-indentify any sensitive production data before it’s used in development
or QA.
Check your Web applications for SQL injection and related input validation
vulnerabilities.
Use a network firewall, such as those available from Juniper Networks —
formerly NetScreen

Those are only some common ways to keep it from getting hacked.


I tried to keep this guide at straight and to the point as i could.

Also i will update this periodicly adding sections. So don't worry.

If you have a story or anymore Anti-Hacking ways. please post here. I would also like to see feedback...

How do i know if someone can MMSQL/MYSQL inject me or my website??????? :'(

Very simple acctualy, let me first give a example of MYSQL injecting a server.

First you would want to navigate over to

A) char res script
B) regestration script.

Then in the username and password type 1=1-- or hi'

if you were able to register, then there is a possibility, another good test is if you can make a account with over 14 characters or with no password....

If you use a MYSQL Database then testing you're website is simple too just find a UR that looks like hackerszbeware.com/index.asp?id=10 then simpley add a ' or 1=1-- after the ? or at the end of the URL, if you come back with MYSQL error, then you need to bost some security.

Also be aware that pages with ASP, JSP, CGI, or PHP web pages are SQL injectible.....

-Bane
Bаne is offline  
Thanks
71 Users
Old 01/19/2011, 02:02   #2
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
People i would like to thank.

ZeroSignal for one. about a year ago a guide like this would have ****** me off.

See i use to be a "bad guy" and reading his post and the article that he had in his sig...made me want to be idk better about my internet knowldge.

don't know if he knows this but i hate "crackers" and ever since i have read that guide i have been trying my hardest to get into the HackerDom society...Mabey this helped a little xD

Next is TexasPride as you all know him by. He was the one to give me my first REAL GM job and well after recent hacks on unity i became more intrested in makeing this guide.

Then OFC is Scruple and Jade. You two are the great freinds and i realy am glad to know both of you...even if you guys own my soul.....

Last is Allio. Where would i be if i did not have you to annoy while i was takeing breaks.

Thank you all.

Edit: also please feel free to add feedback.

Bane
Bаne is offline  
Thanks
4 Users
Old 01/19/2011, 03:21   #3
 
elite*gold: 0
Join Date: Feb 2009
Posts: 94
Received Thanks: 17
Don't mind bumping this, or maybe even requesting it be stickied somewhere, with more and more servers popping up, it's imperative reading. maybe now people will understand that running a server is more then just making sure people can log on, it can be a full time job.
sunder702 is offline  
Old 01/19/2011, 03:22   #4
 
elite*gold: 0
Join Date: Jul 2010
Posts: 498
Received Thanks: 449
Hello bane,

Ok nice guide but i think it's sort of common sense. Anyone slightly serious in making a shaiya server should make sure to work in a secured environment. It's like using a seat belt in a car.

If you dont use it and die stupidly in a car accident you cant complain.
Alladrios is offline  
Old 01/19/2011, 03:26   #5
 
elite*gold: 0
Join Date: Jan 2011
Posts: 6
Received Thanks: 5
Actually i have to say, i don't use any of these things you said and i can keep shutting servers down.
becareful people, i'm around...
and i have a list of my next targets..
DB's deleted... sql injections... everything on these nubbins securities.
btw nice server Alladrios, maybe you are on the list =]
DoNotLie is offline  
Old 01/19/2011, 03:27   #6
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
Quote:
Originally Posted by Alladrios View Post
Hello bane,

Ok nice guide but i think it's sort of common sense. Anyone slightly serious in making a shaiya server should make sure to work in a secured environment. It's like using a seat belt in a car.

If you dont use it and die stupidly in a car accident you cant complain.
I posted it since this is the age of the internet.

Not only do you need this for a server but some people need it for alot more....Also like sunder said, most devs here only think that makeing and running a server is being able to let people log in.

-Bane
Bаne is offline  
Thanks
1 User
Old 01/19/2011, 03:34   #7
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
Quote:
Originally Posted by DoNotLie View Post
Actually i have to say, i don't use any of these things you said and i can keep shutting servers down.
becareful people, i'm around...
and i have a list of my next targets..
DB's deleted... sql injections... everything on these nubbins securities.
btw nice server Alladrios, maybe you are on the list =]

Acctualy fine sir (and sorry for the double post) there is always someone better then you, hate to say it.

See i only scratched the surface on this guide but i do attend to bring more information.

All you're tools IE SQLping Cain and Able Netwarz and so on are all free ware. And there is always counter mesure freeware on it.

And even if you are using paid for tools...still there are mesures that can stop them. I very much attend to bring them all into the light too.

-Bane
Bаne is offline  
Thanks
2 Users
Old 01/19/2011, 09:23   #8
 
AriezOMG's Avatar
 
elite*gold: 100
Join Date: Mar 2009
Posts: 552
Received Thanks: 1,009
Bane, I would like to know what your wall of text says, without reading all of it, as I read extremely slowly and I realize that others may also have this problem, please put a summary at the bottom. Btw, I noticed you're now Jade's *****, that's probably not a good thing, but good luck with it o.O

Edit: Okay.. I read it sir and I don't understand why ZeroSignal and a thread like this about a year ago would have ****** you off, what's going on there?
AriezOMG is offline  
Old 01/19/2011, 09:33   #9
 
elite*gold: 46
Join Date: Nov 2009
Posts: 1,400
Received Thanks: 4,249


well from that part i already red ... i think most devs knows about that..
[Dev]Ansem is offline  
Old 01/19/2011, 13:41   #10
 
elite*gold: 0
Join Date: Aug 2010
Posts: 241
Received Thanks: 255
You forgot about DDoS ^^
zargon05 is offline  
Old 01/19/2011, 16:11   #11
 
Danco1990's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 348
Received Thanks: 260
How about we target the hackers and take them down? If we do it a few times they get sick of it and eventually stop -.-'. I admit, most of you people know my by another name, i used to hack too, but i changed my path, and i try to find ways to prevent it from happening. Alot of usefull scripts can be found RIGHT HERE on Elitepvpers. And DoNoLie? I believe you deserve a ban just for threatening someone. I would like to know who you really are... Either case, every server has tis own specialities, and i would like to see one day that we can all work along. I am STILL working on my matrix program, and i think i found a way how to use different DB's, so we could link ALL servers in one login server, and redirect it to the right server, bit complicated progress. Either case, off topic here, Bane, once again nice post, we could use some more people who want to avoid hacking!
Danco1990 is offline  
Thanks
1 User
Old 01/19/2011, 23:10   #12
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
Everyones questions.

1. Greester. most devs not all.
2. Ariez i love being jades *****.
3. Zargon More info comeing soon, i am adding script prevention SQL injection and DDOs
4. Ariez. If you knew more about zerosignal you would know..
Bаne is offline  
Old 01/19/2011, 23:41   #13
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
# added bold indecaters.

# added DDOS
Bаne is offline  
Old 01/22/2011, 21:44   #14
 
KaliKid's Avatar
 
elite*gold: 0
Join Date: Jun 2009
Posts: 95
Received Thanks: 58
1) As Alladrios basically said, if you don't already know most of this stuff, you shouldn't really be running a public server.

2)Brute Force - most decent programs/websites prevent you from attempting to log in multiple times with wrong pass/usernames anyway. If not, your best bet is to use long passwords with a mix of letters and numbers. Also make it as random as possible, keywords are easy guess.

3)Saying to secure your ports and scan your files doesn't really give any form of information.

4) Users and Admins/Devs should be wary of phishing and setting different passwords for website and in game accounts. You'd be surprised how many people use the same password for everything and every account they use.

5) Not sure how a keylogger is relevant to Devs, assuming they use dedicated/vps server hosts. A keylogger is just as it says, it logs anything type on a keyboard. This would be more of an issue for players who download things they shouldn't.
KaliKid is offline  
Thanks
1 User
Old 01/29/2011, 19:39   #15
 
Bаne's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 2,334
Received Thanks: 1,777
#bump
#NEW guide comeing soon. it's a secret ATM tho.
Bаne is offline  
Thanks
1 User
Reply


Similar Threads Similar Threads
[GUIDE]Before posting read this
06/18/2010 - CO2 PServer Guides & Releases - 6 Replies
Okay, there is alot questions going around. They of course deserv help. But how much help? Well, I think is on time they learn about, when they should get helped and when they deserv it. What do you need to do first? As this section have alot to do with programming. If it's c#, c++, c, php etc. Then you should learn some things about the stuff you are going to use. It will help you alot and it will help us alot, because then we actually can talk same language. (language?). Then you...
Looking for Website devs / Client devs
05/20/2010 - General Gaming Discussion - 0 Replies
Hey, we are looking for some website dev's : what u need to do : creating scripts in php/html for a control panel, or change the site etc. or client dev's. Just PM me and we will decide if we take u or not. greetz.
[Event + Guide] Your 1 Stop "Children's Week" Guide for 2009! >> MUST READ!
05/03/2009 - WoW Guides & Templates - 2 Replies
Children's Week 2009 http://www.worldofwarcraft.com/info/events/childr ensweek/images/ss1-thumb.jpghttp://www.worldofwarc raft.com/info/events/childrensweek/images/ss2-thum b.jpg Blizzard Official Details: World of Warcraft-> Info -> Events -> Children's Week Beginning: May 1st - Saturday End: May 7th Why the hell should I do this? I don't know about you, but the end reward of a 310% mount sounds good, in addition to the many minipets...
[Event + Guide] Your 1 Stop "Love is in the Air" Guide for 2009! MUST READ!
02/12/2009 - WoW Guides & Templates - 3 Replies
I know I'm about two days early, but it takes quite a bit of time to write. I will make this as neat as possible, splitting up the Alliance and Horde quests for instance. http://images2.wikia.nocookie.net/wowwiki/images/2 /21/Orc_Lovers_Heart_Valentines.jpg Blizzard Official Details: WoW -> Info -> Events -> Love is in the Air Beginning: 11th of February End: 16th of February Why the hell should I do this? I don't know about you, but the end reward of a 310% mount sounds good. ...
HOW TO GET 2 GUIDE EVERYDAY ?? READ THIS !!!
09/18/2008 - Zero - 7 Replies
hi everyone...:D how to get 2 Guide everyday...for fast plvl ur noob ?? that so easy...:D Follow the Instructions: 1. After u see Warning SERVER CAN BE BROUGHT..u have 1 guide (new days).. 2. GIVE U GUIDE to Noob.... 3. Log out the noob before server brought 4. Dont ever ur LOG OUT the main Character...just w8 DISCONNECTING...from server...



All times are GMT +1. The time now is 04:31.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.