![]() |
Protect RCs with your own proxy server!
If you want to protect your staff RCs, then create a proxy server on your High speed cable or faster connection.
Make sure you need a username and password to use the Proxy, or else anyone would be able to use them. Once you have a proxy address working, have your staff insert the information in their browser properties. (Such as MSIE5&6). Then set the IP range for your proxy for each member. This makes it so any outside intruder cannot connect due to an incorrect IP address. :) |
What's wrong with the standard method of IP Ranges?
|
Yeah, saying /openrights <acc> and inserting an IP is much easier :P
|
Maybe a proxy is more "secure"....In SOME way....Ive also heard of people changing their IP adresses. But im not sure if it actually works.
|
The idea of the proxy server is pretty nice. Unfortunately, Graal "leeb hax0rs" steal passwords. They could just as easily steal the proxy password, and then they have all the staff on your server's RCs in their grasp. It would be better to stick with standard IP ranges, in my opinion. And yes, LordVyse, you can 'spoof' an IP range with illegal programs.
|
Yeah, Tortoise does that all the time.
|
This is by far the stupidest way to bypass RC's security features I have ever read. If you can set their range to your proxy and ask for trouble, you can set their IP range on RC and be more safe.
|
Perhaps none of you fully understand the technology behind the idea of the Proxy server. But if you wish, feel free to use it or not use it, but you can load more then one proxy address at a time and give each individual his or her on proxy IP.
Stealing Proxy passwords is far more complicated then stealing a Graal RC password. If setup correctly, a proxy password can be encrypted in 256bit. Much higher then Graals encryption. I run a proxy server and I give my friends individual proxy IP address to access vital information on my web server, and out of thousands of attacks, none of them have yet gotten close to cracking through and mine is only set to 128 encryption. |
Quote:
|
Rather than cracking your password, it's much more likely they'd find the password in a text file on a stupid user's computer and simply have to enter it.
|
Quote:
People don't brute force graal passwords, pal. Staff are idiots who get trojans and have their passwords stolen. |
Wow, a few brain cells of mine died after reading this. For a second there I thought this was a good idea. x_x
|
Proxies are useful for some things, but this misfeature just makes life easier for those who would seek to compromise your server. Which of these two scenarios looks easier to you?
"Hmm! I can break GrowlZ' randomly-generated password, then somehow find a way to spoof a TCP connection as coming from me even if GrowlZ is offline and I can't dupe his computer into communicating with me instead of listserver.graalonline.com!" or.. "I'll get this idiot's password and proxy password over Windows File Sharing then I'll log into his RC with no IP spoofing whatsoever needed. Yay!" Every little helps. And proxies do have legitimate uses in some things, without a doubt. But IP ranges are there for a reason and should be used whereever possible. |
Quote:
..lol ^^ |
Quote:
|
All times are GMT +2. The time now is 10:01 AM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.