Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Future Improvements (https://forums.graalonline.com/forums/forumdisplay.php?f=10)
-   -   alternative to ip validation on RC (https://forums.graalonline.com/forums/showthread.php?t=61331)

prozac424242 09-21-2005 07:27 PM

alternative to ip validation on RC
 
Many people who use RC to connect are on dial up, and numerous ip additions are needed. This is sometimes a real inconvenience, and I have been on both the end of the one to update the ip list for someone, and have beem the on e to be not able to log in to rc, and needed to wait for hours for another admin to log in and update my ip list.

Not only is this a problem with dial up, but I have a comcast high speed cable modem, and it seems that they too have recently gone to DHCP, and in the past three days I have had at least five differences in my ip in the second set of numbers. for example, 64.181.*.* where the 181 is, that number almost always changes at least once, if not two or three times a day, and my cable modem is always on!

How about using the MAC address of the network card to identify a specific computer to log in? That hardware integrated number does not change unless you get a different comptuer. Or some kind of consistent number, without needing to shell out big bucks to comcast for a business account, which is the only way to get a static ip from them now.

napo_p2p 09-21-2005 08:00 PM

Stefan said something about being able to ban by "computer ID".

There should also be a way to limit the RC access to Computer ID as well.

Sildae 09-21-2005 08:49 PM

Quote:

Originally Posted by prozac424242
How about using the MAC address of the network card to identify a specific computer to log in?

That is a bad idea because MAC addresses are rather easy to spoof.

Quote:

That hardware integrated number does not change unless you get a different comptuer.
Yes, it does. Also, what about people who connect to the internet without a network card? The IP address is really about the only thing that cannot be manipulated by the client.


Just log the set of IP adresses you receive and make out a pattern. "All the numbers change" is not a pattern.

If there is none that Graal would be content with, settle for the most common one, and if that fails you, gain new IP adresses until you get one that matches.


And what the hell is a computer ID and why would you ban people's computers?

Ajira 09-21-2005 09:11 PM

Quote:

Originally Posted by Sildae
And what the hell is a computer ID and why would you ban people's computers?

...
The new Graal banning system uses some computer ID to ban the player therefore no account can log in. =O

Ibonic 09-21-2005 10:00 PM

Quote:

Originally Posted by napo_p2p
There should also be a way to limit the RC access to Computer ID as well.

Yes - I've suggested this to Stefan a bunch of times, the last being just a few days ago. Glad someone agrees.

Lance 09-21-2005 10:01 PM

Quote:

Originally Posted by Ibonic
Yes - I've suggested this to Stefan a bunch of times, the last being just a few days ago. Glad someone agrees.

Bad idea. It can be spoofed.

Ibonic 09-21-2005 10:04 PM

Quote:

Originally Posted by Lance
Bad idea. It can be spoofed.

True, but it's still better to have something extra for large IP ranges such as AOL. Obviously just computer ID based protection would be bad, I'll agree with that.

Inspiration 09-21-2005 11:17 PM

Perhaps a password system would achieve this, set up in this mannor.

A 56k user, or any user, logs onto RC as normal using their account name and password.

When they connect to the server via RC, no functions, nor RC chat will be available to them, and they will not appear on the playerlist.

The NPC server will then PM them asking for their RC password. This password will be able to be set and saved by a manager or admin. The player then PMs the server the password to authenticate, and if correct, RC works as normal.

While not as secure as an IP, it is for sure an extra level of protection.

Ajira 09-22-2005 12:30 AM

Quote:

Originally Posted by Inspiration
Perhaps a password system would achieve this, set up in this mannor.

A 56k user, or any user, logs onto RC as normal using their account name and password.

When they connect to the server via RC, no functions, nor RC chat will be available to them, and they will not appear on the playerlist.

The NPC server will then PM them asking for their RC password. This password will be able to be set and saved by a manager or admin. The player then PMs the server the password to authenticate, and if correct, RC works as normal.

While not as secure as an IP, it is for sure an extra level of protection.

I was going to suggest something like this. It would make things much easier for me than having to give the manager my 54364346 ips. ;)

Velox Cruentus 09-22-2005 03:18 AM

About the MAC Addresses:

It may be ease to spoof the MAC Address, but it would be hard to know what to spoof it to.
If the person managed to get their password and username, it doesn't matter whether the person is a hacker or not; They just need to ask to add their IP, and they pass in flawlessly; The staff get too used to adding IPs for that person, and the security measure is wrecked by doing so.

Sildae 09-22-2005 03:10 PM

Quote:

Originally Posted by Velox Cruentus
It may be ease to spoof the MAC Address, but it would be hard to know what to spoof it to.

Like passwords. Except that if you want to work on a server, the staff there get your MAC address.
Quote:

They just need to ask to add their IP, and they pass in flawlessly; The staff get too used to adding IPs for that person, and the security measure is wrecked by doing so.
Asking to add MAC addresses will not be much different in this regard.

raiden0899 09-22-2005 04:57 PM

Quote:

Originally Posted by Sildae
Asking to add MAC addresses will not be much different in this regard.

But MAC addresses never change so you will only need to have one or two set. When the person is hired, they can tell the admin how many MAC addresses they'll need (depending on how many different computers they use) and if anyone steals their account and password, they'll need to add one more MAC address than the player said he would need (causing the admin to become suspicious).

If you ask me, using MAC addresses is more secure than IP. A combination of the two might be better.

Velox Cruentus 09-22-2005 05:31 PM

Quote:

Originally Posted by Sildae
Like passwords. Except that if you want to work on a server, the staff there get your MAC address.

Eh? If you're staff on the server, why would you want to hack in another staff's account? I mean, you'd see it through "Change Rights" or "View Other Players" Either of these should be set only if you trust the person in the first place.

Quote:

Asking to add MAC addresses will not be much different in this regard.
Umm... MAC Addresses are diectly linked to your HARDWARE ID (CONSTANT VARIABLE). Of course, changing hardware would cause a change in MAC Address, but it would be a lot more suspectible if you changed. In that case, the person would direct to a higher staff -- Someone (supposidly) more responsible/knowledgible on the subject. Dail-up users would be getting a slack, increasing security. Static IPs can still be used for IP Checking. It's just one more set of protection. (both validating the IP and Hardware.)

Clash 09-23-2005 03:29 AM

Graalians just need to stop being *****s as far as security goes. Most of the problems with account theft is the owners themselves giving out the passwords or allowing players to send them viruses - in which case if a hacker gains access to someones passwords outside of an email account, they don't need a IP to log on. They just need to log on using the staff member's computer.

Graal's security system is far from flawless, but if a security breach occurs it's usually the fault of an ingorant staff member - not the system itself.

ForgottenLegacy 09-23-2005 04:51 AM

Quote:

Originally Posted by Clash
Graalians just need to stop being *****s as far as security goes. Most of the problems with account theft is the owners themselves giving out the passwords or allowing players to send them viruses - in which case if a hacker gains access to someones passwords outside of an email account, they don't need a IP to log on. They just need to log on using the staff member's computer.

Graal's security system is far from flawless, but if a security breach occurs it's usually the fault of an ingorant staff member - not the system itself.

Last time I checked, this was about dynamic ip ranges and not people being idiots and giving people your account and password. And also, if a player sends a virus because of an action on Graal, than (s)he (and correct me if I'm wrong, please) can be banned on Graal.


All times are GMT +2. The time now is 01:25 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.