Graal Forums  

Go Back   Graal Forums > Development Forums > Tech Support
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 07-24-2003, 04:50 AM
TribulationStaff TribulationStaff is offline
Registered User
Join Date: Jul 2003
Location: Pennsylvania
Posts: 368
TribulationStaff is on a distinguished road
Send a message via AIM to TribulationStaff
Exclamation Urgent Rc Bug!!!

A nonstaff was able to log into our RC

New RC: KuJi *Manager* (Admin-Playerworld15)
KuJi *Manager*: O.o
KuJi *Manager*: Wts
KuJi *Manager*: Hi?
Giltwist (GM): hat the?
Giltwist (GM): Who the heck are you?
TribulationStaff loaded the rights of Admin-Playerworld15
Giltwist (GM): you aren't on the staff list
KuJi *Manager*: wts
KuJi *Manager*: I just logged on
KuJi *Manager*: Wow this is wierd
Madmartigan: wtf
KuJi *Manager*: Donno
Giltwist (GM): ill solve this
Madmartigan: what admin are you using?
Madmartigan: what number?
Welcome to the NPC-Server for playerworld1
New NC: TribulationStaff
New NC: Admin-Playerworld1
NC disconnected: TribulationStaff
TribulationStaff disconnects Admin-Playerworld15
RC disconnected: Admin-Playerworld15
Madmartigan: I wonder if it has something to do with him having an Admin-Playerworld15 and mine being a 1
__________________


Help me keep scripting
Reply With Quote
  #2  
Old 07-24-2003, 05:06 AM
draygin draygin is offline
Telmont Bandit
draygin's Avatar
Join Date: Feb 2002
Location: Ohio
Posts: 2,550
draygin is on a distinguished road
Yes very annoying thankfully this bug didnt also include rights with it. As of now I've added an ip range of 0 to all the admin RC's so none of them except mine Admin-Playerworld1 can log on to the server. But I definatly think this needs fixed pronto.
__________________

I stole Spanky's gold!
Reply With Quote
  #3  
Old 07-24-2003, 03:56 PM
Skyld Skyld is offline
Script-fu
Skyld's Avatar
Join Date: Jan 2002
Location: United Kingdom
Posts: 3,914
Skyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud of
Send a message via AIM to Skyld
hmmm

I think I know the problem.
If you have the rights to get into staff accounts and edit the account, one of the fields is adminworlds.
If that's set to all, I think it automatically overrides serveroptions checks.
I dont know, it just could be.
__________________
Skyld
Reply With Quote
  #4  
Old 07-24-2003, 04:58 PM
Spark910 Spark910 is offline
Ex-Graal Global
Spark910's Avatar
Join Date: Oct 2001
Location: England
Posts: 10,892
Spark910 has a spectacular aura about
Re: hmmm

Quote:
Originally posted by Skyld
I think I know the problem.
If you have the rights to get into staff accounts and edit the account, one of the fields is adminworlds.
If that's set to all, I think it automatically overrides serveroptions checks.
I dont know, it just could be.
hmm I think all PW-Admin accounts can log onto all RCs. Of all PW servers paid for. I suspected this a while back, I didnt say anything as well they wouldnt have rights, and I had no proof, and it was possibly me being stupid.
__________________
--Spark911
Reply With Quote
  #5  
Old 07-24-2003, 09:19 PM
draygin draygin is offline
Telmont Bandit
draygin's Avatar
Join Date: Feb 2002
Location: Ohio
Posts: 2,550
draygin is on a distinguished road
No, thats not it spark because I cant log on to other servers. (I tried just to see)

What I think is there is some sort of security check to see if they can log on to the server with out being on the staff list. Example my server the check is Admin-Playerworld1 but it doesnt stop at the 1 so any one with anything after 1 example Admin-Playerworld15 Admin-Playerworld11 can log on to server number 1 because it matches the security check. Just my theory any how. Either way no problem on server one since we set ip ranges on all admin RC's to 0.0.0.0
__________________

I stole Spanky's gold!
Reply With Quote
  #6  
Old 07-24-2003, 09:31 PM
Python523 Python523 is offline
Banned
Join Date: Aug 2001
Location: Illinois
Posts: 3,498
Python523 is on a distinguished road
Re: hmmm

Quote:
Originally posted by Skyld
I think I know the problem.
If you have the rights to get into staff accounts and edit the account, one of the fields is adminworlds.
If that's set to all, I think it automatically overrides serveroptions checks.
I dont know, it just could be.
Obviously not, then they would be able to give themselves a better adminlevel

The problems is that all the admin world has to do is contain the gserver's name, example:
my debug account, Jagen, has adminworld as graal2002d,sdev, and it can log on 2k2 rc, since it contains 'graal2002' as adminworld
Reply With Quote
  #7  
Old 07-24-2003, 10:15 PM
draygin draygin is offline
Telmont Bandit
draygin's Avatar
Join Date: Feb 2002
Location: Ohio
Posts: 2,550
draygin is on a distinguished road
Re: Re: hmmm

Quote:
Originally posted by Python523


Obviously not, then they would be able to give themselves a better adminlevel

The problems is that all the admin world has to do is contain the gserver's name, example:
my debug account, Jagen, has adminworld as graal2002d,sdev, and it can log on 2k2 rc, since it contains 'graal2002' as adminworld
So I was right. Stefan really needs to fix that. :o Talk about a major snafu I dont want just any idiot being able to log onto my server because of a glitch and if in an off chance we ever get to the hundreds thats going to be an annoying hassle as I'll have to set IP ranges on over a hundred RC's..
__________________

I stole Spanky's gold!
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 04:49 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.