Graal Forums  

Go Back   Graal Forums > PlayerWorlds > PlayerWorlds Main Forum
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 08-13-2004, 08:16 AM
TSonicWarp9 TSonicWarp9 is offline
I'm your Boogieman.
TSonicWarp9's Avatar
Join Date: Jun 2004
Location: USA Nebraska
Posts: 61
TSonicWarp9 is on a distinguished road
Send a message via AIM to TSonicWarp9 Send a message via MSN to TSonicWarp9 Send a message via Yahoo to TSonicWarp9
Protect RCs with your own proxy server!

If you want to protect your staff RCs, then create a proxy server on your High speed cable or faster connection.

Make sure you need a username and password to use the Proxy, or else anyone would be able to use them.

Once you have a proxy address working, have your staff insert the information in their browser properties. (Such as MSIE5&6). Then set the IP range for your proxy for each member. This makes it so any outside intruder cannot connect due to an incorrect IP address.

__________________
All you know is alone. You see a Phantom Stranger. Down you go, all alone. You love my Phantom Stranger.

That young generation, that sick generation.
Rob Zombie ft Trina and Lionel Richie - House of 1000 Corpses - Brickhouse 2003.mp3
Reply With Quote
  #2  
Old 08-13-2004, 09:09 AM
Scott Scott is offline
Yoonacorn
Join Date: Oct 2003
Location: Canada
Posts: 3,572
Scott is on a distinguished road
Send a message via MSN to Scott
What's wrong with the standard method of IP Ranges?
__________________
Acornlique.
Reply With Quote
  #3  
Old 08-13-2004, 09:26 AM
ThinkDifferent ThinkDifferent is offline
Banned
ThinkDifferent's Avatar
Join Date: Jul 2004
Location: Apple Labs
Posts: 290
ThinkDifferent is on a distinguished road
Send a message via AIM to ThinkDifferent Send a message via MSN to ThinkDifferent
Yeah, saying /openrights <acc> and inserting an IP is much easier :P
Reply With Quote
  #4  
Old 08-13-2004, 03:53 PM
matt8891 matt8891 is offline
Registered User
matt8891's Avatar
Join Date: Jul 2003
Location: New York
Posts: 0
matt8891 is on a distinguished road
Send a message via AIM to matt8891 Send a message via Yahoo to matt8891
Maybe a proxy is more "secure"....In SOME way....Ive also heard of people changing their IP adresses. But im not sure if it actually works.
Reply With Quote
  #5  
Old 08-13-2004, 04:32 PM
XiLe XiLe is offline
Lylic < Me
XiLe's Avatar
Join Date: Dec 2002
Location: My House
Posts: 224
XiLe is on a distinguished road
Send a message via AIM to XiLe Send a message via MSN to XiLe
The idea of the proxy server is pretty nice. Unfortunately, Graal "leeb hax0rs" steal passwords. They could just as easily steal the proxy password, and then they have all the staff on your server's RCs in their grasp. It would be better to stick with standard IP ranges, in my opinion. And yes, LordVyse, you can 'spoof' an IP range with illegal programs.
__________________
AIM: xilesaim MSN: [email protected]
I'm the Co-Owner of Atrius... If you've got questions, ask me
Reply With Quote
  #6  
Old 08-13-2004, 05:54 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Yeah, Tortoise does that all the time.
__________________
Reply With Quote
  #7  
Old 08-13-2004, 08:11 PM
Lance Lance is offline
dark overlord
Lance's Avatar
Join Date: Sep 2003
Location: Space Jam Mountain
Posts: 5,072
Lance is on a distinguished road
This is by far the stupidest way to bypass RC's security features I have ever read. If you can set their range to your proxy and ask for trouble, you can set their IP range on RC and be more safe.
Reply With Quote
  #8  
Old 08-18-2004, 04:58 AM
TSonicWarp9 TSonicWarp9 is offline
I'm your Boogieman.
TSonicWarp9's Avatar
Join Date: Jun 2004
Location: USA Nebraska
Posts: 61
TSonicWarp9 is on a distinguished road
Send a message via AIM to TSonicWarp9 Send a message via MSN to TSonicWarp9 Send a message via Yahoo to TSonicWarp9
Perhaps none of you fully understand the technology behind the idea of the Proxy server. But if you wish, feel free to use it or not use it, but you can load more then one proxy address at a time and give each individual his or her on proxy IP.

Stealing Proxy passwords is far more complicated then stealing a Graal RC password.
If setup correctly, a proxy password can be encrypted in 256bit. Much higher then Graals encryption.

I run a proxy server and I give my friends individual proxy IP address to access vital information on my web server, and out of thousands of attacks, none of them have yet gotten close to cracking through and mine is only set to 128 encryption.
__________________
All you know is alone. You see a Phantom Stranger. Down you go, all alone. You love my Phantom Stranger.

That young generation, that sick generation.
Rob Zombie ft Trina and Lionel Richie - House of 1000 Corpses - Brickhouse 2003.mp3
Reply With Quote
  #9  
Old 08-18-2004, 12:38 PM
Spark910 Spark910 is offline
Ex-Graal Global
Spark910's Avatar
Join Date: Oct 2001
Location: England
Posts: 10,892
Spark910 has a spectacular aura about
Quote:
Originally Posted by TSonicWarp9
If setup correctly,
Yeah, but if it's not it would be less secure :X
__________________
--Spark911
Reply With Quote
  #10  
Old 08-19-2004, 02:24 AM
HoudiniMan HoudiniMan is offline
Playerworld Administrator
HoudiniMan's Avatar
Join Date: Dec 2001
Location: Calfiornia - USA
Posts: 3,512
HoudiniMan will become famous soon enough
Rather than cracking your password, it's much more likely they'd find the password in a text file on a stupid user's computer and simply have to enter it.
__________________
-HoudiniMan (Chief Playerworld Administrator)
Compulsive Support Center Checker - 5 Years and Change
Graal Support Center

Reply With Quote
  #11  
Old 08-19-2004, 03:02 AM
Python523 Python523 is offline
Banned
Join Date: Aug 2001
Location: Illinois
Posts: 3,498
Python523 is on a distinguished road
Quote:
Originally Posted by TSonicWarp9
Perhaps none of you fully understand the technology behind the idea of the Proxy server. But if you wish, feel free to use it or not use it, but you can load more then one proxy address at a time and give each individual his or her on proxy IP.

Stealing Proxy passwords is far more complicated then stealing a Graal RC password.
If setup correctly, a proxy password can be encrypted in 256bit. Much higher then Graals encryption.

I run a proxy server and I give my friends individual proxy IP address to access vital information on my web server, and out of thousands of attacks, none of them have yet gotten close to cracking through and mine is only set to 128 encryption.
-___________________-
People don't brute force graal passwords, pal. Staff are idiots who get trojans and have their passwords stolen.
Reply With Quote
  #12  
Old 08-19-2004, 04:40 AM
Deek2 Deek2 is offline
Registered User
Join Date: May 2002
Location: Springfield, Missouri
Posts: 1,578
Deek2 is on a distinguished road
Wow, a few brain cells of mine died after reading this. For a second there I thought this was a good idea.
Reply With Quote
  #13  
Old 08-19-2004, 06:11 PM
GrowlZ1010 GrowlZ1010 is offline
defunct
Join Date: May 2002
Posts: 187
GrowlZ1010 is on a distinguished road
Proxies are useful for some things, but this misfeature just makes life easier for those who would seek to compromise your server. Which of these two scenarios looks easier to you?

"Hmm! I can break GrowlZ' randomly-generated password, then somehow find a way to spoof a TCP connection as coming from me even if GrowlZ is offline and I can't dupe his computer into communicating with me instead of listserver.graalonline.com!"
or..
"I'll get this idiot's password and proxy password over Windows File Sharing then I'll log into his RC with no IP spoofing whatsoever needed. Yay!"

Every little helps. And proxies do have legitimate uses in some things, without a doubt. But IP ranges are there for a reason and should be used whereever possible.
Reply With Quote
  #14  
Old 08-20-2004, 08:00 PM
Curt1zzle Curt1zzle is offline
Starting not to love you
Curt1zzle's Avatar
Join Date: Sep 2003
Posts: 3,669
Curt1zzle has a spectacular aura about
Send a message via AIM to Curt1zzle
Quote:
Originally Posted by Python523
-___________________-
People don't brute force graal passwords, pal. Staff are idiots who get trojans and have their passwords stolen.
LOLLOLOLOL.



..lol
__________________

This message has been deleted by Sam. Reason: you should better stop it now
Reply With Quote
  #15  
Old 08-20-2004, 08:02 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by Python523
-___________________-
People don't brute force graal passwords, pal. Staff are idiots who get trojans and have their passwords stolen.
Or keylogged
__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 08:05 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.