Graal Forums  

Go Back   Graal Forums > PlayerWorlds > PlayerWorlds Main Forum
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-25-2006, 03:06 PM
Yen Yen is offline
Banned
Yen's Avatar
Join Date: Oct 2005
Location: Nova Scotia, Canada
Posts: 1,085
Yen is an unknown quantity at this point
Send a message via AIM to Yen Send a message via MSN to Yen
Server Security and You

A lot of problems have been popping up lately, dealing with the hijacking of staff members' accounts.
Someone with malicious intent could log one of your staff's accounts and ask for their IP to be updated.
Do you take precautions to verify that the person asking for the IP change is who you think they are? No, very few (if any) people do.

To prevent giving RC access to hijackers, follow these steps to ensure the person on the account is who you think they are:
  1. Compare their old IP(s) to their new IP using a who-is tool such as ARIN WHOIS. If the ISP has suddenly changed or teleported across the country, something is probably wrong.
  2. Compare their computer ID to their old computer ID. There's no way to see previous computer IDs they logged on with, so it's a good idea to list their regular computer ID somewhere such as comments.
  3. Talk to them and ask questions only they would know. If their typing seems to be strange (i.e. someone who normally uses punctuation and grammar not using it) or they can't answer your questions, it should be obvious they aren't the account's owner.
If you check all of these things over and something is wrong, inquire about it.
For example: if their ISP doesn't match, ask questions such as why they changed ISPs and what their old ISP was.

If you follow these steps to verify the person, your server should stay safe from account hijackers.
Reply With Quote
  #2  
Old 09-25-2006, 03:40 PM
Jackel9 Jackel9 is offline
Dimension Zero Founder
Jackel9's Avatar
Join Date: Nov 2005
Location: NC SONZ
Posts: 193
Jackel9 is on a distinguished road
I hqve a feeling that this wont work out
__________________

Reply With Quote
  #3  
Old 09-25-2006, 05:13 PM
contiga contiga is offline
Graal2001 Administration
contiga's Avatar
Join Date: Jul 2004
Location: Netherlands
Posts: 419
contiga is an unknown quantity at this point
Send a message via ICQ to contiga Send a message via AIM to contiga Send a message via MSN to contiga Send a message via Yahoo to contiga
Hmm.. Is this actually Yen? I've never heard him talk so much ****..
__________________
AIM: Contiga122
MSN: [email protected]
Status:
Quote:
Originally Posted by unixmad View Post
I am also awake 3AM to help correct problems.
Quote:
Originally Posted by Bomy Island RC people
Daniel: HoudiniMan is a bad guy =p
*Bell: rofl. I first read that as houdini is a bad man. like the little kid that wants his mommy to keep her away from that boogie man
Daniel: xD
*Rufus: I wouldn't want my kids around him.
Reply With Quote
  #4  
Old 09-25-2006, 06:29 PM
xAndrewx xAndrewx is offline
Registered User
xAndrewx's Avatar
Join Date: Sep 2004
Posts: 5,260
xAndrewx has much to be proud ofxAndrewx has much to be proud ofxAndrewx has much to be proud ofxAndrewx has much to be proud ofxAndrewx has much to be proud ofxAndrewx has much to be proud ofxAndrewx has much to be proud of
I like it, nice Yen :}
__________________
Reply With Quote
  #5  
Old 09-25-2006, 09:07 PM
Sum41Freeeeek Sum41Freeeeek is offline
Future Coder
Join Date: Feb 2004
Location: New York
Posts: 376
Sum41Freeeeek is on a distinguished road
Send a message via AIM to Sum41Freeeeek
Yeah, no offence to anyone on Era though but all I had to do was ask if they
could add my computer ID (I was on mom's computer) to the list and they did
it without question ;o

this is a good idea.
__________________
Frankie Cassini: ex-Era LAT
Quote:
Originally Posted by brakk View Post
omg just go to your room and draw a pony then

**** the chicken wings!
Reply With Quote
  #6  
Old 09-25-2006, 09:13 PM
killerogue killerogue is offline
Registered Omega
killerogue's Avatar
Join Date: Apr 2006
Location: United States
Posts: 1,920
killerogue is on a distinguished road
Send a message via AIM to killerogue Send a message via MSN to killerogue
Quote:
Originally Posted by Jackel9 View Post
I hqve a feeling that this wont work out
It's actually a very intelligent idea and something nice to write and it should help out alot of people if they pay attention and use their brains. Alot of things you say irritate the **** out of me.
__________________


REMEMBER, IF YOU REP ME, LEAVE A NAME!

Quote:
Originally Posted by haunter View Post
Graal admins don't die. They go to hell and regroup.
Quote:
Originally Posted by Inverness View Post
Without scripters, your graphics and levels wouldn't do anything but sit there and look pretty.
Reply With Quote
  #7  
Old 09-27-2006, 06:22 AM
MysticalDragon MysticalDragon is offline
Global Administration
MysticalDragon's Avatar
Join Date: Oct 2002
Location: Lynn Ma
Posts: 883
MysticalDragon is a jewel in the roughMysticalDragon is a jewel in the rough
Send a message via AIM to MysticalDragon Send a message via MSN to MysticalDragon
Quote:
Originally Posted by Yen View Post
A lot of problems have been popping up lately, dealing with the hijacking of staff members' accounts.
Someone with malicious intent could log one of your staff's accounts and ask for their IP to be updated.
Do you take precautions to verify that the person asking for the IP change is who you think they are? No, very few (if any) people do.

To prevent giving RC access to hijackers, follow these steps to ensure the person on the account is who you think they are:
  1. Compare their old IP(s) to their new IP using a who-is tool such as ARIN WHOIS. If the ISP has suddenly changed or teleported across the country, something is probably wrong.
  2. Compare their computer ID to their old computer ID. There's no way to see previous computer IDs they logged on with, so it's a good idea to list their regular computer ID somewhere such as comments.
  3. Talk to them and ask questions only they would know. If their typing seems to be strange (i.e. someone who normally uses punctuation and grammar not using it) or they can't answer your questions, it should be obvious they aren't the account's owner.
If you check all of these things over and something is wrong, inquire about it.
For example: if their ISP doesn't match, ask questions such as why they changed ISPs and what their old ISP was.

If you follow these steps to verify the person, your server should stay safe from account hijackers.
This is something that has been preached in graal for year on in that always was denied and made playerworlds more vital to those hackers waiting for the right opportunity. In any case if they lack the interest to keep there playerworld secured its there own blame for the inconsistency of there own arrogance.
__________________
~Delteria Support
~Playerworld Support
~PWA Chief
http://support.toonslab.com
[email protected]



Reply With Quote
  #8  
Old 09-27-2006, 03:22 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by Jackel9 View Post
I hqve a feeling that this wont work out
You don't even know what he said. You just randomly typed LOL IT WUN WORK because you don't understand it.

There's nothing in that post that needs to "work out". It's common sense stuff that staff should use to prevent hijackings and such.

__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 07:59 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.