Graal Forums  

Go Back   Graal Forums > PlayerWorlds > PlayerWorlds Main Forum
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 06-12-2007, 06:23 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
Restrict your ClientRC NOW

Put in Server Options:
PHP Code:
restrictclientrctoweapons=comma seperated list of weapon names 
Example:
PHP Code:
restrictclientrctoweapons=ClientRC,System 
This is how its set on Aeon and I absolutely never give anyone access to those weapons.

If you pay attention to updates you people would know this, stop getting hacked by noob script kiddies, jeeze >_>.

Edit: And another thing, if you have access to the admin account of your playerworld and do not know how to access the admin panel, freaking find out right now.
__________________
Reply With Quote
  #2  
Old 06-12-2007, 08:24 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
I warned people so long ago but no-one listened

http://forums.graalonline.com/forums...ad.php?t=72431

For a while, only -Playerlist could access clientrc. Which effectively nullified it :P

Last edited by Twinny; 06-12-2007 at 08:39 AM..
Reply With Quote
  #3  
Old 06-12-2007, 08:37 AM
Pimmeh Pimmeh is offline
Rgesitreed Uesr
Pimmeh's Avatar
Join Date: May 2007
Location: Utrecht, the Netherlands
Posts: 1,586
Pimmeh has a spectacular aura about
Send a message via AIM to Pimmeh Send a message via MSN to Pimmeh
WHy not make that option default?
Nudge @ stefan
__________________
Oh, Death,
No wealth, no ruin, no silver, no gold
Nothing satisfies me but your soul
Reply With Quote
  #4  
Old 06-12-2007, 08:41 AM
Ohnstad Ohnstad is offline
Banned
Join Date: Dec 2005
Posts: 10
Ohnstad is on a distinguished road
*knows a way to work around this*

tatata do what you will.
Reply With Quote
  #5  
Old 06-13-2007, 03:43 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
Quote:
Originally Posted by Ohnstad View Post
*knows a way to work around this*

tatata do what you will.
Of course that what you'd want us to believe.
__________________
Reply With Quote
  #6  
Old 06-13-2007, 06:25 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
Another lovely thing: don't give your NPC-Server rw */* rights! Just letting peeps steal/delete whatever npc-server can access.

Last edited by Twinny; 06-13-2007 at 07:09 AM..
Reply With Quote
  #7  
Old 06-13-2007, 07:05 AM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Twinny View Post
Another lovely thing: don't give your NPC-Server rw */* rights!
haha
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #8  
Old 06-13-2007, 08:32 AM
Pimmeh Pimmeh is offline
Rgesitreed Uesr
Pimmeh's Avatar
Join Date: May 2007
Location: Utrecht, the Netherlands
Posts: 1,586
Pimmeh has a spectacular aura about
Send a message via AIM to Pimmeh Send a message via MSN to Pimmeh
Why would one give the NPC server rw */*?
Complete useless! Its not like the NPC server does anything with it...
__________________
Oh, Death,
No wealth, no ruin, no silver, no gold
Nothing satisfies me but your soul
Reply With Quote
  #9  
Old 06-14-2007, 05:20 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
Quote:
Originally Posted by Pimmeh View Post
Why would one give the NPC server rw */*?
Complete useless! Its not like the NPC server does anything with it...
Shows how much you know.
__________________
Reply With Quote
  #10  
Old 06-14-2007, 07:39 AM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Inverness View Post
Shows how much you know.
Yes, because the NPC server is secretly a real player! ;o

I kid with you, Inver, you know I'm not that stupid
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #11  
Old 06-14-2007, 09:37 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
You should learn more about NPC-Server. It needs rights to access/write to files on the server. I currently have:
PHP Code:
rw mudlib/*
rw mudlib/*/

Although it will soon be r only. Basically, before you can load files into your scripts: you need to give NPC-Server rights to the files you wish it to access.
Reply With Quote
  #12  
Old 06-15-2007, 02:31 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
Stefan's brain had too much coding information in it, so we had to cut parts of it out to prevent his head from exploding. This is how the NPC-Servers were born.
__________________
Reply With Quote
  #13  
Old 06-15-2007, 06:07 AM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Inverness View Post
Stefan's brain had too much coding information in it, so we had to cut parts of it out to prevent his head from exploding. This is how the NPC-Servers were born.
True story, I was there.
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #14  
Old 06-15-2007, 02:17 PM
NicoX NicoX is offline
Kingdoms Management
NicoX's Avatar
Join Date: Mar 2004
Location: Frankfurt/Main, Germany
Posts: 1,933
NicoX will become famous soon enough
Send a message via AIM to NicoX Send a message via MSN to NicoX
Well yeah because of that **** Esteria got hacked yesterday too
Fortunately I have backups so it is not really bad just need a High Admin to restore my Server and so on.....But it is annoying really
Just little 13 years old kids are messing with graal because they dont get love in reality
Nubs
__________________
Yours Sincerely,

-Nico
(GK Management)

Clash: Nico, I'm going to give you an example of good management.
Clash: One of my staff removed my RC and banned me.
Clash: I didn't ban or remove their RC after I got another one to fix me.
Clash: Do you know why?
Björn: Because you IP banned him ?

Stefan logged on.
(npcserver) has reset the attributes of Stefan
*Stefan: ah my client crashed








Reply With Quote
  #15  
Old 06-15-2007, 02:32 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Hah, Nico...Angelu told me about it, and I want to tell you some things too.
First, it was most likely your fault. Why? Because you hired him, so Esteria would be done faster. You didnt even know him I guess.
Second, thats not really "hacking". Its just a large abuse of Graal.
And last, those guys are not 13 year old, and they are also not "nubs". You cant look at some tutorial and BAM destroy a server. Such things require lots of skills, you know.
Reply With Quote
  #16  
Old 06-15-2007, 02:35 PM
NicoX NicoX is offline
Kingdoms Management
NicoX's Avatar
Join Date: Mar 2004
Location: Frankfurt/Main, Germany
Posts: 1,933
NicoX will become famous soon enough
Send a message via AIM to NicoX Send a message via MSN to NicoX
Yeah I hired him but how I know that he is that hacker guy ?? He wanted to apply as NAT and I said okay I didnt thought about it but whatever it happens
I know it was not hacking they just updated scripts which I saw and then got disconnected
Well we have backups so it is not that bad..Just loosing time
Well I shut down Esteria I just need FULL RC rights again so I can restore it myself nothing more...
__________________
Yours Sincerely,

-Nico
(GK Management)

Clash: Nico, I'm going to give you an example of good management.
Clash: One of my staff removed my RC and banned me.
Clash: I didn't ban or remove their RC after I got another one to fix me.
Clash: Do you know why?
Björn: Because you IP banned him ?

Stefan logged on.
(npcserver) has reset the attributes of Stefan
*Stefan: ah my client crashed









Last edited by Sam; 06-15-2007 at 03:04 PM.. Reason: no instigation of violence
Reply With Quote
  #17  
Old 06-16-2007, 12:29 AM
bscharff bscharff is offline
Bloo
bscharff's Avatar
Join Date: Sep 2006
Location: San Antonio, Texas
Posts: 185
bscharff has a little shameless behaviour in the past
Send a message via AIM to bscharff Send a message via MSN to bscharff Send a message via Yahoo to bscharff
yeah... This is the exact bug that hackers or exploiters used to destroy Element/Playerworld141 (Same Thing)
Luckily, I Had Backups :P
Reply With Quote
  #18  
Old 06-16-2007, 12:38 AM
zokemon zokemon is offline
That one guy...
zokemon's Avatar
Join Date: Mar 2001
Location: Sonoma County, California
Posts: 2,925
zokemon is a jewel in the roughzokemon is a jewel in the rough
Send a message via ICQ to zokemon Send a message via AIM to zokemon Send a message via MSN to zokemon Send a message via Yahoo to zokemon
Quote:
Originally Posted by bscharff View Post
yeah... This is the exact bug that hackers or exploiters used to destroy Element/Playerworld141 (Same Thing)
Luckily, I Had Backups :P
Element? That server died when Slash disappeared ever so long ago...
Unless you are talking about that "Elemental Kingdoms" server.
__________________
Do it with a DON!
Reply With Quote
  #19  
Old 06-17-2007, 04:52 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
The restrictclientrctoweapons option has been modified now to only allow -ScriptedRC when it is empty / not set.
Reply With Quote
  #20  
Old 06-17-2007, 05:04 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by zokemon View Post
Element? That server died when Slash disappeared ever so long ago...
Unless you are talking about that "Elemental Kingdoms" server.
heh...

Little does the world know, Outlaw was working on a server called "Element" back in 2001. Got my first LAT position on it, we almost got a dev server too!
__________________
Reply With Quote
  #21  
Old 06-17-2007, 07:40 PM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Stefan View Post
The restrictclientrctoweapons option has been modified now to only allow -ScriptedRC when it is empty / not set.
yay, go you
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #22  
Old 06-20-2007, 04:49 AM
trevor987 trevor987 is offline
Registered User
Join Date: Jun 2007
Posts: 20
trevor987 is on a distinguished road
Client RC IS NOT SECURE EVEN WHEN RESTRICTED.

Somehow someone who didn't even have NC access but did have Client RC managed to have the admin client RC account give him level 4, so he changed admin account pass, etc. Yeah...

CLIENT RC IS NOT SECURE EVEN WHEN RESTRICTED.
Reply With Quote
  #23  
Old 06-20-2007, 05:33 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
If ClientRC is so insecure then just delete it and live with regular RC. If you don't have windows, sucks for you then, you're not worth the insecurities.
__________________
Reply With Quote
  #24  
Old 06-20-2007, 05:49 AM
Infernix Infernix is offline
Inferno (Level Designer)
Join Date: May 2005
Location: U.S,Maryland
Posts: 1,288
Infernix is on a distinguished road
Send a message via AIM to Infernix
Quote:
Originally Posted by Inverness View Post
If ClientRC is so insecure then just delete it and live with regular RC. If you don't have windows, sucks for you then, you're not worth the insecurities.
WOOOOORRRRRRRRRDDDDDD, thx you for saying that before I did.
Reply With Quote
  #25  
Old 06-20-2007, 09:12 AM
Skyld Skyld is offline
Script-fu
Skyld's Avatar
Join Date: Jan 2002
Location: United Kingdom
Posts: 3,914
Skyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud of
Send a message via AIM to Skyld
Quote:
Originally Posted by Inverness View Post
If ClientRC is so insecure then just delete it and live with regular RC. If you don't have windows, sucks for you then, you're not worth the insecurities.
Touchy!
__________________
Skyld
Reply With Quote
  #26  
Old 06-20-2007, 09:41 AM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Skyld View Post
Touchy!
He's got a good point, though.
ClientRC is so silly anyways, there isn't much need for it. I mean, sure it's kinda convenient, but I'll always prefer the good ol' remotecontrol.exe
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #27  
Old 06-20-2007, 10:21 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
Quote:
Originally Posted by coreys View Post
but I'll always prefer the good ol' remotecontrol.exe
Which isn't available on Mac. Which is why Skyld made his version clientrc.
Reply With Quote
  #28  
Old 06-20-2007, 10:22 AM
Pimmeh Pimmeh is offline
Rgesitreed Uesr
Pimmeh's Avatar
Join Date: May 2007
Location: Utrecht, the Netherlands
Posts: 1,586
Pimmeh has a spectacular aura about
Send a message via AIM to Pimmeh Send a message via MSN to Pimmeh
I dont have ClientRC because I have no idea how I can activate it....and now I restricted it to -playerlist
If only my server would be online....argh
__________________
Oh, Death,
No wealth, no ruin, no silver, no gold
Nothing satisfies me but your soul
Reply With Quote
  #29  
Old 06-20-2007, 10:57 PM
coreys coreys is offline
N-Pulse Assistant Manager
coreys's Avatar
Join Date: Mar 2005
Posts: 2,180
coreys has a spectacular aura about
Send a message via AIM to coreys Send a message via MSN to coreys Send a message via Yahoo to coreys
Quote:
Originally Posted by Twinny View Post
Which isn't available on Mac. Which is why Skyld made his version clientrc.
Maybe Skyld should smack around Stefan until he makes one, then? :O Just a though
__________________

Quote:
*SlikRick: so should I even ask about your aim status?
*Xor: well if you want to
*Xor: but i am LARPING
*SlikRick: While on a computer?
*Xor: yes
*Xor: in my living room
*SlikRick: ahh
*Xor: i have a fort setup to hide from beasts
Reply With Quote
  #30  
Old 06-21-2007, 04:22 AM
Inverness Inverness is offline
Incubator
Inverness's Avatar
Join Date: Aug 2004
Location: Houston, Texas
Posts: 3,613
Inverness is a jewel in the roughInverness is a jewel in the rough
Quote:
Originally Posted by Twinny View Post
Which isn't available on Mac. Which is why Skyld made his version clientrc.
Like I said, if you have a Mac you chose to be in the minority. Either get Windows or suck it up, I'm not going to allow a security risk just because you want to use a Mac. "You" being any Mac user that brings up this argument, not you Twinny, unless thats your argument too
__________________
Reply With Quote
  #31  
Old 06-24-2007, 05:33 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
Another handy idea!

PHP Code:
public function destroy()
  echo(
"Nice try, nubcakes"); 
Overrides the default destroy() command where it's added so anti-graals fool can't delete/destroy your NPC from other NPCs. Just add it to anything serverside.

Now, if Stefan added my protected variables idea, all NPCs variables could be set to private by default. This would save objects from accessing/writing to remote objects variables.
Reply With Quote
  #32  
Old 06-25-2007, 10:40 PM
zokemon zokemon is offline
That one guy...
zokemon's Avatar
Join Date: Mar 2001
Location: Sonoma County, California
Posts: 2,925
zokemon is a jewel in the roughzokemon is a jewel in the rough
Send a message via ICQ to zokemon Send a message via AIM to zokemon Send a message via MSN to zokemon Send a message via Yahoo to zokemon
Quote:
Originally Posted by Twinny View Post
Another handy idea!

PHP Code:
public function destroy()
  echo(
"Nice try, nubcakes"); 
Overrides the default destroy() command where it's added so anti-graals fool can't delete/destroy your NPC from other NPCs. Just add it to anything serverside.

Now, if Stefan added my protected variables idea, all NPCs variables could be set to private by default. This would save objects from accessing/writing to remote objects variables.
Yeah I was thinking about that...
You could just do like:

NPC1:
NPC Code:
function onCreated() {
public this.myvar = "Hello!";
NPC2.getMyVar();
private this.myvar;
NPC2.getMyVar();
}



NPC2:
NPC Code:
function getMyVar() {
echo("Test Results: " @ NPC1.myvar);
}



Echoed text:
NPC Code:
Test Results: Hello!
Test Results:



Color coded to show you the format of the code too ;P
(You would use public and private much like you use new, if, else, while, do, etc.)
__________________
Do it with a DON!
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 08:29 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.