Warning For Custom Clients

Forum for alternative clients, mods & discussions on the same.

Re: Warning For Custom Clients

Postby jaguar » Thu Oct 29, 2015 9:39 pm

shubla wrote:Theyre very easy to dig up i agree. But i think some more secure way doing that would be very difficult maybe even cost some money.


Take a look into Ender client. He use tokens, not clear passwords. You can stole token, but you can't get password from that and token expiring when you change your password.
User avatar
jaguar
 
Posts: 251
Joined: Sun Jan 16, 2011 11:59 pm

Re: Warning For Custom Clients

Postby romovs » Thu Oct 29, 2015 11:53 pm

jaguar wrote:
romovs wrote:It doesn't write any settings to files at all. logininfo.conf is from somewhere else.


But it write password to registry. And you can access those passwords using regedit if it is public user logged in...so, not secure. Please consider to use tokens.

Tokens being a more security conscious approach I definitely agree on that.
But imo, the benefits are overestimated in this particular case. This is not exactly bank account authentication.
Probability of someone wanting to snatch H&H passwords, having the know-how, and being able to access same public comp is almost non existent (in b4 we have whole office/class playing on a single pc :) but even if that's the case, with public computers you are pretty much fucked no matter whether it's tokens or passwords).
User avatar
romovs
 
Posts: 1473
Joined: Sun Sep 29, 2013 9:26 am
Location: The Tabouret

Re: Warning For Custom Clients

Postby jaguar » Fri Oct 30, 2015 1:50 am

romovs wrote:Tokens being a more security conscious approach I definitely agree on that.
But imo, the benefits are overestimated in this particular case. This is not exactly bank account authentication.
Probability of someone wanting to snatch H&H passwords, having the know-how, and being able to access same public comp is almost non existent (in b4 we have whole office/class playing on a single pc :) but even if that's the case, with public computers you are pretty much fucked no matter whether it's tokens or passwords).


Are you ready to loos your account after 1 year of game play?
Because for now I can easily steal any user pass who used your client, all what I need to do:
create custom client or map tool and add exploit that will deliver to me registry: [HKEY_CURRENT_USER\SOFTWARE\JavaSoft\Prefs\haven]
That it...
User avatar
jaguar
 
Posts: 251
Joined: Sun Jan 16, 2011 11:59 pm

Re: Warning For Custom Clients

Postby romovs » Fri Oct 30, 2015 2:06 am

To be fair with malicious client you could snatch tokens too, websites cookies, install key loggers, use some 0-day exploit to embed trojan in the BIOS to own someone for life :D
I suppose an argument could be made that with tokens you potentially loose only characters while with passwords chars plus account, but meh.. the consequences are pretty much equal imo.

Once again I agree tokens are better generally but doesn't worth spending 30min on that atm and then keeping answering everyone why the client suddenly stopped working after the update :|. Dunno..
User avatar
romovs
 
Posts: 1473
Joined: Sun Sep 29, 2013 9:26 am
Location: The Tabouret

Re: Warning For Custom Clients

Postby loftar » Fri Oct 30, 2015 2:11 am

romovs wrote:the consequences are pretty much equal imo.

Not in the event that people use the same password as for other services, like e-mail or whatnot.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 8926
Joined: Fri Apr 03, 2009 7:05 am

Re: Warning For Custom Clients

Postby romovs » Fri Oct 30, 2015 2:33 am

Fair enough.
User avatar
romovs
 
Posts: 1473
Joined: Sun Sep 29, 2013 9:26 am
Location: The Tabouret

Re: Warning For Custom Clients

Postby czaper2 » Fri Oct 30, 2015 2:36 am

Are .res files (graphical mods) potentially dangerous at all?
User avatar
czaper2
 
Posts: 389
Joined: Mon Aug 26, 2013 12:48 pm

Re: Warning For Custom Clients

Postby loftar » Fri Oct 30, 2015 4:38 am

czaper2 wrote:Are .res files (graphical mods) potentially dangerous at all?

They may contain code that the client will run, so yeah, you shouldn't get them from untrusted sources.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 8926
Joined: Fri Apr 03, 2009 7:05 am

Re: Warning For Custom Clients

Postby shubla » Fri Oct 30, 2015 7:19 am

Basically everything you download from some haven players might be potential keylogger or tool to send your passwords to them. Wouldnt be anything new on this community really :roll:
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Previous

Return to The Wizards' Tower

Who is online

Users browsing this forum: No registered users and 18 guests