Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[URGENT] I'ma hack you.
#71
Oh Im Purez Wrote:[COLOR="White"][SIZE="2"]

Do you even know what your talking about?[/SIZE][/COLOR]

made a mistake, it's md5 salted and hashed
[Image: image1.php?playerName=Firegirl]
#72
idk why plp getting hacked its so easy to secure ur acc Wink
#73
Just a couple of things that appear incorrect in your post here Brittany. Starting things off, MD5 Hash is completely hackable, not even that hard either. Go up against a cracking application and you'll get destroyed. Salt is the only protection you'll have when applied with Hash. Encryption is nothing but a myth with the new scripts that can be run through ASM with a backend engine. Secondly, remove the command. Runescape runs with an OS/IOStream. Meaning commands are sent to the server through packets, if someone were to simply make a packet editor (BWE Updated for RS) they could duplicate or stimulate the packets used in that command. Just a warning.

Salt uses a special method known pretty simple as randomizing, the reason its considered secure is due to its ability to scramble the key put in place by your hash. Personally, seeing as you're not running your character files from a SQL based server and most likely have them placed in text files or an xml table file, the salt/hash/MD5 is built through a system of Java, making it extremely weak.

No doubt its a method in your characterSave file. Of course, Delta servers use a token algorithm on your characterSave, so you're secure until someone designs a script that simply copies the files and places them into a .jar that decrypts and "peppers" your salt protection. Pepper was designed shortly after reCAPTCHA was cracked by botting software.

Salt is considered "uncrackable" when used in a MySQL or MsSQL server format. Seeing as that's running through the SQL framework, it is uncrackable. Sorry if that was too confusing but just wanted to point out some evident flaws.
#74
[COLOR="White"][SIZE="3"]
Ninjablood2 Wrote:Just a couple of things that appear incorrect in your post here Brittany. Starting things off, MD5 Hash is completely hackable, not even that hard either. Go up against a cracking application and you'll get destroyed. Salt is the only protection you'll have when applied with Hash. Encryption is nothing but a myth with the new scripts that can be run through ASM with a backend engine. Secondly, remove the command. Runescape runs with an OS/IOStream. Meaning commands are sent to the server through packets, if someone were to simply make a packet editor (BWE Updated for RS) they could duplicate or stimulate the packets used in that command. Just a warning.

Salt uses a special method known pretty simple as randomizing, the reason its considered secure is due to its ability to scramble the key put in place by your hash. Personally, seeing as you're not running your character files from a SQL based server and most likely have them placed in text files or an xml table file, the salt/hash/MD5 is built through a system of Java, making it extremely weak.

No doubt its a method in your characterSave file. Of course, Delta servers use a token algorithm on your characterSave, so you're secure until someone designs a script that simply copies the files and places them into a .jar that decrypts and "peppers" your salt protection. Pepper was designed shortly after reCAPTCHA was cracked by botting software.

Salt is considered "uncrackable" when used in a MySQL or MsSQL server format. Seeing as that's running through the SQL framework, it is uncrackable. Sorry if that was too confusing but just wanted to point out some evident flaws.


I was guna say something but all I can say is... True..... either way someone with enough experience can get it. Especially in md5. or they can SQLinject your website but idk if ur website would allow it i'm pretty sure your website is very well protected. anyways..... THANK YOU BRITTANY FOR FINALLY MAKING ALL THIS FOR PEOPLE WHO GIVE THERE PASSWORDS OUT!!!! IT'S SO EASY TO KEEP UR ACC SAFE PEOPLE!!!!!!!!!!!!!!!!!! FOLLO THIS PEEPS![/SIZE][/COLOR]
#75
[SIZE="2"]
Ninjablood2 Wrote:Just a couple of things that appear incorrect in your post here Brittany. Starting things off, MD5 Hash is completely hackable, not even that hard either. Go up against a cracking application and you'll get destroyed. Salt is the only protection you'll have when applied with Hash. Encryption is nothing but a myth with the new scripts that can be run through ASM with a backend engine. Secondly, remove the command. Runescape runs with an OS/IOStream. Meaning commands are sent to the server through packets, if someone were to simply make a packet editor (BWE Updated for RS) they could duplicate or stimulate the packets used in that command. Just a warning.

Salt uses a special method known pretty simple as randomizing, the reason its considered secure is due to its ability to scramble the key put in place by your hash. Personally, seeing as you're not running your character files from a SQL based server and most likely have them placed in text files or an xml table file, the salt/hash/MD5 is built through a system of Java, making it extremely weak.

No doubt its a method in your characterSave file. Of course, Delta servers use a token algorithm on your characterSave, so you're secure until someone designs a script that simply copies the files and places them into a .jar that decrypts and "peppers" your salt protection. Pepper was designed shortly after reCAPTCHA was cracked by botting software.

Salt is considered "uncrackable" when used in a MySQL or MsSQL server format. Seeing as that's running through the SQL framework, it is uncrackable. Sorry if that was too confusing but just wanted to point out some evident flaws.

It's crackable if you have the salt and the keys for it, yah, but none of that can be gotten with out server files, as this thread was about being able to 'not get hacked with out files'

Idc if it's crackable outside of the RSPS world and I'm 100% sure it is, but in this situation, it's 100% not possible with out having access to the files it's stored in.[/SIZE]
[COLOR="White"]
Sometimes we just need a friend.
Someone to hold us when you can't stand.
Sometimes even to pretend like you matter for that split second that everything seems to be crashing down.
And sometimes it's just easier to say goodbye.[/COLOR]
#76
[SIZE="2"]
Ipklucas Wrote:sweet update!!!

This thread's not even about updates. Enjoy those infractions.[/SIZE]
[COLOR="White"]
Sometimes we just need a friend.
Someone to hold us when you can't stand.
Sometimes even to pretend like you matter for that split second that everything seems to be crashing down.
And sometimes it's just easier to say goodbye.[/COLOR]
#77
Bleh I still got hacked
#78
how can i reset a password on the game? ::resetpass?
We build blocks everyday.
#79
[SIZE="1"]
Blocks Wrote:how can i reset a password on the game? ::resetpass?

If you're meaning change it then you go ::changepassword <newpasshere>[/SIZE]
"My conclusion is, Hate is Baggage; Life's too short to be pissed off all the time."
#80
Thanks Brittany Big Grin ill take this under consideration Big Grin thanks for the heads up Big Grin ill change my password Big Grin


Possibly Related Threads…
Thread Author Replies Views Last Post
  [URGENT] Read here. Brittany 298 126,394 05-12-2024, 09:16 AM
Last Post: masagnik1226.ru_ulsl
  [URGENT] Recoveries Brittany 2 6,563 01-22-2012, 10:49 PM
Last Post: Brittany

Forum Jump:


Users browsing this thread: 1 Guest(s)