EntropiaForum.com
Go Back   EntropiaForum.com > Information > About Entropia Universe > Technical
Notice
Technical Technical discussion about your computer and Entropia Universe system requirements.

Reply
 
LinkBack Thread Tools
Old 05-18-2008, 14:41   #11
Mature
Netaquel Poor  
  Activity Longevity
1/203/20
Posts: 48
Gender: Male Ingame: Male
EFD: 1,594.48
Reputation: Poor
Fame: 0 Achievements: 0
Sec reminder

Hi all

Security is real problem.

EF I trust, it's why I post here. Sentence of trust to EF was in orginal post but I removed it - EF is forum too. And owner - Neo - is know in community and probably do not want to do mess with his own reputation.

But still database can be stoled. That passwords are not in clear form (some hash, MD5, SHA, etc) makes just few days difficulty for thefts - bruteforce cracking or dictionary words... Piece of cake if you have hash of password.

But there are many forums! Near every society have one, even new societes makes forums and in soc terminal you can read "forum registration required".

If you do not use EU password in forum you still can use your mail account password on some forum. And EU is not all world: collected data from forums can be used to crack Visa card: birth data, rl name, etc, etc. To many security threads to name them all... Even mail addres is valuable for some kind of businesscreatures, spammers for example.

The main reason that make I post was EU Tracker. It was new tool for me and amount of data colected during registration make I post. But still, I registered account in EUT, so I have nothing against EUT crew. Nor other forum I know, what I say in first post.

Still I think it is good to remind that there is no such thing as 100% security, on any forum, tool, online bank and EU (with GC too). There are just harder-to-crack things and THIS IS WHAT EVERY SECURITY SPECIALIST WILL SAY. What marketing specialist say is other topic. If someone will be realy wanted to crack "ANY AVATAR NAME HERE" or any bank on Earth and have some rl money he will broke what hi want. Probably avatar account sooner then online bank.

We just need to avoide traps - things that wait for false move.

Second thing I reminded in first post was: IF YOU ARE BAD GUY YOU ARE NOT ALLOWED TO DO BAD THINGS. Pls do not comment about this particular subject, maybe it will be usefull for someone.

And sory Kaiser, you have bad nose. I will never have big posts counter and even have no idea is it usefull for somethink. Is it ? Never say never ofc, we see what happend, but I am not such kind of person. Just have some free time from EU and mining forum was boring lastly...

Net
Netaquel is offline Reply With Quote
Old 05-18-2008, 15:43   #12
Old
extince Mediocre  
  Activity Longevity
0/209/20
Posts: 100
Gender: Male Ingame: Male
Avatar Name:
nick extince robertson
Soc: The NBK
Location: Växjö, Sweden
EFD: 1,685.33
Reputation: Mediocre
Fame: 0 Achievements: 0
Marksmanship

Quote:
Originally Posted by 711 View Post
Good suggestion.

For the record, and to set member's minds at ease, EntropiaForum.com does not store member passwords, but rather stores an encrypted hash of the password. Thus, it is impossible for me or anyone else to extract any member's forum password from the EF database, since the actual password is not even stored anywhere.
In theory u can do md5-collisionchecks .. sure i guess the passwords got a salt within the md5, but still, in theory its still possible to get the password back in plaintext Many examples from sweden about that issue (sites gets hacked and databases started to spread, even with salt they succeed to get passwords from this )

But, i guess you as admin don't have any interest of it
extince is offline Reply With Quote
Old 05-18-2008, 21:53   #13
Provider
Omnedon Unskilled  
  Activity Longevity
0/203/20
Posts: 151
Blog Entries: 5
Avatar Name:
Tamryn Oscuro Kelsey
Location: Kalamazoo, MI, USA, in front of the computer(s)
EFD: 2,252.77
Reputation: Unskilled
Fame: 15 Achievements: 1

Quote:
Originally Posted by extince View Post
In theory u can do md5-collisionchecks .. sure i guess the passwords got a salt within the md5, but still, in theory its still possible to get the password back in plaintext Many examples from sweden about that issue (sites gets hacked and databases started to spread, even with salt they succeed to get passwords from this )
This is generally known as a brute force attack (simplified as a dictionary attack as most people use "common" words as passwords) which is throwing everything through the md5 routine and checking to see if anything that comes out matches an encrypted password in the database.

The only reasonable defense is the use of longer passwords with more complexity. Still won't be entirely safe (if the attacker has a copy of the password database) but will increase the time needed to yield anything useful.

Don't use your name, street address, birthdate, or any other "common" words as password and you make your account much harder to crack.

Quote:
Originally Posted by extince View Post
But, i guess you as admin don't have any interest of it
What exactly are the admins supposed to do to "show interest"? Unless they are "teh ubar programmers", other than use of forum software that encrypts passwords and making sure the server is secure (which is behind the scenes), there is not really much they can do.
Omnedon is offline Reply With Quote
Old 05-18-2008, 22:18   #14
711
EntropiaForum Owner/Admin
711's Avatar
711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding  
  Activity Longevity
6/2012/20
Posts: 3,194
Blog Entries: 5
Gender: Male Ingame: Male
Location: EntropiaForum
EFD: 137,711.26
Reputation: Outstanding
Fame: 15 Achievements: 2
Flower

Quote:
Originally Posted by Netaquel View Post
Hi all

But still database can be stoled. That passwords are not in clear form (some hash, MD5, SHA, etc) makes just few days difficulty for thefts - bruteforce cracking or dictionary words... Piece of cake if you have hash of password.
Quote:
Originally Posted by extince View Post
In theory u can do md5-collisionchecks .. sure i guess the passwords got a salt within the md5, but still, in theory its still possible to get the password back in plaintext Many examples from sweden about that issue (sites gets hacked and databases started to spread, even with salt they succeed to get passwords from this )

But, i guess you as admin don't have any interest of it
Please read my post again.

The EF software does not store the password in encrypted format. It stores an encrypted, salted MD5 hash of the password. So even if someone were able hack into the EF database server (very unlikely, the EF servers are very secure) and then crack the salted MD5 encryption (which has never been accomplished by anyone in the world, to my knowledge), they would still only have the hash of the password, not the password itself. As I said, member passwords are not stored anywhere in the forum database, encrypted or otherwise.

However, it should be noted that a malicious webmaster could theoretically capture passwords from form fields before they are submitted to the database, by using a slightly modified stock vBulletin or similiar forum software, so one still needs to be careful. My explantion above was more intended to set member's minds at ease that it is extrememly unlikely that someone could extract such information from EF's database, even if they were successful in gaining unauthorized access to the servers somehow.

Thus, it is still good security practice to use a password different than that from the one you use for sensitive or financial websites, such as your Entropia Universe login.
711 is online now Reply With Quote
Old 05-18-2008, 23:05   #15
Old Alpha
Outman's Avatar
Outman NoviceOutman NoviceOutman Novice  
  Activity Longevity
1/2015/20
Posts: 970
Gender: Male Ingame: Male
Avatar Name:
Daniel Outman Jackson
Soc: Rising Potentials
Location: Earth DUH! NASA won't sell the moon base till 2020
EFD: 562.21
Reputation: Novice
Fame: 0 Achievements: 0

Yea as long as your EF pass is different from your EU pass your fine (not sure why someone would take an EF account). Also if your password is the same there are trillions of possible usernames and they should differ from your avatar name. I guess the big risk is when a keylogger is on your computer.
The biggest worry would be someone hacking the EU server. It would be a hard thing to do but there are people who could do it. It is a big target (I think) considering one could wreck chaos on the economy making tons of money, steal accounts and collect credit card numbers. Also the fact that it would be the first RCE hacked would give the hacker some media attention.

Last edited by Outman; 05-18-2008 at 23:17.
__________________
I tried to craft in real life. Turns out sticking a bunch of rocks in a washing machine just breaks the machine. I also tried jumping on a strangers head in the town square, until then I thought the washing machine was bad.
Outman is offline Reply With Quote
Old 05-19-2008, 12:03   #16
Mature
Netaquel Poor  
  Activity Longevity
1/203/20
Posts: 48
Gender: Male Ingame: Male
EFD: 1,594.48
Reputation: Poor
Fame: 0 Achievements: 0
Sec reminder

Hi all,

I know security is big problem and hard to discuss too. So want to repeat: EF is one of forum we trust moust! If I can speak for others.

But look on adv on main page - banner about rip-of's... So looks that talking about hard things is necesary...

I consider thread can be closed now. But in someday someone can write another reminder, and it will be good thing, IMO.

Best regards all,

Net
Netaquel is offline Reply With Quote
Reply

Bookmarks

Thread Tools
 
EntropiaTracker.com Loot Trends
Hunting Loot: + 24.81 % Mining Loot: + 21.61 % Crafting Loot: + 47.47 %
EntropiaTracker.com Latest Uber Loots
 Phoebe Kiddoe Thrasher Predator Foot Guards (M,L) - 2695 PED: 10/13/2008 06:41 | Devon Deeveon Knight Simple III Conductors - 1254 PED: 10/13/2008 06:04 | Vontang Kwanyi Kwan Atrox Guardian - 1885 PED: 10/13/2008 04:23 | Trinnity Trinn Annam OreAmp OA-101 Light (L) - 1398 PED: 10/13/2008 03:57 | Ashley Audison Kartunes Itumatrox Provider - 1903 PED: 10/13/2008 03:00 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1296 PED: 10/13/2008 02:06 | Runner Blade Blade Argonaut Raider - 1396 PED: 10/13/2008 02:05 | Magnus Mag Ogg Argonaut Scout - 2784 PED: 10/13/2008 01:58 | Jussi Krrk Karkkainen E-Amp 13 - 1143 PED: 10/12/2008 23:32 | Happy Birthday Welcomes! Feffoid Guard - 1190 PED: 10/12/2008 22:49 | SHAKENNO BONDY TSTIRRED Blausariam stone - 1625 PED: 10/12/2008 22:45 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1212 PED: 10/12/2008 22:30 | Olga Svane Dievouchka Simple I Plastic Springs - 1008 PED: 10/12/2008 21:31 | idvali idvali mosu OreAmp OA-101 (L) - 69745 PED: 10/12/2008 21:00 | Mark Coldzik Fergusson OreAmp OA-101 Light (L) - 7722 PED: 10/12/2008 20:44 | Iam Goldie Timberlake OreAmp OA-101 (L) - 3100 PED: 10/12/2008 20:41 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1913 PED: 10/12/2008 20:36 | eye eye-drop drop Zinc stone - 1019 PED: 10/12/2008 20:20 | Fred Ice Issue EnMatAmp MA-102 (L) - 3191 PED: 10/12/2008 20:17 | Zan Waldi Dariel EnMatAmp MA-102 (L) - 3040 PED: 10/12/2008 19:57 | Angelina Sweet Hearts OreAmp OA-101 (L) - 1413 PED: 10/12/2008 19:43 | Black Hawk Hawk Ambulimax Young - 1472 PED: 10/12/2008 19:41 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 7186 PED: 10/12/2008 19:31 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 2106 PED: 10/12/2008 19:23 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1155 PED: 10/12/2008 19:20 | Stoikow Stoikow Mudorow Atrox Young - 1639 PED: 10/12/2008 19:09 | Cloud Cloudy Skywalker Atrox Mature - 21879 PED: 10/12/2008 19:05 | Macco Macco Macco Shriek Basic - 1303 PED: 10/12/2008 19:00 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1611 PED: 10/12/2008 18:42 | Bobby Skankinbob Deluxe Work Pattern Shirt (F,C) - 1904 PED: 10/12/2008 18:28 | Levinstein Lev II Ganganite stone - 1252 PED: 10/12/2008 18:18 | Cali Destiny Sijngaard Atrox Young - 1481 PED: 10/12/2008 18:15 | Adriana ADI Zulawinska EnMatAmp MA-105 (L) - 1298 PED: 10/12/2008 18:13 | Ahbin LaG Pludidee Simple II Conductors - 1255 PED: 10/12/2008 17:43 | Violet Vi Neomir OreAmp OA-101 (L) - 4009 PED: 10/12/2008 17:28 | Lord Keldon Keldon Zinc stone - 1445 PED: 10/12/2008 17:12 | Fahd Scarface Kahn Lysterium stone - 3045 PED: 10/12/2008 17:11 | MH Grave Digger Daspletor Mature - 1081 PED: 10/12/2008 16:58 | Warvar Mortal Wild Blausariam stone - 1149 PED: 10/12/2008 16:49 | Mantus Crosskeeper Wolfenmond OreAmp OA-101 (L) - 10204 PED: 10/12/2008 14:48 | Parker Parker Van Helsing Maffoid Clan Warlord - 1616 PED: 10/12/2008 14:40 | Trox´s must die 2day with Atrox Mature - 17665 PED: 10/12/2008 14:32 | Axel Foley Head Gazzurdite stone - 1405 PED: 10/12/2008 14:19 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3094 PED: 10/12/2008 14:07 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3887 PED: 10/12/2008 14:05 | Max Marmac Power Aurli Weak - 23214 PED: 10/12/2008 13:39 | Toast Toast CHG OreAmp OA-101 (L) - 2449 PED: 10/12/2008 13:36 | nirvana pretty the best Lysterium stone - 1540 PED: 10/12/2008 13:23 | Jade Kaliah Elite OreAmp OA-101 (L) - 1716 PED: 10/12/2008 12:33 | Narcissus nar cissus Cumbriz stone - 1626 PED: 10/12/2008 12:07 | Alex Neophyte Zane OreAmp OA-105 (L) - 5450 PED: 10/12/2008 11:48 | Alex Neophyte Zane OreAmp OA-105 (L) - 1862 PED: 10/12/2008 11:42 | Toast Toast CHG OreAmp OA-101 (L) - 1658 PED: 10/12/2008 10:57 | Jar Jasis Sismondi Atrox Young - 8703 PED: 10/12/2008 10:49 | never say never Lysterium stone - 1925 PED: 10/12/2008 10:42 | Bart Muskito Joosten Typonolic Steam - 2277 PED: 10/12/2008 10:23 | Pieter Belov Belovski EnMatAmp MA-107 (L) - 1594 PED: 10/12/2008 10:10 | lee mundo chis Dino Shoes (F,C) - 2073 PED: 10/12/2008 09:35 | CHUNBIAO WIFELOVER WEI EnMatAmp MA-102 (L) - 1350 PED: 10/12/2008 09:31 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3344 PED: 10/12/2008 09:11 | Maronelle Analytic Thunder Analina Ignisium stone - 1172 PED: 10/12/2008 09:10 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 1689 PED: 10/12/2008 08:07 |

~ Entropia Universe | Entropia Radio | Entropia Wiki | Entropia Tracker | Entropians IM ~

All times are GMT. The time now is 08:08. | Calypso Time: 8:08

Copyright ©2005 - 2008, EntropiaForum.com.
Entropia Universe is a registered trademark of Mindark PE AB.
All other copyrights and trademarks are property of their respective owners.
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.