What's new
Red County Roleplay

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

[READ] Recent server breach

Status
Not open for further replies.
Zayats said:
d7ea96286c1a5b373d2776950601b19e.png

Whos that jordan he seems like a Cool guy
 
The passwords were properly hashed? but they weren't salted. :(

@edit oh WillySilly already explained it

Damn I'm glad I had good secure password for rcrp!

Miss Blue said:
That, does not make sense at all.
This is a server on SA-MP; not a company that holds millions of information.

Fr0st does everything possible to secure this information to the best of their abilities, and i'd shoot myself in the head if he didn't.

damn you gotta shoot yourself in the head cause TommyB removed a salt system booth made
 
Paxie said:
The passwords were properly hashed? but they weren't salted. :(

@edit oh WillySilly already explained it

Damn I'm glad I had good secure password for rcrp!

Miss Blue said:
That, does not make sense at all.
This is a server on SA-MP; not a company that holds millions of information.

Fr0st does everything possible to secure this information to the best of their abilities, and i'd shoot myself in the head if he didn't.

damn you gotta shoot yourself in the head cause TommyB removed a salt system booth made

Paxie - if Tommy had used that salting system Booth would still have been able to crack passwords as people would still have the same passwords.
 
Smally said:
Paxie said:
The passwords were properly hashed? but they weren't salted. :(

@edit oh WillySilly already explained it

Damn I'm glad I had good secure password for rcrp!

Miss Blue said:
That, does not make sense at all.
This is a server on SA-MP; not a company that holds millions of information.

Fr0st does everything possible to secure this information to the best of their abilities, and i'd shoot myself in the head if he didn't.

damn you gotta shoot yourself in the head cause TommyB removed a salt system booth made

Paxie - if Tommy had used that salting system Booth would still have been able to crack passwords as people would still have the same passwords.

If he knew the salting system well(considering he made it he probably did) it could make it easier for him to hijack accounts theoretically. While doing it in bulk would be hard but it would be easier if you did it in 1-2 passwords. (1 being enough to access a high ranking administrator account, and go on from their)


ALSO; Theres a way to make the bare passwords super secure even behind hashing and salting. If you know how to script it correctly, you can make a system that stores the passwords, BUT, rather than being the normal string and letters, you can use a program or one that you made to jumble them up and mix them around.

OFC it would be pretty hard to script, but would make it almost 100x harder to crack and would probably be more evident if someone was trying to breach the server.
 
Status
Not open for further replies.
Back
Top