By registering with us, you'll be able to discuss, share and private message with other members of our community.
Sign up now!You mean the requests that are encrypted with TLS? lol"Hint: wireshark and watch the requests that go to runemate when you're adding a new bot account"
You mean the requests that are encrypted with TLS? lol
Show us your logs and I'll believe you."Hint: wireshark and watch the requests that go to runemate when you're adding a new bot account"
I'm not the one trying to decrypt hashesYou mean installing a self signed local cert to view TLS encrypted requests is impossible? lol
Also really proving you're the one who has no clue about security.
I mean it's possible, but my first impression of him let me believe he would be too retarded to get that doneShow us your logs and I'll believe you.
First you say they're plain text, then you say they're encrypted, now they're plain text again. Which one is it?And what? Let's say an admin goes rogue. Instant free 10,000 accounts for him
There's SO many options to avoid storing plain text passwords and the admins of this site FOR SOME REASON haven't done them. You can store a local generated encryption key per computer on the fly when they first login. Then hash their RS password with it. You store the hashed password online. Then just keep referencing the crypt key on the local computer for decrypting it. If it's a new computer you give them instructions on how to transfer they key.
OR, don't store ANY passwords online and simply store them locally. Like every other bot is doing. Genius, right?
Exposing security risks, totally stupid. LOL
That's great and all, but they're not doing that. They're storing the password in their database, no private key to decrypt.
There are ways around that, check MITMProxy for exampleJust to debunk the whole check the network log claim, (As expected) any communication with Runemate's servers during the process of adding or deleting an account is encrypted.
His point is that they are allegedly stored in plaintext on the servers, which I absolutely can't imagine, knowing arbiterFirst you say they're plain text, then you say they're encrypted, now they're plain text again. Which one is it?
I meant client developer, mb.Bot developers can't access the login data in the first place
Ah gotcha. The bot authors do have access to the aliases though.I meant client developer, mb.
legendary commentman if only i fucking cared enough to reply more decently to this..
User accounts are not, and never have been, sent to the server in cleartext. I advise OP to heed his own advice and Wireshark his own requests after spoofing the SSL certificate.
IfPhZTmAHsrPKBNqZoFwMtysh8lMKAcZT601/+ElDTeuyf8uv6hPFujN3sMi5+YA
just get authenticator and u will be safe i had accounts with more then 1B 07 without that on runemate never got hacked
We use essential cookies to make this site work, and optional cookies to enhance your experience.