![]() |
|
|
|
#1
|
|||
|
And everyone is like, it's only low because people are bored they will come back with planes. Seriously? It's low because 1/3 the server was either banned or ragequit due to super sketchy rules.
__________________
Pharuin Flamewraith-60 epic Archmage
Kovras Bladewraith-30 Rogue Goryn Bearclaw-36 Ranger | ||
|
|
|||
|
#2
|
||||
|
Quote:
Whatever. H
__________________
Haynar <Millennial Snowflake Utopia>
| |||
|
|
||||
|
#3
|
|||
|
this server sounds like shit
| ||
|
|
|||
|
#5
|
|||
|
Here is my honest opinion about p2002.
I know nothing about those running or hosting the server. The people advocating the server the loudest, are brash, outspoken. And have little positive to say of other servers. Their resume says, their dev chatted with CD an hour. Seriously? Since they use their own login server, it is the perfect front for someone like platlord to gather passwords. Then a few months later, use them to log in to idiots accounts on p99 that used same accounts/pass. Strip plat and gear. Make another $50k selling for RMT. My recommendation, if you try this server, do not use any account name or pass u used elsewhere. If u did, then change your other passwords asap. Too many red flags. Play at your own risk. The High Priest has spoken. Move along.
__________________
Haynar <Millennial Snowflake Utopia>
| ||
|
|
|||
|
#6
|
||||
|
Quote:
__________________
| |||
|
|
||||
|
#7
|
||||
|
Quote:
Logins are a pain in the ass, both as a server admin and as a user ... which is why anyone with any sense starting a new website uses OpenID. These people could have used OpenID (with Google or Facebook or ...) OR they could have used EQEmulator, but instead they chose the worst option for both themselves and their users. If the people behind this project can't be bothered to make their users' lives easier when it takes LESS work to do so, what should we expect of them when something actually takes effort?
__________________
Loramin Frostseer, Oracle of the Tribunal <Anonymous> and Fan of the "Where To Go For XP/For Treasure?" Guides Anyone can improve the wiki! If you are new to the Blue or Green servers, you can improve the wiki to earn a "welcome package" of platinum and/or gear! Send me a forum message for details. | |||
|
Last edited by loramin; 03-03-2015 at 08:41 PM..
|
|
|||
|
#8
|
||||
|
Quote:
Mac: https://github.com/cavedude00/Server...lient.cpp#L178 PC: https://github.com/cavedude00/Server...lient.cpp#L283 All passwords are SHA1 hashed with a salt (which isn't the best) but its also not the worst. Personally I would prefer bcrypt or SHA-512 | |||
|
Last edited by jetviper21; 03-03-2015 at 10:46 PM..
|
|
|||
|
#9
|
|||
|
That being said even the official tak login server will log your password in plain text to the servers log files.
https://github.com/cavedude00/Server....cpp#L199-L200 Another fun thing is that if you are on a mac and you run "ps aux | grep Everquest" you can see your password in plain text passed as a command line argument. So arguing security here has little merit in a system that has obvious flaws | ||
|
Last edited by jetviper21; 03-03-2015 at 10:57 PM..
|
|
||
|
#10
|
||||
|
Quote:
It's no different than the plaintext passwords being sent on the client to the EQ server, though that's more of a client restriction.
__________________
Engineer of Things and Stuff, Wearer of Many Hats
“Knowing yourself is the beginning of all wisdom.” — Aristotle | |||
|
|
||||
![]() |
|
|