Project 1999

Go Back   Project 1999 > General Community > Off Topic

Closed Thread
 
Thread Tools Display Modes
  #81  
Old 03-03-2015, 10:19 PM
Pokesan Pokesan is offline
Banned


Join Date: Apr 2014
Posts: 5,958
Default

officially shipping Torven x Secrets

the #1 best contributors to the AK emu projects

now kiss
  #82  
Old 03-03-2015, 10:34 PM
jetviper21 jetviper21 is offline
Kobold


Join Date: Apr 2010
Posts: 143
Default

Quote:
Originally Posted by loramin [You must be logged in to view images. Log in or Register.]
I think this is a red flag entirely separate from Haynar's (very valid) security concerns.

Logins are a pain in the ass, both as a server admin and as a user ... which is why anyone with any sense starting a new website uses OpenID. These people could have used OpenID (with Google or Facebook or ...) OR they could have used EQEmulator, but instead they chose the worst option for both themselves and their users.

If the people behind this project can't be bothered to make their users' lives easier when it takes LESS work to do so, what should we expect of them when something actually takes effort?
Its very apparent that you do not understand how the login server for the peqmac emu works so let me enlighten you. You can't use the eqemu login and you can't use openID to login to peqmac everquest. Mostly because the mac client was changed to use the newer token based authentication. This is hacked around in the mac version that you could use to play on Al'kabor by using a separate routine in the login server itsself. The PC version still uses a version of the eqemu login code. Since the mac clients have no server select screen you are forced to run a login server that will forward the client to your world server.

Mac:
https://github.com/cavedude00/Server...lient.cpp#L178

PC:
https://github.com/cavedude00/Server...lient.cpp#L283

All passwords are SHA1 hashed with a salt (which isn't the best) but its also not the worst. Personally I would prefer bcrypt or SHA-512
Last edited by jetviper21; 03-03-2015 at 10:46 PM..
  #83  
Old 03-03-2015, 10:54 PM
jetviper21 jetviper21 is offline
Kobold


Join Date: Apr 2010
Posts: 143
Default

That being said even the official tak login server will log your password in plain text to the servers log files.

https://github.com/cavedude00/Server....cpp#L199-L200

Another fun thing is that if you are on a mac and you run "ps aux | grep Everquest" you can see your password in plain text passed as a command line argument. So arguing security here has little merit in a system that has obvious flaws
Last edited by jetviper21; 03-03-2015 at 10:57 PM..
  #84  
Old 03-17-2015, 08:04 PM
apio apio is offline
Banned


Join Date: May 2010
Location: Spain
Posts: 288
Default

We are 3 days away from launch so I thought I would introduce you to our team.

http://www.p2002.com/forums/viewtopic.php?f=6&t=148

We will release 1 last huge changelog before launch, to avoid spamming the forum daily, once we are on our way there will be more frequent changelogs!

A good guide on how to get set up can be found here: http://www.rerolled.org/showthread.p...=1#post1017027
Last edited by apio; 03-17-2015 at 08:09 PM..
  #85  
Old 03-17-2015, 08:52 PM
scythic scythic is offline
Orc

scythic's Avatar

Join Date: Oct 2013
Posts: 38
Default

I just want to let everyone know I appreciate Torven as much as he appreciates himself.
__________________
Scythic Wolfeye - Ranger
  #86  
Old 03-17-2015, 09:04 PM
king buzzo king buzzo is offline
Banned


Join Date: Mar 2015
Posts: 52
Default

is this seperate from project 1999?
  #87  
Old 03-17-2015, 09:15 PM
Secrets Secrets is offline
VIP / Contributor

Secrets's Avatar

Join Date: Oct 2009
Posts: 1,354
Default

Quote:
Originally Posted by jetviper21 [You must be logged in to view images. Log in or Register.]
That being said even the official tak login server will log your password in plain text to the servers log files.

https://github.com/cavedude00/Server....cpp#L199-L200

Another fun thing is that if you are on a mac and you run "ps aux | grep Everquest" you can see your password in plain text passed as a command line argument. So arguing security here has little merit in a system that has obvious flaws
It's an option and if it's a security concern I will personally remove it.

It's no different than the plaintext passwords being sent on the client to the EQ server, though that's more of a client restriction.
__________________
Engineer of Things and Stuff, Wearer of Many Hats

“Knowing yourself is the beginning of all wisdom.” — Aristotle
  #88  
Old 03-17-2015, 11:11 PM
mr_jon3s mr_jon3s is offline
Fire Giant


Join Date: Apr 2014
Posts: 517
Default

I would love to play a 2002 server but with no boxing.
  #89  
Old 03-18-2015, 07:45 PM
kain200 kain200 is offline
Scrawny Gnoll


Join Date: Mar 2014
Location: Winter Haven, Florida
Posts: 20
Default

I tried to register on the forums but i'm not getting the activation email. I even did a thing where you can get it to resend another email and I didn't get that one either. I hope this gets resolved i'm looking forward to playing on friday!
  #90  
Old 03-18-2015, 08:24 PM
Wharhog Wharhog is offline
Aviak


Join Date: Jan 2015
Posts: 84
Default

Takes a little bit, it will be there shortly
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:00 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.