Jump to content
Sign in to follow this  
jianwenwu

any new duping method?

Recommended Posts

CO source provides a very simple but powerful antidupe, a handshake between gateserver and gameserver.
The handshake occurs right before player enters the game.
You may extract those codes to use it for yourself.


kong.png

a2.png

Share this post


Link to post
Share on other sites

Oh, I misread. On second note,
there is serious problems of how GroupServer was designed.
Meanwhile players are in the game, if GroupServer crashes, players remain ingame.
And when GroupServer is relaunched, new-login players get transported to that GroupServer
while the players that remained online no longer have a GroupServer to claim.
This may lead to dupe if conditions are right.

So, maybe a way is to transport all players without a GroupServer to newly launched GroupServer if should it crashes.


kong.png

a2.png

Share this post


Link to post
Share on other sites

Another thing, since antidupe falls under security.

I suggest everyone moving away from MD5 as the cipher for storing passwords.
It is known to produce the same digest given 2 different plaintext.


kong.png

a2.png

Share this post


Link to post
Share on other sites

RE: Moving away from MD5.

 

I've been wanting to remove the "originalPassword" column from the db and using bcrypt to hash the passwords instead. I have not read the AccountServer code extensively, but I'm assuming that most of the user login functionality happens through that. Are you aware of any place where the "originalPassword" field is being used? It's a travesty that passwords are being stored in cleartext in a database.

Share this post


Link to post
Share on other sites
On 9/24/2019 at 7:34 AM, jianwenwu said:

looking new dupe method anyone knows?

For what purpose are you asking?


Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Sign in to follow this  

×
×
  • Create New...