Urban Terror Forums: [4.2] Update 4.2.012 - Urban Terror Forums

Jump to content

 Login | Register 
Advertisement
  • (16 Pages)
  • +
  • « First
  • 9
  • 10
  • 11
  • 12
  • 13
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

[4.2] Update 4.2.012 Rate Topic: -----

#101 User is offline   hellraiser Icon

  • Account: hellraiser
  • Country:
  • Joined: 08-March 11
  • Posts: 481

Posted 26 April 2013 - 09:53 PM

View PostH0i, on 26 April 2013 - 02:42 PM, said:

/cg_drawcrosshair 0 will disable the crosshair.


OK thanks but havin an option in the ingame menù, something like:

[...]
Show crosshair: on/off
Crosshair shape: ecc.
[...]

woulb be much much much much much more easier :laugh:

#102 User is offline   Pilou42 Icon

  • Account: pilou42
  • Country:
  • Joined: 01-March 10
  • Posts: 170

Posted 26 April 2013 - 10:09 PM

@n1n: Yep, seriously.
To be honest, I hope there will be a hack soon. It would mean 4.2 is popular. I don't think there's one actually.

Of course there will be servers without auth, ready to welcome newbies.
But for advanced users, they will play in auth servers only.

Fighting hack tool is useless, a good coder will eventually achieve it. You can always encrypt datas sent by server to computer, but it will be the same as Blu-ray or whatever. A good motivated coder will always find the way to decrypt it. :-)

But the auth system is the way to go. A cheater caught was not really easy to track before. Now, you can only use one account (despite using aliases, you will have one account). A cheater caught will have to create a new account (easy to spot) or use an old account, which for me, is also easy to spot.
With a centralized accounts server, it will be easy to keep a maintained list of cheaters. They will have to change location or Internet Provider (most cheaters are young and it won't be easy for them).

The harder task will be to fix security holes in Auth system (keep a backup of the list in case a hacker manages to edit it).


For now, I don't think there are cheat tools since 4.2 is still unpopular.

This post has been edited by Pilou42: 26 April 2013 - 10:10 PM



#104 User is offline   garcassgrinder Icon

Posted 27 April 2013 - 06:49 AM

@All:

Im not sure if its possible but: imagine there will be in next future an account fake tool,
use randomly valid accounts.

All a hacker need is time and to know one or two account key to analyse.
- step one: generate randomly a countless list of fake account keys
- step two: put the keys into a text file named like accounts.cfg and put a simple procedure to register all step by step
- step three: run through the whole list via q3ut4 cmd line till he catch a valid account
- step four: continue and collect the valid keys he found

note the hacker don't need to hack a single account. For him it is enought to catch any account. And he has time...

...that scenario should only describes an account attack not a cheat!!!


The hacker is now able to mess up with some user accounts.

Please troll me if I talk nonsense :wacko:

#105 User is offline   Pilou42 Icon

  • Account: pilou42
  • Country:
  • Joined: 01-March 10
  • Posts: 170

Posted 27 April 2013 - 10:20 AM

Indeed. With just an auth key, it looks possible.
Maybe it should be a good idea to enter a login too (then one auth key valid instead of auth key * accounts created).

bullet_loaderAdvertisement

#106 User is online   JRandomNoob Icon

  •   moderator   
    Community Moderator

Posted 27 April 2013 - 03:45 PM

If the guys who coded the auth are worth anything, these keys are generated as randomly as technically possible, meaning that brute-forcing them would indeed be the only way to find valid ones. Since we’re not breaking encryption here, walking through every single key would take a fair bit less than forever, but you would need a dedicated botnet since (I do hope that) $UNREASONABLY_LARGE number of failed tries from a single IP would get it blocked, and even the number of any kind of devices with Internet connection is orders of magnitude smaller than the number of possible keys.

Basically, yes, you could do that, but it would be completely unfeasible unless you’re developing a paid cheat that would have just a few users anyway.

BTW, when did you last change your auth key?
dswp.de
Beginner’s Guide to Urban Terror (woefully out of date)
Daily Deadnade (Last updated September 9, 2016)

#107 User is offline   garcassgrinder Icon

Posted 27 April 2013 - 04:48 PM

View PostJRandomNoob, on 27 April 2013 - 03:45 PM, said:

If the guys who coded the auth are worth anything, these keys are generated as randomly as technically possible, meaning that brute-forcing them would indeed be the only way to find valid ones. Since we’re not breaking encryption here, walking through every single key would take a fair bit less than forever, but you would need a dedicated botnet since (I do hope that) $UNREASONABLY_LARGE number of failed tries from a single IP would get it blocked, and even the number of any kind of devices with Internet connection is orders of magnitude smaller than the number of possible keys.

Basically, yes, you could do that, but it would be completely unfeasible unless you’re developing a paid cheat that would have just a few users anyway.

BTW, when did you last change your auth key?


IP can change if you get a dynamic one form your provider and ID key can also change by a New UrT Installation

#108 User is offline   x3r Icon

  • Account: x3r
  • Main tag: 24/7.
  • Country:
  • Joined: 04-December 12
  • Posts: 122

Posted 28 April 2013 - 08:30 AM

View Postgarcassgrinder, on 27 April 2013 - 06:49 AM, said:

@All:

Im not sure if its possible but: imagine there will be in next future an account fake tool,
use randomly valid accounts.

All a hacker need is time and to know one or two account key to analyse.
- step one: generate randomly a countless list of fake account keys
- step two: put the keys into a text file named like accounts.cfg and put a simple procedure to register all step by step
- step three: run through the whole list via q3ut4 cmd line till he catch a valid account
- step four: continue and collect the valid keys he found

note the hacker don't need to hack a single account. For him it is enought to catch any account. And he has time...

...that scenario should only describes an account attack not a cheat!!!


The hacker is now able to mess up with some user accounts.

Please troll me if I talk nonsense :wacko:


There are 36 possible different characters (A-Z / 0-9) in 32 different slots in the string.

That is 36^32, or: 6.3340286662973277706162286946812*10^49 different possible keys.

IF my math is correct, I highly doubt hackers have the means to brute force this way.
And FS would not have servers that could handle this, if it was to be done in a reasonable amount of time, it would just overload the server.

I also doubt FS would allow so many auth-key changes from the same IP, before that IP is blacklisted or similar. Even if you had access to 100000 IPs, you would barely make a dent.

I am sure hackers have better things to do if they had these sort of means.

*hopes the math is correct XD, but even if it isn't the number of keys is extremely high*

This post has been edited by x3r: 28 April 2013 - 08:34 AM


#109 User is offline   thelionroars Icon

  •   QA member   
  • Account: thelionroars
  • Country:
  • Joined: 21-September 11
  • Posts: 853

Posted 28 April 2013 - 10:53 AM

View Postx3r, on 28 April 2013 - 08:30 AM, said:

There are 36 possible different characters (A-Z / 0-9) in 32 different slots in the string.

That is 36^32, or: 6.3340286662973277706162286946812*10^49 different possible keys.

...

*hopes the math is correct XD, but even if it isn't the number of keys is extritemely high*


its actually in hexadecimal (0-9 and A-F).

= 16^32 ~= 3.403 * 10^38

which is decent.

#110 User is offline   x3r Icon

  • Account: x3r
  • Main tag: 24/7.
  • Country:
  • Joined: 04-December 12
  • Posts: 122

Posted 29 April 2013 - 03:18 AM

View Postthelionroars, on 28 April 2013 - 10:53 AM, said:

its actually in hexadecimal (0-9 and A-F).

= 16^32 ~= 3.403 * 10^38

which is decent.


Thanks for the correction.

Number of possible keys:
~3,403,000,000,000,000,000,000,000,000,000,000,000,00

lol, anyone know the name of this number?

This post has been edited by x3r: 29 April 2013 - 03:20 AM


  • (16 Pages)
  • +
  • « First
  • 9
  • 10
  • 11
  • 12
  • 13
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Advertisement


Copyright © 1999-2024 Frozensand Games Limited  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of Frozensand Games Limited

Frozensand Games is a Limited company registered in England and Wales. Company Reg No: 10343942