Welcome,
Guest
. Please
login
or
register
.
June 09, 2025, 07:15:41 AM
News:
tastyspleen.net discord server:
http://discord.tastyspleen.net
Home
Forum
Help
TinyPortal
Search
Calendar
Login
Register
tastyspleen::quake 2 community
»
Forum
»
Off-Topic Zone
»
/dev/random
»
Ethics Based Server?
« previous
next »
Print
Pages:
1
2
3
4
5
6
[
7
]
Go Down
Author
Topic: Ethics Based Server? (Read 30442 times)
console
Brobdingnagian Member
Posts: 4518
"Man, this is the way to travel," said my attorney
Rated:
Re: Ethics Based Server?
«
Reply #90 on:
March 06, 2007, 10:55:13 PM »
Well, as the crypto gurus might say, What's Your Threat Model
What's Your Threat Model
?
I know roughly jack about crypto. But for us, since the advent of r1q2 and the exploits r1ch fixed, we've never had anyone hack our rcon password that I'm aware of.
But it also probably helps that we don't give out the rcon password either... we use an admin system where each admin has their own login and password. The rcon password is never transmitted over the network to the client.
So in our case, it might be nice to be able to simply ignore all rcon requests not originating from the IP of the system running our admin scripts.
For that, I could see making rcon a stateful transaction:
client q2 server
--------------------------------------------------------------------------
rcon xpasswordx status
<- "verify 1055d3e698d289f2af8663725127bd4b"
rcon 1055d3e698d289f2af8663725127bd4b status
<- "status info...."
...or something similar. The client tries a normal rcon command, but the server responds with a verify code based on a random number. The client then re-issues the rcon command using the verify code as the password.
Still using UDP, still the same packet structure, so it would technically work with existing clients (even though no human would want to type the verify string by hand.)
This would be trivial to implement, but would presumably be sufficient to allow workable IP-based whitelists for hosts allowed to issue rcon commands.
But again, it gets back to WYTM? The simple system described above is vulnerable to man-in-the-middle attacks, of course; but are we worried about those? I'm not, personally, but again that's probably because there's only one host that knows our rcon passwords--and I don't forsee the liklihood of some employee of some internet backbone sniffing our network packets...
Oh well, fun to talk about anyway...
Regards,
«
Last Edit: March 06, 2007, 10:57:46 PM by console
»
Logged
{TNP}Dukie
Carpal Tunnel Member
Posts: 1570
Rated:
Re: Ethics Based Server?
«
Reply #91 on:
March 07, 2007, 05:18:34 AM »
WTF are you guys talkin about?
Krypto was superboy's dog!
Logged
"To see me, you must download my skin!"
"To see me, you must download my skin!"
[img]http://banners.wunderground.com/weathersticker/gizmotimetemp_both/language/
Dafremen>FAS>
Newbie
Posts: 17
God/Tao/Great Spirit - The First Tro0 Skiller
Rated:
Re: Ethics Based Server?
«
Reply #92 on:
March 07, 2007, 07:55:51 AM »
That looks alot like what I had in mind, but even more secure with the server authentication step. As for the threat model, I think it's obvious: skript kiddies with a grudge, curious hackers who want bragging rights or less likely, but more lethal: ex admins with a grudge and with contacts on the inside or currently active accounts.
That pretty much covers the threat model... It would be fun to mess with it anyway.
Logged
When you play cheaply..you inspire others to do so..and the quality of the game declines.
Fragz Ain't Skillz
74.54.186.236 "goto BTFFFA" Everything u need to work on improving your game.
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
Re: Ethics Based Server?
«
Reply #93 on:
March 07, 2007, 12:51:34 PM »
http://iang.org/ssl/wytm.html
WYTM.
interesting read, the internet is so strange!
«
Last Edit: March 07, 2007, 12:54:03 PM by reaper
»
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
Print
Pages:
1
2
3
4
5
6
[
7
]
Go Up
« previous
next »
tastyspleen::quake 2 community
»
Forum
»
Off-Topic Zone
»
/dev/random
»
Ethics Based Server?
El Box de Shoutamente
Last 10 Shouts:
|iR|Focalor
May 26, 2025, 01:17:30 PM
-Unh0ly-
May 24, 2025, 10:08:35 PM
https://drive.google.com/file/d/1qwsj3EM4s5svp0b8oJLZt_An6990RB-o/view?usp=sharing
QUAKE 2 RTX
-Unh0ly-
May 22, 2025, 05:45:28 PM
https://drive.google.com/file/d/1VB1if3QjStPWCpbB33vbx7OOef-Negd3/view?usp=sharing
DUST 2 HD TEXTURES PUT IN BASEQ2 folder
Yotematoi
May 17, 2025, 08:33:15 AM
Yo desde el año 2007 me enfermé de Q2, es incurable
Morir y revivir es costumbre, lástima q el QT estaba bueno
ImperiusDamian
May 12, 2025, 01:45:35 AM
Quake II is not 27 years old. I refuse to accept THAT much time has gone by.
|iR|Focalor
May 11, 2025, 02:33:39 PM
-Unh0ly-
May 03, 2025, 08:02:46 AM
198.179.6.200:30634
Yotematoi
May 02, 2025, 10:27:47 AM
Note for Player-4109 "Remember, the Guinness Book of Records does not include cowards who shot at someone by treachery."
-Unh0ly-
April 20, 2025, 09:52:16 AM
https://drive.google.com/file/d/1hKRIIKPk_G9TLPpY3B4ZIbVK_00Mbwfw/view?usp=sharing
|iR|Focalor
April 02, 2025, 02:47:07 AM
Show 50 latest
User
Welcome,
Guest
. Please
login
or
register
.
June 09, 2025, 07:15:41 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Search
Advanced search