Jump to content

themegaman

Members
  • Posts

    32
  • Joined

  • Last visited

    Never
  • Donations

    0.00 GBP 

Posts posted by themegaman

  1. For your first problem. If your firewall settings are correct, he can connect to your database from another computer. Database andmangos server do not need to be on the same computer (and in that case thay better should have a fast LAN connection).

    For your second problem: Currently it is not possible to give different GM levels for different realms. I dont even think this is neccessary, accounts can be easily transfered from one realmd database to a completly different realmd database.

  2. Hello.

    Yesterday my private server got attacked be account hackers again. Dont know when the hacking attempt really startet, maybe few days earlier, I could notice a increase of about 50 to 75 TCP/IP connections above normal level in MRTG statistics on tuesday and wednesday. This is not the first time. It makes me think, that it is pretty easy to bruteforce account just by guessing the username from e.g. char names (this time char and usernames where the same). Choosing stronger passwords isnt a good hint, most accounts exist for long, and we never had that problem before, only GM accounts are heavily secured. Reamld or Mangos Server needs additional protection like only accepting a limited amount of connections per ip and per second and only accepting limited attempts per account per second (to prevent proxy server attacks also). Also the `failed_logins` mechanism in account table does not work, I will create a bug/enhancment report for that.

    Please no "not helping hint" here, this thread is not about my passwords its about securing an MMORPG server from account hackers in general.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy Terms of Use