While doing security testing, I found that the password of any user I wanted could be easily decrypted and printed, which is a huge security problem. My new hashing log-in doesn't work. See if you can find an error. It says your password is hashed when it isn't (login-next).
Last edited by SeptimusHeap (2012-06-06 07:55:36)
Offline
SeptimusHeap wrote:
Servine wrote:
SeptimusHeap wrote:
"fun"
never make account deletion part of a game. ever.
Also, passwords aren't hashed, I could change that, but that would require each player to sign up again.
Also, you do know you'll need custom art for the horse and members logo when you actually start selling stuff.Ok, I've changed the horse to my own graphics, just need to change the game logo and rid of the credits.
I'm deciding to go along with account deletion if I think that the account is a spam or just an injector. Although, no accounts will be delete by a nuke.
I'm not really worried about hashing as of now as the encryption is better than nothing.OK, I can set up password reset/changing once I get to know the system. Also, the bottom banner is way to big, it covers most pages almost halfway.
It's MEANT to be like that.
Offline
SeptimusHeap wrote:
While doing security testing, I found that the password of any user I wanted could be easily decrypted and printed, which is a huge security problem. My new hashing log-in doesn't work. See if you can find an error. It says your password is hashed when it isn't (login-next).
You forgot to update the thing you added at the end of the table with the usernames in. Change it to anything other than the default.
I'm trying to keep all info as safe as possible, not even giving away a TRACE of info!
EDIT:
It would help if the SQL query in the variable was called used in the mysql_query() function.
DOUBLE EDIT:
It works. I checked the server, and my password is now encrypted in the new way!
Last edited by Servine (2012-06-06 08:40:14)
Offline
Because I was worried that SQL Injection would be lethal, I disabled spaces on the username sign up. Now lets see people use 'DELETE ...'. Password may have spaces as when it is encoded, it has no spaces, and email automatically disables spaces!
Also added favicon and currently updating games.
Offline
Well, the good news is nuking works! Arakdor (temporarily) is at 542 Health. After a planet is destroyed, all users lose all their possessions and are migrated to a different planet.
However, a planet is not completely destroyed; It is put into crisi mode. Any user can restore it by depositing 1000 experience. It is then restored to natures intent.
Offline
Register page updated as well as login next. Game remains a white screen when I go to the page with the flash game. New member images also added.
Are we going to sell memberships on PayPal?
Last edited by SeptimusHeap (2012-06-06 17:58:52)
Offline
fire219 wrote:
Just uploaded a new, much cleaner members club logo. There aren't many major images that either me or Septimus haven't updated yet.
Do you like the members/join members nukey thing?
Offline
SeptimusHeap wrote:
fire219 wrote:
Just uploaded a new, much cleaner members club logo. There aren't many major images that either me or Septimus haven't updated yet.
Do you like the members/join members nukey thing?
The thing that replaced the poorly drawn boy? Yea
What about my capital city buttons and members club logo?
Offline
fire219 wrote:
SeptimusHeap wrote:
fire219 wrote:
Just uploaded a new, much cleaner members club logo. There aren't many major images that either me or Septimus haven't updated yet.
Do you like the members/join members nukey thing?
The thing that replaced the poorly drawn boy? Yea
What about my capital city buttons and members club logo?
Nice! The member's club rope thing could use some gradients and antialiasing though, but the text and buttons are great!
Offline
SeptimusHeap wrote:
fire219 wrote:
SeptimusHeap wrote:
Do you like the members/join members nukey thing?The thing that replaced the poorly drawn boy? Yea
What about my capital city buttons and members club logo?Nice! The member's club rope thing could use some gradients and antialiasing though, but the text and buttons are great!
Not much I can do when the picture is pretty low res (272x66).
Offline
fire219 wrote:
SeptimusHeap wrote:
fire219 wrote:
The thing that replaced the poorly drawn boy? Yea
What about my capital city buttons and members club logo?Nice! The member's club rope thing could use some gradients and antialiasing though, but the text and buttons are great!
Not much I can do when the picture is pretty low res (272x66).
Oh well.
Servine, could you take a look at rcodenext.html? I get an error when resetting passwords (use beta at http://bluetetra.x11s.org/reset.html, then check your email).
Offline
SeptimusHeap wrote:
fire219 wrote:
SeptimusHeap wrote:
Nice! The member's club rope thing could use some gradients and antialiasing though, but the text and buttons are great!Not much I can do when the picture is pretty low res (272x66).
Oh well.
Servine, could you take a look at rcodenext.html? I get an error when resetting passwords (use beta at http://bluetetra.x11s.org/reset.html, then check your email).
ok. fixed.
Offline
SeptimusHeap wrote:
Register page updated as well as login next. Game remains a white screen when I go to the page with the flash game. New member images also added.
Are we going to sell memberships on PayPal?
Well, if we do DO PayPal, I'm afraid I can't benefit from it. My dad won't let me add HIS Paypal.
If you want, you could add it for your PayPal!
Offline
Servine wrote:
soft319 wrote:
I signed up, but didn't think about using the free membership codes.
One suggestion: Make movement better, because I can easily slide off.Yeah, I kinda need to fix that don't I :\
The game still won't load for me. Using Firefox on Windows 7.
Also, what was wrong with the reset thingy?
EDIT: Still doesn't work, what did you change then?
Last edited by SeptimusHeap (2012-06-07 07:07:13)
Offline
SeptimusHeap wrote:
Servine wrote:
soft319 wrote:
I signed up, but didn't think about using the free membership codes.
One suggestion: Make movement better, because I can easily slide off.Yeah, I kinda need to fix that don't I :\
The game still won't load for me. Using Firefox on Windows 7.
Also, what was wrong with the reset thingy?
EDIT: Still doesn't work, what did you change then?
Ok, game SHOULD load. The swf link was incorrect, tested and works.
I didn't know what I changed with the reset thingy.
Offline
Servine wrote:
SeptimusHeap wrote:
Servine wrote:
Yeah, I kinda need to fix that don't I :\
The game still won't load for me. Using Firefox on Windows 7.
Also, what was wrong with the reset thingy?
EDIT: Still doesn't work, what did you change then?Ok, game SHOULD load. The swf link was incorrect, tested and works.
I didn't know what I changed with the reset thingy.
Can you fix it please? It's in the rcodenext.html file, the password doesn't change after updating. Also, PLEASE tell me that is not the final game. The graphics are stock, and it makes no sense.
Last edited by SeptimusHeap (2012-06-07 08:12:50)
Offline
SeptimusHeap wrote:
Servine wrote:
SeptimusHeap wrote:
The game still won't load for me. Using Firefox on Windows 7.
Also, what was wrong with the reset thingy?
EDIT: Still doesn't work, what did you change then?Ok, game SHOULD load. The swf link was incorrect, tested and works.
I didn't know what I changed with the reset thingy.Can you fix it please? It's in the rcodenext.html file, the password doesn't change after updating. Also, PLEASE tell me that is not the final game. The graphics are stock, and it makes no sense.
Not the final game, and I'll TRY to fix it.
Offline
Servine wrote:
SeptimusHeap wrote:
Servine wrote:
Ok, game SHOULD load. The swf link was incorrect, tested and works.
I didn't know what I changed with the reset thingy.Can you fix it please? It's in the rcodenext.html file, the password doesn't change after updating. Also, PLEASE tell me that is not the final game. The graphics are stock, and it makes no sense.
Not the final game, and I'll TRY to fix it.
Tell me if you can... It worked fine on icarea, but maybe my edits messed it up...
Also, let me verify the storyline: Future planet, total nuclear war. Tetra is the last remaining area. The surviving cities duke it out with ICBMs and there's magical crystals that can be somehow converted into radioactive material for use in nuclear weapons.
Last edited by SeptimusHeap (2012-06-07 16:25:21)
Offline
SeptimusHeap wrote:
Servine wrote:
SeptimusHeap wrote:
Can you fix it please? It's in the rcodenext.html file, the password doesn't change after updating. Also, PLEASE tell me that is not the final game. The graphics are stock, and it makes no sense.Not the final game, and I'll TRY to fix it.
Tell me if you can... It worked fine on icarea, but maybe my edits messed it up...
Also, let me verify the storyline: Future planet, total nuclear war. Tetra is the last remaining area. The surviving cities duke it out with ICBMs and there's magical crystals that can be somehow converted into radioactive material for use in nuclear weapons.
Yup, but like a few other games, when I think that storyline is complete, I'll introduce the new storyline, it has something to do with the title...
Offline