[Tutorial] Short: Security around passwords
#8

Quote:
Originally Posted by AmigaBlizzard
View Post
If the server owner doesn't hash passwords and saves them in the database unhashed, are hackers able to just read the password?
If yes, why would they bother to find your password to log into your account and change data?
They have direct access to your database and if they can see the unhashed password, they can also see the other data and change it without even logging in.

Even when the passwords are hashed and they need to brute-force decode the password to see which password would match "drg8512gsgdrg5dr6sa4f8" (hashed password, which they took from your database), what would they need it for?
They can see the hashed password so they can see the data as well, which usually isn't encoded in any way (money, score, kills, ...).
Server owners want to see their player's password so that they can use their account on anither server.
Reply


Messages In This Thread
Short: Security around passwords - by Alcatrik - 15.10.2016, 01:30
Re: Short: Security around passwords - by BurnZ - 15.10.2016, 01:36
Re: Short: Security around passwords - by Gotham - 16.10.2016, 05:52
Re: Short: Security around passwords - by Spmn - 16.10.2016, 08:58
Re: Short: Security around passwords - by BurnZ - 16.10.2016, 09:02
Re: Short: Security around passwords - by Jayse - 16.10.2016, 09:34
Re: Short: Security around passwords - by AmigaBlizzard - 16.10.2016, 23:10
Re: Short: Security around passwords - by BurnZ - 17.10.2016, 00:18
Re: Short: Security around passwords - by SickAttack - 17.10.2016, 03:21
Re: Short: Security around passwords - by Alcatrik - 18.10.2016, 15:57

Forum Jump:


Users browsing this thread: 2 Guest(s)