1. All Content Posted on Radical Exploits Is for educational purposes: Copyright Disclaimer Under Section 107 of the Copyright Act 1976, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research. Fair use is a use permitted by copyright statute that might otherwise be infringing. Educational or personal use tips the balance in favor of fair use.
    Dismiss Notice

FrenchModdingTeam Password Stealing

Discussion in 'General Programming' started by JoshuaSmith, Jan 17, 2019.

  1. JoshuaSmith

    JoshuaSmith Registered
    Registered

    Joined:
    Jan 7, 2019
    Messages:
    19
    Likes Received:
    9
    [​IMG]

    Language: Object-pascal aka delphi

    So this lovely group of french developers use the clients registry to store client credential as many game cheat devs do but they do with a simple md5 encoding which is easy to crack.


    What's needed:
    • 2 edits
    • 1 memo
    • 1 idhttp




    Example of what this software can do:
    [​IMG]

    Hidden Content:
    You must either reply or click 'Like' to see the hidden information contained here.

    To all the developers out there its important you store client credentials in a ethical and secure way. md5 should not be used nor should plaintext. If someone gives advice to protect the clients do not act like this:

    CS is FM|T iMCSx:
    Code:
    [3:21 PM] CS: hi
    [3:21 PM] CS: i saw your message about md5 pwd, we did that in 2013, in this period md5 was enought, but now yes md5 is very weak
    [3:22 PM] CS: but even if someone grab a valid md5 from someone he could still not login in the website, and couldn't use the software due to computer licence.
    [7:30 PM] HGJosh: You can just login and request a hardware id reset. Boom done.
    [7:31 PM] HGJosh: I mean even if you have a geo check it can be bypassed but atlest it would be another step of security.
    

    Thanks
    ~ Joshua Smith
     
    #1
    • Like Like x 3
  2. PxReDeadly

    PxReDeadly Registered
    Registered

    Joined:
    Dec 6, 2017
    Messages:
    104
    Likes Received:
    8
    cool bro
     
    #2
  3. News4You

    News4You Well-Known Member
    Premium Star Member /ourguy/ Registered

    Joined:
    Apr 4, 2018
    Messages:
    72
    Likes Received:
    26
    Don't use Md5, use AES-256
     
    #3
  4. TazhysYT

    TazhysYT Platinum Member
    Platinum Premium Registered

    Joined:
    Jan 16, 2019
    Messages:
    23
    Likes Received:
    0
    ooof
     
    #4

Share This Page