Results 1 to 4 of 4
Thread: Invite buddy security issue
-
23-02-2011, 16:27 #1
-= TeamSpeak User =-
- Join Date
- Dec 2009
- Location
- Texas
- Posts
- 20
Invite buddy security issue
If you go into Tools -> Invite Buddy and generate a link on a server without a password, it generates a link with the Server Admin password that the server created on it's first run.
Tested on: 3.0.0-beta36 [Build: 12815], Windows 7 (x64), with server version 3.0.0-beta31-pre [Build: 13600]
Windows 7 (x64)
-
24-02-2011, 00:39 #2
-= TeamSpeak Addict =-
- Join Date
- Jun 2003
- Posts
- 246
Did you log on to the server using the admin password at all prior to using the Invite Buddy window?
-
24-02-2011, 04:08 #3
-= TeamSpeak User =-
- Join Date
- Dec 2009
- Location
- Texas
- Posts
- 20
Yeah. It seems as though it's using whatever password you've got in the box on connection -- regardless of if it's valid or not. If you leave it blank, it won't generate a password in the URL. If you use a bogus password, it will insert that instead.
-
24-02-2011, 07:31 #4
-= TeamSpeak Team =-
- Join Date
- Jun 2008
- Posts
- 7,776
But this is no bug.
Your client takes the passowrd you have used before.
It's comparable with this situation: You connect to a server and you fail on it's server password.
What now?
You have to ask someone for a password. So someone gives you the password and now you know 2 things. You know the address and the password for the server.
So now you are a security risk too as you call this here. You know 2 things about the server as long nobody changes the password, when you are on the server.
The invite buddy link does exactly the same thing, the difference is, it is clickable. Nothing more.
It does not know the server password when ...
..it was changed and the client has no new password set.
..you only have the permission to ignore the server password.
..you enter a wrong password into the dialog
If you really wan't to hide your server password, you need to assign b_virtualserver_join_ignore_password to eeveryone or to your group.
What happens with users, that never have connected before?
Let them connect once to yur server, without giving out your password. They will fail, but now they are saved in the database and you can assign permission or groups to them.
Open Permissions > List all client, to find their databse ID or unique ID.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
[Resolved] Privilege key is still there, after invite buddy
By Screech in forum Bug ReportsReplies: 2Last Post: 20-01-2011, 15:27 -
All possible paramter for buddy invite
By Fish in forum General QuestionsReplies: 1Last Post: 06-07-2010, 10:36 -
[Suggestion] INVITE BUDDY
By Jordi in forum Suggestions and FeedbackReplies: 17Last Post: 05-06-2010, 09:55 -
Security issue: SA can create servers
By TidalWave in forum [TeamSpeak 2] Server SupportReplies: 4Last Post: 19-02-2006, 14:54 -
Security issue/enhancement
By siepel in forum [TeamSpeak 2] General QuestionsReplies: 5Last Post: 13-09-2004, 14:00


Reply With Quote