Community Forums Today's Posts     Member List     Archive    
Results 1 to 10 of 10
  1. #1
    Join Date
    Mar 2012
    Posts
    12

    Security issue with Token System?

    Hello,

    i have a Security Question about Server Tokens.
    I'm use a MySQL TS3 Server on Debian Squeeze 6.

    To join in user group normal (ID:7) the peoples can order automaticly a Token(Key).
    It works perfectly, with registration questions & IP.

    But now, some peoples say me, this is a really big Security issue?

    Can you confirm this or help?

  2. #2
    Join Date
    May 2010
    Posts
    6,362
    Hello

    If you allow all users to create a token (to get another groups with other permissions) yes it could be.

  3. #3
    Join Date
    Mar 2012
    Posts
    12
    The users have no permission to create tokens.
    Only the php script create a simple token, without any SQL Injection options.

    The token is only, to add him in group 7, normal.
    is this also no security issue?

    its the same as, if i give an guest token for group normal.

  4. #4
    Join Date
    May 2010
    Posts
    6,362
    I guess your php script use the query commands.

    So if you normal group is correctly set (kick, ban, add_member_remove, etc, etc) for me there is no security issue here.

  5. #5
    Join Date
    Mar 2012
    Posts
    12
    Thanks for answers.

    My PHP Script uses only
    Code:
    INSERT INTO `tokens` ..

  6. #6
    Join Date
    May 2010
    Posts
    6,362
    NEVER MAKE A CHANGES DIRECTLY ON THE DATABASE (we never repeat it enough )

    You have the tokenadd query command for that.

  7. #7
    Join Date
    Mar 2012
    Posts
    12
    How?
    tokenadd?

    Where i can find these commands

    EDIT:

    I found it, but how i can connect from php to server query?

  8. #8
    Join Date
    May 2010
    Posts
    6,362
    You have two main possibilities:
    - The TS3 PHP Framework : http://addons.teamspeak.com/director...Framework.html
    - The TS3 Admin Class : http://addons.teamspeak.com/director...s-for-PHP.html

    You could make a simple search on google about the php and socket

  9. #9
    Join Date
    Mar 2012
    Posts
    12
    Im try'd now the TS3 Admin Class, i set all options, but if im visit the PHP Script i got a error:

    500 Internal Server Error :s

  10. #10
    Join Date
    May 2010
    Posts
    6,362
    Please use this thread to report any problem or question : http://forum.teamspeak.com/showthrea...n.class-v0.5.x

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. tokens or set server group ?
    By Themouse in forum Permission System
    Replies: 4
    Last Post: 09-03-2010, 05:02
  2. password/tokens
    By jonnie-it-is in forum General Questions
    Replies: 7
    Last Post: 18-01-2010, 10:43
  3. Question about tokens
    By HakuAnime in forum General Questions
    Replies: 1
    Last Post: 02-01-2010, 16:10
  4. Question about tokens
    By mvdstroom in forum Permission System
    Replies: 8
    Last Post: 01-01-2010, 15:25
  5. tokens
    By tgcsniper in forum Windows
    Replies: 1
    Last Post: 25-12-2009, 03:43

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •