English   German
  #1  
Old 11-09-2002, 14:00
Maxx Maxx is offline
-= TeamSpeak User =-
 
Join Date: Sep 2002
Location: germany
Posts: 7
Maxx is on a distinguished road
Question Security in 2.0.17.17

Disclaimer: I searched the forum for this issue but didn't find anything related.

I tried the php script at http://www.legion-condor.org/maletin/teamspeak7.php, as described in a posting by Maletin: http://forum.teamspeak.com/show...ghlight=telnet

currently running 2.0.17.17

I connected not providing any login information and found it strange that I saw the Server Password in clear text.


I switched to .20.17, and it doesn't display the password anyword. So either I'm really confused or this could compromise some people's (not updated) server...

Edit: correct URLs

Last edited by Maxx; 11-09-2002 at 14:03.
Reply With Quote
  #2  
Old 11-09-2002, 19:01
maletin's Avatar
maletin maletin is offline
-= TeamSpeak Lover =-
 
Join Date: Aug 2002
Location: Germany
Posts: 79
maletin is on a distinguished road
Send a message via ICQ to maletin Send a message via Skype™ to maletin
in the announce of 2.0.17.17 i found under fixed:
- si dont display anymore some secret string

i have 2.0.17.20 now, so i'm not sure, but this could be a fixed bug.
but even with superadmin-rights, i can't find the actual serverpassword.
Reply With Quote
  #3  
Old 11-09-2002, 19:03
maletin's Avatar
maletin maletin is offline
-= TeamSpeak Lover =-
 
Join Date: Aug 2002
Location: Germany
Posts: 79
maletin is on a distinguished road
Send a message via ICQ to maletin Send a message via Skype™ to maletin
Unhappy securicy

by the way:
i found the passwords of all registered users in my server.db!
Reply With Quote
  #4  
Old 13-09-2002, 16:07
SirEd SirEd is offline
-= TeamSpeak User =-
 
Join Date: Aug 2002
Location: Netherlands/Rdam
Posts: 27
SirEd is on a distinguished road
there is another bug in the new 2.0.17.20 version ...

When u use 2 servers in de server.ini on differend ports in the .17 version u can edit second server with admin htmls.

In 2.0.17.20 version u only can edit and see default server ....


a least this is what i found out
Reply With Quote
  #5  
Old 13-09-2002, 19:04
Jens L.'s Avatar
Jens L. Jens L. is offline
-= TeamSpeak Addict =-
 
Join Date: Jun 2002
Location: Berlin
Posts: 170
Jens L. will become famous soon enough
@maletin

how u can read the server.db ?
thats will be interesting me !

i search a kind to edit and read the server.db with an php script or something
Reply With Quote
  #6  
Old 14-09-2002, 10:42
ScratchMonkey ScratchMonkey is offline
-= TeamSpeak Addict =-
 
Join Date: Jun 2002
Location: Northern California
Posts: 350
ScratchMonkey is on a distinguished road
I noticed right away that the DB contained plaintext passwords.

Can you say what Kylix component is used to read/write the DB? With that in hand, we could perhaps write a small command line program to decompile and compile it.

A future version should probably store the passwords through a one-way hash like MD5, as Unix passwords do. That way one can't read user passwords out of the file.

If a user forgets his password, the admin then resets it to a known value that must be changed on the next login.
Reply With Quote
  #7  
Old 27-09-2002, 14:44
Saubloed Saubloed is offline
-= TeamSpeak User =-
 
Join Date: Jun 2002
Location: Germany
Posts: 14
Saubloed is on a distinguished road
I think security is very important especially stored passwords.
Improvement sugesstions:[list=1][*]md5 encrypted passwords[*]filerights 600 and not read rights for everyone (database, logfile and settings file)[/list=1]
Reply With Quote
  #8  
Old 11-06-2004, 01:14
craveytrain craveytrain is offline
-= TeamSpeak User =-
 
Join Date: Jun 2004
Location: Austin, TX
Posts: 4
craveytrain is on a distinguished road
I can't find any information on this since 2002. Is this still the way it works? Mine was in clear textwhen I imported it into MySQL. Did I do something wrong or is it working as intended?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 07:41.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Add to Bookmarks   |   Printview   |   Contact Us   |   Legal Notices