Author Topic: [BI0-Cloud] - Dedicated Hosting Service [Coming Soon]  (Read 5190 times)

let me show you how easy it would be to steal a key from one of your servers

package keystuff
{
          function key(%key)
          {
                    talk(%key);
          }
};

put that in an add-on and there you go you can steal keys from this service

tdlr: don't ////////////ever//////////// store the key in plaintext
I dont know if its stuff coding or its intentional.

Even if it was kept in the key.dat (because as I've said it's very insecure), I'd seriously want him to be a well known and trusted member of the community with verifiable knowledge on computer security before I'd trust this service. We don't know who this person is; their very first post is this one.
Possible proof of being a bot or an alt.

You would think, but. The % is a local variable (set within that add on and only available within the specific addon) and the file itself is inside that servers installation. No one can upload addons into anyone else's server directory, just the same as no one can access that key file outside of their server installation.
That's not how torkscript works. If that code is executed before running your key function, it will print the key.

I dont know if its stuff coding or its intentional.
it literally takes 6 lines of code to steal keys from this service if you put it in an add-on

Let me reintroduce myself, my in-game name is BI0Hazzard, ID: 14911, old blockland forum account is Hazzard

I've made this account this evening under my brothers blockland id, 14483 due to him getting me banned from the forums a few years ago by excessive post deletion.

I can understand why you'd be wary, running Avast security for the servers. I can pull up all the info tomorrow

I've made this account this evening under my brothers blockland id, 14483 due to him getting me banned from the forums a few years ago by excessive post deletion.
The good old "My brother got into my account!" but even worse. You cannot delete posts you dumb brick. If your post is deleted,theres probably a ban with it.

That's not how torkscript works. If that code is executed before running your key function, it will print the key.

Thanks for enlightening me on that, I will update the add on tomorrow to clear the variable.

As far as I was aware, local variables could only be  read by the add on executing it.

However, as I said before, these files can only be accessed by that users server, if someone uploads an add on onto the server, it checks with the server database to see where their blockland server files are kept


Yep, that was my old one, I believe I was 13 when I started that?

It wasn't 'botched', no.

As I said before, I'm happy to show my code to anyone worried about their key, I will post the add on tomorrow when I return from college.

This is just a project I started a few years ago and decided to revisit.
« Last Edit: January 28, 2016, 06:45:29 PM by BI0-Hazzard »

reminder that critawakets is a moron and nothing he says should be taken to heart.

i look forward to seeing how this goes. good luck.

reminder that critawakets is a moron and nothing he says should be taken to heart.

i look forward to seeing how this goes. good luck.
the fact that 6 lines of code inserted into an add-on by an abusive admin with eval can steal a key should be taken to heart

the fact that 6 lines of code inserted into an add-on by an abusive admin with eval can steal a key should be taken to heart

Just to note, the part that runs the key and rewrites the file is in the preload, which I will modify tomorrow to remove all variables set by the file.

Chill out.

reminder that critawakets is a moron and nothing he says should be taken to heart.

i look forward to seeing how this goes. good luck.

Thank you!

reminder that critawakets is a moron and nothing he says should be taken to heart.

i look forward to seeing how this goes. good luck.
I see you are Friends with Grimlock/patton. This sounds like something he would say way too much. Ignorance is bliss for some people.

Thank you!
Okay never mind i see something definitly wrong. You ninjaed me into making me think that Akio is friends with Hazzard. Are you covering something up?

this looks promising assuming its not a fraud
lets just hope this doesnt crash and burn like Pacnet's and Hammereditors

this looks promising assuming its not a fraud
lets just hope this doesnt crash and burn like Pacnet's and Hammereditors
blocknet didn't crash though