PDA

View Full Version : My next little project


filburt1
06-08-2003, 04:59 PM
Haven for forums with trolls: a Java applet that makes a unique hash based on the user's hardware configuration and sends it to the registration script. Will work in any browser on any computer with the Java plugin.

Partially tested already and only vulnerable to decompiling or completely replacing the applet, but then again nothing you can do there. However the vast majority of trolls won't know how to do either.

Fun? :)

Dean C
06-08-2003, 05:04 PM
Lol yes but what do you want it for ;)?

- miSt

filburt1
06-08-2003, 05:19 PM
It would more firmly establish one registration per machine (obviously IP-based an cookie-based methods are unreliable).

KelteN
06-08-2003, 05:20 PM
That would be cool.

Dean C
06-08-2003, 06:51 PM
Ahh so you could check for dupe users more easily ;)?

Chris M
06-08-2003, 06:52 PM
And it would also ensure that a banning feature based on this uniue hash would be possible, and therefore more likely to result in a permanent ban:)

Satan

filburt1
06-08-2003, 06:53 PM
Well it obviously won't work for existing users, but upon registering it'll store the hash with their account, and when a user tries to register, it'll make sure that hash hasn't been registered.

Some parts of Java kick ass, others suck [random derrogatory term]...

Chris M
06-08-2003, 07:00 PM
Luckily for me none of my existing users are evil doers;)

Satan

Talisman
06-08-2003, 07:30 PM
Today at 12:53 PM filburt1 said this in Post #7 (https://vborg.vbsupport.ru/showthread.php?postid=406206#post406206)
Well it obviously won't work for existing users, but upon registering it'll store the hash with their account, and when a user tries to register, it'll make sure that hash hasn't been registered.
That sounds like a nice feature to have. Will it take long to develop and release the hack?

If we had an option like this, we'd have to think of a way to route existing members through the process, too. But how?

Maybe "invent" a one-time reauthentication requirement.... as part of a security upgrade? Make it like a patch with a pop up they click on next time they visit the site? Or couple the applet with some other (unrelated) hack, that sorta re-registers them.... but seems plausible?

Any ideas on this?

MUG
06-08-2003, 07:35 PM
What happens to people with Java disabled?

MRJ (Mac OS Runtime for Java) is buggy :confused:

filburt1
06-08-2003, 07:37 PM
People without Java are screwed. I agree it's not a very good method, but I wouldn't have to code it in the first place given a perfect world.

I may end up selling it. Right now I'm stuck on the part where it sends the data to the server (Java overcomplicates so many things it's not even funny).

filburt1
06-08-2003, 07:44 PM
Yay:

Tony G
06-09-2003, 11:00 AM
Hehe, that'd be neat. :)

Boofo
06-09-2003, 11:04 AM
What about someone with 2 computers or maybe a home computer and a laptop when they travel? And with this, they couldn't login from somewhere else, could they?

filburt1
06-09-2003, 12:15 PM
From my understanding, the ID I'm generating is a hashcode describing the user's network setup. Now hopefully that means hardware setup and not software (i.e., not IP).

Yes, you can easily get around it by using another computer, but there are only so many computers the troll can get his/her hands on ;)

Chris M
06-09-2003, 12:36 PM
Perhaps an ability to have multiple computers when a solution for existing users is found;)

Satan

Hobbes
06-09-2003, 07:28 PM
mmmmm....this looks reallly really cool...and i vote you dont sell it and release it on vb.org....:D...:p

filburt1
06-10-2003, 02:48 PM
I might release a lite version here and a for-sale version with stronger security (client/server-side checksumming to make it nearly impenitrible). Maybe I should finish coding it, though :p

Chris M
06-10-2003, 02:53 PM
Yeh;)

I'd be willing to invest in it:)

You know me - Security mad:p

Satan

Intex
06-10-2003, 03:59 PM
Very nice idea filburt1 - you'll be writing stuff for TCPA next :p.

Dean C
06-10-2003, 05:32 PM
Release it for free turtle.. you know you want to :p

- miSt

filburt1
06-10-2003, 05:34 PM
Today at 12:59 PM Intex said this in Post #20 (https://vborg.vbsupport.ru/showthread.php?postid=407092#post407092)
Very nice idea filburt1 - you'll be writing stuff for TCPA next :p.

I happen to be writing Java for NASA right now :p

Talisman
06-10-2003, 05:50 PM
Please don't charge people for this one. This sounds like an important hack; it's not some optional bit of fluff people can pass on if they're not able to pay you something.

A lot of people really need help with security problems.

Thanks.

filburt1
06-10-2003, 06:31 PM
As I said, I haven't decided...no need to assume I won't release it for free (or then again, at all :p).

Talisman
06-10-2003, 06:34 PM
Yes... we know. We're just trying to help you decide! ;)

blackice912
06-10-2003, 07:10 PM
Today at 08:31 PM filburt1 said this in Post #24 (https://vborg.vbsupport.ru/showthread.php?postid=407150#post407150)
As I said, I haven't decided...no need to assume I won't release it for free (or then again, at all :p).


Release it for $10 and watch the money flow :)