|
|||||||
This is a discussion on "Basic MUD security for admins and novices" in the Top Mud Sites Tavern of the Blue Hand forum : It seems one of the most recurring posts made on admin, legal and ethical forums either here or on TMC is a cry for help: Help, a former staff member has stolen my MUD or wiped my files, what can I do? It seems the obvious needs to be stated from time to time. To be safe rather than sorry, you should get a few very simple security habits, and fortunately, most of those require no coding at all. Security is not reserved to major corporate networks. It's a safety net to avoid some problems. The few measures below ... |
|
You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our MUD community today! If you have any problems with the registration process or your account login, please contact us. If you are a registered member of the old TMS forums, please click here
|
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 |
|
Member
|
It seems one of the most recurring posts made on admin, legal and ethical forums either here or on TMC is a cry for help: Help, a former staff member has stolen my MUD or wiped my files, what can I do?
It seems the obvious needs to be stated from time to time. To be safe rather than sorry, you should get a few very simple security habits, and fortunately, most of those require no coding at all. Security is not reserved to major corporate networks. It's a safety net to avoid some problems. The few measures below won't stop a determined hacker, but will slow down the casual self-righteous avenger. Five steps to prevent a lot of future trouble: 1. Use at least basic password encryption instead of plain text. If you want to be able to help out players who lost their password, implement a command allowing staff to set a new password, and e-mail it to the addy the player used when creating their char. 2. When ordinary staff member resign, back up their work, then delete their account. You can always restore it if they return at a later date. 3. When staff members with shell accounts leave, immediately change the shell password. If you can't do that yourself, ensure the hoster does it immediately. 4. Ask your hoster to log IPs to shell access. 5. Backup your MUD as often as possible. Ideally once a day, in the worst case before and after any change is introduced. Don't leave the backups on the shell, ftp them to your private computer and delete them. Now that was simple, wasn't it? Of those five steps, only the first one might involve actual coding, if it isn't shipped out of your codebase's distribution. If you ever experience a disgruntled staff member wreaking havoc on your MUD or simply stealing the code, while you didn't implement those five steps, post your horror stories if you want, but remember: you have been warned. |
|
|
|
|
|
#2 |
|
Member
|
6. Use a secure version of telnet and ftp (SecureCRT, OpenSSH, many others) when connecting to your shell account, otherwise your password is liable to be intercepted, it's not a fairy tale, it happened to an unfortunate customer of mine.
|
|
|
|
|
|
#3 |
|
Senior Member
|
Alternatively, code an SSH socket in your codebase because telnet is known to be insecure. The most ideal thing being a codebase only accepting SSH connections for imps/imms. Telnet connections for anyone but players would/should be refused.
|
|
|
|
|
|
#4 | |
|
Member
|
Quote:
I'd rather venture that the people who know how to do that are not likely to post their pleas for help anyway. |
|
|
|
|
|
|
#5 | |
|
Senior Member
|
Quote:
Altho this does give a problem with non-opensource codebases/engines... |
|
|
|
|
![]() |
| Thread Tools | |
Basic MUD security for admins and novices - Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Six Basic Directions | NotL337 | MUD Builders and Areas | 19 | 12-02-2006 03:53 PM |
| Recruiting coders, basic C skills needed | Singer | Advertising for Staff | 0 | 05-01-2005 10:44 AM |
| Security certification | the_logos | Advertising for Players | 2 | 08-26-2004 04:48 AM |
| New Article: Basic Player Wants and Needs | imported_Synozeer | MUD Announcements | 0 | 02-03-2003 01:10 PM |
| Basic Codebase | Zellius | MUD Coding | 6 | 06-30-2002 10:43 AM |
|
|