1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

RuneMate SAVES our passwords in PLAINTEXT

Discussion in 'Discussions' started by rcoder, Dec 17, 2017.

Thread Status:
Not open for further replies.
  1. Seraphic

    Seraphic Buying & Selling RSGP

    Joined:
    Dec 5, 2017
    Messages:
    19
    Likes Received:
    9
    Even if they stored them in plaintext it doesn't matter as long as you have 2FA and don't use the same password elsewhere, it's been said over 50000 billion times lol.
     
    Jux7apose likes this.
  2. Savior

    Savior Java Warlord

    Joined:
    Nov 17, 2014
    Messages:
    4,906
    Likes Received:
    2,748
    You mean the requests that are encrypted with TLS? lol
     
  3. rcoder

    Joined:
    Dec 17, 2017
    Messages:
    17
    Likes Received:
    0
    You mean installing a self signed local cert to view TLS encrypted requests is impossible? lol

    Also really proving you're the one who has no clue about security.
     
  4. Swych

    Joined:
    Dec 9, 2016
    Messages:
    3,031
    Likes Received:
    1,030
    Show us your logs and I'll believe you.
     
  5. Savior

    Savior Java Warlord

    Joined:
    Nov 17, 2014
    Messages:
    4,906
    Likes Received:
    2,748
    I'm not the one trying to decrypt hashes
    --- Double Post Merged, Dec 17, 2017, Original Post Date: Dec 17, 2017 ---
    I mean it's possible, but my first impression of him let me believe he would be too retarded to get that done :D
     
  6. Jhinn

    Joined:
    Jun 9, 2015
    Messages:
    3,646
    Likes Received:
    1,337
    TO CASUAL WE GOOOOOOOOOOOOOOOOOOOO
     
    Swych likes this.
  7. Ozzy

    Joined:
    Nov 5, 2014
    Messages:
    505
    Likes Received:
    162
    Just to debunk the whole check the network log claim, (as expected) any communication with Runemate's servers during the process of adding or deleting an account is encrypted. Of course this doesn't prove that accounts are stored in an encrypted form in the remote database but I'm fairly certain they will be.

    [​IMG]
     
  8. Aidden

    Aidden Author of MaxiBots

    Joined:
    Dec 3, 2013
    Messages:
    6,600
    Likes Received:
    990
    First you say they're plain text, then you say they're encrypted, now they're plain text again. Which one is it?
     
    Jux7apose likes this.
  9. Savior

    Savior Java Warlord

    Joined:
    Nov 17, 2014
    Messages:
    4,906
    Likes Received:
    2,748
    There are ways around that, check MITMProxy for example
    --- Double Post Merged, Dec 17, 2017, Original Post Date: Dec 17, 2017 ---
    His point is that they are allegedly stored in plaintext on the servers, which I absolutely can't imagine, knowing arbiter
     
  10. Aidden

    Aidden Author of MaxiBots

    Joined:
    Dec 3, 2013
    Messages:
    6,600
    Likes Received:
    990
  11. Arbiter

    Arbiter Mod Automation

    Joined:
    Jul 26, 2013
    Messages:
    2,938
    Likes Received:
    1,266
    User accounts are not, and never have been, sent to the server in cleartext. I advise OP to heed his own advice and Wireshark his own requests after spoofing the SSL certificate.
     
    Jux7apose, NYCowboy, Wet Rag and 3 others like this.
  12. Swych

    Joined:
    Dec 9, 2016
    Messages:
    3,031
    Likes Received:
    1,030
  13. skrall

    Joined:
    Jul 24, 2014
    Messages:
    634
    Likes Received:
    161
    I meant client developer, mb.
     
    Savior likes this.
  14. Savior

    Savior Java Warlord

    Joined:
    Nov 17, 2014
    Messages:
    4,906
    Likes Received:
    2,748
    Ah gotcha. The bot authors do have access to the aliases though.
     
  15. 0PrivacyMatter0

    Joined:
    Sep 24, 2017
    Messages:
    261
    Likes Received:
    49
    i'm not worried about this website hacking me, i bot with my funds on my account and never been hacked, peaked at 700m and still botting, no hacks.

    legendary comment
     
    Jux7apose likes this.
  16. Qosmiof2

    Qosmiof2 I've been called a god before.

    Joined:
    Aug 5, 2014
    Messages:
    3,212
    Likes Received:
    924
    I thought i was retarded :thinking_face:
     
  17. rcoder

    Joined:
    Dec 17, 2017
    Messages:
    17
    Likes Received:
    0
    Ok I heeded my own advice and verified that they are encrypted somehow. Both the login name + password are encrypted in one string and sent to the server. The alias is not encrypted. But that's less important.

    Example of one account encrypted. I hope there is a private key associated to this encryption string. I highly doubt there is. So it's STILL able to be deciphered by an intruder gaining access to the database, or by any of the admins.

    Code (Text):
    1. IfPhZTmAHsrPKBNqZoFwMtysh8lMKAcZT601/+ElDTeuyf8uv6hPFujN3sMi5+YA
     
  18. unexist

    unexist Does not exist.

    Joined:
    Jun 8, 2015
    Messages:
    333
    Likes Received:
    57
    just get authenticator and u will be safe i had accounts with more then 1B 07 without that on runemate never got hacked :)
     
  19. rcoder

    Joined:
    Dec 17, 2017
    Messages:
    17
    Likes Received:
    0
    But then I can't run bots overnight. They may get stuck if I lose internet connection. RuneMate should instead store this data locally, or use a private key to encrypt. One supplied by the user, and not stored anywhere. A "mater password".
     
  20. Qosmiof2

    Qosmiof2 I've been called a god before.

    Joined:
    Aug 5, 2014
    Messages:
    3,212
    Likes Received:
    924
    yo forreal are you kidding me?

    This is probably the safest bot website out there and you're trying to complain about aliases not being encrypted?

    cmon.
     
    Jux7apose likes this.
Thread Status:
Not open for further replies.

Share This Page

Loading...