Post Reply 
 
Thread Rating:
  • 1 Votes - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Forcing Orion Client
Author Message
Coruja
Sphere Developer
*****

Posts: 987
Likes Given: 5
Likes Received: 226 in 187 posts
Joined: Jul 2012
Reputation: 7

Dimension Shard

Post: #2
RE: Forcing Orion Client
The 1st rule of security is implement all security checks at server-side and never trust on what comes from client-side

You can find if this client have some specific encrypt key to enable this key on spherecrypt.ini and disable all others keys, but this can be easily faked using some client launcher that can report to server an fake client version with fake encryption key

You can also check if this client send some specific packet to server to report that it's an "orion client" but this also can be easily faked if someone find the packet number to send it manually using any other client

So unfortunately the best way to keep your server secure is using the latest sphere version with latest security fixes to keep it safe at server-side level
05-24-2020 09:06 AM
Find all posts by this user Like Post Quote this message in a reply
[+] 1 user Likes Coruja's post
Post Reply 


Messages In This Thread
Forcing Orion Client - Fronz - 05-19-2020, 11:38 AM
RE: Forcing Orion Client - Coruja - 05-24-2020 09:06 AM
RE: Forcing Orion Client - Fronz - 06-02-2020, 12:21 PM
RE: Forcing Orion Client - Jhobean - 06-11-2020, 01:54 PM
RE: Forcing Orion Client - Coruja - 06-11-2020, 02:59 PM
RE: Forcing Orion Client - Jhobean - 06-11-2020, 09:39 PM
RE: Forcing Orion Client - Coruja - 06-12-2020, 05:21 AM
RE: Forcing Orion Client - Jhobean - 06-12-2020, 05:31 AM
RE: Forcing Orion Client - Fronz - 06-15-2020, 12:53 AM
RE: Forcing Orion Client - cele_35 - 01-24-2021, 05:25 AM
RE: Forcing Orion Client - Jhobean - 08-05-2022, 01:36 AM
RE: Forcing Orion Client - Atilla209 - 08-05-2022, 02:16 AM
RE: Forcing Orion Client - yeoldesphere - 08-28-2022, 06:28 AM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)