Separate names with a comma.
Comments in 'General Discussion' started by deot, May 20, 2015.
Awesome! Can't wait to try it out.
SimpleAuthHelper works with SimpleAuth and will detect multiple passwords attempts and has a time-out setting.
It will give you (some) protection against brute force attacks.
I have also posted an update (1.2.2) that implements an automatic ban by IP if somebody tries to login multiple times.
But I know SimpleAuthHelper already since u first release it.
But I didn't use it becauae I try (first version) to login with /login but it didn't work... Can u make both /login and direct type password work? Because some players don't know about this kind of login method without /login
Thanks in advance
I found this. Is this the right one?
Technically, brute force is not THAT possible, because you need to transmit a lot of message packets between the server and the clients. It will actually lag the server.
According to a test on a fairly fast VPS, brute-force of 16777215 passwords using SimpleAuth's algorithm takes about 89 seconds. (provided the hash is saved in a variable)
so people can lag a server to thats not good
People can always lag a server, for example by DoS (not necessarily DDoS). In this case the lag is good, because it may avoid the user logging in by having a timeout.
i know but most of the people don't know how to dos (ddos)
That isn't the problem. The problem ims someone can, regardless of how many people can.
As an experienced modder, i can tell you that most of the hacks on here won't work on servers.
For a start, any type of:
Block Placement (Auto)
Client Speed Change (Fps : e.g.: slowmo)
Inventory Hacks (on Pocketmine)
Player Modifications Such as Health and Invisibility (Any invis on pocketmine is just a bug)
Gamemodes (Will have the ability to fly, but STILL takes damage, and items will be stopped by pocket mine. Health will look different to the player, but no change will occur)
Speed Mining can be detected.
Will not work on servers and will only have effect on the hacker.
Also, the password hack only spams numbers.
Who sets there pass to only numbers? (lol)
Tell me some more hax on there and ill tell u if they work or not.
Mods/Features that work:
Speed (pocketmine is crud at stopping this xD)
Fly (stopped by pocketmine)
Teleportation (can be stopped by pocket mine)
But I can tell u 1 hack that work like god on Pocketmine, that's invisible!
Player can kill a player without showing himself, invisible!
Nop. Must be a PM bug. Invis = custom model.
I know, okay maybe its a bug, but they really bypass this bug... They are really in invisible and can kill people.. I see by my own eyes! At first, I wasn't trust my players said that too, but after I built the PvP Arena, this kind of thing happen more frequently and I saw them even kill me in invisible
I really hope pocketMine can update and patch this bug
Its not a bug BlockLauncher can control. Its just something random.
I thought BlockLauncher disables any mod when in an server?
Oppositely, BlockLauncher enables all mod to help you to "hack" (Maybe I can't call it hack) the server
Really? TMI does not work in servers.... In fact, the icon does not appear at all.
He programmed it not to as it wouldn't work