• Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • [Q] Is it possible to do IP lookups on who is using a key?

    Discussion in 'General Discussion Forum' started by AutomaticCoding, Apr 10, 2014.

    1. AutomaticCoding

      AutomaticCoding Banned

      Joined:
      Dec 20, 2011
      Messages:
      1,091
      Likes Received:
      1
      Trophy Points:
      0
      [​IMG]

      I was using Hearthbuddy, but, I've not touched Demonbuddy in months, I don't even own a copy of Demonbuddy any more. Obviously, it's never a good sign to see a bot with negative running time that you're not running, so, I'm going to assume it's a bug, but, I'd still like to be sure my BuddyAuth/BuddyKey isn't compromised.
       
    2. DaSoul

      DaSoul Well-Known Member

      Joined:
      Jan 15, 2010
      Messages:
      2,827
      Likes Received:
      47
      Trophy Points:
      48
      You can't look it up yourself, buddy staff can. Contact the support.
       
    3. AutomaticCoding

      AutomaticCoding Banned

      Joined:
      Dec 20, 2011
      Messages:
      1,091
      Likes Received:
      1
      Trophy Points:
      0
      Actually, I just realized this isn't even my key:-

      [​IMG]

      This key starts with 55, my key starts with 6l:-

      [​IMG]

      It would appear as though there's some sort of database lookup error surrounding my account.

      EDIT:- Just tested Demonbuddy with this phantom key (I assume it's someone else's legitimate key):-
      [​IMG]

      It does auth me, compared to running with a fake key:-
      [​IMG]

      So, yeah, database lookups and leaking serial keys. *Yay*. I'd change the key for the other user (As now, theoretically, I have it), work out the issue, and, hope to god it's not a global issue with everyone's serials being leaked.

      For reference, considering the serial is 20 hex-bytes long, and, I've given away the first 12 bits (Plus a sha512sum of a salted version of the serial, which I've since removed), that's sixty eight bits worth of entropy, not amazing, but, enough to actually break it, so, staff really should go about changing this user's serial key, for security of both me knowing it, and, what I've posted.
       
      Last edited: Apr 10, 2014
    4. Tony

      Tony "The Bee" Staff Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      128,834
      Likes Received:
      571
      Trophy Points:
      113
      we will check it,thx for your report
       

    Share This Page