<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forum.eggheads.org/app.php/feed/topic/7013" />

	<title>egghelp/eggheads community</title>
	<subtitle>Discussion of eggdrop bots, shell accounts and tcl scripts.</subtitle>
	<link href="https://forum.eggheads.org/index.php" />
	<updated>2004-06-20T19:05:16-04:00</updated>

	<author><name><![CDATA[egghelp/eggheads community]]></name></author>
	<id>https://forum.eggheads.org/app.php/feed/topic/7013</id>

		<entry>
		<author><name><![CDATA[Alchera]]></name></author>
		<updated>2004-06-20T19:05:16-04:00</updated>

		<published>2004-06-20T19:05:16-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=37651#p37651</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=37651#p37651"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=37651#p37651"><![CDATA[
[SD]Amon:<blockquote class="uncited"><div>a simple solution (unless your useing a windrop....) <br>chmod</div></blockquote>ppslim:<blockquote class="uncited"><div>4: Bingo, they should have the information needed to further the quest.</div></blockquote>Once again ppslim has hit the nail on head. <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3646">Alchera</a> — Sun Jun 20, 2004 7:05 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[j0n]]></name></author>
		<updated>2004-06-19T22:18:41-04:00</updated>

		<published>2004-06-19T22:18:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=37627#p37627</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=37627#p37627"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=37627#p37627"><![CDATA[
Public encryption will only keep your files secure from "good guys".<br>Your brother decides to log into your shell and play with the files, but because he is an idiot he won`t know know how to decrypt.<br><br>This is the same concept of those 3rd party firewall software, it only blocks out people with no knowledge.<br><br>If someone really wanted to, they could decrypt your files regardless.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3133">j0n</a> — Sat Jun 19, 2004 10:18 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2004-06-19T06:09:41-04:00</updated>

		<published>2004-06-19T06:09:41-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=37586#p37586</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=37586#p37586"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=37586#p37586"><![CDATA[
a simple solution (unless your useing a windrop....)<br>chmod<br>unless root is trying to access your files, dont worry.  you haveto tick someone off alot if they hack a machine, make themselves root, and all they do is look for your bot passwords and settings.  Its safe just to restrict access to the file to you.<p>Statistics: Posted by Guest — Sat Jun 19, 2004 6:09 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[strikelight]]></name></author>
		<updated>2004-03-08T20:10:47-04:00</updated>

		<published>2004-03-08T20:10:47-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34370#p34370</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34370#p34370"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34370#p34370"><![CDATA[
However, with method 2, you must assume there are more than one bot (across multiple machines) guarding the channel.. In which case, a single bot not being there for protection isn't going to hurt any... Assuming of course, only the one machine is comprimised.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2005">strikelight</a> — Mon Mar 08, 2004 8:10 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[ppslim]]></name></author>
		<updated>2004-03-08T19:36:28-04:00</updated>

		<published>2004-03-08T19:36:28-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34369#p34369</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34369#p34369"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34369#p34369"><![CDATA[
Right, I have a little more time on my hands now, so lets go a little more indepth as to why encryption of this kind is silly and impossible.<br><br>OK, I conceed there are a few ways to prevent people from getting the password.<br><br>One method is to code the bot such that it reacts to being traced. There are two cources of action here.<br><br>1: Destroy the de/encryption password key<br>2: Kill the bot, so there is no longer a process to trace<br><br>There is one large flaw here. An attacker only needs to attempt a trace, and they bring your channel to a standstill with regards to protection.<br><br>With method 1, it can no longer tell who a bot owner is from an attacker. The user list is usless. With method two, the bot isn't there to do the protection.<br><br>Also with method one, you could potentialy put the channel into a deep security mode. Where the bot will not let anybody change a mode, and deop people. The only issue with this, if two bots are attacked, they would not know each other is safe, thus you end up with a shortlived war, then when bots are restarted, a channel without ops.<br><br>That covers protections methods. Lets talk about what they are designed to protect the bot from.<br><br>Common tools used to trace program execution, are usualy intended for programers to know what data is where and when.<br><br>All well and good, but it also allows attackers to know what passwords are where and when.<br><br>There are three locations you could specify the password de/encryption key.<br><br>1: Within the source code<br>2: Specified on the command line at startup<br>3: When you start the bot, you are asked for it before the program continues.<br><br>All three will occupy memory once the bot is loaded. You can't just destroy it once the bot has started, otherwise, what password is used to re-encrypt the userfile and such.<br><br>The said debug tools noted above will do the following.<br><br>1: Trace the code path and store it<br>2: The attacker then reads back this information.<br>3: They locate a line relating to decryptiing the data or resaving<br>4: Bingo, they should have the information needed to further the quest.<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2">ppslim</a> — Mon Mar 08, 2004 7:36 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[KevKev]]></name></author>
		<updated>2004-03-08T14:26:35-04:00</updated>

		<published>2004-03-08T14:26:35-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34366#p34366</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34366#p34366"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34366#p34366"><![CDATA[
<blockquote class="uncited"><div>2: If you specified it embeded into the code, they could easily get the information using common debug tools.</div></blockquote>He already covered embedding it in the source<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=3940">KevKev</a> — Mon Mar 08, 2004 2:26 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2004-03-07T12:45:07-04:00</updated>

		<published>2004-03-07T12:45:07-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34333#p34333</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34333#p34333"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34333#p34333"><![CDATA[
<blockquote class="uncited"><div>Then you should have heard why the peoplet hat do this, closly protect there methods.<br><br>If they where to become public, then the encryption would be usless.<br><br>You have to somehow tell the bot the password to decrypt it<br><br>1: If you told it on the command line. People could easily read it.<br><br>2: If you specified it embeded into the code, they could easily get the information using common debug tools.<br><br>Think about it for a second. How do you tell the bto the password without anybody reading it? You can't!</div></blockquote>When you tweak eggdrop, and put the key in the source, it is possible.<p>Statistics: Posted by Guest — Sun Mar 07, 2004 12:45 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[ppslim]]></name></author>
		<updated>2004-03-07T11:57:05-04:00</updated>

		<published>2004-03-07T11:57:05-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34331#p34331</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34331#p34331"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34331#p34331"><![CDATA[
Then you should have heard why the peoplet hat do this, closly protect there methods.<br><br>If they where to become public, then the encryption would be usless.<br><br>You have to somehow tell the bot the password to decrypt it<br><br>1: If you told it on the command line. People could easily read it.<br><br>2: If you specified it embeded into the code, they could easily get the information using common debug tools.<br><br>Think about it for a second. How do you tell the bto the password without anybody reading it? You can't!<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=2">ppslim</a> — Sun Mar 07, 2004 11:57 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2004-03-07T11:41:44-04:00</updated>

		<published>2004-03-07T11:41:44-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34330#p34330</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34330#p34330"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34330#p34330"><![CDATA[
<blockquote class="uncited"><div>you cant<br>use the forum search, you'll find topics on that only a few days old</div></blockquote>I cannot ? Sure I can, I heard alot about it.<p>Statistics: Posted by Guest — Sun Mar 07, 2004 11:41 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[GodOfSuicide]]></name></author>
		<updated>2004-03-07T10:36:38-04:00</updated>

		<published>2004-03-07T10:36:38-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34328#p34328</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34328#p34328"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34328#p34328"><![CDATA[
you cant<br>use the forum search, you'll find topics on that only a few days old<p>Statistics: Posted by <a href="https://forum.eggheads.org/memberlist.php?mode=viewprofile&amp;u=1433">GodOfSuicide</a> — Sun Mar 07, 2004 10:36 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2004-03-07T08:05:21-04:00</updated>

		<published>2004-03-07T08:05:21-04:00</published>
		<id>https://forum.eggheads.org/viewtopic.php?p=34323#p34323</id>
		<link href="https://forum.eggheads.org/viewtopic.php?p=34323#p34323"/>
		<title type="html"><![CDATA[How to encrypt your config &amp; script files]]></title>

		
		<content type="html" xml:base="https://forum.eggheads.org/viewtopic.php?p=34323#p34323"><![CDATA[
As the title says how to encrypt your configuration file, so that IF someone get into your box, he cannot read your configuration file because it is encrypted, but the eggdrop have to read it, otherwise he cannot load the settings <img class="smilies" src="https://forum.eggheads.org/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by Guest — Sun Mar 07, 2004 8:05 am</p><hr />
]]></content>
	</entry>
	</feed>
