• Welcome to Valhalla Legends Archive.
 

I found a problem with BNLS.

Started by Deception, May 05, 2005, 11:51 PM

Previous topic - Next topic
|

Deception

I found a problem with BNLS.

To explain this problem, we must first understand what BNLS does.

BNLS receives your account passwords and CD-Keys in plaintext from the client.
It then hashes them and sends back the hashed value to the client to be sent to Battle.net.

Now, the whole purpose of hashing in the first place is to make it impossible to obtain the password/CD-Key when sending it to Battle.net (through sniffers and what not). You send a hashed value instead of the plaintext value.

So, the problem with BNLS is simple: It defeats the purpose of hashing in the first place.

Unfortunetly this is a problem with only one solution: Stop using BNLS.

It's pointless.
- Deception of Dark Council

Warrior

Wow, you're a fucking genius. Shutup.
Quote from: effect on March 09, 2006, 11:52 PM
Islam is a steaming pile of fucking dog shit. Everything about it is flawed, anybody who believes in it is a terrorist, if you disagree with me, then im sorry your wrong.

Quote from: Rule on May 07, 2006, 01:30 PM
Why don't you stop being American and start acting like a decent human?

UserLoser.

What's the problem?  You're jealous now because you use that NLS.dll or what

QwertyMonster

BNLS isnt Pointless everywhere. It is helpful, if you know how to use it in the right way.

EG: For connecting to some clients. (Warcraft perhaps..)

Eternal

Quote from: Deception on May 05, 2005, 11:51 PM
I found a problem with BNLS.

To explain this problem, we must first understand what BNLS does.

BNLS receives your account passwords and CD-Keys in plaintext from the client.
It then hashes them and sends back the hashed value to the client to be sent to Battle.net.

Now, the whole purpose of hashing in the first place is to make it impossible to obtain the password/CD-Key when sending it to Battle.net (through sniffers and what not). You send a hashed value instead of the plaintext value.

So, the problem with BNLS is simple: It defeats the purpose of hashing in the first place.

Unfortunetly this is a problem with only one solution: Stop using BNLS.

It's pointless.

Then don't use it.
^-----silly Brit
-----------------------------
www.brimd.com

Networks

#5
Wow..weren't you doing a "clan" (group) project that was going to impliment BNLS along with a hashed connection? And I believe you were mad at ArchAngel because he didn't want to a project that implimented BNLS and you did.

Deception that was retard post and you're simply stating the obvious many people (a good majority of respected programmers) already knew about. Congratulations!

Quote
It's pointless.

Yes this entire post is. I give you the most pointless post of the year. Infact you're slowly losing my respect with such immaturity.

The solution is quite simple:
If you don't like it, DO NOT use it.

R.a.B.B.i.T

The point of using BNLS to hash passwords and CD-Keys isn't because you need them hashed so nobody can read them, it's to hash them because that's what Battle.Net requires to determine a valid copy of the game.  Please understand what BNLS does before you try and bash it.
<translation>Shut the fuck up.</translation>

CrAz3D

Quote from: Warrior on May 06, 2005, 12:13 AM
Wow, you're a fucking genius. Shutup.
I second that motion.

BNLS, like it, love it, or shove it
rebundance - having or being in excess of sheer stupidity
(ré-bun-dance)
Quote from: Spht on June 22, 2004, 07:32 PMSlap.
Quote from: Adron on January 28, 2005, 09:17 AMIn a way, I believe that religion is inherently evil, which includes Christianity. I'd also say Christianity is eviller than Buddhism (has more potential for evil).
Quote from: iago on April 19, 2005, 01:06 PM
CrAz3D's ... is too big vertically, at least, too big with ... iago ...

Warrior

I don't believe you have any right to be telling anyone what they should and should not run, so when you run BNLS then you can do whatever you want with the server, as wrong as your thinking may be.
Quote from: effect on March 09, 2006, 11:52 PM
Islam is a steaming pile of fucking dog shit. Everything about it is flawed, anybody who believes in it is a terrorist, if you disagree with me, then im sorry your wrong.

Quote from: Rule on May 07, 2006, 01:30 PM
Why don't you stop being American and start acting like a decent human?

Deception

You kids make me laugh.

And no, Networks, ArchAngel refused to use anything but BNLS on the clan bot project. That is why I banned him.
- Deception of Dark Council

QwertyMonster

Quote from: Deception on May 06, 2005, 12:45 PM
And no, Networks, ArchAngel refused to use anything but BNLS on the clan bot project. That is why I banned him.

We dont care.

Quote from: Deception on May 06, 2005, 12:45 PM
You kids make me laugh

You, calling us kids? Get a life Deception. No-one likes you, you jealous ignorant worthless peice of dirt on this planet. Go live on Mars.

shout

I think the point of BNLS is to provide a way to hash because you don't want to use or can't use local hashing.

UserLoser.

#12
Quote from: Shout on May 06, 2005, 12:54 PM
I think the point of BNLS is to provide a way to hash because you don't want to use or can't use local hashing.

As Spht once told me when I told him that someone else who was banned here a long time ago and I (way before the whole maddox/iago/theministered/whoever else ordeal) were going to start reversing War3 logon things year(s) ago, "why reinvent the wheel?"

Archangel

#13
Quote from: Deception on May 06, 2005, 12:45 PM
You kids make me laugh.

And no, Networks, ArchAngel refused to use anything but BNLS on the clan bot project. That is why I banned him.

1st of all you didnt banned me, i left your clan. (lol you are an idiot)

2nd, i didnt rejected Local hashed connection, i just said it was a clan project and we would use what we (members) wanted, but you are so damn immature and selfish that you wanted us to make a operator bot just for you.

And like warrior told you:
If you are scared to send data to a server over a game, get off the internet.

[The only problem here is you]
I'm not an Addict.

QwertyMonster

In simple:

Dont like BNLS? Dont use it then![/size]

|