[MUD-Dev] strong encryption for authentication

Dave Rickey daver at mythicentertainment.com
Sun Jul 15 14:15:14 New Zealand Standard Time 2001

From: J C Lawrence <claw at kanga.nu>

> I have visions of things like:
>   A worm that coordinates via a private IRC channel and which
>   monitors use of the local game client.  It does two things
>   when-ever the game client is run:
>     a) Sends the userID/passwords back home via the IRC channel.
>     b) Monitors any played characters for gold pieces and sends
>     home reports of in-game account balances etc.
>   The cracker then collects the passwords, bank accounts, etc,
>   tithes them at his leisure and sells the proceeds via EBay.

li0n (the most common "zombie") could already do this, with little
to no modification.

> Not a very tricky thing to do.  The next step up would be
> remote-automating or 'botting the character(s) either directly via
> the IP reported via the IRC channel, or via commands on the IRC
> channel.

With adequate knowledge, a li0n zombie could do that as well.

--Dave Rickey

