ORANGE: Can lead to service disruption, but not lost of control
ORANGE: Can lead to service disruption, but not lost of control
BLUE: "Too" Secure, doesn't allow admins to control the server
BLUE: "Too" Secure, doesn't allow admins to access the server
GREEN: Secure for service, allow admins to carry their tasks
GREEN: Secure for service AND allow admins to carry their tasks
In a perfect world, there should be at least one green lib installed, and no lib worse than blue
In a perfect world, there should be at least one green lib installed, and no lib worse than blue
# Types of users
root: the super-administrator, accessing any data about it is a security violation
user: an account accessed by a script or a human, assumed public knowledge but resetting the password is a security violation
ghost: a user created for the sole purpose of controlling the "registered user" exploit requirement and therefore have no rights as they aren't meant to be used. as they are treated as users by the game engine, exploits won't treat users and ghosts in the same way
guest: a password-less account which can't be accessed by legitimate requests, which makes it a perfect entry point for an admin backdoor
Here's the exploit
TODO: Lib requirements + type of users -laplongejr
TODO: Lib requirements + type of users -laplongejr