Re: rlogin.js -h[pepper]
By: Digital Man to xbit on Sun Apr 13 2025 02:15 pm
Great update. Testing now on a few systems connected to Global War
Gate (rlogin server). So far so good.
Might have spoke too soon. When replacing the -p with -h a test caller
rloging into global war got the following:
Resolving hostname...
Invalid Logon
Password:
This test was from another BBS. My first tests was from my linux bbs to
windows bbs local.
That would be expected if the user already had an account with their password from the client BBS. You would need to delete their user account so it can be recreated with the right hashed-password or just change the account password to match the hashed-password that was attempted.
It sounds like the -s[tag] might need to be in play then? With out it, if a user first rlogs into the game and sync applies the pepper (hash) all is great. But if the user then wants to telnet via normal methods using the same user name they would need to know the long hashed password. Yes?
The -s[tag] would segregate a rlogin from a normal account. For example someone rlogging into xbit bbs from vert with a -s[vert] tag might look like [vert]xbit.
I did some testing before the -s[tag] idea and got this error:
FAILED Password attempt: 'testpass' expected:'7278D2BA..(long hash).
Am i on the right path or not getting somthing? Thank you DM.
...It is not enough to succeed. Others must fail.
---
þ Synchronet þ |15<|07<|08< +h3 |02><|08-bi+ >|07>|15>
* Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)