[DiscordArchive] for WowSimpleRegistration?
[DiscordArchive] for WowSimpleRegistration?
Archived author: Kelpie • Posted: 2024-02-12T05:25:46.018000+00:00
Original source
since then, there have been 2 versions of srp6 that have been implemented, the version that's used is stored in the `battlenet_accounts` table as `srp_version`
Archived author: Kelpie • Posted: 2024-02-12T05:26:22.578000+00:00
Original source
https://trinitycore.info/database/master...t_accounts
[Embed: battlenet_accounts]
This table holds information on all available battlenet accounts.
https://trinitycore.info/database/master...t_accounts
Archived author: Kelpie • Posted: 2024-02-12T05:26:32.340000+00:00
Original source
as you can see they're not very well documented here
Archived author: Kelpie • Posted: 2024-02-12T05:27:21.238000+00:00
Original source
but the gist of it is that in order to create an account, you no longer just hash your password, you must include the srp version, and then break the password into salt and verifier fields
Archived author: Kelpie • Posted: 2024-02-12T05:27:52.504000+00:00
Original source
and srp version 1 is handled differently than srp version 2, as srp version 2 can handle passwords up to 128 characters
Archived author: Kelpie • Posted: 2024-02-12T05:28:51.310000+00:00
Original source
the salt is just a random binary value, and the verifier is the password after being encrypted, using the salt
Archived author: Kelpie • Posted: 2024-02-12T05:29:07.753000+00:00
Original source
using the srp6 algorithm
Archived author: Kelpie • Posted: 2024-02-12T05:30:57.735000+00:00
Original source
again, that's about as much advice as I can give...in the end, I ended up enabling soap on my server, and then completely rewrote the appropriate sections of user.php to connect via soap...I can send you my version of user.php if you'd like
Archived author: Kelpie • Posted: 2024-02-12T05:32:05.501000+00:00
Original source
but I think if you're trying to write an sql injection script, it won't help, since I avoided sql injection
Archived author: Kelpie • Posted: 2024-02-12T05:34:19.977000+00:00
Original source
(for anyone who might be using WSR, like <@764299824124002346> you might want to know that just enabling soap in the config is not enough, because enabling soap does nothing if your core has bnetaccounts)