password bug


FitzSimmons

 

Posted

I have found a bug that may indicate something's wrong with the function used to check passwords. In other words I have found that I can login to my account with an inaccurate password under some circumstances. I don't think I should give details here but want to bring it to dev's attention. I have sent a private message to niviene about the details.

So why this thread? want to see if anyone else has noticed similar issues? Ever mistype your password and be let to login anyway?


 

Posted

I just purposely tried adding "\" or other characters to the end of it. I tried adding a space at the beginning or the middle of it. It doesn't even let me in if I capitalize something.

I have not found any case where it lets me in without my specific and exact password.


 

Posted

this is not true of passwords but is true with loggin names. you can screw up your loggin name to a point and it will still log you into the game. i know because this happened to me about 2 weeks ago. i switched 2 letters around by mistake and it still let me in. if it is happening with the password, then do a complete cleaning and scan of your system and get rid of anything that may be affecting it and change your password after.


 

Posted

Sharker - you may be on to something with this also being able to happen with a change in the login name rather than the password.

But, I have made sure it is on the server, not my computer.

Here's how:

Using the same alternate password that I found by accident, I was able to login to my account from a relative's computer (who also plays CoH so they had it installed). And I was even able to login using either the real or alternate passwords to the message boards now that it uses the same password setup.

So it is not anything on my system causing this. It is a server side issue.

If Sharker was able to mistype a login name and get the same result, that might be important.. or maybe not. I can't tell from here. I just hope the devs/community people look into this.


 

Posted

bug still exists, no one has contacted me


 

Posted

then you have to verify files. if it still does it, then uninstall the game and reinstall it. i also don't care that it says you should turn off your virus/spyware protection while installing. DO NOT do this. you will most likely end up with a lot of bad stuff on your comp that you do not want.

there is no possible way if all the files are correct for CoX that you should be able to log in with a different/slightly modified password. the only way to log into the game with a different password is if you went to your master account and changed the game password.


 

Posted

Quote:
Originally Posted by Sharker_Quint View Post
there is no possible way if all the files are correct for CoX that you should be able to log in with a different/slightly modified password. the only way to log into the game with a different password is if you went to your master account and changed the game password.
...or unless there is a bug. He said the forum lets him log in with the "different/slightly modified password" as well, so I doubt the game files would have anything to do with that. It also let him log in at a relative's house using the same "method".

On a side note, I still have yet to replicate this myself.


 

Posted

Quote:
Originally Posted by Sharker_Quint View Post
there is no possible way if all the files are correct for CoX that you should be able to log in with a different/slightly modified password. the only way to log into the game with a different password is if you went to your master account and changed the game password.
Hi, I'm the relative whose computer Flare was able to login to his account with... with all 3 versions of his password, apparently.

I agree that there certainly should not be any possibility of this happening. But there is... and it seems like it has to be a bug, right?


 

Posted

Is the password abnormally long? 16 or 32 characters? On some operating systems passwords more than a certain number of characters long will silently ignore anything after the nth character. Now my password is 10 characters long and I know if I add characters to the end of that it doesn't make a difference but I guess it's possible this is what's hapenning.


 

Posted

I've had problems it telling me its the wrong password when i tried to access it when i know for the fact that its the right one. I got to the point that the game telling me please contact support. But i just exited out the game and reloaded and tried again and it worked eventually, but it was really annoying.


Tempstra 50 Rad/Dark Defender/War'nt 50 Warshade/Heliosa 50 Fire/Rad Controller//Captain Blue Balls 50 Fire/Ice Blaster/Pinky Swear 50 Dark/Dark ScrapperMind Dreamer 50 Mind/Kinetics Controller/Rex Bubbles 50 Illusion/Forcefield Controller/Cool Wind 50 Ice/Storm Controller/Lil' Miss Dangerous 50 Gravity/Kinetics Controller/Observationist 50 Illusion/Empathy Controller/Kansas City Brawler 50 Stone/Fire Tank/Hades Exhibit One 50 Dark/Robots MM

 

Posted

Fitzsimmons, my password is not abnormally long. No longer than your 10 character one. Now your situation where you can add an 11th character and it still lets you login is a problem similar to mine - is that the case with any program in your OS or is it specific to CoH?

Tempstra, your problem might be your capslock key. I'm more worried about a wrong password that always works, than I would be about a correct one occasionally failing...


 

Posted

Flare, I had a similar problem to you. It allowed a 1 character variation in my password. It was fixed eventually though without me doing anything.


 

Posted

i remember, a while back, that Houtex had found something that sounds very similar to this. i'll try to find it..but it was a LONG time ago. :-(

something about adding certain digits to the end of the password...or some such...can't remember.


 

Posted

It sounds like this is a persistent long time bug. And that no one wants to respond about it. Sweeping it under the rug is not going to help


 

Posted

did you open a ticket with support?



"Sorry bucko, but CoH and CoV are the same game." -BackAlleyBrawler
"Silly villain, CoX is for Heroes!" -Saicho

 

Posted

Quote:
Originally Posted by Flare_NA View Post
It sounds like this is a persistent long time bug. And that no one wants to respond about it. Sweeping it under the rug is not going to help
What were you expecting to happen here? If you look at the title of this section of the forums it reads as follows:

Technical Issues & Bugs Discuss technical questions and/or bugs here! This is NOT a forum where official technical/QA support is available. To report a bug use the /bug command in game. For technical assistance email support@coh.com.




This is a section of the forums to discuss things only. Yes, quite a few of the players here help other players with problems, and very rarely a Dev will pop in to a thread here to acknowledge a particular issue or ask for more information on it, but that's pretty much it.

If you want it fixed, file a /bug report with steps that can reproduce it 100% of the time. If they can't reproduce it, they can't find what causes it and thus can't fix it. I've not been able to reproduce it, Master-Blade hasn't been able to reproduce it, and it's very possible that QA hasn't been able to reproduce it (if you filed a /bug report or support ticket) or CS hasn't been able to reproduce it (if you filed a support ticket). You said you PM'd Niviene about it, but all she can do is forward the information you gave to CS or QA. If you don't file a /bug report or support ticket, they possibly have no way of contacting you for more information.


If the game spit out 20 dollar bills people would complain that they weren't sequentially numbered. If they were sequentially numbered people would complain that they weren't random enough.

Black Pebble is my new hero.

 

Posted

Yes, I entered a bug report and also a support ticket about this. I did those before starting this thread in fact.

However, the repro steps are problematic. To give them, I'd have to give my password. I think that this might be a bad idea. I was waiting for them to say whether or not I should.

I tried to (and failed to) make a support account, so I am not sure how to follow up on the support ticket. The email that was supposed to create my support account never arrived, and I did check that my email is set correctly in my plaync master account also. So at that point I was not sure what else I could do.

This is not the sort of bug you can make a simple repro for. It may be that only certain combinations of username and password have the erroneous mutliple acceptable codes. I'd have to be employed there and able to make a bunch of different usernames and passwords and try them out, preferably scripted. If I try doing that as a user it is a huge security issue! i don't think I should.

Basically this is something important that should be a priority to fix but not something a player can give that much help with.