From 116ec3201acb28c368cc525e9ce54decce3040bd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Lo=C3=AFc=20Hoguin?= Date: Fri, 3 Sep 2010 22:17:47 +0200 Subject: [PATCH] psu_game: Don't delete the user on system_key_auth_request failure! This would be usable as a DOS attack against a specific user. --- src/psu/psu_game.erl | 1 - 1 file changed, 1 deletion(-) diff --git a/src/psu/psu_game.erl b/src/psu/psu_game.erl index 386f8fd..4e31af9 100644 --- a/src/psu/psu_game.erl +++ b/src/psu/psu_game.erl @@ -128,7 +128,6 @@ process_event({system_key_auth_request, AuthGID, AuthKey}) -> ?MODULE:char_select(); _ -> log("quit, auth failed"), - egs_user_model:delete(AuthGID), ssl:close(CSocket) end end.