Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Resort World Genting password limit, RIP security?

views
     
TSSkylinestar
post Dec 11 2025, 08:01 AM, updated 2w ago

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
this is my first time seeing password limit with symbols.
feels like something is wrong with the way the password is stored.

Only these symbols are supported @ . / # & + -

user posted image

kindly enlighten me this is ok.

This post has been edited by Skylinestar: Dec 11 2025, 08:02 AM
ZerOne01
post Dec 11 2025, 08:04 AM

Getting Started
**
Junior Member
124 posts

Joined: Feb 2007
From: Pahang




probably old system or db that dont support parsing fancy symbols
soul78
post Dec 11 2025, 08:10 AM

Enthusiast
*****
Junior Member
938 posts

Joined: Jul 2005


TS should cukur... they didn't say..

alphabet only a,b,c,d,e

numeric only 1,2,3,4,5
supsupsui
post Dec 11 2025, 08:11 AM

Getting Started
**
Junior Member
77 posts

Joined: Jun 2019


Best of luck!
DarkAeon
post Dec 11 2025, 08:13 AM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
QUOTE(ZerOne01 @ Dec 11 2025, 08:04 AM)
probably old system or db that dont support parsing fancy symbols
*
but generally, u don't store plaintext pwd in the db. it should be encrypted, therefore the "fancy symbols" shouldn't even matter bcoz they will be converted to something else

at least that's how it should be
H3artBreakKid
post Dec 11 2025, 08:49 AM

💔💔💔
***
Junior Member
455 posts

Joined: Jun 2012


Ok lettew

Some don't even allow symbols

Ez crack
TruboXL
post Dec 11 2025, 09:06 AM

Keep on keeping on! 👍
******
Senior Member
1,050 posts

Joined: Jan 2016
From: Land of floods, Kota Tinggi


storing password should be hashed not plaintext
macyhouse
post Dec 11 2025, 09:09 AM

Getting Started
**
Junior Member
273 posts

Joined: Feb 2008
15 character ok la
countingcrows
post Dec 11 2025, 09:11 AM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
Mebbe tak support foreign lang symbols?

ß, ç, æ
Virlution
post Dec 11 2025, 09:53 AM

Casual
***
Junior Member
484 posts

Joined: Jan 2010


I like !@#$%^&*

few already cannot

why so many restriction
TSSkylinestar
post Dec 11 2025, 11:32 AM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(Virlution @ Dec 11 2025, 09:53 AM)
I like !@#$%^&*

few already cannot

why so many restriction
*
agree.
any expert here can explain why cannot have password with ? character?
andrewhtf
post Dec 11 2025, 11:36 AM

Regular
******
Senior Member
1,583 posts

Joined: Apr 2006
From: Clerking. Data Entry like a Mad Man


QUOTE(Skylinestar @ Dec 11 2025, 08:01 AM)
this is my first time seeing password limit with symbols.
feels like something is wrong with the way the password is stored.

Only these symbols are supported @ . / # & + -

user posted image

kindly enlighten me this is ok.
*
I just throw these parameters into chathpt ask it to generate a few password options. Then randomly choose one and save. Let chrome help me autofill after that.
katijar
post Dec 11 2025, 11:36 AM

Look at all my stars!!
*******
Senior Member
2,294 posts

Joined: Sep 2011
Maybe it is key word in sql

Owait…
SourLemons
post Dec 11 2025, 11:36 AM

Getting Started
**
Junior Member
223 posts

Joined: Jun 2011
From: Hatfield. England


normal je , alot also restrict symbols
netmatrix
post Dec 11 2025, 11:52 AM

The machine... it sees everything.
*******
Senior Member
6,733 posts

Joined: Jan 2003
From: Zion


Alt 255 x 8.
failed.hashcheck
post Dec 11 2025, 12:03 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(DarkAeon @ Dec 11 2025, 08:13 AM)
but generally, u don't store plaintext pwd in the db. it should be encrypted, therefore the "fancy symbols" shouldn't even matter bcoz they will be converted to something else

at least that's how it should be
*
It's hashed, not encrypted. Different thing.
Virlution
post Dec 11 2025, 12:05 PM

Casual
***
Junior Member
484 posts

Joined: Jan 2010


QUOTE(Skylinestar @ Dec 11 2025, 11:32 AM)
agree.
any expert here can explain why cannot have password with ? character?
*
The system is not secure against SQL Injection, easy way is to block it.


Programming Errors/Security Flaws: This is the most common reason. Special characters like single quotes ('), semicolons (wink.gif, or the exclamation mark (!) can have specific meanings in programming languages or database queries (like SQL). If a developer doesn't properly "sanitize" or handle the input, an attacker could use these characters to run malicious commands (an "injection attack"). The easiest, but poor, solution for a developer is to simply block these characters altogether
Quantum Geist
post Dec 11 2025, 12:32 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(DarkAeon @ Dec 11 2025, 08:13 AM)
but generally, u don't store plaintext pwd in the db. it should be encrypted, therefore the "fancy symbols" shouldn't even matter bcoz they will be converted to something else

at least that's how it should be
*
usually the old "easy" way to prevent sql injection, emphasis on the "old" part, nowadays there are better ways to sanitize the input without limiting the characters.
Atrocious
post Dec 11 2025, 12:37 PM

Getting Started
**
Junior Member
100 posts

Joined: Oct 2022
Skyl1nest@r will do.
TSSkylinestar
post Dec 11 2025, 01:44 PM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(SourLemons @ Dec 11 2025, 11:36 AM)
normal je , alot also restrict symbols
*
example of popular websites?

This post has been edited by Skylinestar: Dec 11 2025, 01:44 PM
fireballs
post Dec 11 2025, 01:47 PM

10101
*******
Senior Member
5,650 posts

Joined: Mar 2012
15 character still ok..
i see some limiting to 8 characters. very difficult to make memorable password
TSSkylinestar
post Dec 11 2025, 01:52 PM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(Atrocious @ Dec 11 2025, 12:37 PM)
Skyl1nest@r will do.
*
RIP
haveibeenpwned.com/passwords
ktek
post Dec 11 2025, 02:07 PM

小喇叭
********
All Stars
13,215 posts

Joined: Jul 2006
QUOTE(Skylinestar @ Dec 11 2025, 01:44 PM)
example of popular websites?
*
long2 ago lyn here also got maa
ppl play hack terus admin do their job
brkli
post Dec 11 2025, 02:11 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
the name field got restriction? can put like this?

user posted image

This post has been edited by brkli: Dec 11 2025, 02:12 PM
Atrocious
post Dec 11 2025, 02:15 PM

Getting Started
**
Junior Member
100 posts

Joined: Oct 2022
QUOTE(Skylinestar @ Dec 11 2025, 01:52 PM)
RIP
haveibeenpwned.com/passwords
*
It's ok, here quite safe one. I've been using @troc10us123 also no problem so far..
brkli
post Dec 11 2025, 02:37 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(DarkAeon @ Dec 11 2025, 08:13 AM)
but generally, u don't store plaintext pwd in the db. it should be encrypted, therefore the "fancy symbols" shouldn't even matter bcoz they will be converted to something else

at least that's how it should be
*
QUOTE(TruboXL @ Dec 11 2025, 09:06 AM)
storing password should be hashed not plaintext
*
inb4, the hashing is using database function during data insertion.. owai...
SourLemons
post Dec 11 2025, 02:40 PM

Getting Started
**
Junior Member
223 posts

Joined: Jun 2011
From: Hatfield. England


QUOTE(Skylinestar @ Dec 11 2025, 01:44 PM)
example of popular websites?
*
cant recall exactly but nandos / starbucks macam restricts
DarkAeon
post Dec 11 2025, 02:41 PM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
QUOTE(failed.hashcheck @ Dec 11 2025, 12:03 PM)
It's hashed, not encrypted. Different thing.
*
this is a teachable moment

before hashing algo is developed, old school devs use encrypt first. now u know
voscar
post Dec 11 2025, 04:53 PM

Regular
******
Senior Member
1,526 posts

Joined: Dec 2005
Can set P@ssw0rd which matches all criteria

 

Change to:
| Lo-Fi Version
0.0185sec    1.05    5 queries    GZIP Disabled
Time is now: 18th December 2025 - 09:55 PM