Why wont the dumbass owner contact me lol? I have an exploit which grants access to the character database; I've given it to Clawlancer to hurry him up on taking action.
Why wont the dumbass owner contact me lol? I have an exploit which grants access to the character database; I've given it to Clawlancer to hurry him up on taking action.
Retrieve Password Failure, making an easy injection to get the PW from ERROR Invalid User / password
Now made over 50 query which needs only a launch button![]()
Nice find! After all this is over and fixed, could you tell us how did you do it? Would be nice to see your method.
Was it after all an ingame sql injection? Or webserver sql injection, blind sql injection?![]()
Last edited by xkyve; 08-12-2012 at 08:40 AM.
I've given him a webserver sql injection; But his method was a simple exploit in password recovery which they've now fixed. The dumbasses wont contact me for the fix to the sqli, however.
Ok, so both exploits were webserver sql injections. I thought the exploits were ingame, demanding sanitizing inputs in the c++ core.
Post the exploits here, after they will be fixed, of course, so that nobody can abuse the servers further. I don't even play there, I was just curious in the sql injection subject and how people discover methods in exploiting private servers.
Would be nice if more people would post hacking stories. It's a good read![]()
No, 1 of them was a webserver sqli, the other 1 was a retarded site admin.
When you will release the Char DB ?