Jump to content

[Exploit + guide]Lets hack: Unsanitized input tutorial + Kick from com Channel.


Recommended Posts

About four years ago i knew absolutelly nothing about l2j and exploits. I was a typical player ( noob ) that was surfing around maxcheaters ( maxbastards then ) for exploits without understanding anything. What i always wondered, was how do exploits work and why there is no serious guide in mxc explaining it. But i made a promise to myself, to get to know everything that there is to it. So with some delay i think i pretty much got there ;) This guide aims to show you how the sanitization of input when not done creates exploits. Since i did the same with race condition exploits in another topic ill do the same here for the shake of illumination :) The guide will be followed by an exploit i just found out that works both in freya and in interlude ( checked in brazil and l2jserver freya ). Unless im wrong it is not re-shared since its not fixed anywhere.

 

Unsanitized input:

 

The client gives you limmited interaction with the server. You cant try attack players that you dont "see" and so on. Packet hacking software ( like phx ) allow you to erase this limmit by giving you full payload crafting ability. The server must check itself everything the client sends. Never to trust the client data. But since developers are humans themselves, they cant check everything. Thats how those exploits exist. But enough with the bla bla. Lets look at an example:

 

Kick parties from their command channels:

 

Look at the following code. It is a packet send from the client to the server.

 

 

        @Override

protected void readImpl()

{

_name = readS(); This is executed first, it reads the character name you give from the client ( or .... the phx ;) )

}

 

 

@Override

protected void runImpl() <-- Then it calles the runImplementation to actually try to do what you told it to.

{

L2PcInstance target = L2World.getInstance().getPlayer(_name); <-- The player i want to kick from my commandChannel.

L2PcInstance activeChar = getClient().getActiveChar(); <-- My character.

 

if (target != null && target.isInParty() && activeChar.isInParty() && activeChar.getParty().isInCommandChannel()

&& target.getParty().isInCommandChannel()

&& activeChar.getParty().getCommandChannel().getChannelLeader().equals(activeChar)) <-- Here is the big deal. This line checks some conditions to dissallow you to do what is considered illegal. So what does it do. It says: if i am in party and if my target is in party, if i have command channel and if he has command channel and if i am the leader of my command channel, procceed with doing what you want to do. Wait a minute !! It didnt check if our command channels are the same did it ? It took the player from the "world" and didnt check if he is in my command channel. In other words, you can kick someones party from his command channel just by filling in his name and being the leader of a command channel yourself.

 

                {

if (activeChar.equals(target))

return;

 

target.getParty().getCommandChannel().removeParty(target.getParty()); <--Here the target's party gets removed from his command channel.

 

SystemMessage sm = SystemMessage.getSystemMessage(SystemMessageId.DISMISSED_FROM_COMMAND_CHANNEL);

target.getParty().broadcastToPartyMembers(sm);

 

// check if CC has not been canceled

if (activeChar.getParty().isInCommandChannel())

{

sm = SystemMessage.getSystemMessage(SystemMessageId.C1_PARTY_DISMISSED_FROM_COMMAND_CHANNEL);

sm.addString(target.getParty().getLeader().getName());

activeChar.getParty().getCommandChannel().broadcastToChannelMembers(sm);

}

}

else

{

activeChar.sendPacket(SystemMessage.getSystemMessage(SystemMessageId.TARGET_CANT_FOUND));

}

}

 

 

As you can see a simple check ( command channels are the same ) missing gives you the ability to mess up an enemy ally command channel when they are sieging or raiding. Simple missing checks like that lead to exploits. To execute the exploit, you simply grab the OustFromCC packet and change the hex representing the name with the name you want. Voila ;)

 

 

Link to comment
Share on other sites

Timestamp:

04/17/11 16:08:41 (less than one hour ago)

Author:

UnAfraid

Message:

BETA: Exploit fix for removing party from channel that's not in yours! (thanks Nik and JIV)

 

 

A dawn, l2j spies everywhere :) You guys are fast :)

Link to comment
Share on other sites

Timestamp:

04/17/11 16:08:41 (less than one hour ago)

Author:

UnAfraid

Message:

BETA: Exploit fix for removing party from channel that's not in yours! (thanks Nik and JIV)

 

 

A dawn, l2j spies everywhere :) You guys are fast :)

fixed y on freya, not but not interlude :)
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • 2 Factor Authentication Code for 100% secure login. Account provided with full information (email, password, dob, gender, etc).
    • ready server for sale, also available for testing with ready and beautiful npc zone pvp with custom 2 epic core orfen lvl2 with all maps ready all quests work at 100% ready comm  board with buffer teleport gm shop service anyone interested send me a pm many more that I forget  Exp/Sp : x30 (Premium: x40)    Adena : x7 (Premium: x10)   Drop : x7 (Premium: 10)   Spoil : x7 (Premium: 10)   Seal Stones : x7 (Premium: 10)   Raid Boss EXP/SP : x10   Raid Boss Drop : x3 (Premium: x5)   Epic Boss Drop : x1 Enchants   Safe Enchant : +3   Max Enchant : +16   Normal Scroll of Enchant Chance : 55%   Blessed Scroll of Enchant Chance : 60% Game Features   GMShop (Max. B-Grade)   Mana Potions (1000 MP, 10 sec Cooldown)   NPC Buffer (Include all buffs, 2h duration)   Auto-learn skills (Except Divine Inspiration)   Global Gatekeeper   Skill Escape: 15 seconds or /unstuck   1st Class Transfer (Free)   2nd Class Transfer (Free)   3rd Class Transfer (700 halisha mark)   Subclass (Items required from Cabrio / Hallate / Kernon / Golkonda + Top B Weapon + 984 Cry B)   Subclass 5 Subclasses + Main (Previous subclasses to level 75 to add new one)   Noblesse (Full Retail Quest)   Buff Slots: 24 (28 with Divine Inspiration LVL 4)   Skill Sweeper Festival added (Scavenger level 36)   Skill Block Buff added   Maximum delevel to keep Skills: 10 Levels   Shift + Click to see Droplist   Global Shout & Trade Chat   Retail Geodata and Pathnodes   Seven Signs Retail   Merchant and Blacksmith of Mammon at towns   Dimensional Rift (Min. 3 people in party to enter - Instance)   Tyrannosaurus drop Top LS with fixed 50% chance   Fast Augmentation System (Using Life Stones from Inventory)   Chance of getting skills (Normal 1%, Mid 3%, High 5%, Top 10%)   Wedding System with 30 seconds teleport to husband/wife Olympiad & Siege   Olympiad circle 14 days. (Maximum Enchant +6)   Olympiads time 18:00 - 00:00 (GMT +3)   Non-class 5 minimum participants to begin   Class based disabled   Siege every week.   To gain the reward you need to keep the Castle 2 times. Clans, Alliances & Limits   Max Clients/PC: 2   Max Clan Members: 36   Alliances allowed (Max 1 Clans)   24H Clan Penalties   Alliance penalty reset at daily restart (3-5 AM)   To bid for a Clan Hall required Clan Level 6 Quests x3   Alliance with the Ketra Orcs   Alliance with the Varka Silenos   War with Ketra Orcs   War with the Varka Silenos   The Finest Food   A Powerful Primeval Creature   Legacy of Insolence   Exploration of Giants Cave Part 1   Exploration of Giants Cave Part 2   Seekers of the Holy Grail   Guardians of the Holy Grail   Hunt of the Golden Ram Mercenary Force   The Zero Hour   Delicious Top Choice Meat   Heart in Search of Power   Rise and Fall of the Elroki Tribe   Yoke of the Past     Renegade Boss (Monday to Friday 20:00)   All Raid Boss 18+1 hours random respawn   Core (Jewel +1 STR +1 DEX) Monday, Wednesday and Friday 20:00 - 21:00 (Maximum level allowed to enter Cruma Tower: 80)   Orfen (Jewel +1 INT +1 WIT) Monday to Friday, 20:00 - 21:00 (Maximum level allowed to enter Sea of Spores: 80)   Ant Queen Monday and Friday 21:00 - 22:00 (Maximum level allowed to enter Ant Nest: 80)   Zaken Monday,Wednesday,Friday 22:00 - 23:00 (Maximum level allowed to enter Devil's Isle: 80)   Frintezza Tuesday, Thursday and Sunday 22:00 – 23:00 (Need CC of 4 party and 7 people in each party min to join the lair, max is 8 party of 9 people each)   Baium (lvl80) Saturday 22:00 – 23:00   Antharas Every 2 Saturdays 22:00 - 23:00 Every 2 Sundays (alternating with Valakas) 22:00 – 23:00   Valakas Every 2 Saturdays 22:00 - 23:00 Every 2 Sundays (alternating with Antharas) 22:00 – 23:00   Subclass Raids (Cabrio, Kernon, Hallate, Golkonda) 18hours + 1 random   Noblesse Raid (Barakiel) 6 hours + 15min random   Varka’s Hero Shadith 8 hours + 30 mins random (4th lvl of alliance with Ketra)   Ketra’s Hero Hekaton 8 hours + 30 mins random (4th lvl of alliance with Varka)   Varka’s Commander Mos 8 hours + 30 mins random (5th lvl of alliance with Ketra)   Ketra’s Commander Tayr 8 hours + 30 mins random (5th lvl of alliance with Varka)
    • Have a great day! Unfortunately, we can not give you the codes at the moment, but they will be distributed as soon as trial is back online, thanks for understanding! Other users also can reply there for codes, we will send them out some time after.
    • Ok mates i would like to play a pridestyle server (interluide, gracie w/ever) Is there any such server online and worth playing?
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock