Jump to content

[Share]http://www.l2epical.com.ar - DataBase Admin Access Only !


Recommended Posts

Posted

i will share only admin access because dont have time to wait for all DataBase :)

Log in Game and Give access to everyone and server will be closed after 2 days :)

 

 

Account: efedos
Password: volkswagen
Charname: Stratovarius

 

P.S dont change admin password just create your char and give access on your char

leave admin account for everyone who want to make fun or broken server !

Posted

will try this right now and edit with results !

 

Thanks for sharing it !

yes test it and reply because i not tested but im sure that is right :)

 

your welcome

Posted

account works pefrect !

 

But server laaging to much and there is 23 players online with 10 Shops !

 

Anyway every1 can try it , it worths if you want to make some fun ;)

Posted

account works pefrect !

 

But server laaging to much and there is 23 players online with 10 Shops !

 

Anyway every1 can try it , it worths if you want to make some fun ;)

lol its show me 4450 accounts and 7812 chars in DB and only 23 online ? grr

they need be more oneline because i see top pvp have 1300 pvps :)

so maybe today they got and any flood attack :P and because lag

Posted

The password does not coincide with the account, bobi used webcruiser or havij? I treat of hack and I could not.

Bobii plz check PM.

 

Analyzing http://foro.l2epical.com.ar/index.php?board=2.0

Host IP: 31.170.162.101

Web Server: Apache

Powered-by: PHP/5.2.17

Keyword Found: Server

Injection type is Integer

Keyword corrected: Recuerden

Can't find db server type! But maybe there be some chances! [-o<

Trying another method using keyword for finding columns count

Selected Column Count is 2

Retying to find string column

Retying to find string column

Retying to find string column

Retying to find string column

Retying to find string column

Retying to find string column

Cannot find string column!

Testing for MySQL error based injection method

MySQL error based injection method cant be used!

Trying blind method

Finding current data base

It seems that target is not vulnerable. it's a false positive, Injection Failed!

MsSQL time based injection method can't be used

MySQL time based injection method can't be used

 

Posted

It doesn't work, cause this "dork" is not vulnerable.You have to find other "dork" in order to work.And use Havij...it's more effective and easier to work if you don't want to inject manually.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Hi, great work! Are there any bugs? And will it work with a high five?
    • For others that would like to understand in more details:   The login server also uses a protocol (sent by the server to the client in the very first packet). For instance, the C4 client (the one I'm developing my emulator for) expects the protocol number `50721` (or `0xc621`) which works as follow (from what I've gathered): Preamble: L2 packets are divided into two parts: size and payload; As mentioned, every packet starts with two bytes containing the whole packet size (thus including those two bytes, e.g. a packet of size 15 will have the number `15` written onto its first two bytes and a following payload of 13 bytes); For login server, first byte of the payload is the opcode (game server must deal with variable-sized opcodes); Next bytes are the packet content; Before sending the packet, its buffer size (minus the initial two bytes) is padded to 8 bytes (required by upcoming Blowfish encoding); A checksum of the packet is appended at the end, then the payload is again padded to 8 bytes; If the opcode is not `0` (also written as `0x00`), then the payload is encoded by Blowfish; Packet is sent over the network. You can have a look at my implementation (in C++) here (do note I'm assuming little-endian).   In this protocol, the auth packet (`0x00`) sent back by the client is RSA encrypted using the RSA modulus sent in the first server packet, inserted right after the protocol number.  
    • Hello guys I wanna buy some  Lessons for an L2J Developer
    • Let me give you something for inspiration and get you addicted to bot AI     And a siege 😛     What I have notice helps a lot the LLM to act real, is to give it a real-persons background. So for each LLM in the context beggining, besides the L2 facts, give it a real-life back story "You are a 67 years old retired nurse who plays Lineage 2 while her husband reads his newspaper, you are calm, collected but get mad if insulted". But that makes for a creative bot but its repetitive. So what you can also do, is pick random 20 news sites and for each bot every 2-3 days, initialize a context that is affected by the "news" the bot reads in the "real world".  So for example there's Iran - US war ok ? You take the news, put it in an LLM and ask it, extract the "abstract feelings" that this news piece invokes into you without mentioning anything related to the news. Then you take the result and inject it to the bots LLM prompt after its backstory.  This leads to some VERY human-like behavior from bots. 
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..