Jump to content

Recommended Posts

Posted

Server http://l2spartacus.com/

 

I am using d4t4b4s3 cr4ck3r 1.2

After few minutes it said password, but when i try to connect i get 1045 access denied for user root@MyWanIp (using password YES)

 

Any1 know what next? Or its impossible since gameserver and website has the same ip, so there isnt remote access to SQL databse?

 

 

 

hmm i cant get a password to my own local database using this program... wtf it simply passes "root" whioch is the pass Oo

 

And other question: Is there any way to see if the database allows to conenct from other computers? If not, whats the result of brute force? it will give password but i wont be able to connect?

  • 2 weeks later...
Posted

mmm...im new in maxcheaters's family..so im gonna start with a HI :) ... we'll these brute force tools are kinda "expired" imo...the tip i can give to ya is to check that website's vulnerability....and if its vulnerable to sql injection u're gonna be GG! ... most private l2 servers got crappy protection on websites...download backtrack 5 ... check some tutorials on youtube about sql injection ... and their hole database will be yours (including acc/pass / email and all stuffs that are required when u register an account...to be honest..u're kinda loosing time with that brute force...bcz for a complex passowrd which includes numbers and !@#$% ... its gonna take years to decript ^_^... so the best sollution to get all the accounts from that server is sql injection -> hack the website and their database is yours :D...hope this is gonna help ya :P

  • 2 weeks later...
Posted

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Posted

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Hmm accorded to researches , 50-60% of websites are vulverable to sql injection my friend :) The only thing you have to do is , to find the path ..There are a lot of programs which can do that instead of you :) Such as, webcruiser or NetsParker ..I also have a netsparker guide in hacking section in greek language, i could translate it to you if you want :)
Posted

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

Posted

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

http://l2.trancegaming.com/ check this site..100% vulverable
Posted

Got the vulenrable point, thx. To be honest i checked like 100 sites and didnt find evern one vulnerable point... i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Posted

Got the vulenrable point, thx. i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Well ,there are some programms which detect the vulverable places themselves..Such as WebCruiser or Netsparker..I have a guide on how to find vulverable places in a website by using Netsparker,but it is in greek language...You can download Netsparker via google !It's very easy to use..you just copy and paste the url link from the page in the scan place ,and then the programm is scanning for vulverable places..if it finds any vulverable place it shows you the url place.. !
Posted

im using webcruiser, it very very often gives me "post sql injection" but nothing happens then. Also using havij to finish the job

Posted

im using webcruiser, it very very often gives me "post sql injection" but nothing happens then. Also using havij to finish the job

Well ,you can not always inject a website ..It's better to use BackTrack Software to make sql injection..Havij is a good program but if you have the demo version your abilities are low
Posted

thx it was rly helpfull. lets see what am i able to do

 

 

By the way, what are ur steps to make a successful injection? I mean when u get a site, what u start with what then ans next?

Is it something like a typical pattern, u enter site check subsites,link and u know that it is vulenrable?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • We've added 5% discounts for bulk purchases of Google accounts for orders of 300 or more, and 10% for orders of 500 or more. The discount is applied automatically when you place your order! The discount is indicated in the product title and description for each category.  
    • 🎄 CHRISTMAS EVENT 🎄   ‼️ Information and details: https://forum.l2harbor.com/threads/rozhdestvenskie-xlopoty-christmas-chores.9430/post-171464
    • METATG.ORG Direct Telegram Service Provider A bonus of +7% on every order! *We add 7% more followers than your ordered amount to proactively cover potential drops and guarantee you an honest result." Telegram Followers - Price per 1000 SUBSCRIBERS Subscribers 3 days - $0.10 ~ 8 RUB Subscribers. Daily Completion: 200,000,000 Subscribers 7 days - $0.17 ~ 13.6 RUB Subscribers. Daily Completion: 200,000,000 Subscribers 14 days - $0.20 ~ 16 RUB Subscribers. Daily Completion: 200,000,000 Subscribers 30 days - $0.30 ~ 24 RUB Subscribers. Daily Completion: 200,000,000 Subscribers 60 days - $0.40 ~ 32 RUB Subscribers, 14-day guarantee. Daily Completion: 200,000,000 Subscribers 90 days (Super Fast) - $0.50 ~ 40 RUB Subscribers, 14-day guarantee. Daily Completion: 200,000,000 Subscribers 120 days (Super Fast) - $0.60 ~ 48 RUB Subscribers, 14-day guarantee. Daily Completion: 200,000,000 Subscribers Lifetime (Super Fast) - $0.70 ~ 56 RUB Lifetime Subscribers. 14-day guarantee. Daily Completion: 200,000,000 Telegram Services - Price per 1000 Post Views - $0.06 ~ 5 RUB Reactions - $0.08 ~ 6.5 RUB Bot Starts - $0.10 ~ 8 RUB Bot Starts with referrals - $0.15 ~ 12 RUB DISCOUNTS and CASHBACK for large volumes Direct Supplier. We work from our own accounts with our own software! High execution speed. Multiple payment methods. We work 24/7! Additional discounts are discussed for volumes starting from $1000 per day. SUPPORT 24/7 - TELEGRAM WEBSITE 24/7 - METATG.ORG
    • Added: a brand-new default dashboard template. You can now add multiple game/login server builds. Full support for running both PTS & L2J servers simultaneously, with switching between them. Payment systems: added OmegaPay and Pally (new PayPal-style API). Account history now stores everything: donations, items delivered to characters, referrals, transfers between game accounts, and coin transfers to another master account. Personal Promo Code System: you can create a promo code and assign it to a user or promoter. When donating, a player can enter this promo code to receive bonus coins, and the promo code owner also receives a bonus — all fully configurable in the admin panel.     Look demo site: demo
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock