Jump to content

[HELP] Brute force


Recommended Posts

Server http://l2spartacus.com/

 

I am using d4t4b4s3 cr4ck3r 1.2

After few minutes it said password, but when i try to connect i get 1045 access denied for user root@MyWanIp (using password YES)

 

Any1 know what next? Or its impossible since gameserver and website has the same ip, so there isnt remote access to SQL databse?

 

 

 

hmm i cant get a password to my own local database using this program... wtf it simply passes "root" whioch is the pass Oo

 

And other question: Is there any way to see if the database allows to conenct from other computers? If not, whats the result of brute force? it will give password but i wont be able to connect?

Link to comment
Share on other sites

  • 2 weeks later...

mmm...im new in maxcheaters's family..so im gonna start with a HI :) ... we'll these brute force tools are kinda "expired" imo...the tip i can give to ya is to check that website's vulnerability....and if its vulnerable to sql injection u're gonna be GG! ... most private l2 servers got crappy protection on websites...download backtrack 5 ... check some tutorials on youtube about sql injection ... and their hole database will be yours (including acc/pass / email and all stuffs that are required when u register an account...to be honest..u're kinda loosing time with that brute force...bcz for a complex passowrd which includes numbers and !@#$% ... its gonna take years to decript ^_^... so the best sollution to get all the accounts from that server is sql injection -> hack the website and their database is yours :D...hope this is gonna help ya :P

Link to comment
Share on other sites

  • 2 weeks later...

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Link to comment
Share on other sites

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Hmm accorded to researches , 50-60% of websites are vulverable to sql injection my friend :) The only thing you have to do is , to find the path ..There are a lot of programs which can do that instead of you :) Such as, webcruiser or NetsParker ..I also have a netsparker guide in hacking section in greek language, i could translate it to you if you want :)
Link to comment
Share on other sites

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

Link to comment
Share on other sites

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

http://l2.trancegaming.com/ check this site..100% vulverable
Link to comment
Share on other sites

Got the vulenrable point, thx. To be honest i checked like 100 sites and didnt find evern one vulnerable point... i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Link to comment
Share on other sites

Got the vulenrable point, thx. i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Well ,there are some programms which detect the vulverable places themselves..Such as WebCruiser or Netsparker..I have a guide on how to find vulverable places in a website by using Netsparker,but it is in greek language...You can download Netsparker via google !It's very easy to use..you just copy and paste the url link from the page in the scan place ,and then the programm is scanning for vulverable places..if it finds any vulverable place it shows you the url place.. !
Link to comment
Share on other sites

im using webcruiser, it very very often gives me "post sql injection" but nothing happens then. Also using havij to finish the job

Well ,you can not always inject a website ..It's better to use BackTrack Software to make sql injection..Havij is a good program but if you have the demo version your abilities are low
Link to comment
Share on other sites

thx it was rly helpfull. lets see what am i able to do

 

 

By the way, what are ur steps to make a successful injection? I mean when u get a site, what u start with what then ans next?

Is it something like a typical pattern, u enter site check subsites,link and u know that it is vulenrable?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • DISCORD : utchiha_market telegram : https://t.me/utchiha_market SELLIX STORE : https://utchihamkt.mysellix.io/ Join our server for more products : https://discord.gg/hood-services https://campsite.bio/utchihaamkt  
    • Server Rates: » Xp 500x. » Sp 500x. » Aden 500x. » Drop 1x. » PartyXp 2x. » PartySp 2x. » Starting character level -61. Enchant rates: » Safe enchant +4. » Blessed and simple scrolls max enchant (+16). » Crystal scrolls max enchant (+20). » Simple enchant scrolls chance – 65%. » Blessed enchant scrolls chance – 100%. » Crystal enchant scrolls chance – 50% Augmentations: » Mid life stone skill chance – 5%. » High life stone skill chance – 10%. » Top life stone skill chance – 20%. » Augments 1+1 Unique features: » Main town – Giran » Automatic-Manual Potions. » Working 2 castle sieges. (Giran-Aden) » SPS cancel lasts 10 seconds and than buffs come back. » Stackable scrolls, lifestones, book of giants. » Unique pvp zone » More then 11 active raid bosses. » Wedding system. » Unique farming areas. » Npc skill enchanter. » Full npc buffer with auto buff. » Max count of buffs – 55. » Max subclasses – 4. » Free and no quest class change. » Free and no quest sub class. » Raid boss drop nobless item. » No weight limit. » Unique protection anti-hwy armor for archers/daggers etc. » Ingame password change. » Top pvp/pk/online ranks NPC. » Unique monsters & NPC. » Interlude retail skills. » Server up-time [24/7] [99]%. » Perfect class balance (all class can kill all class depending on players skill and setup knowledge,gear,augmentations). » Announcements on double kills triple kills etc. » Announcements on Grand Boss death , with the name of the killer as well as clan name of the player. » Information Npc in game with all servers infromations. Custom server gear : 1). Titanium Armor Lv.1 2). Epic Armor Lv.2 3). Epic Weapons-Kamikaze-Black S grade (Same Stats) 4). Demonic-Angelic Wings-Baium Hair-Custom Accessories (SameStats) 5). Custom Fighter/Mage tattoo Lv1-Lv2-Lv3 6). Shirt (STR,CON,INT +1) 7). Custom Shields Server Commands: .tvtjoin .tvtleave – Join or leave tvt event. .ctfjoin .ctfleave – Join or leave ctf event. .dmjoin .dmleave – Join of leave dm event. .online – current online players count. .repair – repairs stuck character in world. .menu – opens online menu panel. .exit – PVP zone exit in case you are bullied. .changepassword - Opens online menu then u can change ur password in game. .farm - Enable/disable autofarm Event system: » TVT event » CTF event » DM event » Tournament Event » Party Zone » Unique event shop. Olympiad game: » Retail olympiad game. » Competition period [1] week. » Olympiad start time [18:00] end [00:00] GMT+2. » New Heroes every Sunday.
    • Tomorrow grand opening lests go 🙂 
    • New season of Warfire X150 has been postponed to September 28th.
  • Topics

×
×
  • Create New...