Jump to content

Recommended Posts

Posted

Server http://l2spartacus.com/

 

I am using d4t4b4s3 cr4ck3r 1.2

After few minutes it said password, but when i try to connect i get 1045 access denied for user root@MyWanIp (using password YES)

 

Any1 know what next? Or its impossible since gameserver and website has the same ip, so there isnt remote access to SQL databse?

 

 

 

hmm i cant get a password to my own local database using this program... wtf it simply passes "root" whioch is the pass Oo

 

And other question: Is there any way to see if the database allows to conenct from other computers? If not, whats the result of brute force? it will give password but i wont be able to connect?

  • 2 weeks later...
Posted

mmm...im new in maxcheaters's family..so im gonna start with a HI :) ... we'll these brute force tools are kinda "expired" imo...the tip i can give to ya is to check that website's vulnerability....and if its vulnerable to sql injection u're gonna be GG! ... most private l2 servers got crappy protection on websites...download backtrack 5 ... check some tutorials on youtube about sql injection ... and their hole database will be yours (including acc/pass / email and all stuffs that are required when u register an account...to be honest..u're kinda loosing time with that brute force...bcz for a complex passowrd which includes numbers and !@#$% ... its gonna take years to decript ^_^... so the best sollution to get all the accounts from that server is sql injection -> hack the website and their database is yours :D...hope this is gonna help ya :P

  • 2 weeks later...
Posted

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Posted

sql injection, for example when i see any pvp stats i add ' char to link, nothing happens,no error. Cant generate any error on ony of l2server site, in any section, trying many ways

Hmm accorded to researches , 50-60% of websites are vulverable to sql injection my friend :) The only thing you have to do is , to find the path ..There are a lot of programs which can do that instead of you :) Such as, webcruiser or NetsParker ..I also have a netsparker guide in hacking section in greek language, i could translate it to you if you want :)
Posted

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

Posted

GreyHat, it would be great if u:1. translate and add some own experience, 2. Show how u use it on one server. Thanx in advance

 

Could u send me any link to l2server site which is vulnerable to try if i can do something? If u say its 50-60% it wouldnt be hard

http://l2.trancegaming.com/ check this site..100% vulverable
Posted

Got the vulenrable point, thx. To be honest i checked like 100 sites and didnt find evern one vulnerable point... i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Posted

Got the vulenrable point, thx. i know methods only when on website are endings like id=?31 so i add symbol ' to make id=?31' and it generates error on website, then its vulnerable. But are there other methods? Any ideas? PM please

 

 

It seems like i got only website side DB and tables, the website didnt lead me to serverDB

Well ,there are some programms which detect the vulverable places themselves..Such as WebCruiser or Netsparker..I have a guide on how to find vulverable places in a website by using Netsparker,but it is in greek language...You can download Netsparker via google !It's very easy to use..you just copy and paste the url link from the page in the scan place ,and then the programm is scanning for vulverable places..if it finds any vulverable place it shows you the url place.. !
Posted

im using webcruiser, it very very often gives me "post sql injection" but nothing happens then. Also using havij to finish the job

Well ,you can not always inject a website ..It's better to use BackTrack Software to make sql injection..Havij is a good program but if you have the demo version your abilities are low
Posted

thx it was rly helpfull. lets see what am i able to do

 

 

By the way, what are ur steps to make a successful injection? I mean when u get a site, what u start with what then ans next?

Is it something like a typical pattern, u enter site check subsites,link and u know that it is vulenrable?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Update M54: Global HP/MP/CP consumable handling expanded beyond combat-only usage. Offensive mage idle recovery with learned skill Battle Heal. Spellhowler/Storm Screamer prioritizes Hurricane, using Vampiric Claw mostly below 90% HP. Major structural refactor initialized: Added category/class organization such as Archer, Dagger, Tank, Mage, Healer, Support and Specialized class files. Further structural cleanup. Extracted combat memory/state and more class-policy logic from the main controller. Added global stuck/inactivity watchdog for bots blocked by terrain/geodata. Added unreachable dropped ground-item timeout/temporary blacklist. Reworked Necromancer/Soultaker PvP: Dominator level 78+ maintains learned Arcane Power toggle on. Overlord/Dominator level 44+ maintains learned Soul Guard toggle automatically. Stability/scalability update: Bot controller ticks staggered instead of all starting in the same phase: Same 350 ms update rate retained Reduces simultaneous AI workload bursts. Removed the old manual aggressive-monster EVT_AGGRESSION bridge. Phantoms now use native Lucera setActive() behavior so monsters aggro them naturally. Reduced unnecessary NPC scans and native AI event pressure. Added saved-bot equipment overrides using a separate database table:         lucera_autobots_items Existing lucera_autobots remains the main saved-bot identity/state table. Equipment rows are linked to saved bots through bot_id. Added optional convenience view to show bot name together with equipment overrides:         lucera_autobots_items_view Added editable equipment slots in columns: Weapon Shield Helmet Chest Legs Gloves Boots Necklace Left/Right Earrings Left/Right Rings Equipment override values: 0 = use normal class/level profile item -1 = force slot empty >0 = equip that Item ID Custom equipment works only for saved database bots. Default class/level equipment profiles remain unchanged. Supports custom equipment from No Grade to S Grade, regardless of the bot's current level. Added validation for invalid item IDs and incompatible equipment slots. Added handling for: Two-handed weapons vs shields Full-body armor vs separate leggings Added all-grade Soulshots and Spiritshots to bot inventory/replenishment so custom lower-grade weapons still use the correct shots. Mage profiles that already use Blessed Spiritshots keep that behavior with all relevant grades available. First save the bot normally so it exists in table:         lucera_autobots Then open:         lucera_autobots_items Find the row with the same bot_id and edit only the equipment slots you want. Example: weapon_id = 6608 shield_id = -1 helmet_id = 0 chest_id = 0 legs_id = 0 gloves_id = 0 boots_id = 0 This means: weapon_id 6608 → custom weapon shield_id -1 → no shield all 0 values → keep normal default profile equipment After editing the DB, despawn and respawn the saved bot so M54 reloads its equipment overrides. Do not edit bot_id. Use it only to identify which saved bot the equipment row belongs to.   DOWNLOAD
    • It will be multi client so it will detect the client from the files and adapt the packets and asset loading. I am aiming for C4 and H5 after IL
    • this is just to simplify your life, time, and can be done for free by yourself just watch some tutorials, in case you don't wanna waste time check it out!   https://l2getwork.art   https://l2getwork.art/showcase.html  
    • Good job! Any chance for it to be downgradeable or at least compatible with older chronicles?
    • Fermata now runs in a web browser too. Try it here: https://web.fermata.gg/    
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..