Jump to content

Recommended Posts

  • 3 weeks later...
Posted

Only an idiot would make an account called admin. And only an idiot would not password their SQL, and their Navicat. And only an idiot will leave an account with admin user, and blank password. If you are in any of those categories, God Speed!

Posted

how we know that  it is not a virus.how i am sure?

 

Because the share was posted from a global moderator

which i highly doubt he would post anything "infected".

Besides if you are not even bothered checking what this

does don't reply at all because from your replies it is prety

obvious that you are trying to spam.

 

PS:I believe that the 45% of the servers are from "lame" teenagers

that use preconfigured packs.They use a database with user and pass "root".

Isn't there a way to hack their database from just adding their ip in the configs and

enter their database? :)? (I'm not sure what i am saying makes sense but i have seen

friends of mine setting up a database i don't really bother with l2 developing... and as

i tried i saw at the config files that there was options and ips where you connect to your

database... learn their user and database info and get their ip and i believe that you

are going to find a way to hack them :) Be creative :D)

 

Reply if this makes any sense at all... i'm curius to find out :)

Posted

Jesus wtf?! This is NOT an exploit. It's just a program that tries as many possible variables of a username/password.

 

Three things that sql servers check for

Username

Password

Host that's logging in (whitelist)

 

If your username/password are incorrect AND if you are not comming from the ip specified in the host it will reject your connection.

 

Even if somehow magically the admin is a fucking idiot and has username root and password fuckmeImdumb there is a high chance he will have allowed ip with 127.0.0.1 which means NOONE but him from localhost can connect to mysql. If you do have all of those opened to public then you deserve to be shot on sight.

 

But lets say he does have % on host origin and username root. In case his password is consisted of something like this 34%V#4t3gc3$G34t the bruteforce will NEVER figure it out. Well, maybe in a couple of years...

Posted

But lets say he does have % on host origin and username root. In case his password is consisted of something like this 34%V#4t3gc3$G34t the bruteforce will NEVER figure it out. Well, maybe in a couple of years...

Hahah! Sad but true!

 

The majority of l2j servers are set to "%" and not to localhost(naabs adminz).

  • 3 weeks later...
Posted

Ech.... dont work for me...

 

I think u need -1 karma, this is the second post that u make like that.

 

:s !

 

BtW XxRxX Great Sharing !! :)

  • 2 weeks later...
  • 3 weeks later...
  • 2 weeks later...
Posted

Oh yes I forgot that you can change localhost to an IP and connect to it Smiley

Thanks hax0r ;]

 

I'am going to find a guide for it, if I do I will post it somewhere =]

 

Google Ftw Wink

 

SQLPing right? Or should I search for teh bruter hax0r gave? Cheesy

 

I downloaded both but I've done more things with Bruter I think but no passwordlist and userlist -.-

 

Have fun Cheesy Let the hack be with us Cheesy

Guest
This topic is now closed to further replies.

  • Posts

    • You invent yourself a life - bad for you, one of the inner core dev, fernandopm, which worked hard over aCis quests from 2011 to 2016 is argentinian. I teached him back in time to work and make proper quests. My dev team comes from 10+ countries and I'm myself french. "Racist/nationalist" card ? Not working bro.   Not sure why I should thank you to send me questions, and regarding bug reports, so far, I got none of yours in either discord, gitlab, or forums. I'm sorry if you feel "ignored", but that's more a psychanalyst you need to speak with if you put emotions towards someones' appreciation over a forum. I never ignore a bug report, and if so (like skills reports), it's because I got a bigger plan (skills refactor, in that case). In any case, I delivered cookies for the bug report/fix, even if it dated of months, with proper credits over changesets. "Victim card" ? Not really working, but ok, maybe you're "emotional".   I barely make money out of aCis, for the spent time - simply selling my services, or even coding/administrating a minecraft/L2J server would make far more money. Breaking intentionally things would be stupid. If you don't understand I'm not the only one working on that pack, I can't help you. Also, the scale of edits is sometimes extreme - AI L2OFF ? 1800 files added. How do you want everything works in a single shot ? "Exploiting noobz for money" card ? Still not working, or I'm a terrible businessman.   Meanwhile - you shadow advertise your project, L2JOne (since 2017 btw) - you should maybe start by the beginning saying you're a competitor and aCis is actually a spike in your foot. That also explains why you act like that. RusAcis got the exact same strategy, speaking bad of me, saying they got unique fixes (you speak about I break things, they break and recode things 4 times sometimes, btw), but successfully reselling latest revision with poorly executed stuff. "aCis is good, Tryskell is ok, but I solve all issues in extreme low time so I can piss over him" card ? Mmmmhhhh.   Our conversation ends here if you want, I don't force ppl to speak with me if they don't want - hopefully, people would understand I'm not the arrogant one and the one who doesn't want to talk, or even collaborate. :). I understand you got your own project and got no will to improve aCis.   NOTE : I'm extremely happy for your call of ExShowServerPrimitive with getValidGeoLocation, extremely impressive. Arrogant, no. Sarcastic ? Maybe.   Good night everyone.
    • Hi. @GX-Ext, svn does not work. is there anywhere else where we can get source code? Thank you so much.
    • new synchronized movement with neoengine obstacle correction I reported bugs to you and you completely ignored me because of my nationality. Yes, you were arrogant towards me. I sent you many questions on your forum and you didn't even thank me or say anything about it. I stopped using your updates a long time ago and focused on fixing my own aCis because you intentionally break the code. Just buy versions 401 to 409; you intentionally broke a lot of things for "IDIOTS" to buy from you. Anyway, our conversation ends here. Good luck with renaming and organizing; that probably makes you more money than fixing the basics. With this debug I created valid notes for monsters and NPCs, fixing the maxZ that you broke, and also corrected fly/water movements, making them more efficient. I only spent 2 months and I'm using Geoengine l2.j   NOTE: I'm not selling my GeoEngine, don't waste your time sending messages!
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock