Jump to content

Recommended Posts

  • 3 weeks later...
Posted

Only an idiot would make an account called admin. And only an idiot would not password their SQL, and their Navicat. And only an idiot will leave an account with admin user, and blank password. If you are in any of those categories, God Speed!

Posted

how we know that  it is not a virus.how i am sure?

 

Because the share was posted from a global moderator

which i highly doubt he would post anything "infected".

Besides if you are not even bothered checking what this

does don't reply at all because from your replies it is prety

obvious that you are trying to spam.

 

PS:I believe that the 45% of the servers are from "lame" teenagers

that use preconfigured packs.They use a database with user and pass "root".

Isn't there a way to hack their database from just adding their ip in the configs and

enter their database? :)? (I'm not sure what i am saying makes sense but i have seen

friends of mine setting up a database i don't really bother with l2 developing... and as

i tried i saw at the config files that there was options and ips where you connect to your

database... learn their user and database info and get their ip and i believe that you

are going to find a way to hack them :) Be creative :D)

 

Reply if this makes any sense at all... i'm curius to find out :)

Posted

Jesus wtf?! This is NOT an exploit. It's just a program that tries as many possible variables of a username/password.

 

Three things that sql servers check for

Username

Password

Host that's logging in (whitelist)

 

If your username/password are incorrect AND if you are not comming from the ip specified in the host it will reject your connection.

 

Even if somehow magically the admin is a fucking idiot and has username root and password fuckmeImdumb there is a high chance he will have allowed ip with 127.0.0.1 which means NOONE but him from localhost can connect to mysql. If you do have all of those opened to public then you deserve to be shot on sight.

 

But lets say he does have % on host origin and username root. In case his password is consisted of something like this 34%V#4t3gc3$G34t the bruteforce will NEVER figure it out. Well, maybe in a couple of years...

Posted

But lets say he does have % on host origin and username root. In case his password is consisted of something like this 34%V#4t3gc3$G34t the bruteforce will NEVER figure it out. Well, maybe in a couple of years...

Hahah! Sad but true!

 

The majority of l2j servers are set to "%" and not to localhost(naabs adminz).

  • 3 weeks later...
Posted

Ech.... dont work for me...

 

I think u need -1 karma, this is the second post that u make like that.

 

:s !

 

BtW XxRxX Great Sharing !! :)

  • 2 weeks later...
  • 3 weeks later...
  • 2 weeks later...
Posted

Oh yes I forgot that you can change localhost to an IP and connect to it Smiley

Thanks hax0r ;]

 

I'am going to find a guide for it, if I do I will post it somewhere =]

 

Google Ftw Wink

 

SQLPing right? Or should I search for teh bruter hax0r gave? Cheesy

 

I downloaded both but I've done more things with Bruter I think but no passwordlist and userlist -.-

 

Have fun Cheesy Let the hack be with us Cheesy

Guest
This topic is now closed to further replies.



  • Posts

    • I suggest you provide Test server for public and add a price.
    • Kroma — Lineage II Interlude on LU4 Client (Latest client)   I'm selling this project. Here's what it actually is and what's been done.   This is a few months of work, most of it on the reverse engineering side. I built it because I wanted to open my own Interlude server on it. That's not happening any more — I've moved on to other projects and don't have the free time left to take it the rest of the way, so I'd rather it went to someone who will.   The idea was to take the modern LU4 client and make it run an Interlude version of the game. Not a reskin of an old client — the actual current client, playing Interlude, against a server I wrote. That's what this is, and it works end to end: the client boots, authenticates, connects, and you play. There are six repositories. Roughly, it splits into three kinds of work: reverse engineering the client, writing the server, and rebuilding the client's own content so it matches Interlude.   Fully reverse engineered   The client's protocol wasn't documented anywhere, so it was derived from scratch off real traffic. I built a sniffer (bypassing anticheat packet encryption) that drops into the client's binaries folder and dumps live traffic to disk, then a separate Java toolchain that decrypts those captures — login and game traffic, both directions. Everything the server knows about the protocol came out of that loop: capture, decrypt, read, implement, test against the real client.   On top of that there's a native x64 hook and injector in C++. It points the client at your own servers and handles its authentication and session layer, plus a few client-side stability fixes that were needed to keep it from falling over once it's talking to something that isn't the official backend. The hooking is pattern-based rather than address-based, so a client patch doesn't automatically break it.   The reverse-engineering notes are in the repos — the patterns, the disassembly, the decompiled functions, what each one does and why it's hooked. That documentation is a real part of what's being sold; it's the difference between inheriting a working system and inheriting a black box.   The server   Interlude ruleset, aCis lineage, but substantially rewritten and extended to speak the LU5 client's protocol with modern features like Party matching, Offline shops or Mailbox. The geodata has been updated according to some layout changes in LU4 cities. There's also a separate login server handling the client's auth flow.   Customized client to adapt to Interlude   This is the part people underestimate. The retail client ships retail content — retail NPCs, retail items, retail zones, retail UI. All of that had to be reshaped. The whole client-side pipeline is scripted: extract the retail PAKs, apply every edit from data files, rebuild, drop the result back into the game folder. 23 purpose-built C# tools, ~6,700 lines, organised into three pipelines that are guaranteed not to write over each other. There's a documented checklist for regenerating everything from scratch when a new patch drops. The important thing is that none of it is hand-editing. Every change is a line in a data file. When the client updates, you re-run the scripts instead of redoing the work from memory.   All NPC / item / drop lists updated according to Interlude   The client's own data tables were rewritten from the real Interlude client data files — `npcname-e`, `itemname-e`, `skillname-e`, `systemmsg-e`, `npcgrp`. That means roughly 6,470 NPC and skill name/title updates and about 4,000 Drops/Spoils rows written directly into the client's `NPCDataTable` and `SkillTable`, so the client shows Interlude names, Interlude item text, Interlude system messages, and Interlude drop and spoil lists. There are also custom NPC rows on top of that, plus 304 game action rewrites.   Opened the catacombs   In the LU4 client the catacombs and necropolises are unusable — flooded, unlit, and with holes in the geometry. All three were fixed: Water removed. Water exclusion volumes were placed over all 12 of them: Rifts, Apostate, Patriots, Devotion, Dark Omens, Heretics, Pilgrims, Saints, Worship, Martyr, Forbidden Path and Witch. This was more involved than it sounds — the volumes' scale is ignored at runtime, so the tool picks the best-fitting native template per hole, and nearby lakes and rivers are separate water bodies that have to be excluded individually or you get leftover water borders. Lights added. About 28,900 light definitions imported into the client's level files. Missing walls fixed. Mesh actors replaced and spawned to close the gaps in the geometry.   Removed the modern "slop" features from the UI   The LU4 client is full of things that have no business in an Interlude server, and most of them are wired into the UI. Those are stripped out: The assistant manager — the auto-hunt / auto-play slot on the XP bar Vitality*and the XP lock button The fatigue system — updated the format to a regular VIP format The in-game browser and in-game radio buttons The "Learn Skill" tab in the player skills window Removals are scripted by path, so they survive a client patch and are trivially reversible if a buyer wants any of them back.   Reworked the UI toward an actual Lineage II feel   The original LU4 UI looks AI-generated. It doesn't feel like Lineage II. A good part of it has been reworked toward the classic look — the menu button row rebuilt as a wrapping layout with a proper background, the self status and target windows cleaned up, and 590 asset field edits covering textures, positions, colours, text and compiled Blueprint literals.   This part is not finished, and I want to be straight about that But the tooling to continue it is all there, and it's the good kind of tooling: you can target any widget property in any UI asset by dotted path, remove widgets by path without knowing their auto-generated slot names, and edit text that's dynamically bound through Blueprint bytecode rather than stored as a plain property. Continuing the UI work means adding lines to a data file, not reverse engineering anything new.   Other client-side work   A custom login scene, built in a real Unreal Engine project that's included Interlude music restored, plus ambient sound work (cities only for now) Custom splash and branding   What's included   All six git repositories, the Unreal Engine project and its custom assets, all the tooling — injector, hook, sniffer, decryptor, asset editor — every data set including geodata, XML, HTML and the SQL schema, the build and repack scripts, and the per-repo technical documentation including the reverse-engineering notes.   Happy to answer questions or show it running.   Gallery
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..