Jump to content

Recommended Posts

Posted

and also, if 154+ amped or a patch doesnt get released, and people just start changing authd ports to block apex, ill release a dll file that will work with any antibot, and any server, changed ports or not... that will crash it...

 

also u guys need to go crash more servers! my favorite server needs more players ;o

Posted

Xmmm, good one, but this will work with client antibot patch too? Most servers in order to keep hlapex away (and bots), use a system patch, they don't simply change the ports (hlapex works in a range of ports for those who don't know). I'm still curious for the GM Shop exploit (i hope it will work as you say ;) ). We have just to sit down and wait right down :P

[me=killer_007] is having fun crashing newbie servers like a 10 years old child atm XD[/me]

Posted

I got a code for crashing L2J server and the fixes for that packet i only got them as i know so be aware cuz  my favorite server need ppl too :D sorry if i shut down ur server :D:D ;D ;D

Posted

pff if u think my favorite server is l2j that ur mistaken... -beep- l2j i wouldnt play that shit if the last server alive was an l2j server.. buggy ass laggy piece of shit...

 

anyway... killer_007... hlapex has a flaw with the way it differnciates the authd connection from the l2server connection, it hooks ws2_32.connect and checks the port of the address header sent to it, if the port is 2106, 2222 or 5001-4, then it treats the connection as an authd connection and returns to the normal connect function, if its any other port then it detects it as an l2server connection and replaces the ip in the header to 127.0.0.1, checks if apex is still running, and then returns to the normal connect, which then connects to apex which then proxies to the server which enables it to view/send packets, so yeah... and i just gave every server owner that reads this an explanation of how to block apex, but nevermind because its on PP anyway...

 

also the GM Shop exploit is 100% dependant on the server... not only that its easy to fix just by taking out the items that are exploitable lol... which is why im probably not going to release it...

Posted

pff if u think my favorite server is l2j that ur mistaken... -beep- l2j i wouldnt play that shit if the last server alive was an l2j server.. buggy ass laggy piece of shit...

 

anyway... killer_007... hlapex has a flaw with the way it differnciates the authd connection from the l2server connection, it hooks ws2_32.connect and checks the port of the address header sent to it, if the port is 2106, 2222 or 5001-4, then it treats the connection as an authd connection and returns to the normal connect function, if its any other port then it detects it as an l2server connection and replaces the ip in the header to 127.0.0.1, checks if apex is still running, and then returns to the normal connect, which then connects to apex which then proxies to the server which enables it to view/send packets, so yeah... and i just gave every server owner that reads this an explanation of how to block apex, but nevermind because its on PP anyway...

 

also the GM Shop exploit is 100% dependant on the server... not only that its easy to fix just by taking out the items that are exploitable lol... which is why im probably not going to release it...

 

Anarchy i wasnt talk about YOUR favorite server .... I was talking about ALL servers not ur.....

Posted

pff if u think my favorite server is l2j that ur mistaken... -beep- l2j i wouldnt play that shit if the last server alive was an l2j server.. buggy ass laggy piece of shit...

 

anyway... killer_007... hlapex has a flaw with the way it differnciates the authd connection from the l2server connection, it hooks ws2_32.connect and checks the port of the address header sent to it, if the port is 2106, 2222 or 5001-4, then it treats the connection as an authd connection and returns to the normal connect function, if its any other port then it detects it as an l2server connection and replaces the ip in the header to 127.0.0.1, checks if apex is still running, and then returns to the normal connect, which then connects to apex which then proxies to the server which enables it to view/send packets, so yeah... and i just gave every server owner that reads this an explanation of how to block apex, but nevermind because its on PP anyway...

 

also the GM Shop exploit is 100% dependant on the server... not only that its easy to fix just by taking out the items that are exploitable lol... which is why im probably not going to release it...

 

Anarchy i wasnt talk about YOUR favorite server .... I was talking about ALL servers not ur.....

ahhh okey xD either way l2j sucks ^_^ i dont waste my time trying to find exploits there... i find it much more entertaining punching holes in the ego of l2off owners that think they are untouchable because they use amped..
Posted

Hm...in my server theres a smthing liek a louncher, which automaticaly closes all kind of stuff(etc. walker,bot,hlplex). How can I bypass a -beeeeep- louncher,witch has some packets in it, couse u can't just log-in by l2.exe

PS:  server is www.bfdr.eu

PPS: Anarchy, nice exploit. Never though,that l2off can be killed by some packets,lol. ^_^

Guest Thanos47
Posted

i have start to learn about l2off ... i hope i would make it to be a off dev too .

L2off i have try to open it or check wtf have i cant its very hard,in my opinion,java its easyest think i know :P

Posted

We are going off topic this topic is about Crash Exploit plz dont go off topic  :-[ :-[ :P :P :P i went off topic too before sorry about that.

Posted

If you wish to cause more dmg, press the auto button than the send... when i did this (i left it to auto till server disconnected me) the login and NPC server also got owned (that server had 2, a rpg and one pvp...). Try it :P

Posted

i can assure u that was a coincidence... the authd ("login server") and then l2server are linked only by a tcp connection... which means one can not crash the other... putting the packet on auto wont do anything more than send it more times... may make it d/c u faster because more memory gets overwritten by the overflow... but thats about it... also, the npc server will get owned because when the l2server crashes, the l2npc follows.

Guest
This topic is now closed to further replies.



  • Posts

    • tratando de crear un GvE tengo problemas con el scripts como no se mucho de esto me estoy ayudando con IA pero no puedo salir de este bache      [06:19:43]  WARN Quest GvE_AI not found! [06:19:45]  WARN Quest GvE_AI not found! [06:19:50]  WARN Quest GvE_AI not found! [06:25:51]  WARN Quest GvE_AI not found!
    • ## [1.5.5] - 2026-02-02   ### ✨ New Features - **Discord Login**: You can now sign in with your Discord account. Admins enable and configure Discord login in **cpadmin → Users** (Discord auth settings: Client ID, Client Secret, Redirect URI). If you already have an account with the same email (e.g. forum, Google, or legacy), signing in with Discord links to that account so you keep one profile. Discord login is available on Add Server, My Servers, Vote page, and Premium Ads booking. - **Setup Links**: In **cpadmin → Users**, both Google and Discord login settings now include direct links to their official developer portals (Google Cloud Console and Discord Developer Portal) for easier OAuth app setup.   ### 🔒 Security - **Email Required for Registration**: New user registration via OAuth (Forum, Google, Discord) now requires a valid email address. If the OAuth provider doesn't provide an email (e.g. unverified Discord email), registration is rejected with a clear message. This prevents anonymous accounts and ensures all users can receive important notifications.   ### 🔄 Improvements - **User Auth Badges**: In **cpadmin → Users**, the Registered Members table now shows auth method badges: **Forum**, **Google**, **Discord**, or **Legacy**. Users can have multiple badges if they've linked multiple login methods. - **Server Info Labels**: Translated server info labels (Owner Name, Language, Server Location) are now properly localized in all 5 languages (English, Spanish, Portuguese, Greek, Russian).   ---   ## [1.5.4] - 2026-02-01   ### ✨ New Features - **Google Login**: You can now sign in with your Google account. Admins enable and configure Google login in **cpadmin → Users** (Google auth settings: Client ID, Client Secret, Redirect URI). If you already have an account with the same email (e.g. forum or legacy), signing in with Google links to that account so you keep one profile. The login menu (navbar and login prompts) offers **Login with Forum Account**, **Login with Google** (when enabled), and **Create Forum Account**. Google login is available on Add Server, My Servers, Profile Settings, Vote page, and Premium Ads booking. - **Ban/Unban Members**: In **cpadmin → Users**, admins can ban or unban registered members. Banned users see a full-page message: "Sorry, you are banned from using this site." When a user is banned, all their servers are set to inactive. - **Moderator Activity Log**: **cpadmin → Moderators** now records when a moderator or admin enters the CPAdmin panel (e.g. "Moderator X entered CPAdmin panel at <time>") and when they change any cpadmin settings (only write actions are logged; read-only use is not). - **Clear Moderator Logs**: Admins can clear all moderator activity log entries via a **Clear logs** button with confirmation. Logs are shown at 100 per page with pagination. - **Filter by Moderator**: In the Moderator Activity Log, a **Filter by moderator** dropdown lets you view activity for a specific moderator or "All moderators." - **cpadmin → Users Tab**: New **Users** tab in the admin panel with Registered Members list (paginated), Google auth settings card, and per-user Ban/Unban and server links.   ### 🔄 Improvements - **cpadmin → Servers**: Each server name in the servers table is now clickable and opens that server’s info page. - **cpadmin → Users – Servers column**: The servers count/list is clickable and opens a small modal listing that user’s servers; each server name in the modal links to the server info page. - **cpadmin → Users – Search**: A search bar above the Registered Members table lets you search by **username**, **email**, or **server name**. Results are filtered on the server (paginated); clearing the search resets the list. - **Moderator Activity Log**: Pagination shows "Showing X–Y of Z" and "Page N of M" with Previous/Next when there are more than 100 entries. - **Login UI**: Login options (Forum, Google, Create account) are shown in a consistent dropdown and in modals (Add Server, My Servers, Vote, Premium Ads) for a clearer sign-in experience. - **Vote Page – Unauthenticated**: When you must log in to vote, the page now shows "Vote for [Server Name]" as the main heading and presents login options in a compact section.   ---   ## [1.5.3] - 2026-01-30   ### ✨ New Features - **File Logs in Admin Panel**: Admins can now view CodeIgniter PHP logs (api/writable/logs) directly in **cpadmin → Logs**. Select a date to view the log file, refresh to reload, or delete all log files to free up space.   ### 🔄 Improvements - **Cache System**: Full cache audit and improvements — when you clear cache in cpadmin, both backend and frontend caches are cleared. Server listings, My Servers, pricing, ad config, and chronicles all refresh with fresh data. New paid servers now appear in listings and My Servers immediately. - **Admin Panel – Server Rates**: Server rates in the admin servers table now display in compact format (e.g. x10000 → x10k, x100000 → x100k, x1000000 → x1m) for easier scanning. Hover to see the full value.
    • WTB High Five source running on Salvation/Fafurion client
    • MoMoProxy has updated more static residential proxies for USA location, anyone interested in can view: https://momoproxy.com/static-residential-proxies
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..