Jump to content

Recommended Posts

Posted

1st: sorry to break your heart but the hash ain't MD5

 

2nd:

test1113; INSERT INTO `user_auth` (`account`,`password`) VALUES (`3698775411144`,`81dc9bdb52d04dc20036dbd8313ed055`)--

This is wrong a correct one would be

test1113'; etc...

do you see the ' ? it's necessary or else your query will fail.

 

3rd: with that query you'd be inserting, not updating with is what you want to do.

Posted

490020006400690064006E0027007400200075006E006400650072007300740061006E00640020004100

4E0059005400480049004E004700210021002000410072006500200079006F0075002000740072007900

69006E0067002000530051004C00200049006E006A0065006300740069006F006E00200069006E002000

610020007200650061007400610069006C0020007300650072007600650072003F002000540068006500

6E0020007400680069007300200073006900740065002000690073002000610020006200690074002000

69006E0061007000700072006F007000720069006100740065002E00200047006F002000660069006E00

64002000610020006D006F0072006500200061006400760061006E00630065006400200066006F007200

75006D00200070006C007A002E000000 (HEX)

Posted

No lostos I don't think he's talking about official server... he's just talking about some l2off server where he thinks he can SQL inject...^^

Posted

yeah duall's thought makes some sense, however, you can only be given a new password for the victim's acc as the passwords are encrypted and cannot be retrieved, so, I don't know if this would work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Hi, great work! Are there any bugs? And will it work with a high five?
    • For others that would like to understand in more details:   The login server also uses a protocol (sent by the server to the client in the very first packet). For instance, the C4 client (the one I'm developing my emulator for) expects the protocol number `50721` (or `0xc621`) which works as follow (from what I've gathered): Preamble: L2 packets are divided into two parts: size and payload; As mentioned, every packet starts with two bytes containing the whole packet size (thus including those two bytes, e.g. a packet of size 15 will have the number `15` written onto its first two bytes and a following payload of 13 bytes); For login server, first byte of the payload is the opcode (game server must deal with variable-sized opcodes); Next bytes are the packet content; Before sending the packet, its buffer size (minus the initial two bytes) is padded to 8 bytes (required by upcoming Blowfish encoding); A checksum of the packet is appended at the end, then the payload is again padded to 8 bytes; If the opcode is not `0` (also written as `0x00`), then the payload is encoded by Blowfish; Packet is sent over the network. You can have a look at my implementation (in C++) here (do note I'm assuming little-endian).   In this protocol, the auth packet (`0x00`) sent back by the client is RSA encrypted using the RSA modulus sent in the first server packet, inserted right after the protocol number.  
    • Hello guys I wanna buy some  Lessons for an L2J Developer
    • Let me give you something for inspiration and get you addicted to bot AI     And a siege 😛     What I have notice helps a lot the LLM to act real, is to give it a real-persons background. So for each LLM in the context beggining, besides the L2 facts, give it a real-life back story "You are a 67 years old retired nurse who plays Lineage 2 while her husband reads his newspaper, you are calm, collected but get mad if insulted". But that makes for a creative bot but its repetitive. So what you can also do, is pick random 20 news sites and for each bot every 2-3 days, initialize a context that is affected by the "news" the bot reads in the "real world".  So for example there's Iran - US war ok ? You take the news, put it in an LLM and ask it, extract the "abstract feelings" that this news piece invokes into you without mentioning anything related to the news. Then you take the result and inject it to the bots LLM prompt after its backstory.  This leads to some VERY human-like behavior from bots. 
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..