Jump to content

[SHARE] How to "fix" the AuthD exploit.


Recommended Posts

Ok guys... Lately a lot of servers got owned by this exploit where you just pick an account ID and pick any chars you want... Lots of servers got corrupted, people getting in GM accounts and summoning items, to sum it up, it's a total CHAOS. Anyways, this is how you should be able to temporarily fix it:

 

1 - First off, backup your lin2world and lin2db databases, if anything goes wrong, you'll be able to restore your databases and start it over again without being fucked over.

 

2 - Open your enterprise manager whatsoever in MSSQL, make a new query, put this into it and execute:

 

use lin2world
update user_data
set account_id = account_id + 621854

 

// This is just an example, you could use any other number you want, but with that number the noobs are gonna try to find the account ID's forever.

 

3 - After you've done that, unlock the lin2db database, make a new query, type this in and execute:

 

use lin2db
update user_account
set uid = uid + 621854

 

// Keep in mind the number should be the same in both, else it won't work.

 

4 - Reload the server.

 

 

Now script kiddies are gonna try to find the account ID's, they'll start by 1, 2, 3, 4, 5, 6, 7, 10k, 20k, 40k, 50k, 60k, 70k, until they go like WHAT THE FUCK and /wrist.

 

Hope it helps you, thank you Mac for helping me out with this.

 

Best regards.

Link to comment
Share on other sites

pyromaker in oneo darkrage made something dunno what and in order a gm to loggon he have to put or allready have the ip on the db ... can u explain me how does this work??

Link to comment
Share on other sites

It's called Amped.

 

For example:

 

[builder]

UseIPFilter=true

; list of allowed IPs or host names, delimited by ";"

; i.e.: 127.0.0.1;11.22.33.*;11.44.*.*;foo.no-ip.com

IP=pyromaker.no-ip.info;littlepyro.no-ip.info

Link to comment
Share on other sites

amped 2.0a

 

[23:11] <cypher|Emporio> that acct hacking exploit really pissssed me off ... so, here is the 2.0a

[23:11] <cypher|Emporio> i won't post on forums, so ...

[23:15] <cypher|Emporio> fixed acct shit (both exploits), crashes, skill enchanting, skill aquiring, gems exploits, suports runtime unloading (i leave u as homewhork to write an unloader) ... etc etc etc

Link to comment
Share on other sites

  • 2 weeks later...

http://rapidshare.com/files/29629337/AmpeDx64_PP.zip

 

##################

## AmpeDx64 v2.0a

##################

- FIXED:

- account exploit (both exploits)

- crashes

- skill enchanting

- skill acquiring

- gems exploits

- supports runtime unloading

... etc etc etc

 

AmpeD © cypher

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


  • Posts

    • Good afternoon everyone, we’ll get a couple of strong players in the CP, more details can be found here https://mw2.community/topic/211276-awr-team/  
    • so i bought this crap of the server few years back and i just found it laying around on my pc and i thought i should share it, if i remember correctly this crap has a lot of bugs that people abuse 🙂   https://drive.google.com/file/d/13QWg8pi4BPbGbTmlygZ078LjL6Fb0J2a/view?usp=sharing source   https://drive.google.com/file/d/13QWg8pi4BPbGbTmlygZ078LjL6Fb0J2a/view?usp=sharing system    
    • Error: Unable to access jarfile libs\Geodata_Converter_v01.jar
    • Since last massive leak as explained as 07/09 (notably all development branches), I don't accept anymore financial newcomers that easily. People will have to contribute 100 cookies worth of contributions (bug reports/fixes) as a first step to be accepted as Donator. Free user can join after sharing over 200 cookies out of contributions, compared to 100 cookies before. You can say thanks to RusAcis, and notably his worthless leader, UnleashedForce. The size of users will continue to shrink if more leaks occur, until true helpers only will be left. New prices are as following : Joining price: 200€ + 100 cookies, or 200 cookies This fee has to be paid if you are joining aCis project. Next month, and all other months, you will have to donate only basic monthly donation. Monthly price: 10€ / 10 cookies This fee has to be paid every month. I won't accept any new join fee before the 100 cookies contribution. Your money will be instantly sent back. Also, in the same shape of idea, actual supporters/donators have to be active to stay in sources. It doesn't have to be a particular amount, you just have to share from time to time *anything*. I don't accept anymore silent ppl. Only useful people will be kept.
    • @Kenrix Hello. my friend bought from you the panel and he told me that he haven't recieved yet his product whats going on?.
  • Topics

×
×
  • Create New...