Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Shaiya > Shaiya Private Server > Shaiya PServer Development
You last visited: Today at 16:40

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[HELP] ps_login Injection Again

Discussion on [HELP] ps_login Injection Again within the Shaiya PServer Development forum part of the Shaiya Private Server category.

Reply
 
Old 01/22/2015, 10:55   #16
 
elite*gold: 0
Join Date: Mar 2014
Posts: 119
Received Thanks: 27
Hi Dotzie

It's a good answer that you give, i will answer with what i know.

You figure out a good security point, by this way, (changing port), you will avoid standar attack on this point.

But injection are not here.
I personnaly think it's only in the databases.
Yes, we can avoid this by reduction of the amount of char that we can enter(and send) by the way of the login (that interact with ps_login)

But, if your trigger in the databases are not secure, a man you will you packet injector to bypass ps_login char (i dont know if it's possible), will send an injection.

Here is a simple injection :
' Drop database ***

Where *** is the name of the database.
The ' will trunc the previous request, like select ... from ... where
And will execute "Drop database ..." with the admin privilege cause it's executed on the server side.

Maybe, the first point to do is to locate the trigger that check de login (to permit the connexion), and had a huge filter on this , rejecting word and char like : ',",%, || .. drop,select,union

I'm not sure, but when i develop databases, i do this stuff to avoid SQL injection .

I don't know if someone agree with me, but i think it's a point the think about.
Boul27 is offline  
Old 01/22/2015, 15:09   #17
 
elite*gold: 0
Join Date: Dec 2014
Posts: 22
Received Thanks: 1
no use changing doors, or encrypt the game.exe. is very easy to find out the ip and port on a server, simply log into the game and give a simple command in cmd.
Namikaz3 is offline  
Old 01/22/2015, 15:28   #18
 
elite*gold: 0
Join Date: Mar 2014
Posts: 119
Received Thanks: 27
What kind of command ?
A normal player can do this ?
Boul27 is offline  
Old 01/22/2015, 17:22   #19
 
elite*gold: 0
Join Date: Dec 2014
Posts: 22
Received Thanks: 1
yes command netstat. anyone can do it, no matter if the game.exe is encrypted or not. need to find the flaws in ps_login, ps_game and ps_dbagent and correct. is the only way. and to me that's difficult. I have so much knowledge. I need your help
Namikaz3 is offline  
Reply


Similar Threads Similar Threads
ps_login hack how to
05/02/2020 - Shaiya PServer Guides & Releases - 7 Replies
I'll show you how it was done but first the fixs for it: http://www.elitepvpers.com/forum/shaiya-pserver-g uides-releases/3525712-release-fixed-ps_login.html http://www.elitepvpers.com/forum/shaiya-pserver-g uides-releases/3525341-release-ps_login-anti-injec tion.html get a copy of working packet injector and attach to game.exe before login send this packet
[RELEASE] ps_login anti-injection
04/27/2015 - Shaiya PServer Guides & Releases - 28 Replies
There you go, it won't accepte this injections from those bad people.. Yes, I payd for get it, I release it for free because Im a man who will never sell any files. Virus Total Scan
[HELP] ps_login Injection Again,
01/13/2015 - Shaiya PServer Development - 1 Replies
Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...
[HELP] ps_login Injection Again
01/12/2015 - Shaiya PServer Development - 0 Replies
Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...
[HELP] ps_login Injection Again
01/12/2015 - Shaiya PServer Development - 1 Replies
Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...



All times are GMT +2. The time now is 16:40.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.