[IMPORTANT]TQ Entering in PServers and Using CODES with Normal Player ?

12/16/2009 18:47 XxFearReaperXx#16
Quote:
Originally Posted by snailtrail View Post
Why would all servers be hacked? no1 else has these problems.. as far as i know the mannequin updates made it impossible for the normal players to use codes like scaling etc. all thats gone.. It really looks like someone is hacking your pc..
And TQ/NetDragon are not allowed to play any pservers let alone log on to them.
Thats the reason the DMCA letters go out.

Really i think you just pissed a hacker off and your server is paying the price for it. sorry =/
i agree with snailtrail completely
DCMA letters are the only thing NetDragon can do
and no player or PM can create/delete an NPC from an in game command that im aware of its al done by database which leads me to believe some one hacked ur database and screwed with it
or most possible thing try checking GMLogs see if there were any commands used by a "Hidden PM" or a special character if there were any codes used it'd show up in ur log files
12/16/2009 19:06 CyberServer#17
so need beware from now i think :)
12/16/2009 20:05 sandolkakos#18
Quote:
Originally Posted by XxFearReaperXx View Post
and no player or PM can create/delete an NPC from an in game command that im aware of its al done by database which leads me to believe some one hacked ur database and screwed with it
Look, all times that happened the problems,
the last Loggin, was the IP CHINESE, and the same LOGGIN.
Later seconds of this LOGGIN, the Problems Happened.
Tomorrow, if the people try again, i go back here to Post the Result ^^

Quote:
Originally Posted by XxFearReaperXx View Post
or most possible thing try checking GMLogs see if there were any commands used by a "Hidden PM" or a special character if there were any codes used it'd show up in ur log files
I know about GMLogs, login_rcd Logs, etc....
Was looking in Logs, that i found this CHINESE :p

***********
My Server is the biggest competitor here in Brazil.

and YES, the GNN along with the TQ want to Down the Eo Paraiba, and will do anything to it.
because only DMCA letters dont have Results.

So I AM SURE that this people is doing one of 2 things:

1. Using Normal Player Commands (secrets)
or
2. They have a modified client, which can do some things within the game.


And to make one of these 2 things, only the TQ / NetDragon could, as they developed the server and client, and know everything about him, and may instead have created something to combat the Private Servers.

There is no other explanation for it.

So now all are well aware.
This is happening to me now, because I am their target, :mad:
and in the future you can target them as well.
12/16/2009 20:12 CyberServer#19
well dude thanks for the info i will take safety steps for mine...anyways maybe they interested of your website its same like official...its just my guess
12/16/2009 20:21 FKGrut#20
Screenshot for the sandol server "error":

[Only registered and activated users can see links. Click Here To Register...]
12/16/2009 20:23 sandolkakos#21
Quote:
Originally Posted by CyberServer View Post
well dude thanks for the info i will take safety steps for mine...anyways maybe they interested of your website its same like official...its just my guess
yes :p
i am making other Website.
12/16/2009 20:34 SoulNecturn#22
Ok heh thats pretty ODD what is here happening

I still believe its not TQ itself but others could as well be behind this ....

sandolkakos I will start from fast idea for you to solve this (maybe at least temporary etc)

1) Delete temporary your spider queen from your DB - at least it wont be spawning anymore whatever will happen ;) (delete its id under monstertype - so in case if its under action bug it wont spawn this monster .. and you can later check in logs of errors - actions that are not right- if its connected ;))

2) about your NPC (not sure if you have only one composer that is missing etc) - but try to make one or 2 more somwhere in market temporary to check what will happen

3) about actions that you can check and prevent from spawning:
as we know there is 3 ways to spawn monster:
a) via NPC server - generator etc
b) via cq_action specific type and param
c) via PM command
(I could be missing something now becase thining fast)

anyway about each one:
c) ==> this can be hack into your server via kind of port etc (check if this IP is not using specific other then others port...)
...
b) ==> I advise you to check inside your DB table cq_action if someone (accidently or not....) didnt put an action that is automatically processing
search under type: 2006
could be something like 0 0 1000 etc ... check check ;)

c) ==> this one you can settle under your MSGserver ;) Open it via ollydbg - search for "tetsmonster" or create etc ... (dont remember) - and just edit it - change into your own one etc ;) (should help ;))


Lasly - since I had already few months ago a journey with attacks from plenty of chinese IPs as well from whole country -> advise - scan carefully your ports ....

Good luck there and dont give up ;) Creator or not, you can always trick them (if its even connected with TQ lol bhe)

Regards
12/16/2009 20:54 sandolkakos#23
Quote:
Originally Posted by Soulerman View Post
Ok heh thats pretty ODD what is here happening

.....
ok, thanks my friend i will make this steps ;)

if i have any sucess to Get this Noob, i post here
12/16/2009 21:33 forcer#24
ok, I dont think this is TQ either, however, everything is possible in "soviet" china...
so, I would suggest to run wireshark and capture all packets to msgserver ports that come from chinese IPs(you can find all chinese ranges on google).
send me private message when you want to set it up. I always knew there is exploit for both acc/msg, but never seen anybody using it. interesting stuff!!!.
12/16/2009 23:24 sandolkakos#25
Quote:
Originally Posted by forcer View Post
ok, I dont think this is TQ either, however, everything is possible in "soviet" china...
so, I would suggest to run wireshark and capture all packets to msgserver ports that come from chinese IPs(you can find all chinese ranges on google).
send me private message when you want to set it up. I always knew there is exploit for both acc/msg, but never seen anybody using it. interesting stuff!!!.
Thanks for your attention forcer.

I am studying the wireshark to learn how it work and can use it.
12/17/2009 00:39 AaronzitoBR#26
Marllon Hey, you here?
So, as I said in Orkut ... The TQ Digital can not go around hacking Private Servers. First, if they did that you already have something against them. Second, I think it's some stupid shit GNN.

Stay calm. Anything, just the players stop playing in the GNN, and TQ Digital will lose their players in Brazil.

If they close even Eudemons Paraiba, simply create another private server of some cool game and send the TQ Digital to shit.
12/17/2009 06:54 CyberServer#27
Quote:
Originally Posted by forcer View Post
ok, I dont think this is TQ either, however, everything is possible in "soviet" china...
so, I would suggest to run wireshark and capture all packets to msgserver ports that come from chinese IPs(you can find all chinese ranges on google).
send me private message when you want to set it up. I always knew there is exploit for both acc/msg, but never seen anybody using it. interesting stuff!!!.
Nice Forcer;)
12/17/2009 07:34 funhacker#28
@Everyone
It does not matter who done it, it's the fact that it can and has happened. Personaly with this kind of stuff I would say it was a packet attack of some kind. Basicaly ALL the tables are stored in some kind of array or data structure so with the correct packets you could edit that data.

Also if it is a packet attack firewalls will NOT do anything as that port has to be open to the player or they will not be able to play the game.

Quote:
Originally Posted by XxFearReaperXx View Post
i doubt it there are no commands that a regular player can use that will shut down the server or create monsters in market
however you probly got ur server hacked which is very common with noob servers its not to hard to gain access to DB
You need to learn the difference between newb and noob, your attitude towards this defines you as a noob. A fresh server would be defined as a newbie server. As for EOParabia they are neither.
12/17/2009 13:26 sandolkakos#29
Quote:
Originally Posted by funhacker View Post
@Everyone
It does not matter who done it, it's the fact that it can and has happened. Personaly with this kind of stuff I would say it was a packet attack of some kind. Basicaly ALL the tables are stored in some kind of array or data structure so with the correct packets you could edit that data.

Also if it is a packet attack firewalls will NOT do anything as that port has to be open to the player or they will not be able to play the game.
They already Down me 2 times today :(
I have saved the Packets send to they.

If somebody understand about Packets, i can POST here the Packets to be analysed.
12/17/2009 14:52 zukoo#30
I'm with this problem, from 13/12 days, today is down.
my server is on a short time, fall day.
and I have done almost everything, reinstalled the entire server, the messages have changed since I installed an ant-ddos, I have no external door open, and I mentioned to LimeStone, they informed me that have done the filtering of ddos and spoke that had not DDos attacks

then I do not know what else might be.



Sorry my bad English.


______________________________________________

Quote:
Originally Posted by sandolkakos View Post
Then what the explain to Create Monster, and desappear NPCs ?
Dont have how make this with Server Running.

and the IPs?
218.5.2.219
202.177.22.84
202.155.204.174

and the emails?
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]

In my Server, the Register need Validate ^^

invasion yes, the IP that entered the server are the same as entered eofenix.

heather21 login EoFeniX from 218.5.2.219 at 2009-12-20 12:03:30
__________________________________________
@ Edit
My problem is identical to eoparaiba, with the spiders, npc's and down server.
Anybody know how blockier Chinese ports?
Remember: my server has no connection with the eoparaiba both the data base as any other system.
If anyone get a solution, please can you tell me? Thank you.