[INFORMATION] SQL Injection (ingame)

09/10/2016 08:47 rares495#31
No chat window seems to work. Not sure where we could find a similar dialog box.
09/10/2016 11:38 CarolineForbes#32
Quote:
Originally Posted by LogLoft420 View Post
what about guild notice and msg box? tried that but doesn't work probably my ending line is wrong hmm
and @[Only registered and activated users can see links. Click Here To Register...] :D that qoute was good in the season finale xD
Yeah that was the best ever *.* can't wait for the next ^^
09/10/2016 12:12 Syloxx#33
Quote:
Originally Posted by CarolineForbes View Post
Don't stop the war guys, keep on flaming each other. Was such a fun read yesterday :c
It's not nice to take credit from some1 else Syloxx :/ Dam bad boy ..
Dafuq are u talking about just because some1 claim it's his stuff doesn't mean it's true (if so then wonder why he didn't released it be4 or fixed it in his "improved" 188 serverfiles)

Read my 1st post about it there I explained how I found it but srsly if u have no clue at all u should just shut up.
09/10/2016 13:33 LogLoft420#34
Does Message box work or guild notice?
09/11/2016 08:21 tschulian#35
Quote:
Originally Posted by LogLoft420 View Post
Does Message box work or guild notice?

Ofc not.
Guess why It took so long to find this glitch?
Only guildmaster WITH a Fortress are able to to do so.
And Most of guildmasters are reliable players which Never came straight to the Idea to SQL Inject some Boxes
09/11/2016 11:10 duboisi#36
A few populated turkish private servers have been sent to oblivion due to this exploit. Yeah well, thats what you get for not using a reliable filter i guess.
09/11/2016 14:17 MeGaMaX#37
Quote:
Originally Posted by Syloxx View Post
Dafuq are u talking about just because some1 claim it's his stuff doesn't mean it's true (if so then wonder why he didn't released it be4 or fixed it in his "improved" 188 serverfiles)

Read my 1st post about it there I explained how I found it but srsly if u have no clue at all u should just shut up.
First, im not someone, second, i didn't fix it because it wasn't public until you came and made a party. You better shutup because im still nice with you until now.
09/11/2016 15:12 Syloxx#38
Quote:
Originally Posted by MeGaMaX. View Post
First, im not someone, second, i didn't fix it because it wasn't public until you came and made a party. You better shutup because im still nice with you until now.
I am also Nice with u, I'm just not nice to people they believe everything they hear without any research and even spread that false information.

It might be u know it be4 me but u NEVER gave me any information about it



OVH blocked traffic from HyperFilter to normal IP because of an false positive attack

Since it was on weekend we had to change the IP of the server

Since we run Login and Shard DB in different server we forgot to change the IP in the Linked Server

Means people could buy Silk Items without silk being removed

I checked the Fatal Log to get all the SQL errors and extracted the silk to remove them manuelly with a query and then I saw there some Fortress War related stuff (some1 tried to use correct English and wrote smt like We're bla bla)

That's how I discovered it so MeGa u totally wrong and I received a screen while u was blaming about me in this discord or how it's called that wasn't nice actually.

If you aren't sure from where or how I discovered it you should better just shut up srsly.
09/11/2016 16:13 ILowe#39
just fortress war ?
09/11/2016 17:28 AceSpace#40
Quote:
Originally Posted by MeGaMaX. View Post
First, im not someone, second, i didn't fix it because it wasn't public until you came and made a party. You better shutup because im still nice with you until now.
Even if you discovered it first, did you even think about telling the community about it? I guess not. Syloxx was the one who warned the community, so please save all your words to yourself.
09/11/2016 21:06 Timlock#41
Quote:
Originally Posted by Locklyon View Post
Even if you discovered it first, did you even think about telling the community about it? I guess not. Syloxx was the one who warned the community, so please save all your words to yourself.
Did you ever think he kept it quiet for a reason? maybe because servers are unprotected and vulnerable.

I wonder why someone who knows about such exploits took time out of his busy schedule to release recoded server files to fix things like this... instead of just "releasing" it to "take credit" and fuck over people who cant protect themselves.
09/11/2016 21:30 WickedNite.#42
Quote:
Originally Posted by Timlock View Post
Did you ever think he kept it quiet for a reason? maybe because servers are unprotected and vulnerable.

I wonder why someone who knows about such exploits took time out of his busy schedule to release recoded server files to fix things like this... instead of just "releasing" it to "take credit" and fuck over people who cant protect themselves.
Arab logic applies to all of them man.
09/11/2016 21:47 Syloxx#43
Quote:
Originally Posted by Timlock View Post
Did you ever think he kept it quiet for a reason? maybe because servers are unprotected and vulnerable.

I wonder why someone who knows about such exploits took time out of his busy schedule to release recoded server files to fix things like this... instead of just "releasing" it to "take credit" and fuck over people who cant protect themselves.
1st) 99% of Silkroad Private Servers use a packet filter and a fix is released, everybody can just copy paste it and gg

2nd) I could also do it like MeGaMaX (incase he really knew it be4 me) and keep the exploit as a secret and abuse it as fck but i prefer to release it so everybody can fix it.

3rd) he already released VSRO 188 "improved", adding a filter isn't that hard (maybe 2-5 mins of work)
09/11/2016 22:23 MeGaMaX#44
Its simple, fights never fix things.
09/12/2016 03:17 AceSpace#45
Quote:
Originally Posted by Timlock View Post
Did you ever think he kept it quiet for a reason? maybe because servers are unprotected and vulnerable.

I wonder why someone who knows about such exploits took time out of his busy schedule to release recoded server files to fix things like this... instead of just "releasing" it to "take credit" and fuck over people who cant protect themselves.
Instead of keeping it a secret, he could just share it and done. It's fix is pretty easy, you know though the reason he didn't share it for, is holding such a bug is valuable, might become handy in the future.