A bout Emme's Database Injector? lol - explanation-

07/17/2009 22:51 _Villain_#1
detailed explanation of the archlord injector that Emme Wrote (before he deleted it from the attachment hehe):

well practically, its a fake program lol, and these are the details of the files he provided, before he deleted the attachments:

(the connect button)
Code:
private void button1_Click(object sender, EventArgs e)
    {
        if (((this.textBox4.Text == "localhost") && (this.textBox5.Text == "19.21.555.2")) && (this.textBox6.Text == "archlordv3"))
        {
            MessageBox.Show("Connected to Archlord database!", "Success!");
            this.panel1.Visible = true;
        }
        else
        {
            MessageBox.Show("Could not connect to Archlord database", "No connection!");
        }
    }
(it basically views a typical ip address (from the us lol) and a string to the localhost

and creates a fake message the the connection to the archlord database succeeded!



(get accounts)
Code:
private void button2_Click(object sender, EventArgs e)
    {
        Random r = new Random();
        this.textBox7.Text = "Getting characters...";
        this.t.Interval = r.Next(0x1770, 0x2710);
        this.t.Tick += new EventHandler(this.t_Tick);
        this.t.Start();
    }
it basically creates a timer with a 6-10secs random interval and starts that timer to call this method:
Code:
    private void t_Tick(object sender, EventArgs e)
    {
        MessageBox.Show("Loaded 2148 accounts. Wish to save?");
        this.textBox7.Text = "Wish to save accounts?";
        this.t.Stop();
    }
which simply creates anothe rfake message of displaying 2148 fake accounts too.


(save accounts button?)
Code:
    private void button3_Click(object sender, EventArgs e)
    {
        if (this.textBox7.Text == "Wish to save accounts?")
        {
            File.WriteAllText(Application.StartupPath + @"\accounts.txt", File.ReadAllText(Application.StartupPath + @"\CppApplication-form.exe"));
            MessageBox.Show("Accounts have been saved in 'accounts.txt'");
        }
        else
        {
            MessageBox.Show("No accounts are loaded");
        }
    }
which simply creates a txt file called accounts.txt by reading the contents of anther txt file which is (CppApplication-form.exe )---> rename it to CppApplication-form.txt to see the contentes


so in general what that code does is this: provides fake info, fake coding, fake timer, no connection to any database and nothing.

so basically, all the code is just a fake, and it might be a joke to u emme
but its not for most of the users

Emme dont delete this post lol

srry i didnt run the application lol (because i remember when i was with u emme the other day u were writting another fake C# program which terminates task manager repeatedly and displays a message: "you got owned" and the name of that applicatoni was: "account hacker" lol -- that was when u were asking Dnote to talk to u on msn lol- i caught a glimpse of the other "account hacker" source code on the fly when u were with me on teamsviewer before we dced :).

so i didnt run the tools u provided, just refected them :( to see the source code.

any way, read my email, i still want what i asked for if u have it lol.
07/17/2009 23:45 _Emme_#2
Sure, the whole program is fake, but it gives real accounts. Who in earth would think I would put up a real injector that takes 0.2 seconds to decompile? Well, I won't.
And for the 'Account Hacker', noone was supposed to use that I just wanted to see if it's possible to create a program and while it's running you can't open taskmgr, got it to work eventually.

And no Villian, I won't give you anything, just forget it.

Btw ,
#infraction for doubleposting

;)
07/18/2009 05:10 _Villain_#3
Quote:
Originally Posted by EmmeTheCoder View Post
Sure, the whole program is fake, but it gives real accounts. Who in earth would think I would put up a real injector that takes 0.2 seconds to decompile? Well, I won't.
And for the 'Account Hacker', noone was supposed to use that I just wanted to see if it's possible to create a program and while it's running you can't open taskmgr, got it to work eventually.

And no Villian, I won't give you anything, just forget it.

Btw ,
#infraction for doubleposting

;)
but why u posted a fake code from the begining? u didnt need to make such a move lol, just say that these are the accounts and voila

and by the way tx for the infraction point lol.


Emme :( srry to say this: but u dont have access to the database, and u never had lol, gathering all the pieces now, and the posts u deleted of urself, and our prev conversations, i have the image loud and clear.


the sql commands that u were using were those:

SELECT * FROM `accounts` WHERE `AccID` = `Password`
SELECT * FROM `accounts` WHERE `Password` ="'archlord1'"
SELECT * FROM `accounts` WHERE `Password` = "'password1'"

SELECT * FROM `accounts` WHERE `Password` = `AccID` + "'1'

and your MySqlConnection to the localhost, was only to access the accounts table(which is a local table) and checking the (WHERE clause syntax) means that the accounts table is local and has (username - password [word dictionary] - both username and password columns have the same values mostlikely, but they exist for join purpose)

lol, this is a typical dictionary attack considering all the names like: flamer - flamer Bloodshed1 - bloodshed1 aeritimus - archlord1 -
berto94 - berto94 - all these names are in dictionary files used for a typical password dictionary attack (and by using the prev sql commands only confirms that its account-password dictionary attack for a web page....)


and i know where and how u applied ur attack now hehe (took some hints from a post u deleted too) .... i wont post any further details.


Emme, claiming to have access to a major company's database records isnt something to be taken lightly and isnt simple as u think these days.


cheers.


P.S. (for normal players: i suggest u choose ur passwords more wisely next time)
07/18/2009 09:43 _Emme_#4
Villian, the MySQL injection was real and was directly connected to the main archlord database.
The program that I released yesterday was not a real injector, it was a fake program but it got 2148 accounts.

No, I do not claim that you connect to 'localhost', or IP '21.9.555.21' etc etc, those are all fake.

I told you on MSN yes, that you connect to localhost, but ofcourse you don't! And, why would I tell you how to connect? Forget it.

May I close this thread now?
07/18/2009 13:28 Ph4ra0#5
Quote:
took some hints from a post u deleted too
hint hint?
07/18/2009 13:28 Ph4ra0#6
Quote:
took some hints from a post u deleted too
hint hint?
07/18/2009 16:08 _Villain_#7
Quote:
Originally Posted by EmmeTheCoder View Post
Villian, the MySQL injection was real ...
May I close this thread now?
i rather prefer it stays open for now.

and i wont create more discussion whether u used sql injections or not, because im rather sure of what i said already (its not a rocket science)....

but again i say to the players: if u change ur passwords into a strong and good formatted password (letters-number-capital letters...) then this dictionary attack wont work.

i created this thread, to make players feel safer about their accounts... without trying to hide the truth, because we all now that sht happens.
07/18/2009 18:43 hernan#8
well i believe emme since ive found the account of a really old guild member
07/19/2009 09:20 Bolesni#9
lol i wonder why one guy Letterofpardon posted these accounts years ago ?
and like 1000 of these accounts have lvl 1 char and nothing more....
and yea names are like hghghfhgf or vadfdag
-.-
i just have to say emme shame on you ;)
07/19/2009 11:15 Baaso#10
Quote:
Originally Posted by Bolesni View Post
lol i wonder why one guy Letterofpardon posted these accounts years ago ?
and like 1000 of these accounts have lvl 1 char and nothing more....
and yea names are like hghghfhgf or vadfdag
-.-
i just have to say emme shame on you ;)

We all know who is Letterofpardon...He didnt hack nothing...
07/19/2009 17:48 -Haxor-#11
Quote:
Originally Posted by Baaso View Post
We all know who is Letterofpardon...He didnt hack nothing...
so emme did? no
villain > emme
dnote > emme

sad but true for u
now hes abusing his mod powers...and delete our posts
gg u fail
07/19/2009 21:32 Newbb#12
lol^^
07/19/2009 21:38 _Emme_#13
I'm not abusing anything.
The accounts I got was from my own SQL injection, I have no idea who LetterOfPardon is.

Thread closed,
discussion ended,
sold what I need sold.
The buyers will stay private to prevent Dnote to catch their names on e*pvp, get their IP addresses and IP ban them in-game.