A Traitor in our mist

04/19/2005 03:58 Fiya#1
Awww Kitsunepaws, you felt like you had to tell conquer but not us?!?

Kitsunepaws post : [Only registered and activated users can see links. Click Here To Register...]

Can you share with us or is it too late now ;)
04/19/2005 04:49 KitsunePaws#2
Sorry, this hack is wayyyy to serious to release here.
I won't have any script kiddies ripping the server apart.
04/19/2005 04:57 KitsunePaws#3
Also, This site from what I have seen is mostly macros. And little exploits. Unless you have linux, knowledge of mysql, and a security scanner, and the IP of the server. This hack is useless to you
04/19/2005 07:42 Flank#4
Oh man, If I got ahold of details I could definatly make something out of it =D
04/19/2005 08:03 KitsunePaws#5
Well, f**k it...
Stupid GMs..
Here
Those of you that can read this
Have fun
There 2 services that are running on all
the servers
One is an OLD exploitable version of
mySQL. It can have all sorts of shit
done to it... DoS attackes, and most
importantly... It accepts 0 length passwords
so you could log into root
with no password, have fun trying to get ahold
of a client that will let you send one though.

Second thing that is a big security risk
Is all the game servers are running
Terminal Services
For those of you that don't know what
that is....
It's also called REMOTE DESKTOP CONNECTION
=) Have fun with those brute force programs kiddies!

Edit: No vulgarities xP
04/19/2005 15:37 Flank#6
So someone could run port scanners on them and determine what services are open. Then depending on what the results are they could try default passwords and brute forceing on and of the remote connections.

And what is being held on the server with MySQL?
04/19/2005 16:40 rey#7
can u help me get some acc from my server?.. i dnt like some ppl..:(
04/19/2005 17:33 craiglincs#8
any joy in brute forcing it? when i get back from my office i'll have a play ;)
04/19/2005 17:42 Flank#9
When I get home today I will do a full port and vulnerablity scan on the login server, game server and site server.
04/19/2005 17:43 KitsunePaws#10
Have fun :)
And I am going to guess
that mysql
probably holds
err I dont know..
all the player info
monster data?
04/19/2005 17:45 Flank#11
Well say I find a vulnerablity in the the MySQL and I somehow get it to pull up a list of player accounts and then I would have to download their encrypted password file for any one account and proceed to crack it.
04/19/2005 22:30 whitespyder#12
hey kitsunepaws, you could make quite a buisness out of this, lots of people get hacked, and since half of the people who were hacked arnt the original owners, theres now way for them to get there password back. since there not original owners GM's wont do a damn thing, you could charge like a db for each account u get back.

HINT HINT WINK WINK ;)

wifes account was hacked the other day, shes not original owner so now shes screwd......

HINT HINT WINK WINK ;)
04/19/2005 22:43 KitsunePaws#13
lmao, I could.. But Knowledge is free.
:)
So I won't be charging anything for anything I discover
*HACK THE PLANET!*

Karma to anybody who knows where that's from :P
Anyways..
Mysql is pretty much open from what I understand
You pull the playernames in plain text, you pull the passwords in plain text :)
04/19/2005 22:44 KitsunePaws#14
Be careful though... massive exploitation with this, will cause server roll back ^.~
04/19/2005 22:50 whitespyder#15
i dunno what mysql is or any other programs that people use, im not that great with using programs, so im offerin a db to whoever tells me what her password is :)

*HACK THE PLANET!*

isnt that from the movie hackers?????