The Revolution of 9Dragons - Update Patch 95 - Support for Gamer

05/21/2015 08:18 tuansang18#1
webs: 9d.g2playvn.com
fanpage : [Only registered and activated users can see links. Click Here To Register...]
groups : [Only registered and activated users can see links. Click Here To Register...]

+ To facilitate hero Renaissance Kowloon in particular as well as brothers in the world in general Nine Dragons 1 start

advantages and help you not lose as much anymore, it still recommended train today. Leaders decided Renaissance Kowloon

brothers donated when the new prime state of play

[Only registered and activated users can see links. Click Here To Register...]

With these lines quite well opt help you more comfortable in the train lv

[Only registered and activated users can see links. Click Here To Register...]

Blogs And support you on +10 weapons parts with new prime gift

+ Besides server reopened the item matching hustler + 15

[Only registered and activated users can see links. Click Here To Register...]

To give you the ability to build servers with better grades and more convenient

[Only registered and activated users can see links. Click Here To Register...]

On behalf of the Board of Trustees Renaissance server .. Wish you enjoyed playing in server sales and having a lot of fun.

Please Sincere Thank You
05/21/2015 10:46 Tengerecki#2
Get out of here, man.
05/22/2015 16:13 bastiannw#3
Quote:
Originally Posted by xtJamie View Post
The website is not secure.

Every register_username_name and register_password_name are sent plaintext so anyone listening to the network or MITM could possibly see every username and password being sent.

Example of this:

[Only registered and activated users can see links. Click Here To Register...]

The passwords are being submitted via GET and not POST. The GET method will contain the password as a parameter within the URL which means they could be seen in the headers.

The forms themselves provide no CSFR security meaning anyone with CSFR understanding can elevate attacks via the applications

The HTTP methods are not disabled meaning you could exploit the options methods on the web server.

The login is open to brute force attack: GET /?login_password_name=gdjVmXCf&login_username_name= EUBNHBnB

The SSL is 2.0 which is outdated, insecure and deprecated - exploitation available using CRB.

The conf directory is exposed

The custom 404 allows the attacker to view information on the web server.


[Only registered and activated users can see links. Click Here To Register...] was detected when launching your ndlogin because it was opening a number of large range udp/tcp ports - something it shouldn't be doing. Also can you please explain the command prompt loading for a single second and spawning a process which was 'hidden'?

"There was no one radish nothing here! By the way, your IP stored in the system:, careful nhoa !! Where touch nhoa wrong here !! :)"

Storing someone's IP address in the system because you're able to use any packet analysis tool to find the IP addresses of the servers - cute.
in other words:
rekt