[Release] Fix SQL Injection in GM commands

05/27/2020 14:57 Eric-Dutra16#1
This exploit has become better known now, so I decided to release my fix. The fix works for all commands (warning, notice, gmnotice...) and doesn't disable the action log. Works only for ep5.4 ps_game.
05/27/2020 17:20 [GM]Crypton#2
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.
06/16/2020 19:31 IlusionXtreme#3
Quote:
Originally Posted by Eric-Dutra16 View Post
This exploit has become better known now, so I decided to release my fix. The fix works for all commands (warning, notice, gmnotice...) and doesn't disable the action log. Works only for ep5.4 ps_game.
Quote:
Originally Posted by [GM]Crypton View Post
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.

Does anyone know which version is more useful, the Erick-Dutra version is short and short the cups version, and a larger script with the possible correction for the commands, someone tested and can tell which one is more useful or more complete?

I appreciate if anyone knows any useful information.
06/17/2020 08:32 Eric-Dutra16#4
Quote:
Originally Posted by IlusionXtreme View Post
Does anyone know which version is more useful, the Erick-Dutra version is short and short the cups version, and a larger script with the possible correction for the commands, someone tested and can tell which one is more useful or more complete?

I appreciate if anyone knows any useful information.
Both fixes work. My script replaces the quote character with space in the function that creates the action log, the cups and bowie scripts disables calls to the function.
06/28/2020 02:44 Diego Jairo#5
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
06/28/2020 16:27 IlusionXtreme#6
Quote:
Originally Posted by Diego Jairo View Post
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
This is a CT script, the code is open, you can check each of the functions and do tests, or you are too dumb to do this.
a ct correction is different from a modified ps_login where it has thousands of codes, dumb people just like you that spoils the community, THAT is a CT file your code is visible, for you check its effectiveness.
06/28/2020 21:43 Eric-Dutra16#7
Quote:
Originally Posted by Diego Jairo View Post
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
Ok, this is my last release on this forum.
06/29/2020 01:25 Diego Jairo#8
Quote:
Originally Posted by IlusionXtreme View Post
This is a CT script, the code is open, you can check each of the functions and do tests, or you are too dumb to do this.
a ct correction is different from a modified ps_login where it has thousands of codes, dumb people just like you that spoils the community, THAT is a CT file your code is visible, for you check its effectiveness.
Very good for you friend, I did not mention this release, I just took advantage of the subject to talk about an event that hurt many people, if you don't know how to interpret text, I have nothing to do with it, it's your problem.
06/29/2020 03:25 Eric-Dutra16#9
Quote:
Originally Posted by Diego Jairo View Post
Very good for you friend, I did not mention this release, I just took advantage of the subject to talk about an event that hurt many people, if you don't know how to interpret text, I have nothing to do with it, it's your problem.
That's a lie, I'm probably the only Brazilian who posted releases on this forum and they are all open source. I checked your profile, your only release is useless, it was not made by you and it is not open source.
06/29/2020 16:19 IlusionXtreme#10
Diego Jairo and the well-known Vonstrucker, he uses a fake profile to publish things that are not his, he propagates files and stolen things, things he will never be able to do, never created anything and never did anything for the community.
I am waiting for you to publish your Shaiya Ernasis server in Brazil, which will have a limited duration
04/07/2021 14:06 superklamus#11
is there any for ep4 ?
04/22/2021 13:43 [adm]Bowser#12
Quote:
Originally Posted by IlusionXtreme View Post
Diego Jairo and the well-known Vonstrucker, he uses a fake profile to publish things that are not his, he propagates files and stolen things, things he will never be able to do, never created anything and never did anything for the community.
I am waiting for you to publish your Shaiya Ernasis server in Brazil, which will have a limited duration
that VonStrucker is a kid, he was selling me things that he stole
09/16/2021 20:01 likevil#13
Quote:
Originally Posted by [GM]Crypton View Post
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.
It not working on ep4.5
09/16/2021 20:04 [GM] Purple#14
Thanks, good work.
09/18/2021 05:27 KingKush88#15
Quote:
Originally Posted by likevil View Post
It not working on ep4.5
Do people even read?
It clearly says it only works for 5.4 episode ps_game...