Register for your free account! | Forgot your password?

You last visited: Today at 16:36

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



common exploits

Discussion on common exploits within the CO2 PServer Guides & Releases forum part of the CO2 Private Server category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Sep 2012
Posts: 775
Received Thanks: 329
common exploits

here is the most common exploits i've found at private servers , you may visit my old thread about exploits

first exploit
it happens when you are giving your players a free bounded +8 gears with having a rubbisher npc (unbounding gears 2k each)
so with doing some math if you kept creating accounts and using that npc to unbound the gears you will end up having a +12 item with only a price of 8k cps instead of 104k cps

solution : remove rubbisher npc or atleast restrict the unbounding to only unbound the +12 gears
second exploit
it happens when you are allowing players to summon demonbox monsters anywhere but some restricted maps
for example they can spawn it anywhere but not at market/jail/plapla
which happens to be an exploit if you are having special drops depending on map id and not monster id ex. if map id == 50 drop super duper db

solution : limit where to spawn demonbox in postive and not negative way
postive way is spawn it only at certain maps
negative way is to spawn it at any map but not certain maps

solution 2: set your special drops to be switched by monster id/name instead of map id

third exploit
it happens when you set your conditional instructions (if/switchs) to search for substring of names and not comparing the whole string
ex. if name contain "Guard" return attack 999999
ex. if name contain "GM" apply command

solution : search for exact strings ex. Guard1/Guard2 also make sure it have a false player flag , you may also want to have some more restrictions for naming char. (not to contain "[]") but a better solution is to search for player status for being gm/pm/normal player from the db
fourth exploit
it happens with poison blade and toxic fog spell , people are able to cast it on bosses (ex. treato and banshee)

solution : set restriction on casting both not to cast them on bosses (assuming that you are using the boss flag right at the monsters db , else you should just add monsters id manually)
fifth exploit
it happens when you just don't remove a pop up from player screen , and you forget to put restrictions on when the player can enter the map/quest/use the pop up in general , i use that exploit to enter maps after the events are over
solution : send the pop up and set timer to remove any active pop ups or this pop up
sixth exploit
it happens when you manage to give the item first then take the cps depending on a check you made in a previous dialog
solution : for trinity you are having a bool removing method which should be your check , if it returns true for taking the cps/item you can then give what it should be giving
seventh exploit
i also want to add that trusting client is a fatal mistake you should never do , with some reversing for the client you can do stuff normal you should not be doing , so building up your logic depending on the client restrictions is a fatal mistake
players got the clients , you got the server , no matter what client send you , you should always check your db
eighth exploit
it happens when you allow players to cast displacement spells such as dragon whirl , (that other priate skill) on maps like gw , or in general anywhere they could get advantage of
solution : an easy solution is to prevent/restrict using that spell at the coords near/throw the gates , an advanced solution is to have checks on any kind of transportation (including walking/jumping/using such spells) to be restricted at certain coords including gates (which is sure in case of gates mesh indicates that it's closed)
ill be adding more whenever i find more common exploits , thanks for reading , have a great day
go for it is offline  
Thanks
1 User
Old 05/26/2013, 05:50   #2
 
Super Aids's Avatar
 
elite*gold: 0
Join Date: Dec 2012
Posts: 1,761
Received Thanks: 950
Aka. these exploits exist in servers with owners who have no idea what they're doing.

The third exploit made me lol, does nobody handle mobs, guards etc. proper? LOL

I'm not sure if I would call number 4 an exploit, however maybe limiting the poison effect on bosses instead of making it not possible.
Super Aids is offline  
Old 05/26/2013, 07:09   #3
 
Spirited's Avatar
 
elite*gold: 12
Join Date: Jul 2011
Posts: 8,282
Received Thanks: 4,191
It is quite ridiculous. I'd make a public source if I had 6 hands, but at the moment, I only have four (2 physical, 2 logical). *Dangs face against desk* I'm pretty worn out. I know there are sources out there that show things done properly (such as Chris's source and Roy's source), it's just that members don't know to go looking for them. Hopefully someone reads this thread and finds use in it, but maybe we should also be making more of an effort to give beginning members better advice.
Spirited is offline  
Old 05/26/2013, 07:38   #4
 
InfamousNoone's Avatar
 
elite*gold: 20
Join Date: Jan 2008
Posts: 2,012
Received Thanks: 2,885
Quote:
Originally Posted by Fаng View Post
It is quite ridiculous. I'd make a public source if I had 6 hands, but at the moment, I only have four (2 physical, 2 logical). *Dangs face against desk* I'm pretty worn out. I know there are sources out there that show things done properly (such as Chris's source and Roy's source), it's just that members don't know to go looking for them. Hopefully someone reads this thread and finds use in it, but maybe we should also be making more of an effort to give beginning members better advice.
Sorry, I'd like to correct this to, don't understand what they're looking at.
InfamousNoone is offline  
Old 05/26/2013, 09:26   #5
 
marcbacor6666's Avatar
 
elite*gold: 0
Join Date: Oct 2006
Posts: 557
Received Thanks: 76
nice post newbies will starting digging their public source from now on.
marcbacor6666 is offline  
Old 05/26/2013, 19:18   #6
 
Mr_PoP's Avatar
 
elite*gold: 0
Join Date: Apr 2008
Posts: 759
Received Thanks: 285
you should really care about exploits that occurs , because of race conditions etc , instead of this "silly" exploits rofl, just saying
Mr_PoP is offline  
Reply




All times are GMT +1. The time now is 16:38.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.