Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Eudemons Online > EO PServer Hosting > EO PServer Guides & Releases
You last visited: Today at 21:25

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[RELEASE] Server Security Flaws: What Every Admin Should Know

Discussion on [RELEASE] Server Security Flaws: What Every Admin Should Know within the EO PServer Guides & Releases forum part of the EO PServer Hosting category.

Reply
 
Old   #1
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
Exclamation [RELEASE] Server Security Flaws: What Every Admin Should Know

  1. [INFO] Weaknesses in the classic version: a warning to the community


    I decided to gather here some possible weaknesses related to the security of the classic version. I will soon bring suggestions for solutions, but it would be great if you also contributed ideas and alternatives. Together, we can build a fairer community, without malicious administrators or players exploiting loopholes to harm other servers.

    Note: I will not address basic issues here, such as the use of default passwords or open MySQL — this is the minimum expected of any responsible administrator.

    1. NPCServer Vulnerability – External Connection Exploit
    2. AccountServer/MsgServer Vulnerability – Excessive Packet Traffic Exploit
    3. Regular players can summon monsters
    4. Zoom Hack and skill range

    If you know of other exploits or have found ways to protect your server against these threats, please share them! The idea is to strengthen the community and ensure a safer experience for everyone.


  2. [INFO] Weaknesses in the 1655 version: a warning to the community
1. Possible System-Level Malware Risk
2. Speedhack Usage
3. LoginTools Detected as Virus

Still under construction
  1. If you have ever experienced any server security issues, please let us know so we can update this list and help you and other administrators.
  2. Also, if you have any additional suggestions or improvements for the solutions mentioned, feel free to share them.
  3. We truly need more contributors to help grow this community. Remember — we all benefit from working together. The Eudemons player base is already small, and server attacks not only hurt individual servers but can also discourage players from the entire game. This often leads them to abandon Eudemons altogether in favor of more secure alternatives.
zukoo is offline  
Thanks
6 Users
Old 05/07/2025, 15:43   #2
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
Please help me build this post!
zukoo is offline  
Old 05/07/2025, 19:21   #3
 
nomercyskin1's Avatar
 
elite*gold: 0
Join Date: Apr 2012
Posts: 155
Received Thanks: 122
Either classic or new engine , both are vulnerable to be exploited where all the database can be stollen, deleted or adjusted. Unless you have expertise to fix that. For example, once you completed upgrade your server and bug fixed, some one can easily stole that. Unless you open the server to the circle that you know. This is my cent tips.
nomercyskin1 is offline  
Old 05/07/2025, 20:42   #4
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
I've been an administrator of eudemons since 2009; as far as I know, I've never had a problem with that. It can probably happen due to lack of MySQL or PHP configuration. I already had my database leaked, but that was because I shared my database with a partner in 2009 and it robbed me.
zukoo is offline  
Old 05/10/2025, 21:56   #5
 
corey88's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 114
Received Thanks: 63
It’s also important to highlight a major security concern that affects nearly all EO servers: the use of outdated MySQL (4.x) and PHP (4.x–5.x) versions. These versions are no longer supported and are vulnerable to well-documented critical CVEs such as:

- CVE-2012-2122 – MySQL password authentication bypass
- Remote Code Execution via register_globals and file inclusion
- SQL Injection due to lack of prepared statements
- Session hijacking and privilege escalation vulnerabilities

If you’re running a site that interacts directly with your database (register pages for example), here’s a good practice to help mitigate those risks:

- Host your public-facing website using a modern PHP version (preferably 8.0+), and use it as a proxy to communicate securely with the legacy backend (PHP 5.x/MySQL 4.x).
- Restrict access to the legacy environment by IP whitelisting, so only your modern website can interact with it.

It’s not a full solution, but it’s a solid step toward reducing your attack surface.
corey88 is offline  
Thanks
6 Users
Old 06/05/2025, 17:51   #6
 
elite*gold: 0
Join Date: Oct 2024
Posts: 10
Received Thanks: 1
Good morning everyone.
First of all, we would like to clarify that, unfortunately, Chinese servers have several security flaws — including backdoors and open ports integrated into the executable itself. These vulnerabilities cannot be fixed permanently, and they also cause serious performance problems and other technical risks.

The problems with these files involve remote connections that the server itself allows.
Without going into the client's details, it is important to highlight that these files were leaked to the community by someone who, in addition to distributing them, inserted several malicious codes.
Several loopholes were left that allow the server to be hacked, including commands to stop, restart or even delete the VPS, in addition to full remote access.

Quote:
Originally Posted by zukoo View Post
I've been an administrator of eudemons since 2009; as far as I know, I've never had a problem with that. It can probably happen due to lack of MySQL or PHP configuration. I already had my database leaked, but that was because I shared my database with a partner in 2009 and it robbed me.
I strongly recommend that you review your website's structure and security as there are several serious flaws that need immediate attention.

Quote:
Originally Posted by nomercyskin1 View Post
Either classic or new engine , both are vulnerable to be exploited where all the database can be stollen, deleted or adjusted. Unless you have expertise to fix that. For example, once you completed upgrade your server and bug fixed, some one can easily stole that. Unless you open the server to the circle that you know. This is my cent tips.
but people do not accept this truth
revinmage2 is offline  
Old 06/06/2025, 04:46   #7
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
Was version 1655 leaked or just a revamped classic version?
zukoo is offline  
Old 06/06/2025, 19:03   #8
 
elite*gold: 0
Join Date: Oct 2024
Posts: 10
Received Thanks: 1
Quote:
Originally Posted by zukoo View Post
Was version 1655 leaked or just a revamped classic version?
There is no version 1655. That number was just something 178 put in his version of the font. The version that leaked is exactly the one you use today, 1655.

In fact, it was a mix-up he had with WebDesign, who leaked the source and added malware, backdoors and other things on purpose to harm 178. (I'm using the name he uses in the community).
revinmage2 is offline  
Old 06/06/2025, 20:57   #9
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
With all due respect, this statement is not true.

We have a clear track record: since 2018, version updates have been implemented continuously, using our dedicated archive, which includes a TXT with all corrections and improvements.

In addition, the final version that was released online is visibly incomplete. Many features that were previously perfectly operational — such as the Castle, the Family and the Hall of Fame — simply do not work in it. This leads us to believe that the version we are using is, in fact, different and edited.
zukoo is offline  
Old 06/06/2025, 21:14   #10
 
elite*gold: 0
Join Date: Oct 2024
Posts: 10
Received Thanks: 1
Quote:
Originally Posted by zukoo View Post
With all due respect, this statement is not true.

We have a clear track record: since 2018, version updates have been implemented continuously, using our dedicated archive, which includes a TXT with all corrections and improvements.

In addition, the final version that was released online is visibly incomplete. Many features that were previously perfectly operational — such as the Castle, the Family and the Hall of Fame — simply do not work in it. This leads us to believe that the version we are using is, in fact, different and edited.
I think you should do a little more research. This 1655 engine is still sold in China, with a monthly subscription and payment for the software, without backdoors or viruses embedded in the ones presented, but with some additional improvements. There is still an update changelog to this day, but only for the paid version, exclusively in China. However, the server continues to present several structural errors due to the update from version 1.0 to the current one, done without the proper technical treatments.I will not take this further, as it does not benefit me at all, since I do not use such programs.
revinmage2 is offline  
Old 06/07/2025, 05:52   #11
 
zukoo's Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 560
Received Thanks: 209
Quote:
Originally Posted by revinmage2 View Post
There is no version 1655. That number was just something 178 put in his version of the font. The version that leaked is exactly the one you use today, 1655.

In fact, it was a mix-up he had with WebDesign, who leaked the source and added malware, backdoors and other things on purpose to harm 178. (I'm using the name he uses in the community).
Reread your first paragraph and you will understand what you meant.
It was very confusing, even if you edited, he remained confused.

In your previous post, you said that version 1655 was leaked and that malicious items were inserted before the leak. I already mentioned this as a known weakness in some editions of this version.

That might have happened in isolated cases, but 1655 itself was not leaked. What was actually leaked was the classic version, which was later modified by 178studio and adapted into godlev-based versions back in 2017. Version 1655 was only finalized in 2021. I have access to Chinese servers, and it looks like development stopped there. Fortunately, the official version did not progress much.

I've seen only two reports in three years, and both involved file exchanges with third parties, suggesting contamination from external editors. The number of issues is very low considering how many servers used this version.

Also, as I’ve said before, there is no need to use LoginTools. I don’t use it — only the original client — so there is no risk to the client side.

So, to be clear: version 1655 was not leaked. It is an improved version of the classic. Yes, some variations of 1655 have security flaws, and I already pointed that out in the first post.

It seems like you're confusing an edited version with the official one, which nobody here even mentioned.
Honestly, your statements sound like someone who just heard about it without fully understanding the topic.
In the end, I still don’t see what your actual point is.
zukoo is offline  
Reply


Similar Threads Similar Threads
[Flaws & Improvement] of PServers | Let’s make PSro great again!
03/22/2021 - SRO Private Server - 46 Replies
Greetings, worst community ever! I’ve initiated this thread because I haven’t been a player for so long, which resulted in me viewing things from a perspective that’s different to your own. Think of this as a survey that serves the purpose of making drastic improvements to the field of Private Silkroad. Pour your brain out in the comments, and let’s see if we really do view things from different perspectives. Example of our different points of view: Some players hate silk scrolls,...
Brauche Hilfe:Your browser is out of date. It may have security flaws
05/03/2014 - Technical Support - 1 Replies
Your browser is out of date. It may have security flaws and may not display all features of this and other websites. Learn how to update your browser Ich bekomme diese Meldung, download I explorer neu auf einem Server von Webtropia, es ändert sich jedoch nichts. Ich brauche dringend Hilfe, kann momentan nicht arbeiten da bei einem Account login die Geheimantwort frage nicht erscheint. Kennt wer das problem ? was muss ich machen
Bot Flaws
10/05/2007 - Conquer Online 2 - 4 Replies
ok so this is my first post, and i didnt find anything on it, used the search function and all. if its been brought up my apologizes cause i dont like saying things if its not worth saying. I noticed while hunting in an area, there where a few bots going around, at first i didnt know they were bots, but when i got close with my guard they began to ignore the monsters and follow my guard like they were trying to attack it. In other words it appears that this particular bot sees reborn guards...



All times are GMT +1. The time now is 21:28.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.