Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Rappelz > Rappelz Private Server
You last visited: Today at 17:08

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[VERY IMPORTANT] — SERVER SECURITY RISK!!!

Discussion on [VERY IMPORTANT] — SERVER SECURITY RISK!!! within the Rappelz Private Server forum part of the Rappelz category.

Reply
 
Old 04/02/2026, 15:01   #16
 
yosiemelo's Avatar
 
elite*gold: 0
Join Date: Apr 2017
Posts: 228
Received Thanks: 158
Quote:
Originally Posted by Masumichan View Post
I dont think he can, he just simply relayed information he learned from others.
i can, working on it right now.

this fix will be FREE, and will work on ANY exe server. no metter if custom source or not.
yosiemelo is offline  
Old 04/02/2026, 16:08   #17
 
Masumichan's Avatar
 
elite*gold: 0
Join Date: Jul 2020
Posts: 212
Received Thanks: 92
Quote:
Originally Posted by i33ELYTE View Post
NPC commands can't be exploited as they are not tagged as dlg_special trigger or fixed dialog trigger
So only feather\secret portal\channel change\cube dungeon portals etc are affected
Provided fix is sluggish, all you need to do is replace 3 strstr calls inside onDialog function to strcmp and flip the comparison

If any server owner is running compiled binary and is willing to pay me some cash - slide into my dm's, I'll patch it in an instant, since I've done it for 2 servers already



Also this is a lie
If only I had like some kind of DM log, talking about this with friends and providing a Fix for sh4d0x. ( mind you it's like half a year old? )

Quote:
Originally Posted by yosiemelo View Post
i can, working on it right now.

this fix will be FREE, and will work on ANY exe server. no metter if custom source or not.
That would be awesome, when you did throw it my way I will check it out.
Masumichan is offline  
Old 04/02/2026, 16:43   #18
 
yosiemelo's Avatar
 
elite*gold: 0
Join Date: Apr 2017
Posts: 228
Received Thanks: 158
Quote:
Originally Posted by i33ELYTE View Post
NPC commands can't be exploited as they are not tagged as dlg_special trigger or fixed dialog trigger
So only feather\secret portal\channel change\cube dungeon portals etc are affected
Provided fix is sluggish, all you need to do is replace 3 strstr calls inside onDialog function to strcmp and flip the comparison

If any server owner is running compiled binary and is willing to pay me some cash - slide into my dm's, I'll patch it in an instant, since I've done it for 2 servers already



Also this is a lie

I know — I wrote it that way on purpose, both to make the situation easier to understand for the reader and at the same time avoid giving the exact 1:1 method of how to abuse it.
I hope that part is understandable.

What is not understandable is making money from things like this.

Yes, the fix took time.
But monetizing something like that in this community is simply unfair, especially when at the same time you were allowing servers to be literally destroyed in the meantime.

And what makes it even worse is that in the end you were not really destroying just some random low-quality servers — you were destroying the time, effort and fun of the small group of players who still play this game, no matter what server they are on.

So what is worse then?

A cash-grab server, where the player is at least aware of what he is doing with his money and time?

Or a group of people destroying servers regardless of whether they are cash-grab or not, making it harder for everyone else to simply enjoy the game?

~YoSiem


Quote:
Originally Posted by Masumichan View Post
If only I had like some kind of DM log, talking about this with friends and providing a Fix for sh4d0x. ( mind you it's like half a year old? )

The fact that you knew about this for half a year only shows your real face even more.

You were so worried about servers running compiled .exe files and kept acting like I would not be able to fix it myself?
Well... here you go.

I made a patcher for every Game Server in exe version.
It can patch the issue directly, and there is also a way to use it through DLL injection, so you do not even need to modify the original exe itself.

And on top of that, you fixed something for your friends that literally puts all servers at risk, explained them how it works, then let them walk around acting like a complete clown and abuse it on other servers.
That is disgusting.

If you actually cared even a little bit about the servers you were pretending to be so worried about at the beginning, you would have contacted people and offered them a fix.
Or at the very least, you would have warned server owners that such an exploit exists.

But instead, you stayed silent and allowed your little lapdog — the same guy running around licking your asses — to abuse it on other servers.

I repeat: this is disgusting behavior.

Before, I honestly considered you good friends.
Now you look no less pathetic than the same people we used to laugh at together.

Anyway, here is the fix.
It patches the most serious security hole.

And yes, I am fully aware there are still many other vulnerabilities in the server.
But this one was by far the most dangerous of them all, so this is the one I fixed first.








Link cuz OPEN SOURCE:




~YoSiem
yosiemelo is offline  
Thanks
6 Users
Old 04/02/2026, 16:54   #19
 
Masumichan's Avatar
 
elite*gold: 0
Join Date: Jul 2020
Posts: 212
Received Thanks: 92
Quote:
Originally Posted by yosiemelo View Post

I know — I wrote it that way on purpose, both to make the situation easier to understand for the reader and at the same time avoid giving the exact 1:1 method of how to abuse it.
I hope that part is understandable.

What is not understandable is making money from things like this.

Yes, the fix took time.
But monetizing something like that in this community is simply unfair, especially when at the same time you were allowing servers to be literally destroyed in the meantime.

And what makes it even worse is that in the end you were not really destroying just some random low-quality servers — you were destroying the time, effort and fun of the small group of players who still play this game, no matter what server they are on.

So what is worse then?

A cash-grab server, where the player is at least aware of what he is doing with his money and time?

Or a group of people destroying servers regardless of whether they are cash-grab or not, making it harder for everyone else to simply enjoy the game?

~YoSiem





The fact that you knew about this for half a year only shows your real face even more.

You were so worried about servers running compiled .exe files and kept acting like I would not be able to fix it myself?
Well... here you go.

I made a patcher for every Game Server in exe version.
It can patch the issue directly, and there is also a way to use it through DLL injection, so you do not even need to modify the original exe itself.

And on top of that, you fixed something for Shadox that literally puts all servers at risk, explained to him how it works, then let him walk around acting like a complete clown and abuse it on other servers.
That is disgusting.

If you actually cared even a little bit about the servers you were pretending to be so worried about at the beginning, you would have contacted people and offered them a fix.
Or at the very least, you would have warned server owners that such an exploit exists.

But instead, you stayed silent and allowed your little lapdog — the same guy running around licking your asses — to abuse it on other servers.

I repeat: this is disgusting behavior.

Before, I honestly considered you good friends.
Now you look no less pathetic than the same people we used to laugh at together.

Anyway, here is the fix.
It patches the most serious security hole.

And yes, I am fully aware there are still many other vulnerabilities in the server.
But this one was by far the most dangerous of them all, so this is the one I fixed first.








Link cuz OPEN SOURCE:




~YoSiem
For your info I can fix this, However just like always I don't want everyone to rely on what I do. I have a lot more and alot more things that I have not shared, because exactly these reason. In Rappelz anything that's important will be abused we've seen this over and over again, This is a lesson I've learned from AgeOfRappelz and also for your information Sh4d0x does NOT know how to abuse this, and if he does which I doubt he has figured it out himself, I just simply told him to copy and paste something somewhere. And also I really doubt that you considered me a friend based on DMS I've seen from people, Let's not get into that publicly though. And the reason I assumed you could not ( which I think is reasonable ) when I have spoken about the protocol before you simply didn't understand. What I'm saying here not necessarily a judgement on you as a character but on what you've shown so far.

How I do think you should've done this, IF you wanted to expose this which is fine you should start by first having the solutions in every use case. Because right now if someone has half a brain cell they can use this, because like I said the "protection" Rappelz has even with game guard is a fucking joke, And I do not think it is reasonable for you to expect me to solve this issue for every single person, because each time I fix something for someone 100 people come with different questions. This is my last piece on this topic and I think I'm being quite reasonable here.
Masumichan is offline  
Thanks
1 User
Old 04/02/2026, 16:59   #20
 
i33ELYTE's Avatar
 
elite*gold: 141
Join Date: Nov 2016
Posts: 33
Received Thanks: 5
Quote:
Originally Posted by Masumichan View Post
If only I had like some kind of DM log, talking about this with friends and providing a Fix for sh4d0x. ( mind you it's like half a year old? )
You do? That would be cool to look at to be honest
i33ELYTE is offline  
Old 04/02/2026, 17:01   #21
 
yosiemelo's Avatar
 
elite*gold: 0
Join Date: Apr 2017
Posts: 228
Received Thanks: 158
Quote:
Originally Posted by Masumichan View Post
For your info I can fix this, However just like always I don't want everyone to rely on what I do. I have a lot more and alot more things that I have not shared, because exactly these reason. In Rappelz anything that's important will be abused we've seen this over and over again, This is a lesson I've learned from AgeOfRappelz and also for your information Sh4d0x does NOT know how to abuse this, and if he does which I doubt he has figured it out himself, I just simply told him to copy and paste something somewhere. And also I really doubt that you considered me a friend based on DMS I've seen from people, Let's not get into that publicly though. And the reason I assumed you could not ( which I think is reasonable ) when I have spoken about the protocol before you simply didn't understand. What I'm saying here not necessarily a judgement on you as a character but on what you've shown so far.

How I do think you should've done this, IF you wanted to expose this which is fine you should start by first having the solutions in every use case. Because right now if someone has half a brain cell they can use this, because like I said the "protection" Rappelz has even with game guard is a fucking joke, And I do not think it is reasonable for you to expect me to solve this issue for every single person, because each time I fix something for someone 100 people come with different questions. This is my last piece on this topic and I think I'm being quite reasonable here.

"Hey mate how are you ... bla bla bla ... a Polish guy wanna sell to us cheat where he can spawn everything on any server, i didnt trusted him but he showed me +200 cards on Dewian and gambit for ONLY 800$ we are considering to buy it... bla bla bla"


we all know mate
yosiemelo is offline  
Old 04/02/2026, 17:05   #22
 
Masumichan's Avatar
 
elite*gold: 0
Join Date: Jul 2020
Posts: 212
Received Thanks: 92
Quote:
Originally Posted by yosiemelo View Post
"Hey mate how are you ... bla bla bla ... a Polish guy wanna sell to us cheat where he can spawn everything on any server, i didnt trusted him but he showed me +200 cards on Dewian and gambit for ONLY 800$ we are considering to buy it... bla bla bla"


we all know mate
For your info, I am on disability I cannot receive big payments such as that. Anyone who kind of knows me can confirm this, so you're pretty much talking from your rear.
Masumichan is offline  
Old 04/02/2026, 17:08   #23
 
yosiemelo's Avatar
 
elite*gold: 0
Join Date: Apr 2017
Posts: 228
Received Thanks: 158
Quote:
Originally Posted by Masumichan View Post
For your info, I am on disability I cannot receive big payments such as that. Anyone who kind of knows me can confirm this, so you're pretty much talking from your rear.
im not talking about you, well didnt know you are polish xd
yosiemelo is offline  
Old 04/02/2026, 17:10   #24
 
Masumichan's Avatar
 
elite*gold: 0
Join Date: Jul 2020
Posts: 212
Received Thanks: 92
Quote:
Originally Posted by yosiemelo View Post
im not talking about you, well didnt know you are polish xd
Your dms say otherwise.
Masumichan is offline  
Old 04/02/2026, 17:26   #25
 
elite*gold: 0
Join Date: Mar 2025
Posts: 16
Received Thanks: 19
Well considering you shared patcher, I'm taking words back about not sharing it publicly. But you also need to make it available for end user, if you share stuff for them. A common John Doe wouldn't be able to build your tool. He don't even know what a "build" is. He is struggling with server setup, that's why repacks exists. I think you need to add binary of your tool in releases. Think about end user and make it simpler. And you probably would like to add GNU license file
RappelzInferno is offline  
Old 04/02/2026, 17:41   #26
 
i33ELYTE's Avatar
 
elite*gold: 141
Join Date: Nov 2016
Posts: 33
Received Thanks: 5
Quote:
Originally Posted by Masumichan View Post
Your dms say otherwise.
So what about those half year dms bro?
i33ELYTE is offline  
Old 04/02/2026, 17:42   #27
 
Masumichan's Avatar
 
elite*gold: 0
Join Date: Jul 2020
Posts: 212
Received Thanks: 92
Quote:
Originally Posted by i33ELYTE View Post
So what about those half year dms bro?
In the last conversation I've had with you publicly, I offered to talk about it in private; You didn't reach out, So I'm not going to take anything you say serious, as obviously you do NOT have good intentions.
Masumichan is offline  
Old 04/02/2026, 18:12   #28
 
i33ELYTE's Avatar
 
elite*gold: 141
Join Date: Nov 2016
Posts: 33
Received Thanks: 5
Quote:
Originally Posted by Masumichan View Post
In the last conversation I've had with you publicly, I offered to talk about it in private; You didn't reach out, So I'm not going to take anything you say serious, as obviously you do NOT have good intentions.
I just want to see them, you can block me afterwards or whatever
i33ELYTE ds
i33ELYTE is offline  
Old 04/02/2026, 19:32   #29

 
.KaiZy's Avatar
 
elite*gold: 194
Join Date: Sep 2018
Posts: 578
Received Thanks: 199
Shout out @ for pulling through with the fix, amen brother. You are what we need on forums like these. epvp has become reseller infested misinformation minefield
.KaiZy is offline  
Thanks
1 User
Old 04/02/2026, 21:33   #30
 
i33ELYTE's Avatar
 
elite*gold: 141
Join Date: Nov 2016
Posts: 33
Received Thanks: 5
Yeah shout out to LLM and some user posted about strcmp fix
i33ELYTE is offline  
Reply


Similar Threads Similar Threads
[VSRO] Very Important Security !!
08/12/2012 - SRO Private Server - 4 Replies
Hello all. I have 1 private server, but, 1day im go to sleep and later in the morning i see my pc, my server have error, my data base (dbo.TB_User) is CLEAN, and i say OMG, WHY ??? My qstion is, how i can protect my data base? Thanks !!!
What the...MSSQL server fuc**d up?
05/30/2012 - SRO Private Server - 2 Replies
Hello, so i was working on vote reward system, adding functions etc. When suddenly with no reason i get this error Warning: mssql_connect() : Unable to connect to server: The name,password are good. I thought i recently delted or edited something, so i tried to open my other mssql scrip, and i get the same fcking error. I cant understand why, becouse in few seconds worked perfect. Iam using AppServ. Iam really bad ad the sql server managment studio and other mssql programs.
IMPORTANT VERY IMPORTANT!!!
08/22/2011 - S4 League - 2 Replies
you guys really need to make or update cytriik or id changer hacks i dont like working with hacks like inf. sp+god mode+inf ammo(etc.) i only like cash shop items hack such as those two (cytriik or id changer) if you guys can do it that will be great very very great :(:(:(



All times are GMT +2. The time now is 17:08.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.