It's a good answer that you give, i will answer with what i know.
You figure out a good security point, by this way, (changing port), you will avoid standar attack on this point.
But injection are not here.
I personnaly think it's only in the databases.
Yes, we can avoid this by reduction of the amount of char that we can enter(and send) by the way of the login (that interact with ps_login)
But, if your trigger in the databases are not secure, a man you will you packet injector to bypass ps_login char (i dont know if it's possible), will send an injection.
Here is a simple injection :
' Drop database ***
Where *** is the name of the database.
The ' will trunc the previous request, like select ... from ... where
And will execute "Drop database ..." with the admin privilege cause it's executed on the server side.
Maybe, the first point to do is to locate the trigger that check de login (to permit the connexion), and had a huge filter on this , rejecting word and char like : ',",%, || .. drop,select,union
I'm not sure, but when i develop databases, i do this stuff to avoid SQL injection .
I don't know if someone agree with me, but i think it's a point the think about.
no use changing doors, or encrypt the game.exe. is very easy to find out the ip and port on a server, simply log into the game and give a simple command in cmd.
yes command netstat. anyone can do it, no matter if the game.exe is encrypted or not. need to find the flaws in ps_login, ps_game and ps_dbagent and correct. is the only way. and to me that's difficult. I have so much knowledge. I need your help
ps_login hack how to 05/02/2020 - Shaiya PServer Guides & Releases - 7 Replies I'll show you how it was done
but first the fixs for it:
http://www.elitepvpers.com/forum/shaiya-pserver-g uides-releases/3525712-release-fixed-ps_login.html
http://www.elitepvpers.com/forum/shaiya-pserver-g uides-releases/3525341-release-ps_login-anti-injec tion.html
get a copy of working packet injector and attach to game.exe
before login send this packet
[RELEASE] ps_login anti-injection 04/27/2015 - Shaiya PServer Guides & Releases - 28 Replies There you go, it won't accepte this injections from those bad people..
Yes, I payd for get it, I release it for free because Im a man who will never sell any files.
Virus Total Scan
[HELP] ps_login Injection Again, 01/13/2015 - Shaiya PServer Development - 1 Replies Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...
[HELP] ps_login Injection Again 01/12/2015 - Shaiya PServer Development - 0 Replies Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...
[HELP] ps_login Injection Again 01/12/2015 - Shaiya PServer Development - 1 Replies Hello to one month ago many database were invaded. and so 4 people launched ps_login fix. Nubness, JujiPoli, Juuf and szobonya3. But three days began attacks again, I used all ps_login, yet could edit my database. Before they deleted user_master. Are now editing my dbo.Chars. I ask all the best Shaiya developers, the elitepvpers, to investigate this and can help me and several more who are suffering because of that, and losing their players won honestly. And for those who do not know, who is...