Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Shaiya > Shaiya Private Server > Shaiya PServer Guides & Releases
You last visited: Today at 17:39

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Release] Fix SQL Injection in GM commands

Discussion on [Release] Fix SQL Injection in GM commands within the Shaiya PServer Guides & Releases forum part of the Shaiya Private Server category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Dec 2012
Posts: 142
Received Thanks: 686
[Release] Fix SQL Injection in GM commands

This exploit has become better known now, so I decided to release my fix. The fix works for all commands (warning, notice, gmnotice...) and doesn't disable the action log. Works only for ep5.4 ps_game.
Attached Files
File Type: rar fix sql injection gm commands.rar (583 Bytes, 474 views)
Eric-Dutra16 is offline  
Thanks
19 Users
Old 05/27/2020, 17:20   #2
 
elite*gold: 0
Join Date: Feb 2020
Posts: 16
Received Thanks: 8
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.
Attached Files
File Type: zip prevent sql injection Cups and Bowie.zip (868 Bytes, 314 views)
[GM]Crypton is offline  
Thanks
8 Users
Old 06/16/2020, 19:31   #3
 
elite*gold: 0
Join Date: Aug 2017
Posts: 35
Received Thanks: 10
Quote:
Originally Posted by Eric-Dutra16 View Post
This exploit has become better known now, so I decided to release my fix. The fix works for all commands (warning, notice, gmnotice...) and doesn't disable the action log. Works only for ep5.4 ps_game.
Quote:
Originally Posted by [GM]Crypton View Post
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.

Does anyone know which version is more useful, the Erick-Dutra version is short and short the cups version, and a larger script with the possible correction for the commands, someone tested and can tell which one is more useful or more complete?

I appreciate if anyone knows any useful information.
IlusionXtreme is offline  
Old 06/17/2020, 08:32   #4
 
elite*gold: 0
Join Date: Dec 2012
Posts: 142
Received Thanks: 686
Quote:
Originally Posted by IlusionXtreme View Post
Does anyone know which version is more useful, the Erick-Dutra version is short and short the cups version, and a larger script with the possible correction for the commands, someone tested and can tell which one is more useful or more complete?

I appreciate if anyone knows any useful information.
Both fixes work. My script replaces the quote character with space in the function that creates the action log, the cups and bowie scripts disables calls to the function.
Eric-Dutra16 is offline  
Thanks
4 Users
Old 06/28/2020, 02:44   #5
 
elite*gold: 0
Join Date: Jun 2020
Posts: 3
Received Thanks: 0
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
Diego Jairo is offline  
Old 06/28/2020, 16:27   #6
 
elite*gold: 0
Join Date: Aug 2017
Posts: 35
Received Thanks: 10
Quote:
Originally Posted by Diego Jairo View Post
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
This is a CT script, the code is open, you can check each of the functions and do tests, or you are too dumb to do this.
a ct correction is different from a modified ps_login where it has thousands of codes, dumb people just like you that spoils the community, THAT is a CT file your code is visible, for you check its effectiveness.
IlusionXtreme is offline  
Thanks
1 User
Old 06/28/2020, 21:43   #7
 
elite*gold: 0
Join Date: Dec 2012
Posts: 142
Received Thanks: 686
Quote:
Originally Posted by Diego Jairo View Post
Watch out for releases from people who say they prevent SQL injections. A few years ago an adm from a Brazilian server published a supposed fix for the problem and in fact this supposed fix was an even more serious flaw caused by this ADM. Be very careful!
Ok, this is my last release on this forum.
Eric-Dutra16 is offline  
Thanks
1 User
Old 06/29/2020, 01:25   #8
 
elite*gold: 0
Join Date: Jun 2020
Posts: 3
Received Thanks: 0
Quote:
Originally Posted by IlusionXtreme View Post
This is a CT script, the code is open, you can check each of the functions and do tests, or you are too dumb to do this.
a ct correction is different from a modified ps_login where it has thousands of codes, dumb people just like you that spoils the community, THAT is a CT file your code is visible, for you check its effectiveness.
Very good for you friend, I did not mention this release, I just took advantage of the subject to talk about an event that hurt many people, if you don't know how to interpret text, I have nothing to do with it, it's your problem.
Diego Jairo is offline  
Old 06/29/2020, 03:25   #9
 
elite*gold: 0
Join Date: Dec 2012
Posts: 142
Received Thanks: 686
Quote:
Originally Posted by Diego Jairo View Post
Very good for you friend, I did not mention this release, I just took advantage of the subject to talk about an event that hurt many people, if you don't know how to interpret text, I have nothing to do with it, it's your problem.
That's a lie, I'm probably the only Brazilian who posted releases on this forum and they are all open source. I checked your profile, your only release is useless, it was not made by you and it is not open source.
Eric-Dutra16 is offline  
Thanks
6 Users
Old 06/29/2020, 16:19   #10
 
elite*gold: 0
Join Date: Aug 2017
Posts: 35
Received Thanks: 10
Diego Jairo and the well-known Vonstrucker, he uses a fake profile to publish things that are not his, he propagates files and stolen things, things he will never be able to do, never created anything and never did anything for the community.
I am waiting for you to publish your Shaiya Ernasis server in Brazil, which will have a limited duration
IlusionXtreme is offline  
Thanks
2 Users
Old 04/07/2021, 14:06   #11
 
elite*gold: 0
Join Date: Oct 2011
Posts: 220
Received Thanks: 62
is there any for ep4 ?
superklamus is offline  
Old 04/22/2021, 13:43   #12
 
elite*gold: 0
Join Date: Apr 2021
Posts: 8
Received Thanks: 0
Quote:
Originally Posted by IlusionXtreme View Post
Diego Jairo and the well-known Vonstrucker, he uses a fake profile to publish things that are not his, he propagates files and stolen things, things he will never be able to do, never created anything and never did anything for the community.
I am waiting for you to publish your Shaiya Ernasis server in Brazil, which will have a limited duration
that VonStrucker is a kid, he was selling me things that he stole
[adm]Bowser is offline  
Old 09/16/2021, 20:01   #13
 
elite*gold: 0
Join Date: Jun 2014
Posts: 9
Received Thanks: 0
Quote:
Originally Posted by [GM]Crypton View Post
Great release, a version has already been published, I don't know about the effectiveness of CT with Cups and Bowie scripts, and a larger version with several injections, I'll leave it here, if you want to test an alternative solution or even analyze for failures, why too many files, not reliable.


Credits Cups and Bowie, has been released for free, distribution and free, be very careful.
It not working on ep4.5
likevil is offline  
Old 09/16/2021, 20:04   #14
 
[GM] Purple's Avatar
 
elite*gold: 0
Join Date: Sep 2021
Posts: 23
Received Thanks: 2
Thanks, good work.
[GM] Purple is offline  
Old 09/18/2021, 05:27   #15
 
elite*gold: 0
Join Date: Dec 2019
Posts: 12
Received Thanks: 3
Quote:
Originally Posted by likevil View Post
It not working on ep4.5
Do people even read?
It clearly says it only works for 5.4 episode ps_game...
KingKush88 is offline  
Reply


Similar Threads Similar Threads
[Release] Simple FIX FOR "SQL Injection (ABOUT GUILD)"
02/06/2017 - SRO PServer Guides & Releases - 18 Replies
http://i.epvpimg.com/Ybguf.png First, you go to "SRO_VT_SHARD" > Tables > _SiegeFortress > Right Click > Design > GO DOWN TO > IntroductionModificationPermission > Column Properties > Default Value Or Binding ((1)) > Change to ((0)) " just like the screen shot http://image.prntscr.com/image/2e358d0b2e1d4a45a2 509d364efe8fbc.png
[FIX][C++] SQL Injection in Messenger and Guild
09/04/2016 - Metin2 PServer Guides & Strategies - 82 Replies
Hello, today there were attacks to several servers all using the same exploits. I will not further explain the method used to attack these servers. To fix it go to messenger_manager.cpp:
[04.09.13] GigaByte v2.6 [FIX, FIX, FIX, FIX AND FIX]
09/11/2013 - WarRock Hacks, Bots, Cheats & Exploits - 79 Replies
http://www.elitepvpers.com/forum/warrock-hacks-bot s-cheats-exploits/2843300-11-09-gigabyte-public-v2 -7-a.html



All times are GMT +2. The time now is 17:49.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.