Register for your free account! | Forgot your password?

You last visited: Today at 14:25

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



SQL injection???????

Discussion on SQL injection??????? within the SRO Coding Corner forum part of the Silkroad Online category.

Reply
 
Old   #1

 
Haxor's Avatar
 
elite*gold: 0
Join Date: Feb 2008
Posts: 3,777
Received Thanks: 1,455
SQL injection???????

Hello guys
I heared there a way in sql injection
i hear they do it in isro in 2008 and they get like 2000 accounts and share here
and then after some time they fixed it
And i hear it happend in Pservers
I asked my friends and i saw really video of a guy getting punsh of 120 accounts in swsro2
!!
Is that possible
And if any 1 can tech me how
Haxor is offline  
Old 04/08/2011, 17:46   #2
 
elite*gold: 0
Join Date: Jul 2009
Posts: 51
Received Thanks: 4
teach sql injection its hard but you can do it
vhrut is offline  
Old 04/08/2011, 18:44   #3
 
Shane¸'s Avatar
 
elite*gold: 100
Join Date: May 2010
Posts: 1,948
Received Thanks: 1,635
it's hax/crax related and not sro, however epvp doesn't really support you in those. google.com > sql injection tutorials but you can't do any kind of sql injections if the sql server isn't vulnerable
Shane¸ is offline  
Old 04/08/2011, 19:26   #4
 
elite*gold: 0
Join Date: Jul 2007
Posts: 71
Received Thanks: 8
you can't do any SQL injection in SRO, because it is an Client application... You do it in ...

Well just let me explain something : I was there as that happened... We told it to rev6, and they warned joymax. Joymax didn't toke it serious. The problem was : If you write as password a combinations of "?*_!~><^" special chars, which is not defined in the code table, you got an SQL failure... Then you could use that to make an easy SQL injection to

You have written : Select * From * : it gave you all DB
Than you have written

Select "Charname" , "ID","ServerName","PW"
From "Tablename of char, tablename of accounts, table name of servers
Where Tablename of char.AccountID = Tablename of accounts.AccountID
AND TablenameofServers.ServerID = Table Name of Chars.ServerID

then you get ID PW Server of a char in only 10 seconds...

rev6 automized it, putted it in his server and many people got hacked. Many players flamed and Joymaxa Fixed it before Legend 2 came out...
belgther is offline  
Old 04/08/2011, 19:32   #5
 
elite*gold: 0
Join Date: Sep 2009
Posts: 520
Received Thanks: 435
Did they had access only to account db ?
CraYu is offline  
Old 04/08/2011, 20:05   #6
 
elite*gold: 0
Join Date: Jul 2007
Posts: 71
Received Thanks: 8
Well Rev6 didn't wanted to hack all silkroad. Klevre did it once, to warn them... Joymax didn't toke him serious, so he hacked ....

They had access to everything in DB what had an interface on homepage... Account DB was one of them...
belgther is offline  
Old 04/08/2011, 20:27   #7

 
Haxor's Avatar
 
elite*gold: 0
Join Date: Feb 2008
Posts: 3,777
Received Thanks: 1,455
Quote:
Originally Posted by CraYu View Post
Did they had access only to account db ?
My friend has also stole the QQ and email for every1
So he was have full access



Quote:
Originally Posted by belgther View Post
Well Rev6 didn't wanted to hack all silkroad. Klevre did it once, to warn them... Joymax didn't toke him serious, so he hacked ....


They had access to everything in DB what had an interface on homepage... Account DB was one of them...

And that what i wanna want
Haxor is offline  
Old 04/08/2011, 21:44   #8
 
Keyeight's Avatar
 
elite*gold: 844
Join Date: Oct 2010
Posts: 839
Received Thanks: 192
will to make somthing like that you must learn SQL at frist ^^
Keyeight is offline  
Old 04/09/2011, 09:53   #9
 
elite*gold: 20
Join Date: Jan 2009
Posts: 3,560
Received Thanks: 2,814
Quote:
Originally Posted by saif1999 View Post
My friend has also stole the QQ and email for every1
So he was have full access





And that what i wanna want
Uhm isro doesnt use QQ?
Dropdead* is offline  
Old 04/09/2011, 11:23   #10
 
lesderid's Avatar
 
elite*gold: 0
Join Date: Dec 2007
Posts: 2,400
Received Thanks: 1,517
Quote:
Originally Posted by Dropdead* View Post
Uhm isro doesnt use QQ?
He never said he was talking about iSRO.
lesderid is offline  
Reply


Similar Threads Similar Threads
[C#]Dll Injection
08/05/2010 - .NET Languages - 11 Replies
Hallo Leute, ich möchte einen Dll Injector in C# schreiben. Eigentlich ist alles andere fertig bis auf das wichtigste: den Teil des Programms der die Dll injected. Wie funktioniert eine Injection in C#? Habe in google gesucht aber nichts gefunden. Mfg BlackWu
SQL injection Help
06/08/2010 - Kal Online - 9 Replies
hi every one im just wanna request i need some one give me link or so to how to do SQL injection On Private Server and Examples on any server because i learned alot but on other sites when i start with kalonline sites XD i got fucked up and i can't do any thing so i hope some one help me to do
SQL injection.
02/12/2008 - Zero - 0 Replies
Hi all, This is a curious topic because i have found numerous occasions where this has happened on the chinese version of the game. Also i was wondering if anyone knows of any occasions where it has been done on the English servers? I've been researching into this and apparently it requires tracing the packets back to the DB server then using a program (once you have the address) to inject your own SQL code into the database indefinitely editing your character to what ever your choosing...
help in sql injection
11/10/2007 - Kal Online - 24 Replies
hello m8's do any body in here know some things in sql injection he could share with us search gimme alot of shit .. waiting for answer thnx



All times are GMT +1. The time now is 14:25.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.