Register for your free account! | Forgot your password?

You last visited: Today at 15:59

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



New SQL inject ?

Discussion on New SQL inject ? within the SRO Private Server forum part of the Silkroad Online category.

Reply
 
Old   #1
 
sonzenbi's Avatar
 
elite*gold: 0
Join Date: Feb 2017
Posts: 186
Received Thanks: 117
New SQL inject ?

Someone keeps teasing with my database (truncate talbe , create GM account , bla bla )
it was related to Procedures Memo_Add ?


sonzenbi is offline  
Thanks
1 User
Old 11/02/2017, 11:36   #2

 
R3D*'s Avatar
 
elite*gold: 1400
Join Date: May 2011
Posts: 1,200
Received Thanks: 740
I think he is using old chernobyl's sql injection, block your iis port & everything will be fine.
R3D* is offline  
Thanks
2 Users
Old 11/03/2017, 15:40   #3
 
KingDollar's Avatar
 
elite*gold: 857
Join Date: Dec 2013
Posts: 857
Received Thanks: 679
you could fix it using packet filter using send msg packet
and read ascii of msg and charname
because i'm not sure what of them are allow injection
then check if they contain ' || /
ignore or block
KingDollar is offline  
Thanks
1 User
Reply

Tags
sql inject


Similar Threads Similar Threads
Open Source Injector - Auto/Manual Inject, Verify Inject, Saves Settings
01/28/2013 - Combat Arms Hacks, Bots, Cheats & Exploits - 5 Replies
Open Source Injector - Auto/Manual Inject, Verify Inject, Saves Settings Features: -Auto Inject -Customizable Delay -Manual Inject -Verify Inject
[RELEASE] Simple login Script (with anti SQL inject and reCAPATCHA)
07/01/2010 - Dekaron Private Server - 6 Replies
login.php (you can change the name) DO NOT USE THIS SCRIPT! if you got a error, please reply with a error code have fun ! @Mod this is not a double topic, its 2 different scripts so ... to prevent any confusion :) @Everyone THIS IS MADE FOR DEKARON SO IAM POSTING IN THE RIGHT SECTION :bandit:
[Tutorial]How to SQL inject into a server with OSDS
02/11/2010 - Dekaron PServer Hacks, Bots, Cheats & Exploits - 22 Replies
This is a nice trick how to bypass janvier's anti-sql-injection, that he put into OSDS in just a few steps. First, get Opera browser. Find a server that has an OSDS control panel and go to the panel login page. Now, janvier's anti-sql-injection comes in. You can't write more then 12 letters, so you can't inject anything decent... http://img686.imageshack.us/img686/4285/96591071. jpg So here's what we do. Press Ctrl+U to open up the source code and press Ctrl+F to open up search in the...



All times are GMT +2. The time now is 15:59.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.