Serveur hacked with Swift emu r5

Results 1 to 11 of 11
  1. #1
    Newbie Mal3ck is offline
    MemberRank
    Dec 2012 Join Date
    8Posts

    Serveur hacked with Swift emu r5

    Today I opened a French server, I am under swift emu r5 then coded CMS 0, when I have opened us directly hacked, hackers have us delete the users table! I do not think this is a flaw in the CMS so you can tell me if there is a flaw in the emulator? it's urgent thank you in advance

    Sorry for my bad english im french


  2. #2
    Newbie Quentin Thomine is offline
    MemberRank
    Jan 2013 Join Date
    14Posts

    Re: Serveur hacked with Swift emu r5

    hello I'm french I had the same hack for my case it was a good break on habbophp, not the emu pirateurs also simply remove the user table as you.

  3. #3
    Check http://arcturus.pw The General is offline
    DeveloperRank
    Aug 2011 Join Date
    7,613Posts

    Re: Serveur hacked with Swift emu r5

    Check your MySQL error logs to see if they made a mistake. If they did then you're able to easily find out the exploit.

  4. #4
    Newbie PsyBen is offline
    MemberRank
    Aug 2013 Join Date
    3Posts

    Re: Serveur hacked with Swift emu r5

    Quote Originally Posted by HillBilly View Post
    Check your MySQL error logs to see if they made a mistake. If they did then you're able to easily find out the exploit.
    Hi, I'm the owner of the server whose Mal3ck speak. I can not check my mysql logs because I have not had time to enable the log function.


    In fact, the users table was cleared, but the rest was not touched. Surely injection via the emulator. Is that possible?

  5. #5
    Sorcerer Supreme AKllX is offline
    Member +Rank
    Aug 2007 Join Date
    @ akllxprojectLocation
    366Posts

    Re: Serveur hacked with Swift emu r5

    I wouldn't say surely if you are using phpmyadmin or some exploitable CMS such HabboPHP or one of these RevCMS edits. Anyway all mysql injection possibilities were patched in the open thread so all you need to do is read it and patch your code

  6. #6
    "(still lacks brains)" NoBrain is offline
    Grand MasterRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: Serveur hacked with Swift emu r5

    It probably wasn't the emulators fault and more likely your own for not reviewing all code before sending the website live. Kinda foolish of you :)

  7. #7
    ส็็็็็็็ Bloodraven is offline
    Grand MasterRank
    Sep 2009 Join Date
    AntarcticaLocation
    2,414Posts

    Re: Serveur hacked with Swift emu r5

    I found no exploits in Swift that haven't already been patched in the thread, and I work on it daily.

  8. #8
    Newbie PsyBen is offline
    MemberRank
    Aug 2013 Join Date
    3Posts

    Re: Serveur hacked with Swift emu r5

    We encode our php by ourselves we can use PDO so no SQL injection. However I find it strange that only the user table was empty and not delete the hacker might well have deleted the database to complete what he did not.

    Sorry for my bad english I'm french..

    According to a member it would be possible to register with an account that would grader administrator directly. It is also possible to disconnect members in an apartment with a fail. it is possible that member told me?

  9. #9
    "(still lacks brains)" NoBrain is offline
    Grand MasterRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: Serveur hacked with Swift emu r5

    Quote Originally Posted by PsyBen View Post
    We encode our php by ourselves we can use PDO so no SQL injection. However I find it strange that only the user table was empty and not delete the hacker might well have deleted the database to complete what he did not.

    Sorry for my bad english I'm french..

    According to a member it would be possible to register with an account that would grader administrator directly. It is also possible to disconnect members in an apartment with a fail. it is possible that member told me?
    Maybe you fucked up a bit with the PHP? Maybe you used a too weak password for MySQL

  10. #10
    Newbie PsyBen is offline
    MemberRank
    Aug 2013 Join Date
    3Posts

    Re: Serveur hacked with Swift emu r5

    I found the problem, it was a SQL injection via the marketplace_offer.
    But however I have another problem now, when we an apostrophe, as it follows a slash: / '


    What to do?

  11. #11
    The Omega Superfun is offline
    Grand MasterRank
    Dec 2006 Join Date
    The NetherlandsLocation
    5,221Posts

    Re: Serveur hacked with Swift emu r5

    Secure all user input on querys with magic quotes or use PDO (bindvalue's)



Advertisement