[SERVICE] Patch Exploits/Leaks ect.. [TRYING]

Page 1 of 3 123 LastLast
Results 1 to 15 of 33
  1. #1
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    shout [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    How do you meen 'trying' well im not really 100% PRO so im also gonna test my skills here...

    What i need to do?
    Describe your situation and report what the scripters do.

    For example:
    My database is getting deleted
    [Check before you report: apache/logs/acces.log]

    Index me / me is getting redirected
    [Check before you report: database]

    All room names are suddenly changed
    [Check before you report: database or apache/logs/acces.log]

    etc .........

    Notice! I can`t patch everything... but i can patch the most.

    Sorry for my bad english, im dutch.


    EXPLOITS RESOLVED:
    Quote Originally Posted by Habblet View Post
    its the checknametaken injection, ok first go to 'inc/class.users.php'

    Look for
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . $nm . "' LIMIT 1")) > 0) ? true : false);
    	}
    replace that with
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . mysql_real_escape_string(stripslashes($nm)) . "' LIMIT 1")) > 0) ? true : false);
    	}
    Last edited by Habblet; 05-04-11 at 03:09 PM.


  2. #2
    Your Favorite Stalker Arnii is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    579Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    so you will make it some kind of anti-hack stuff? well, goodluck marco?

    Grr..
    Arnii

  3. #3
    Infraction Banned HabMoon is offline
    MemberRank
    Jun 2007 Join Date
    HM OfficesLocation
    3,068Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Don't need any help with it yet, but goodluck with this service :]

  4. #4
    The one and only! Hejula is offline
    MemberRank
    Nov 2008 Join Date
    4,128Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Looks good, but to stop the database getting deleted, just put the database on another account on the SQL Server (not root) and remove the DELETE privileges..! Just thought I would say in case anyone wanted to know :P

  5. #5
    Account Upgraded | Title Enabled! FlyCoder is offline
    MemberRank
    Jan 2011 Join Date
    United KingdomLocation
    469Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Doubt this will go far..
    Posted via Mobile Device

  6. #6
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Hejula View Post
    Looks good, but to stop the database getting deleted, just put the database on another account on the SQL Server (not root) and remove the DELETE privileges..! Just thought I would say in case anyone wanted to know :P
    Hmm, mostley on xampp can only localhost connect with root account, and to stop this really you need to patch.

  7. #7
    The one and only! Hejula is offline
    MemberRank
    Nov 2008 Join Date
    4,128Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Habblet View Post
    Hmm, mostley on xampp can only localhost connect with root account, and to stop this really you need to patch.
    I have multiple MySQL accounts on my XAMPP Development server, and they work fine, I tried deleting a database with the DELETE command and seeing as it was disabled on the MySQL account chosen, it wouldn't execute the command. This might not patch the exploit, but it renders it useless pretty much? I do see where you are coming from though!

  8. #8
    Grenafukindear Grenadier is offline
    MemberRank
    Feb 2010 Join Date
    127.0.0.1Location
    1,299Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    How can anyone trust you?

  9. #9
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Space-Bar View Post
    How can anyone trust you?
    There are more programmes and they can check it... or else im telling you the exploit/leak, and you can try it youreselfs.

  10. #10
    Minor Devolper ntl200 is offline
    MemberRank
    Dec 2007 Join Date
    EnglandLocation
    538Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    right ok so your goin to patch first? the tcp connection of uberemu? ;)

  11. #11
    Account Upgraded | Title Enabled! FlyCoder is offline
    MemberRank
    Jan 2011 Join Date
    United KingdomLocation
    469Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Hmm, i see. This thread is waste of space.
    Posted via Mobile Device

  12. #12
    Account Upgraded | Title Enabled! salah-salah is offline
    MemberRank
    Jan 2009 Join Date
    UndergroundLocation
    716Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Hablet , thanks for this service but i think that no one needs this..
    No one is posting anything

  13. #13
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by ntl200 View Post
    right ok so your goin to patch first? the tcp connection of uberemu? ;)
    More information, i dont know anything about this one...

  14. #14
    Developer Eronisch is offline
    MemberRank
    Jul 2009 Join Date
    The NetherlandsLocation
    1,328Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Direct hacking, some fággot keeps going in my database and edit everything he wants ..

  15. #15
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Eronisch View Post
    Direct hacking, some fággot keeps going in my database and edit everything he wants ..
    i think its the checknametaken injection, ok first go to 'inc/class.users.php'

    Look for
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . $nm . "' LIMIT 1")) > 0) ? true : false);
    	}
    replace that with
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . mysql_real_escape_string(stripslashes($nm)) . "' LIMIT 1")) > 0) ? true : false);
    	}
    Last edited by Habblet; 23-03-11 at 02:55 PM.



Page 1 of 3 123 LastLast

Advertisement