[SERVICE] Patch Exploits/Leaks ect.. [TRYING]

Page 1 of 2 12 LastLast
Results 1 to 25 of 33
  1. #1
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    shout [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    How do you meen 'trying' well im not really 100% PRO so im also gonna test my skills here...

    What i need to do?
    Describe your situation and report what the scripters do.

    For example:
    My database is getting deleted
    [Check before you report: apache/logs/acces.log]

    Index me / me is getting redirected
    [Check before you report: database]

    All room names are suddenly changed
    [Check before you report: database or apache/logs/acces.log]

    etc .........

    Notice! I can`t patch everything... but i can patch the most.

    Sorry for my bad english, im dutch.


    EXPLOITS RESOLVED:
    Quote Originally Posted by Habblet View Post
    its the checknametaken injection, ok first go to 'inc/class.users.php'

    Look for
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . $nm . "' LIMIT 1")) > 0) ? true : false);
    	}
    replace that with
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . mysql_real_escape_string(stripslashes($nm)) . "' LIMIT 1")) > 0) ? true : false);
    	}
    Last edited by Habblet; 05-04-11 at 03:09 PM.


  2. #2
    Your Favorite Stalker Arnii is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    579Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    so you will make it some kind of anti-hack stuff? well, goodluck marco?

    Grr..
    Arnii

  3. #3
    Infraction Banned HabMoon is offline
    MemberRank
    Jun 2007 Join Date
    HM OfficesLocation
    3,068Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Don't need any help with it yet, but goodluck with this service :]

  4. #4
    The one and only! Hejula is offline
    MemberRank
    Nov 2008 Join Date
    4,128Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Looks good, but to stop the database getting deleted, just put the database on another account on the SQL Server (not root) and remove the DELETE privileges..! Just thought I would say in case anyone wanted to know :P

  5. #5
    Account Upgraded | Title Enabled! FlyCoder is offline
    MemberRank
    Jan 2011 Join Date
    United KingdomLocation
    469Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Doubt this will go far..
    Posted via Mobile Device

  6. #6
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Hejula View Post
    Looks good, but to stop the database getting deleted, just put the database on another account on the SQL Server (not root) and remove the DELETE privileges..! Just thought I would say in case anyone wanted to know :P
    Hmm, mostley on xampp can only localhost connect with root account, and to stop this really you need to patch.

  7. #7
    The one and only! Hejula is offline
    MemberRank
    Nov 2008 Join Date
    4,128Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Habblet View Post
    Hmm, mostley on xampp can only localhost connect with root account, and to stop this really you need to patch.
    I have multiple MySQL accounts on my XAMPP Development server, and they work fine, I tried deleting a database with the DELETE command and seeing as it was disabled on the MySQL account chosen, it wouldn't execute the command. This might not patch the exploit, but it renders it useless pretty much? I do see where you are coming from though!

  8. #8
    Grenafukindear Grenadier is offline
    MemberRank
    Feb 2010 Join Date
    127.0.0.1Location
    1,299Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    How can anyone trust you?

  9. #9
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Space-Bar View Post
    How can anyone trust you?
    There are more programmes and they can check it... or else im telling you the exploit/leak, and you can try it youreselfs.

  10. #10
    Minor Devolper ntl200 is offline
    MemberRank
    Dec 2007 Join Date
    EnglandLocation
    538Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    right ok so your goin to patch first? the tcp connection of uberemu? ;)

  11. #11
    Account Upgraded | Title Enabled! FlyCoder is offline
    MemberRank
    Jan 2011 Join Date
    United KingdomLocation
    469Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Hmm, i see. This thread is waste of space.
    Posted via Mobile Device

  12. #12
    Account Upgraded | Title Enabled! salah-salah is offline
    MemberRank
    Jan 2009 Join Date
    UndergroundLocation
    716Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Hablet , thanks for this service but i think that no one needs this..
    No one is posting anything

  13. #13
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by ntl200 View Post
    right ok so your goin to patch first? the tcp connection of uberemu? ;)
    More information, i dont know anything about this one...

  14. #14
    Developer Eronisch is offline
    MemberRank
    Jul 2009 Join Date
    The NetherlandsLocation
    1,328Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Direct hacking, some fággot keeps going in my database and edit everything he wants ..

  15. #15
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Eronisch View Post
    Direct hacking, some fággot keeps going in my database and edit everything he wants ..
    i think its the checknametaken injection, ok first go to 'inc/class.users.php'

    Look for
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . $nm . "' LIMIT 1")) > 0) ? true : false);
    	}
    replace that with
    Code:
    	public function IsNameTaken($nm = '')
    	{
    		return ((mysql_num_rows(dbquery("SELECT null FROM users WHERE username = '" . mysql_real_escape_string(stripslashes($nm)) . "' LIMIT 1")) > 0) ? true : false);
    	}
    Last edited by Habblet; 23-03-11 at 02:55 PM.

  16. #16
    Developer Eronisch is offline
    MemberRank
    Jul 2009 Join Date
    The NetherlandsLocation
    1,328Posts
    I forgot to say that i am using phpretro

  17. #17
    Not active anymore! Winter is offline
    MemberRank
    Aug 2009 Join Date
    AustraliaLocation
    461Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Space-Bar
    How can anyone trust you?
    All a matter of if you don't trust, don't post.

    Anyway this seems like a good service. Thanks for doing this!

  18. #18
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Eronisch View Post
    I forgot to say that i am using phpretro
    Hmm, do you got any idea how he did it, or you got logs on 'xampp/apache/logs/acces.log' look for article.php?id= things or shomething with ?thing=thing

  19. #19
    Developer Eronisch is offline
    MemberRank
    Jul 2009 Join Date
    The NetherlandsLocation
    1,328Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Habblet View Post
    Hmm, do you got any idea how he did it, or you got logs on 'xampp/apache/logs/acces.log' look for article.php?id= things or shomething with ?thing=thing
    He said he was "direct hacking"

  20. #20
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by Eronisch View Post
    He said he was "direct hacking"
    Send me a privet message and say our link and i will check for injections, than i know how to patch. thankyou. patch will be here in the thread!

  21. #21
    Alpha Member Zak© is offline
    MemberRank
    Oct 2007 Join Date
    2,693Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    i trust this guy known him for long.

  22. #22
    Banned NewLights is offline
    BannedRank
    Mar 2011 Join Date
    NorwayLocation
    35Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    You can search you cms for exploits by using a anti-virus program, etc. Norton, Avast, Normann ++ But there is always exploits in apache/ server languages, thats why theese service are ALWAYS updated

  23. #23
    The Omega Superfun is offline
    MemberRank
    Dec 2006 Join Date
    The NetherlandsLocation
    5,223Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by NewLights View Post
    You can search you cms for exploits by using a anti-virus program, etc. Norton, Avast, Normann ++ But there is always exploits in apache/ server languages, thats why theese service are ALWAYS updated
    'le' excuse moi? (oh i sound so french) Scan for exploits? You probaly mean scan for a infected exe that people put in .zip folders as well. Finding these exploits is more like "find and destroy", aka debugging.

  24. #24
    HTML,CSS and a bit C# Richardjuhh is offline
    MemberRank
    Dec 2010 Join Date
    NetherlandsLocation
    351Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Quote Originally Posted by NewLights View Post
    You can search you cms for exploits by using a anti-virus program, etc. Norton, Avast, Normann ++ But there is always exploits in apache/ server languages, thats why theese service are ALWAYS updated
    Lol, if that is right i download right now an Anti-virus program

  25. #25
    Account Upgraded | Title Enabled! Habblet is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    324Posts

    Re: [SERVICE] Patch Exploits/Leaks ect.. [TRYING]

    Erm lol? but maybe it's a good idea..
    that people posts exploits and then I try to patch them,
    for everyone is it useful ...



Page 1 of 2 12 LastLast

Advertisement