The current server seems to have loopholes

Results 1 to 5 of 5
  1. #1
    Enthusiast pozxnm123 is offline
    MemberRank
    Jan 2011 Join Date
    27Posts

    The current server seems to have loopholes

    The current server seems to have loopholes

    After the role of the intruder to create, with GM permissions

    Seems to modify the packet?

    Ask how to solve


  2. #2
    Enthusiast pozxnm123 is offline
    MemberRank
    Jan 2011 Join Date
    27Posts

    Re: The current server seems to have loopholes

    How to solve?

  3. #3
    Moderator Eric is offline
    ModeratorRank
    Jan 2010 Join Date
    DEV CityLocation
    3,188Posts

    Re: The current server seems to have loopholes

    Quote Originally Posted by pozxnm123 View Post
    How to solve?
    I am not really sure what you're asking, but I can assure you that remotely, nobody can give themselves GM authentication levels within your OnCheckPassword/getAuthSuccess packets directly. They could activate some client-sided admin handling, but you would likely check for things like that without a doubt in your handler, if it is even being handled. Maybe you have a database exploit or some npc, etc?

  4. #4
    not a programmer eshays is offline
    MemberRank
    Mar 2015 Join Date
    532Posts

    Re: The current server seems to have loopholes

    I remember seeing a source where it checked the charname or password and if matched it would make them gm. Another checked the player command or chat handler instead.
    I forgot which ones but maybe he is talking about that if it is an odin based repack.
    Last edited by eshays; 18-12-16 at 08:03 AM.

  5. #5
    Account Upgraded | Title Enabled! Zydee is offline
    MemberRank
    Jul 2013 Join Date
    725Posts

    Re: The current server seems to have loopholes

    Quote Originally Posted by eshays View Post
    I remember seeing a source where it checked the charname and if matched it would make them gm. Another checked the player command instead of charname.
    I forgot which ones but maybe he is talking about that.
    I believe it checked the players IP on login-thats how they did it in a few lithium sources



Advertisement