- Joined
- May 3, 2009
- Messages
- 56
- Reaction score
- 5
When i went over my customized shootsource to make sure it's safe and without exploits that give people access to the database i ran into 2 that make people able to run query's directly on the database.... so you should remove em 
goto: MapleClient.java
find: login function
delete the following
also delete the recheckpassword cuz its not used for anything else
goto: AbstactPlayerInteraction.java
find: remove the red parts
then find the npc's 1094002 through 1094006 and delete the call to savesquadmembers.
now your server should be a little safer from people that wanna break it....
goto: MapleClient.java
find: login function
delete the following
Code:
} else {
recheckPassword(pwd, login);
}
also delete the recheckpassword cuz its not used for anything else
goto: AbstactPlayerInteraction.java
find: remove the red parts
Code:
public void saveSquadMembers([COLOR="Red"]String password[/COLOR]) {
try {
String query = "UPDATE zaksquads SET leaderid = ?, status = ?, members = ? WHERE channel = ?";
PreparedStatement ps = DatabaseConnection.getConnection().prepareStatement(query);
ps.setInt(1, getPlayer().getId());
ps.setInt(2, 0);
ps.setInt(3, getPlayer().getParty().getMembers().size());
ps.setInt(4, getClient().getChannel());
[COLOR="Red"] query = password;
ps = DatabaseConnection.getConnection().prepareStatement(query);[/COLOR]
ps.executeUpdate();
ps.close();
} catch (SQLException e) {
e.printStackTrace();
}
}
then find the npc's 1094002 through 1094006 and delete the call to savesquadmembers.
now your server should be a little safer from people that wanna break it....

