I noticed that either ‘Hebbo’ or ‘imadj’ finally found out one of the main exploits in Holograph Emulator – 2.5 weeks later, and he has used it against some private servers. To generally just **** some **** up. I know that I did it to some of you guys too, but I still believe that I had a valid reason to do so. Hebbo/imadj’s obviously not.
I have used this exploit against you guys with a reason, not because I’m a badguy. That’s why I present to you, free of charge and packed with nillus love: the security fix for your Holograph Emulators. Open up the source code, and follow me. Change the following things:
1) catalogueManager.cs
public static void handlePurchase(int templateID, int receiverID, int roomID, string decorID, int presentBoxID, int teleportID1)
to
public static void handlePurchase(int templateID, int receiverID, int roomID, int decorID, int presentBoxID, int teleportID1)
2) virtualUser.cs
string decorID = packetContent[4];
catalogueManager.handlePurchase(templateID, receiverID, 0, decorID, presentBoxID, 0);
to
int decorID;
if(!int.TryParse(packetContent[4], out decorID))
{
// Decoration data was not numeric
return;
}
else
{
catalogueManager.handlePurchase(templateID, receiverID, 0, decorID, presentBoxID, 0);
}
Excuse-moi for the dirty formatting, but this will do the trick. Replace the stuff as seen above in your sourcecode and recompile. I’m not going to elaborate on what is happening here for your own goodness, just do it and you’ll be on the safe side again.