Plus Emulator Security Fixes

it seems that in removing a favorite group's with an error exploit

You mean, "it seems that exists an exploit in removing someone's favorite's group." (i think)..

But give any proof of that.



Also i think doesn't seems be possible an exploit in removing favorite group. Since the packet consist only in a single integer (GroupID).
So is impossible. I think. Since the Integer is handled by something like "Request.GetInt32()", so SQL Injection seems be impossible.
 
For you resolve this error exploit you have to set if the group is null, use the same packet structure but with default values, int 0 string empty and if you have any bool is false, give you makes a return or create an else to execution of which is not null



PurchaseFromCatalogEvent

find:
dbClient.RunQuery("UPDATE `catalog_items` SET `limited_sells` = '" + Item.LimitedEditionSells + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");


replace:
dbClient.SetQuery("UPDATE `catalog_items` SET `limited_sells` = @limited_sells, `gender` = '" + Item.LimitedEditionSells.gender + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");
dbClient.AddParameter("limited_sells",Item.Id.limited_sells );
dbClient.RunQuery();

obs:
if wrong please correct'm still junior

 
For you resolve this error exploit you have to set if the group is null, use the same packet structure but with default values, int 0 string empty and if you have any bool is false, give you makes a return or create an else to execution of which is not null



PurchaseFromCatalogEvent

find:
dbClient.RunQuery("UPDATE `catalog_items` SET `limited_sells` = '" + Item.LimitedEditionSells + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");


replace:
dbClient.SetQuery("UPDATE `catalog_items` SET `limited_sells` = @limited_sells, `gender` = '" + Item.LimitedEditionSells.gender + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");
dbClient.AddParameter("limited_sells",Item.Id.limited_sells);
dbClient.RunQuery();

obs:
if wrong please correct'm still junior

LimitedEditionSells is a integer, you can't inject here
 
LimitedEditionSells is a integer, you can't inject here

Exactly!



For you resolve this error exploit you have to set if the group is null, use the same packet structure but with default values, int 0 string empty and if you have any bool is false, give you makes a return or create an else to execution of which is not null



PurchaseFromCatalogEvent

find:
dbClient.RunQuery("UPDATE `catalog_items` SET `limited_sells` = '" + Item.LimitedEditionSells + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");


replace:
dbClient.SetQuery("UPDATE `catalog_items` SET `limited_sells` = @limited_sells, `gender` = '" + Item.LimitedEditionSells.gender + "' WHERE `id` = '" + Item.Id + "' LIMIT 1");
dbClient.AddParameter("limited_sells",Item.Id.limited_sells);
dbClient.RunQuery();

obs:
if wrong please correct'm still junior


What the hell are you saying João. LimitedSells is an integer, you just can't do injection here.

Also this of the Group is Null, isn't an injection.
 
Hi guys, i'm try to coded forum but i have a problem, forum don't work.

namespace Plus.Communication.Packets.Incoming.Inventory.Purse
{
class GetForumsListDataEvent : IPacketEvent
{
public void Parse(GameClient Session, ClientPacket Packet)
{
int GroupId = Packet.PopInt();
int startindex = Packet.PopInt();
int endindex = Packet.PopInt();
Group Group = null;

PlusEnvironment.GetGame().GetGroupManager().TryGetGroup(GroupId, out Group);

if (Group == null || !Group.HasForum)
return;
 
Code:
namespace Plus.Communication.Packets.Incoming.Inventory.Purse
{
    class GetForumsListDataEvent : IPacketEvent
    {
        public void Parse(GameClient Session, ClientPacket Packet)
        {
            int GroupId = Packet.PopInt();
            int startindex = Packet.PopInt();
            int endindex = Packet.PopInt();
            Group Group = null;

            PlusEnvironment.GetGame().GetGroupManager().TryGetGroup(GroupId, out Group);

            if (Group == null || !Group.HasForum)
                return;

What is this code? Can you send it in "
Code:
" and and send it entirely, and specify what is wrong. Also here is not a help section.
 
Hi,

When I was checking Plus I found a exploit which makes it possible to send queries, drop tables, whatever you like. I noticed that someone finally found out the exploit and I decided to release the fix because this guys just want **** some **** up.

Open the source and follow me.

1). HabboHotel\Items\Wired\Boxes\Effects\BotChangesClothesBox.cs
I'm fairly certain that User.BotData.Gender is also a string.

Besides, the SQL injection would be of no risk if the user does not have any way of providing their own figure string. On Habboon edit (which I'm certain everyone now uses) there is a figure parser which would take care of any scripting attempts to try this.
 
Last edited:
I'm fairly certain that User.BotData.Gender is also a string.

Besides, the SQL injection would be of no risk if the user does not have any way of providing their own figure string. On Habboon edit (which I'm certain everyone now uses) there is a figure parser which would take care of any scripting attempts to try this.

u can save your own figure with a packetlogger.
 
u can save your own figure with a packetlogger.

Even then, it's ran through the anti mutant which will prevent any invalid strings.

Code:
string Look = PlusEnvironment.GetGame().GetAntiMutant().RunLook(Packet.PopString());

If any SQL is passed through it'll simply return a figure:

85278385277353753f29ed1ec7448333 - Plus Emulator Security Fixes - RaGEZONE Forums


These SQLi patches are still useful for people not running the boon edit though.
 
Even then, it's ran through the anti mutant which will prevent any invalid strings.

Code:
string Look = PlusEnvironment.GetGame().GetAntiMutant().RunLook(Packet.PopString());

If any SQL is passed through it'll simply return a figure:

85278385277353753f29ed1ec7448333 - Plus Emulator Security Fixes - RaGEZONE Forums


These SQLi patches are still useful for people not running the boon edit though.

I tried to inject and i can without problems.
 
Back