Page Index Toggle Pages: [1] 2  Send TopicPrint
Normal Topic SQL injection (Read 4858 times)
Jon Van Caneghem
Abbot Raider
**
Offline


I pee on thee

Posts: 975
Location: Destard
Joined: May 1st, 2013
Gender: Male
SQL injection
Sep 29th, 2014 at 9:52am
Print Post  
Anyone ever tried an SQL injection on turbine's servers?

My guess is that it's not vulnerable to that but i might be wrong.
  
Back to top
 
IP Logged
 
FuckThisShit
Abbot Raider
**
Offline



Posts: 787
Joined: Jun 18th, 2014
Re: SQL injection
Reply #1 - Sep 29th, 2014 at 9:55am
Print Post  
Jon Van Caneghem wrote on Sep 29th, 2014 at 9:52am:
Anyone ever tried an SQL injection on turbine's servers?

My guess is that it's not vulnerable to that but i might be wrong.

tried once about 3 years ago, account got insta banned Tongue
in all fairness it was a pretty sloppy attempt just to test if they had any security at all, turns out they did Tongue
  



Back to top
 
IP Logged
 
Jon Van Caneghem
Abbot Raider
**
Offline


I pee on thee

Posts: 975
Location: Destard
Joined: May 1st, 2013
Gender: Male
Re: SQL injection
Reply #2 - Sep 29th, 2014 at 9:59am
Print Post  
Yeah, lol. Well i would only attempt that through a proxy or better yet , through tor.

Most SQL injection tools have settings to perform the attacks through a proxy without the need to make extra configurations to your net with proxychains or all that stuff.

  
Back to top
 
IP Logged
 
FuckThisShit
Abbot Raider
**
Offline



Posts: 787
Joined: Jun 18th, 2014
Re: SQL injection
Reply #3 - Sep 29th, 2014 at 10:01am
Print Post  
Jon Van Caneghem wrote on Sep 29th, 2014 at 9:59am:
Yeah, lol. Well i would only attempt that through a proxy or better yet , through tor.

Most SQL injection tools have settings to perform the attacks through a proxy without the need to make extra configurations to your net with proxychains or all that stuff.


it was a throaway account made for the sole purpose of that test anyways so no harm done Tongue
in all fairness if you're gonna attempt something like this, using readily available tools you get from the net is not really what you wanna be doing Tongue
  



Back to top
 
IP Logged
 
Some Guy Here On The Boards
Ghostbaned
*****
Offline


Somewhere on Korthos Island

Posts: 528
Location: Thelanis
Joined: Nov 3rd, 2013
Gender: Male
Re: SQL injection
Reply #4 - Sep 29th, 2014 at 10:03am
Print Post  
Is it wrong that my first thought is, "Go ask China"? Don't they have slave operations going on where people are forced to bot / exploit games? And also are a major source of online hacking/exploiting in general? Could be wrong.
  
Back to top
 
IP Logged
 
Jon Van Caneghem
Abbot Raider
**
Offline


I pee on thee

Posts: 975
Location: Destard
Joined: May 1st, 2013
Gender: Male
Re: SQL injection
Reply #5 - Sep 29th, 2014 at 10:08am
Print Post  
Yeah, i use Kali linux distro that comes with a lot of "official" tools to get these kind of jobs done. Those still require you to have knowledge of terminal commands and how networking works so they are not tools for the complete script kiddies.

Never download any hacking tools from the net and especialy tools made for windows as all those are guaranteed to have a virus attached to them.

I've only used SQLmap, and succesfully perfomed attacks to restaurants and other small buisnesses in my area.
« Last Edit: Sep 29th, 2014 at 10:12am by Jon Van Caneghem »  
Back to top
 
IP Logged
 
FuckThisShit
Abbot Raider
**
Offline



Posts: 787
Joined: Jun 18th, 2014
Re: SQL injection
Reply #6 - Sep 29th, 2014 at 10:09am
Print Post  
Some Guy Here On The Boards wrote on Sep 29th, 2014 at 10:03am:
Is it wrong that my first thought is, "Go ask China"? Don't they have slave operations going on where people are forced to bot / exploit games? And also are a major source of online hacking/exploiting in general? Could be wrong.

yep yep
i for one am extremely fuckin scared of them yellow bastards Tongue they are soo freaking good i cant even begin to phantom how they do their stuff
  



Back to top
 
IP Logged
 
Aeolwind
HERALD OF HATE
*
Offline


DDO: More broken than
peanut brittle

Posts: 2074
Location: Sarlona
Joined: Apr 13th, 2011
Gender: Male
Re: SQL injection
Reply #7 - Sep 29th, 2014 at 10:25am
Print Post  
Some games are vulnerable to those attacks through the in game chat server.  I remember EQ having that at one point.  And wow did even in beta at a point or two.  Most games are completely invulnerable now.  I think SWTOR had it for a short period on live, but I can't remember the reference.
  
Back to top
 
IP Logged
 
Sim-Sala-Bim
Completionist (i.t.p.)
******
Offline


Wha...?

Posts: 5356
Joined: Nov 2nd, 2013
Gender: Male
Re: SQL injection
Reply #8 - Sep 29th, 2014 at 10:29am
Print Post  
FuckThisShit wrote on Sep 29th, 2014 at 10:09am:
yep yep
i for one am extremely fuckin scared of them yellow bastards Tongue they are soo freaking good i cant even begin to phantom how they do their stuff


  
Back to top
 
IP Logged
 
FuckThisShit
Abbot Raider
**
Offline



Posts: 787
Joined: Jun 18th, 2014
Re: SQL injection
Reply #9 - Sep 29th, 2014 at 10:35am
Print Post  
Sim-Sala-Bim wrote on Sep 29th, 2014 at 10:29am:

that made my laugh so hard i spilt beer on my keyboard, you sir owe me 120 dollars now Tongue
  



Back to top
 
IP Logged
 
Durk
The Deranged
*
Offline


I've got a secret!

Posts: 705
Location: The Harbor
Joined: May 15th, 2012
Gender: Male
Re: SQL injection
Reply #10 - Sep 29th, 2014 at 11:41am
Print Post  
Hmm.  I wouldn't at all be surprised if Turbine's forums were open to SQL injection, you would be an idiot to play around with it if you cared about your account.  However, it isn't like they are using a really old version of PowerBoard or anything...
  
Back to top
 
IP Logged
 
Flav
Vault Frog
*
Offline


One Frog to Rule them
All!

Posts: 10011
Location: Land of the Frogs
Joined: Aug 29th, 2010
Gender: Male
Re: SQL injection
Reply #11 - Sep 29th, 2014 at 12:13pm
Print Post  
Anyway, the database servers are on the backend notwork ( the one in 10.*.*.* ) so you can't reach it.
( there's some that knows where to look for the right addresses here )

The only way to injcet things is from In Game, or by intercepting the game communications and sending bogus datas... and it takes a lot more than standard tools.
Why do you think Turbine act with Exxxxxtreme Prejudice on those that shows that they have been able to look at and understand client/server communications ?

  

Yes my avatar is an Hermine eating a Greenland Lemming for brunch.
Back to top
 
IP Logged
 
Jon Van Caneghem
Abbot Raider
**
Offline


I pee on thee

Posts: 975
Location: Destard
Joined: May 1st, 2013
Gender: Male
Re: SQL injection
Reply #12 - Sep 29th, 2014 at 12:36pm
Print Post  
Durk wrote on Sep 29th, 2014 at 11:41am:
Hmm.  I wouldn't at all be surprised if Turbine's forums were open to SQL injection, you would be an idiot to play around with it if you cared about your account.  However, it isn't like they are using a really old version of PowerBoard or anything...

If you perform the attack through a proxy then there is no way for them to link your account to the attacker's IP
  
Back to top
 
IP Logged
 
harharharhar
Epic Poster
*****
Offline


Girthless Trolllicker

Posts: 3421
Joined: Aug 31st, 2012
Gender: Male
Re: SQL injection
Reply #13 - Sep 29th, 2014 at 1:19pm
Print Post  
jesus christ how bad is your life and addiction to DDO that you want to sql inject them.

get a new hobby.
  
Back to top
 
IP Logged
 
Aeolwind
HERALD OF HATE
*
Offline


DDO: More broken than
peanut brittle

Posts: 2074
Location: Sarlona
Joined: Apr 13th, 2011
Gender: Male
Re: SQL injection
Reply #14 - Sep 29th, 2014 at 3:06pm
Print Post  
Jon Van Caneghem wrote on Sep 29th, 2014 at 12:36pm:
If you perform the attack through a proxy then there is no way for them to link your account to the attacker's IP

Have you spoken with Arkat about Tor?

Grin
  
Back to top
 
IP Logged
 
Sim-Sala-Bim
Completionist (i.t.p.)
******
Offline


Wha...?

Posts: 5356
Joined: Nov 2nd, 2013
Gender: Male
Re: SQL injection
Reply #15 - Sep 29th, 2014 at 4:49pm
Print Post  
FuckThisShit wrote on Sep 29th, 2014 at 10:35am:
that made my laugh so hard i spilt beer on my keyboard, you sir owe me 120 dollars now Tongue


You must have one hell of a keyboard. Mine is like 20 dollars.  Sad

  
Back to top
 
IP Logged
 
Aeolwind
HERALD OF HATE
*
Offline


DDO: More broken than
peanut brittle

Posts: 2074
Location: Sarlona
Joined: Apr 13th, 2011
Gender: Male
Re: SQL injection
Reply #16 - Sep 29th, 2014 at 5:08pm
Print Post  
You have nice hands!
  
Back to top
 
IP Logged
 
DropBear
Dropbear Awareness Society
*
Offline


Don't forget to look up....

Posts: 4380
Location: Landdownunder
Joined: Oct 11th, 2013
Re: SQL injection
Reply #17 - Sep 29th, 2014 at 8:03pm
Print Post  
Jon Van Caneghem wrote on Sep 29th, 2014 at 10:08am:
I've only used SQLmap, and succesfully perfomed attacks to restaurants and other small buisnesses in my area.


Why?
  
Back to top
 
IP Logged
 
Sasha
Abbot Raider
**
Offline



Posts: 821
Joined: Apr 13th, 2014
Re: SQL injection
Reply #18 - Sep 29th, 2014 at 8:15pm
Print Post  
DropBear wrote on Sep 29th, 2014 at 8:03pm:
Why?


It's tough to get a good reservation these days.
  
Back to top
 
IP Logged
 
Hiding
Shroud Slacker
***
Offline


I Love Drama!

Posts: 1298
Joined: Feb 5th, 2014
Gender: Male
Re: SQL injection
Reply #19 - Sep 29th, 2014 at 9:56pm
Print Post  
DropBear wrote on Sep 29th, 2014 at 8:03pm:
Why?


'cause he's like so bad. so so bad.

Freedom to the people!
  
Back to top
 
IP Logged
 
DropBear
Dropbear Awareness Society
*
Offline


Don't forget to look up....

Posts: 4380
Location: Landdownunder
Joined: Oct 11th, 2013
Re: SQL injection
Reply #20 - Sep 29th, 2014 at 10:00pm
Print Post  
Sasha wrote on Sep 29th, 2014 at 8:15pm:
It's tough to get a good reservation these days.


Obviously.

l33t hax0rs an0n.
« Last Edit: Sep 29th, 2014 at 10:01pm by DropBear »  
Back to top
 
IP Logged
 
Sim-Sala-Bim
Completionist (i.t.p.)
******
Offline


Wha...?

Posts: 5356
Joined: Nov 2nd, 2013
Gender: Male
Re: SQL injection
Reply #21 - Sep 30th, 2014 at 1:56am
Print Post  
Aeolwind wrote on Sep 29th, 2014 at 5:08pm:
You have nice hands!


LOL. Noticed now. I was trying to find an IOU picture.
  
Back to top
 
IP Logged
 
iliveyourdream13
Puppy Farmer
****
Offline


I Love Drama!

Posts: 1521
Joined: Oct 8th, 2013
Re: SQL injection
Reply #22 - Sep 30th, 2014 at 11:27am
Print Post  
Jon Van Caneghem wrote on Sep 29th, 2014 at 10:08am:
I've only used SQLmap, and succesfully perfomed attacks to restaurants and other small buisnesses in my area.

Did WalMart send you a thank you letter for attacking the competition?  Tongue
  
Back to top
 
IP Logged
 
Flav
Vault Frog
*
Offline


One Frog to Rule them
All!

Posts: 10011
Location: Land of the Frogs
Joined: Aug 29th, 2010
Gender: Male
Re: SQL injection
Reply #23 - Sep 30th, 2014 at 12:46pm
Print Post  
I always see lots of fun stuff happening when I fire up my home server...

Too bad for all the wanabee hackers it's :
- not a PC
- not under Linux
- not under Windows
- not running any PHP system atm. ( that might change once I have FTTH )
- not running any SQL db atm. ( that might change once I have FTTH )

Basically an Ultra 45 Sparc Server under Solaris 10 with just SSH and HTTP opened ( at Router level, via port forwarding and NAT ) is not fun to them.

  

Yes my avatar is an Hermine eating a Greenland Lemming for brunch.
Back to top
 
IP Logged
 
KilgoreTrout
Dragon Raider
***
Offline


I Love Drama!

Posts: 214
Joined: Mar 17th, 2014
Re: SQL injection
Reply #24 - Sep 30th, 2014 at 12:48pm
Print Post  
Sim-Sala-Bim wrote on Sep 29th, 2014 at 4:49pm:
You must have one hell of a keyboard. Mine is like 20 dollars.  Sad

http://i.imgur.com/mQ5hsj0.jpg


Who the fuck is taking that photo? Does she have three hands?
  
Back to top
 
IP Logged
 
Page Index Toggle Pages: [1] 2 
Send TopicPrint