Go Back   EQ2Flames Forum > EQ2Flames Center Stage > Rate-a-Retard

Reply
 
LinkBack Thread Tools
Old 05-11-2008, 08:08 PM  
/meow
 
Character: vortfu
Server: Retired

Posts: 22
Photos: (0)

Default Everyone using EQDKP

The EQDKP team was notified about a serious vulnerability in their authentication code on April 10th (emphasis on 'notified').... and not only have they not replied to the PMs, they haven't even released a patch so the randoms of the world can sleep better at night.

Retards.

And for everyone using this shit

Retards.

And a special mention for everyone who uses the same DKP password as they do for their account / forum passwords (it has been confirmed how unbelievably fucking funny this is - especially now the cracked hashes are publicly available on Free Rainbow Tables)

Retards++.


And for anyone interested ....

Quote:
D. Criminal Law: Don’t post instructions on how to build a drug lab, an explosive device, or any other information that if used would result in a crime. Never link to pages containing this type of information.

Sorry, this could start a wildfire that I don't want to be responsible for. <3 Niber



Discuss.
Circle Jerk.

vortfu

Last edited by Niber; 05-12-2008 at 02:26 PM.
vortfu is offline   Reply With Quote
Old 05-11-2008, 09:26 PM  
Retired?
 
Niber's Avatar
 

Posts: 3,472
Photos: (203)

Send a message via AIM to Niber Send a message via MSN to Niber
Default Re: Everyone using EQDKP

Interesting, but who would go out of their way to crack eqDKP passwords?
__________________
Niber is online now   Reply With Quote
Old 05-11-2008, 09:47 PM  
Visitor
 
Character: Ambarta
Guild: Nexus
Server: Najena

Posts: 45
Photos: (2)

Default Re: Everyone using EQDKP

If EQDKP Password = Guild Forum Password (and many do)
Then I guess some people would be interested in having a peak into other guilds forums... or officer sections even.
Call lists.. Strats.. Drama..
__________________
http://www.thorongil.net/media/sigs/ambarta.jpg
Ambarta is offline   Reply With Quote
Old 05-12-2008, 08:27 AM  
Regular
 
Arlen Bouldersmi's Avatar
 
Character: Arlen Bouldersmite
Guild: FURY
Server: Lucan D'lere

Posts: 190
Photos: (0)

Default Re: Everyone using EQDKP

ok - color me niave, but , why the fuck would someone want to raid someone elses forum?? sure - maybe read some shit for giggles, but c'mon is this game that serious to folks that they feel the need to see what uber guild x internal drama is and post it, or steal roster info, or read up on thier leet strats? shit the strats are already posted all over this site. sometimes I am truly amazed by some folks. (now if this was a way to obtain actual account info - then I stand corrected and ill stfu)
__________________
Arlen Bouldersmite
80Guardian LDL
everything you hold dear , life, love and happiness has been bought and paid for by a Soldier. "freedom is never free"
Arlen Bouldersmi is offline   Reply With Quote
Old 05-12-2008, 09:37 AM  
WW Disco Warlock Mythical!
 
Udoaka's Avatar
 
Character: Udoaka [Syndarin]
Guild: Golden Spoon [Dreadnaught]
Server: AB [Ghostlands (WoW)]

Posts: 817
Photos: (0)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Arlen Bouldersmi View Post
ok - color me niave, but , why the fuck would someone want to raid someone elses forum??
For the lolz!
__________________

Udoaka is offline   Reply With Quote
Old 05-12-2008, 10:49 AM  
A Pimp Named Slickback
 
Hoss's Avatar
 
Character: Tool
Guild: Bloodlines of the Fallen
Server: Mistmoore

Posts: 1,685
Photos: (0)

Default Re: Everyone using EQDKP

Well, people are extraordinarily lazy. Thats a fundamental fact of life. So, in all likelihood, there is a large percentage of people who use the exact same login info for the game that they use for everything else game related. Flames, guild websites, eqdps, soe boards, the place we all downloaded our UI from (drawing a blank on the name right now), etc. So yeah, if you could, for instance, easily get the eqdkp login info for 100 people, there would be a good chunk of them that would allow you to log into the game. Not only that, if you cared to follow it up, I bet there'd be a few in that hundred where you could log into their email accounts or work computers. Because people are dumb and hackers exploit that.


-h
__________________
Let us Pray the Pimp's Prayer.
Lord, please pray for the soul of this bitch and guide my pimp hand and make it strong Lord, so that she might learn a hoe's place.

Amen
Hoss is offline   Reply With Quote
Old 05-12-2008, 12:23 PM  
-------------------
 
Johnathon's Avatar
 
Character: Devastatin
Guild: Revelations
Server: Unrest

Posts: 1,795
Photos: (69)

Default Re: Everyone using EQDKP

Well, easiest way to make it harder for someone to screw with your DKP is to setup your admin account to be an arbitrary account number where "1, " . // * user_id does not equal 1.

I would select something very random and in line with everything else. This will deter many 'script kiddies' away. But there are other SQL Injection Exploits that involve eqdkp.

Until they fix listmembers.php, its going to be an ongoing issue. (it has to do with the rank feature within listmembers)
__________________
Sign up and get a free ITOUCH

Johnathon is online now   Reply With Quote
Old 05-12-2008, 12:43 PM  
Nobody
 

Posts: 8,194
Photos: (0)

Send a message via ICQ to Pinski Send a message via AIM to Pinski Send a message via MSN to Pinski Send a message via Yahoo to Pinski
Default Re: Everyone using EQDKP

Quote:
Originally Posted by Niber View Post
Interesting, but who would go out of their way to crack eqDKP passwords?
Retards mostly!
__________________
Pinski is online now   Reply With Quote
Old 05-12-2008, 01:42 PM  
gm9
*
 
gm9's Avatar
 

Posts: 136
Photos: (0)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Niber View Post
Interesting, but who would go out of their way to crack eqDKP passwords?
You don't need to crack anything, you don't even need a brain to use the PoC in the OP and log into any eqdkp installation with admin priviledges and start messing with their data. Might be your own raiders giving themselves more dkp...

Quote:
Originally Posted by Johnathon View Post
Until they fix listmembers.php, its going to be an ongoing issue. (it has to do with the rank feature within listmembers)
The SQL injection via listmembers.php has been fixed long ago. The OP uses SQL injection via cookie data, i.e. the current bug has to be fixed in sessions.php.
__________________
Quote:
Originally Posted by Pryz View Post
this site went through a huge decline when it went from a place for endgame players to exchange information and flames into a full on pathetic casual gangbang with e-friends.
gm9 is offline   Reply With Quote
Old 05-12-2008, 01:47 PM  
Nobody
 

Posts: 8,194
Photos: (0)

Send a message via ICQ to Pinski Send a message via AIM to Pinski Send a message via MSN to Pinski Send a message via Yahoo to Pinski
Default Re: Everyone using EQDKP

Quote:
Originally Posted by gm9 View Post
You don't need to crack anything, you don't even need a brain to use the PoC in the OP and log into any eqdkp installation with admin priviledges and start messing with their data. Might be your own raiders giving themselves more dkp...
Good thing for logs in eqdkp, that most people are too stupid to delete :0

Of course, there's always the SQL database which is the hardest part to delete, since everything you do in eqdkp is logged, so you can easily just recreate everything from that information.
__________________
Pinski is online now   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 12:07 AM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0