AlterEgo99
5,000+ posts
Streaming consciousness
OK, we're throwin' in some ronies too.Pepporonis mayne
http://www.bouncingbigboobs.com/wordpress/wp-content/uploads/2007/12/huge-*****.jpg![]()
OK, we're throwin' in some ronies too.Pepporonis mayne
http://www.bouncingbigboobs.com/wordpress/wp-content/uploads/2007/12/huge-*****.jpg![]()
Hmmmm...nice...just tossed in some SQL into the search function or somethin' along those lines I assume?Yep sure do! Some one got into the admin account on there a while back using an sql injection I told them about. But they were stupid and started bragging and someone told on them. Could have made some easy money selling stats and stuff.
yeah nothing like a little sound quality injection //content.invisioncic.com/y282845/emoticons/naughty.gif.94359f346c0f1259df8038d60b41863e.gifHmmmm...nice...just tossed in some SQL into the search function or somethin' along those lines I assume?
he wasnt talking to you slim. talkin to phatThat cuts to the bone bro...I'm not scammin' ya...and we're up to $55 and two beers with "The HACKER". //content.invisioncic.com/y282845/emoticons/fyi.gif.9f1f679348da7204ce960cfc74bca8e0.gif
I'm keepin' it real here and the monies is in my PayPal ready to head your way. //content.invisioncic.com/y282845/emoticons/naughty.gif.94359f346c0f1259df8038d60b41863e.gif
//content.invisioncic.com/y282845/emoticons/boink.gif.91933e72f927f2cefc79aff02573090c.gifAll this talk of injecting is getting me rather worked up.
For that particular game it was an injection into the login name. Neither the username or password field were protected. So it worked in either. If you injected into the username field you could get into specific accounts by specifying the id of the account. If you injected into the password field you could specify a certain password and it would give you access to the first account that it found a matching password for.Hmmmm...nice...just tossed in some SQL into the search function or somethin' along those lines I assume?
My new homie //content.invisioncic.com/y282845/emoticons/biggrin.gif.d71a5d36fcbab170f2364c9f2e3946cb.gifFor that particular game it was an injection into the login name. Neither the username or password field were protected. So it worked in either. If you injected into the username field you could get into specific accounts by specifying the id of the account. If you injected into the password field you could specify a certain password and it would give you access to the first account that it found a matching password for.
Other games I've found you can inject by modifying the headers or direct url injection.
There was one game I played with a person from ca.com and I ended up getting banned for injecting into the items table. I guess the admin got lucky and happened to be looking at logs when I was doing it because I had been doing it for a long time. He refused to unban me. A while later I figured out I could inject by modifying the headers so I made myself an admin. I was nice though, just had a look around in the control panel and sent him a message telling him to fix his game. The bastard banned me for that! Not like I was out to screw with the game because I easily could have done so.