PDA

View Full Version : Toplist issue resolved



Ikiliki
June 25th, 2010, 22:45
Hello,

The toplist issue with the hacking has been resolved. It turned out to be a simple SQL injection and it has been solved with one simple rule I forgot when remaking the toplist in a hurry (yeah, it's a shame).

Anyway, Pie and I have done some research.
The applet on the link (the IP address) turns out to be downloading a file callled Update.exe and afterwards execute it.
It's seems to be some kind of server (maybe a gaming server or something?) because the rest of the Java applet seems to be handling maps.

I have contacted the host of the file and the provider already.
You'll probably hear from me about this next week.

Shishir G
June 25th, 2010, 23:01
good job, iki, and pie.
i love pie.

Smudge
June 25th, 2010, 23:05
Good job, can't blame yourself to be honest.
and Pie` is a legend. Seen a lot of his PHP work etc. <3

pedobear
June 25th, 2010, 23:17
good job thanks !

Dann
June 25th, 2010, 23:21
Hey, ik had je nog offline bericht gestuurd daarover.
Kom zo even op msn dan.

Gr Daniël

Ikiliki
June 25th, 2010, 23:36
Hey, ik had je nog offline bericht gestuurd daarover.
Kom zo even op msn dan.

Gr Daniël

This is an English speaking community. I'm going to sleep now.

Oh and an update on the situation; the website hosting the game server files has been suspended by their host. Next step is datacenter my , I'll see what I do.
Whoever this kid is, he messed with the wrong person.

Runelocus isn't the only site facing this, it's pretty much a patern because some Real Time Shooter game was also infected and the source was pretty much proving it's a patern kinda thing.

In case the kid reads this: Nice try, next time try getting rid of my domlogs first. Your injection URLs were too easy to find. I lold pretty hard when I tricked you into my "Something is wrong with your login" error msg/code and you kept re-trying (a.k.a. ruining your cover).
Have fun in life, just don't waste any more time because life is short,

lilsnoop
June 25th, 2010, 23:39
It looks like it was done by a bunch of people, it was released on a public forum, including a list of all the passes. Maybe that was just one person who saw it?

Shishir G
June 25th, 2010, 23:44
This is an English speaking community. I'm going to sleep now.

Oh and an update on the situation; the website hosting the game server files has been suspended by their host. Next step is datacenter my , I'll see what I do.
Whoever this kid is, he messed with the wrong person.

Runelocus isn't the only site facing this, it's pretty much a patern because some Real Time Shooter game was also infected and the source was pretty much proving it's a patern kinda thing.

In case the kid reads this: Nice try, next time try getting rid of my domlogs first. Your injection URLs were too easy to find. I lold pretty hard when I tricked you into my "Something is wrong with your login" error msg/code and you kept re-trying (a.k.a. ruining your cover).
Have fun in life, just don't waste any more time because life is short,

lmfao at the last part. he fell for it?
if your reading this; FAG FUCK YOU

pedobear
June 25th, 2010, 23:54
lmfao at the last part. he fell for it?
if your reading this; FAG FUCK YOU

if he swears it will look like he wants more, and then he will not stop but if he sends a serious text that makes him a bit scared, I think that he will not do any more, he pick the wrong person anyway.

well i know he wont do anything more beacuse he cant! :D<3

by the way, thank you ikiliki for fixed this :)

Absol
June 26th, 2010, 00:56
Don't look fixed to me? Still porn adverts + kids email.

I honestly think it was that one guy who was bitching about being banned/reset on the toplist for cheating. The server sites that we're hacked, we're oddly enough the ones who he tried to bring down.

Smudge
June 26th, 2010, 01:03
Don't look fixed to me? Still porn adverts + kids email.

I honestly think it was that one guy who was bitching about being banned/reset on the toplist for cheating. The server sites that we're hacked, we're oddly enough the ones who he tried to bring down.

That's what everyone assumed at first, but this was all done my MySQL injections. I don't think he has the knowledge or the tools to do so, Unless he became a skiddie. Nobody knows who it is until Iki searches further into this.

pedobear
June 26th, 2010, 02:17
That's what everyone assumed at first, but this was all done my MySQL injections. I don't think he has the knowledge or the tools to do so, Unless he became a skiddie. Nobody knows who it is until Iki searches further into this.

he can catch him easy, hes ip adress is writed, and he can check if the ip adress is member of runelocus and he can check where he lives and do really much with it.

Smudge
June 26th, 2010, 02:22
he can catch him easy, hes ip adress is writed, and he can check if the ip adress is member of runelocus and he can check where he lives and do really much with it.

He can't get his address from a IP unless the ISP is contacted, Only government etc can track the exact location of an IP. Otherwise Pedo's would rule the webs. Lol

Cart
June 26th, 2010, 02:25
Either way, my server isnt affected so im happy so far LOL

New Clear
June 26th, 2010, 02:34
Good job Iki, and everyone else who helped in this.
Looking forward to hearing further into this.

Cart
June 26th, 2010, 02:35
Good job Iki, and everyone else who helped in this.
Looking forward to hearing further into this.
Still happening, not fixed yet LOL kids messing around with top 20 servers.

Aaron
June 26th, 2010, 03:08
Uh, How is this resolved, Look at the toplist..

Austin
June 26th, 2010, 03:14
Good jobs guys!

Shishir G
June 26th, 2010, 03:21
Uh, How is this resolved, Look at the toplist..

you noob, your late.
he posted this when he did fix it, but they got it again.

Absol
June 26th, 2010, 03:29
He easily could use a proxy. Hell- I can connect from my neighbors net, and my IP gets reassigned to one that actually lists to their home/IP.

(Cause everyone behind the router has the same one.)

Forthelolz
June 26th, 2010, 06:22
Ikiliki, I have a lot of information on who did it, and I personally have a copy of the Toplist database from the person. I do not plan on doing anything with it, however, I advise everyone change their emails, and passwords for the toplist, since that's what the database shows. The SQL injections only took place once, as far as I'm concerned, unless there is another person doing it. If you would like to speak to me about it, please PM me. I will not be releasing any information publicly, I will only tell Ikiliki if he wishes to PM me.

Ikiliki
June 26th, 2010, 06:33
lulz another one, I'll take a look.
Glad it's the end of the month anyway.

Edit:
No SQL injections. It's just obvious he has either a backup or just many passwords of important servers.
It's almost the end of the month, so I'll just do an early toplist reset. The big servers should re-add, WITH A NEW PASSWORD.

WebMaster
June 26th, 2010, 06:52
Ummm... That's not all. Only the registered members can see the link.

I got this in a email that came from here. It has everything about the website old users and password. It's alot and messed up.

Joshua F
June 26th, 2010, 06:58
Ummm... That's not all. Only the registered members can see the link.

I got this in a email that came from here. It has everything about the website old users and password. It's alot and messed up.

It has a virus.. I loaded the java, my antivirus(Kasperski, detected it right away..) running a full scan over night though.

Edit, if you look.. The homepage is fake. It's not real java, and it redirects you to index2.html.

pedobear
June 26th, 2010, 06:59
it has a virus.. I loaded the java, my antivirus(kasperski, detected it right away..) running a full scan over night though.

Edit, if you look.. The homepage is fake. It's not real java, and it redirects you to index2.html.


do not click on the run! Its a rat,

Joshua F
June 26th, 2010, 07:01
do not click on the run! Its a rat,

A rat?

pedobear
June 26th, 2010, 07:10
A rat?

its a virus as i got when i runned frostiescape client he can se your screen, passwords evrything he took my email, paypal, evrything, but the police catched him after he took the paypal so i sue him for like 987 or it was 879 dont remember usd.

Joshua F
June 26th, 2010, 07:13
its a virus as i got when i runned frostiescape client he can se your screen, passwords evrything he took my email, paypal, evrything, but the police catched him after he took the paypal so i sue him for like 987 or it was 879 dont remember usd.

Ouch, because I ran it O.o, but my virus scanner caught it?

Forthelolz
June 26th, 2010, 07:15
Everyone just report the website and don't go to it.

pedobear
June 26th, 2010, 07:16
Ouch, because I ran it O.o, but my virus scanner caught it?

dont really know, hope you didnt get the rat. check your computer files now and search if you find something you downloaded.

Joshua F
June 26th, 2010, 07:17
dont really know, hope you didnt get the rat. check your computer files now and search if you find something you downloaded.

Were should I look?
P.S. My scanner found something in temp internet files.

Full Scan: running (events: 3, objects: 187427, time: 00:20:29)
6/26/2010 1:08:16 AM Detected: Trojan-Downloader.VBS.Psyme.rn C:\Documents and Settings\Josh\AppData\Local\Temp\winconfig.vbs
6/26/2010 1:08:23 AM Deleted: Trojan-Downloader.VBS.Psyme.rn C:\Documents and Settings\Josh\AppData\Local\Temp\winconfig.vbs

Codeusa
June 26th, 2010, 09:10
ohman33@live.com


I sold him my injecting tools, he said he was the one doing it and to "look at" runelocus about 2 seconds before it went down.

Have fun,

His phone number is
443-307-6283
John


Most dox I could pull on him, enjoy.

Faab234
June 26th, 2010, 10:39
A Free scooter for Ikiliki and Pie`.

Nice job.

I D3stroy I
June 26th, 2010, 12:29
Thanks for fixing the Issue !

pedobear
June 26th, 2010, 12:37
Thanks for fixing the Issue !

it's not fixed yet.

Joe
June 26th, 2010, 14:09
The nightmare is not over yet and also if you use same pass as toplist i suggest changing immediately.

Nathan'
June 26th, 2010, 14:10
My server has been deleted from the toplist. I had over 350 votes. whats going to happen....

SIR MOJO
June 26th, 2010, 14:10
Good job iki.

Eduardo
June 26th, 2010, 14:56
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.

Smudge
June 26th, 2010, 15:01
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.

Someone really has a rage-quit going on don't they?

Joe
June 26th, 2010, 15:08
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.

You Mofo i know its you who did it . Only the registered members can see the link. its all there XD

pedobear
June 26th, 2010, 15:21
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.

you're pointless, as you know now as you have posted this you ip is writed, be careful on the internet idiot, dont do shit you dont know what is gonna happen in the future. only 1 thing to say.

Good Game.

Jusstin
June 26th, 2010, 15:23
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.

i lold so hard, fail hacker is fail.

Smudge
June 26th, 2010, 15:28
you're pointless, as you know now as you have posted this you ip is writed, be careful on the internet idiot, dont do shit you dont know what is gonna happen in the future. only 1 thing to say.

Good Game.

He wouldn't of left his IP. He would of used a proxy or a VPN. He has some common sense. Lol

Jusstin
June 26th, 2010, 15:30
He wouldn't of left his IP. He would of used a proxy or a VPN. He has some common sense. Lol

No, I was speaking with a friend of mine that was helping marc with the problem.
He uses a dynamic Ip.

pedobear
June 26th, 2010, 15:32
No, I was speaking with a friend of mine that was helping marc with the problem.
He uses a dynamic Ip.

ffs :/ oh well, its not impussible catch him.

Friss
June 26th, 2010, 15:35
He used a proxy to make that post.

pedobear
June 26th, 2010, 15:38
He used a proxy to make that post.

damn, but hes ip adress is writed on quatrax website if we just ask a staff from there to give us or whatever?

Eduardo
June 26th, 2010, 15:39
Every single packet sent by my network is encrypted by a 512 byte algorythm and then send to a VPS to which I connect via SSL, my hard drives are encrypted on a 256bit encryption, I can delete everything on them with one click.
You are not going t catch me, my signal bounces to South America, USA, Africa and Russia

Eduardo
June 26th, 2010, 15:41
My IP at QuarterX has always been a proxied IP from some South American country

pedobear
June 26th, 2010, 15:42
Every single packet sent by my network is encrypted by a 512 byte algorythm and then send to a VPS to which I connect via SSL, my hard drives are encrypted on a 256bit encryption, I can delete everything on them with one click.
You are not going t catch me, my signal bounces to South America, USA, Africa and Russia

lol, i swear you cant remove evrything..

Aaron
June 26th, 2010, 15:43
What has runelocus done to you?

pedobear
June 26th, 2010, 15:43
What has runelocus done to you?

a really good question you asked now.

Smudge
June 26th, 2010, 15:44
He reminds me of this movie I saw ages ago, Forgot what it was called, Thing it was Kill with me or something, signal bouncing. Wonder which group he's a part of.

Ikiliki
June 26th, 2010, 15:47
It is really funny hwo you left a SQL injection vulnerability, here it is if you want to fix it: Only the registered members can see the link.
And not saving passwords like a MD% hash is quite stupid, you really think this just goes to your website?
People in the internet are stupid enough to use the same password for everything, I have email addresses, I have their passwords, I can even go ahead and go into their websites and hack them.

And Forthelolz, I have your IP, I will not rest until I have searched for every single 3rd party vulnerability, until every single meterpreter session hijacking is tested, I will MSN reverse your email, I will hack every single thing you own on the internet.
I had to remake the toplist in a hurry, wasn't bothered encrypting and obviously left a simple part as injectable.

The accounts of servers on RuneLocus are safe. I'm not responsible if they use the emails for other things. I have told them to use other passwords, I can't be blamed if they ignore that.

Anyway, I can't blame you but only myself. You actually reminded me.

Joe
June 26th, 2010, 15:47
He reminds me of this movie I saw ages ago, Forgot what it was called, Thing it was Kill with me or something, signal bouncing. Wonder which group he's a part of.

he is a wanna be hacker who is a new hacker who learned couple mysql injections big deal everyone acting like he is someone he just found a glitch and abused it.

Aaron
June 26th, 2010, 15:49
he is a wanna be hacker who is a new hacker who learned couple mysql injections big deal everyone acting like he is someone he just found a glitch and abused it.

I'm not sure so sure if he's a 'wannabe' hacker but to me, he did alot, but I'm not sure if he really did or not:O

Marc
June 26th, 2010, 15:52
Every single packet sent by my network is encrypted by a 512 byte algorythm and then send to a VPS to which I connect via SSL, my hard drives are encrypted on a 256bit encryption, I can delete everything on them with one click.
You are not going t catch me, my signal bounces to South America, USA, Africa and Russia

Did google teach you all that?

pedobear
June 26th, 2010, 15:55
Did google teach you all that?

fucking clean comment.

Eduardo
June 26th, 2010, 15:56
Ahahaha, I am a wannabe hacker?
You know very little about me, I would love to hack you but I do not have the time to deal with 8 years old that do not know what hacking actually is.
The whole point of hacking is finding flaws in the system and abusing them.

pedobear
June 26th, 2010, 15:57
Ahahaha, I am a wannabe hacker?
You know very little about me, I would love to hack you but I do not have the time to deal with 8 years old that do not know what hacking actually is.
The whole point of hacking is finding flaws in the system and abusing them.

are you proud?

Eduardo
June 26th, 2010, 16:00
Servers are going to start falling. 1 by 1.

Brayden
June 26th, 2010, 16:02
Servers are going to start falling. 1 by 1.

what about servers that do not use the toplist?

BTW Pedo shut the hell up you sound like such a fag.

Aaron
June 26th, 2010, 16:02
what about servers that do not use the toplist?

Owned...He can't do shit about those.

Eduardo
June 26th, 2010, 16:04
Well, with this over 700 sites list should be enough for me

Smudge
June 26th, 2010, 16:05
Servers are going to start falling. 1 by 1.

I have a feeling you use the name Eduardo from the film V For Vendetta? The face of anonymous; well, put it this way; you're much different to the usual 'hackers' who visit such as H0rn, TX, etc.. I've got a d0x on H0rn actually, quite big. But meh. If you're so advanced why are you using the skiddie method's? i.e. MySql Injections, RATs. I would think someone of you're "intelligence" would be able to expand to more advanced area's.

Brayden
June 26th, 2010, 16:06
Well, with this over 700 sites list should be enough for me

oh ok. do you play a p server?

Lewis
June 26th, 2010, 16:08
Servers are going to start falling. 1 by 1.

It's funny how you think you can hack runelocus. There was 1 flaw in the system and now it's fixed. And at the moment your just bragging how much your going to hack runelocus and i haven't seen nothing happen. So stop bragging about how much you can hack when it probly wasen't even you who did the sql injection.

Eduardo
June 26th, 2010, 16:11
RAT? are you kidding me? I would never use a RAT, well it is not my fault that such a stupid vulnerability was left open. I was searching for fuzz LFI vulnerabilities when I found it. Was also looking into creating meterpreter sessions with the host, but I could not get into the kernel of the server to be able to root the site.

Smudge
June 26th, 2010, 16:13
RAT? are you kidding me? I would never use a RAT, well it is not my fault that such a stupid vulnerability was left open. I was searching for fuzz LFI vulnerabilities when I found it. Was also looking into creating meterpreter sessions with the host, but I could not get into the kernel of the server to be able to root the site.

Ahh, someone mentioned RAT before; also I think I found you're rltoplist.txt logs. :)

Smudge
June 26th, 2010, 16:16
And how do we know this isn't fake? Just stop posting and leave runelocus and carry on "Hacking" with a basic sql injection. You realy need to grow up. NO ONE HERE CARES IF YOU CAN HACK

It's not fake, I've found the entire log list.

Eduardo
June 26th, 2010, 16:16
Yes, I have published the backup in several places

Lewis
June 26th, 2010, 16:22
Yes, I have published the backup in several places

You must feel very proud that you know how to Sql inject. A 9 year old kid can research it and do it within 24 hours.

Friss
June 26th, 2010, 16:23
This thread is out of hand.