Page 1 of 2 12 LastLast
Results 1 to 15 of 26
  1. #1
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic

    Exclamation CF SEA admin accounts.

    Hey,

    I've no idea where I can post this of I'm even allowed to post it, but the protection of CF SEA's we website is so bad..

    CF SEA Admin accounts: (MD5 protected, I've no idea where the actual admin login is..)
    https://pastebin.com/XJNE7F0H (Separated by line breaks.)
    Databases: (Hashed passwords !)
    root:*568A8C07FA1D98D3CC10B46FFE52B3A019EB353F:loc alhost
    root:*07F94955AD26E2F0FF20E4444A2F37C87CDB241C:vL-WEB-DB-02
    root:*07F94955AD26E2F0FF20E4444A2F37C87CDB241C:127 .0.0.1
    root:*07F94955AD26E2F0FF20E4444A2F37C87CDB241C:::1
    root:*568A8C07FA1D98D3CC10B46FFE52B3A019EB353F:%
    sgsea_root:*2E1604C3ADEE7C57AF9AB81363B078D7182ACF 1A:%
    sgsea_app:*2E1604C3ADEE7C57AF9AB81363B078D7182ACF1 A:172.16.80.106
    mogile:*A1F1B2A7F3B2C124AE91B424477A6AC49A3D6C4B:%
    zuyao.chin:*83A66AC4E6709FD211392432EAD4F0DDB865D5 50:%
    myrepl:*568A8C07FA1D98D3CC10B46FFE52B3A019EB353F:%

    There are also >200.000 IP's and E-mail adresses in the database, but it takes too long for me :P.

    Please close this topic if it isn't allowed.
    Poedeltje.
    Last edited by poedeltje; 05-16-2014 at 07:14 PM.




  2. The Following 2 Users Say Thank You to poedeltje For This Useful Post:

    Purple. (05-17-2014),Sheep (05-17-2014)

  3. #2
    Paradoxium's Avatar
    Join Date
    May 2014
    Gender
    male
    Location
    The world 0_o
    Posts
    24
    Reputation
    10
    Thanks
    1
    My Mood
    Pensive
    woahh not even going to though... might want to let them know...
    Contact:
    Skype: LeParadoxium

  4. #3
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic
    Quote Originally Posted by Paradoxium View Post
    woahh not even going to though... might want to let them know...
    I already did, but isn't it bad that a game like this has so much vulnerabilities?




  5. #4
    Paradoxium's Avatar
    Join Date
    May 2014
    Gender
    male
    Location
    The world 0_o
    Posts
    24
    Reputation
    10
    Thanks
    1
    My Mood
    Pensive
    Quote Originally Posted by poedeltje View Post


    I already did, but isn't it bad that a game like this has so much vulnerabilities?
    Oh yeah, its due to bad webmasters. They probably wanted to save money and outsourced their webmaster.
    Contact:
    Skype: LeParadoxium

  6. #5
    quanschink's Avatar
    Join Date
    Jul 2011
    Gender
    male
    Posts
    368
    Reputation
    10
    Thanks
    36
    My Mood
    Sneaky
    Damn I thought it was CF NA @poedeltje When are you releasing CF NA accounts?

  7. #6
    Purple.'s Avatar
    Join Date
    Aug 2012
    Gender
    male
    Location
    R.Moldova
    Posts
    1,308
    Reputation
    20
    Thanks
    882
    My Mood
    Crappy
    well, Thanks for Share )

  8. #7
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic
    I may be able to get free redeem codes.
    https://redemption.gambooz.com/item_claim/CFSEA




  9. #8
    Ima?'s Avatar
    Join Date
    Dec 2012
    Gender
    male
    Location
    Εξάρχεια
    Posts
    873
    Reputation
    146
    Thanks
    195
    My Mood
    Bitchy
    Can you explain me please what exactly is that?

  10. #9
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic
    Quote Originally Posted by Ima? View Post
    Can you explain me please what exactly is that?
    Administrator accounts of https://cf.gambooz.com/, but I've no idea where the admin login page is.




  11. #10
    Delta[X]'s Avatar
    Join Date
    Sep 2011
    Gender
    male
    Location
    France
    Posts
    449
    Reputation
    53
    Thanks
    49
    My Mood
    Sleepy
    These aren't MD5 hashes but MySQL5 hashes
    Oppa Delta style !

  12. #11
    -Ben's Avatar
    Join Date
    Jun 2013
    Gender
    male
    Posts
    1,174
    Reputation
    72
    Thanks
    68
    wait, i dont get it. Are they free accounts? or..
    Skype: someninjamut1
    MSN: whytrympgh@live.com


    Successful trades. 50+

    1 - Jack.hook
    1 - TheLudWick
    2 - Leagueoflegendsrocks
    2 - Fight of my life
    2 - Unit113
    1 - Misoman
    3 - Crazybloo
    1 - Chad911
    1 - Atlantafalcons
    3 - isSUR
    1 - ok1234
    4 - Wassabi
    1 - Ezreal Brah
    1 - vendetta140
    3 - maxedout
    1 - Dracojacky
    2 - Poxer
    3 - Lavigne
    1 - BurningAshes
    1 - Greenone9
    3 - [k]iltz
    2 - Ck0910
    3 - Datass0
    1 - InSane-Skillz
    1 - Dreamer.Jr
    1 - hl611999
    1 - hoping
    1 - notrace2me

  13. #12
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic
    @-Ben administrator accounts of CF SEA.




  14. #13
    Delta[X]'s Avatar
    Join Date
    Sep 2011
    Gender
    male
    Location
    France
    Posts
    449
    Reputation
    53
    Thanks
    49
    My Mood
    Sleepy
    I want to point out that you can't use these db credentials -even if you manage to decrypt the hashed passwords-, you wouldn't be able to log in because it's localhost.
    You'd have to be part of their local network to access their database.

    For example, it's like you were trying to connect to my router by typing "192.168.1.1" in your url bar, no, it won't connect to mine but yours.

    You can use those accounts https://pastebin.com/XJNE7F0H but the (decrypted) passwords seems to be incorrect... I guess they changed them already, or the data you gathered was bullshit honeypot.. it would explains why most of all the passwords are "123456" or "123@#456" crap
    Last edited by Delta[X]; 05-19-2014 at 07:44 AM.
    Oppa Delta style !

  15. #14
    poedeltje's Avatar
    Join Date
    May 2010
    Gender
    male
    Posts
    817
    Reputation
    10
    Thanks
    454
    My Mood
    Psychedelic
    Quote Originally Posted by Delta[X] View Post
    I want to point out that you can't use these db credentials -even if you manage to decrypt the hashed passwords-, you wouldn't be able to log in because it's localhost.
    You'd have to be part of their local network to access their database.

    For example, it's like you were trying to connect to my router by typing "192.168.1.1" in your url bar, no, it won't connect to mine but yours.

    You can use those accounts https://pastebin.com/XJNE7F0H but the (decrypted) passwords seems to be incorrect... I guess they changed them already, or the data you gathered was bullshit honeypot.. it would explains why most of all the passwords are "123456" or "123@#456" crap
    It's actually not localhost, you are acting like someone that doesn't know anything about this sort of things.

    https://cf.gambooz.com/cfsea/weapons_...9;AssaultRifle

    Please can you please stop talking crap now that you read on the internet.


    //FYI take a look at the database called `db_admin`.
    Last edited by poedeltje; 05-19-2014 at 08:24 AM.




  16. #15
    Delta[X]'s Avatar
    Join Date
    Sep 2011
    Gender
    male
    Location
    France
    Posts
    449
    Reputation
    53
    Thanks
    49
    My Mood
    Sleepy
    root:*568A8C07FA1D98D3CC10B46FFE52B3A019EB353F:loc alhost
    root:*07F94955AD26E2F0FF20E4444A2F37C87CDB241C:vL-WEB-DB-02
    root:*07F94955AD26E2F0FF20E4444A2F37C87CDB241C:127 .0.0.1

    This is localhost

    sgsea_app:*2E1604C3ADEE7C57AF9AB81363B078D7182ACF1 A:172.16.80.106

    This is local network

    And I guess it's the same with the other. You seems to know more about the subject than me, then just log in, if you can.

    https://cf.gambooz.com/cfsea/weapons_...27AssaultRifle
    This is SQL injection, I know that. You may use the credentials from pastebin but not the root credentials

    edit: oh, guess what I found, a XSS vulnerability. You don't even need to "decrypt" the hashes, just steal the staff cookies and then mess with the website...
    Last edited by Delta[X]; 05-19-2014 at 01:16 PM.
    Oppa Delta style !

Page 1 of 2 12 LastLast

Similar Threads

  1. Selling Dragon Nest SEA Pala Account SpringWood
    By tyxben in forum Dragon Nest Selling / Trading / Buying
    Replies: 4
    Last Post: 09-26-2011, 02:25 PM
  2. Selling DN SEA Westwood Account Paladin +8 Ancient set & +9 ancient Flail.
    By dharnex in forum Dragon Nest Selling / Trading / Buying
    Replies: 0
    Last Post: 09-22-2011, 08:55 PM
  3. Selling Dragon Nest SEA (Springwood) Account 5000g worth.
    By 31314567 in forum Dragon Nest Selling / Trading / Buying
    Replies: 8
    Last Post: 09-19-2011, 10:26 AM
  4. Selling Dragon Nest SEA (Springwood) Account 5000g worth.
    By 31314567 in forum Selling Accounts/Keys/Items
    Replies: 0
    Last Post: 09-07-2011, 06:05 AM
  5. [Tutorial] How to make a WarRock Admin Account (Fake)
    By Snape in forum WarRock Discussions
    Replies: 15
    Last Post: 03-15-2010, 11:34 AM

Tags for this Thread