OutdatedFinding exploits in addons

Posts 1–5 of 5 · Page 1 of 1
Finding exploits in addons
First thing before beginning, get your self an IDE to edit/create lua files (For lua in gmod you have two common solutions):
- Notepad++
- Sublime Text
- Or any other text editor if you have a preference

Note! There is a plugin for notepad++ "gmod lua lexar" it just highlights any code that garry's mod adds so that you know what code you're typing actually exists. So install that if you like.

Secondly you need to be able to see what addons the server has, and any console commands or net messages that the addon uses. To get this, do a quick browse on the forum for scripthook. This is a simple dll, all you need to do to use it is get a dll injector and open it up. For most injectors you select a process which is hl2.exe and then select a dll which would be scripthook. This process is usually done whilst you are in the main menu. After you have injected, any server you join will create a new folder with the server's ip in the directory C:/Program Files (x86)/Steam/steamapps/common/Garry's Mod/scripthook/

To find addons navigate to the scripthook folder and you should find the ip of the server you joined then proceed to open the addons folder. These are all the addons on the server.

There are a lot of newbies out there when it comes to code. So I am gonna give you the information that everyone comes here seeking.
Open the addons folder of the server you want, you are going to need to search every lua file in this directory so it's best if your editor has a feature to search all files. With Notepad++ you can do ctrl+f and select the Find in Files tab. Just select the addons directory and you want to search for "net.Start".

You will get results that may appear like so:
Code:
net.Start( "action_addon_isdoing" )
net.WriteString( "Some text" )
net.WriteFloat( 200 )
net.SendToServer()
Pretty much this is the player communicating with the server, and the server responds appropriately most of the time. But in rare cases when the addon has been coded by a potato there are going to be exploits. The net.start is just starting a conversation with the server, it is followed by net.WriteString( "Some text" ) which is to send some data which is text to the server, it is going to be read on the server and acted upon later. net.WriteFloat( 200 ) A Float is a specific type of number, but you don't really need to worry about that. The important thing is it is a number and number often means money if it is this high usually. net.SendToServer() compiles all of the conversation together and sends it to the server.

So pretty much if you see a net.Start that has net.WriteInt, net.WriteFloat, net.WriteLong ( These are just different ways of saying number ) check what is in the brackets.

So if you see net.WriteInt( price, 4 ) or net.WriteFloat( price ) etc.
There is not always going to be an exact number like 200, it could be a variable eg. price so you could see net.WriteFloat( 200 ) or net.WriteFloat( price )

You have to be perceptive and have an understanding of what's going on around the code that the net.Start is being called around.

This same process should be repeated for console commands, so search all the files for RunConsoleCommand. When you find a console command it may look like this:

RunConsoleCommand( "shop", "buy", "Ak 47", 50 )
This just runs the shop command with 3 parameters, this is an unlikely to occur realistically but it allows for you to visdualize an example.

Ok, so now that you have found the exploit how do you code it? Where to put it? And how to execute it?
Well in your lua folder create a new lua, it's best to name this something that isn't suspicious so just make it file.lua for the lolz.
And paste the net.Start in here with your modified values.

For instance if the code was originally:
Code:
net.Start( "shittyaddon" )
net.WriteString( "Buy" )
net.WriteInt( variable_item,4 )
net.WriteInt( variable_price,8 )
net.SendToServer()
You would be a complete beast and know that the addon is most likely exploitable considering you tell the server what the price of the item is. So you would change it to remove any variables and make sure to do a negative price so that it adds money.

Code:
net.Start( "shittyaddon" )
net.WriteString( "Buy" )
net.WriteInt( 1,4 )
net.WriteInt( -1000,8 )
net.SendToServer()
This will buy item "1" for "-1000" thus give you the item from the shitty addon and adding 1000 to your wallet theoretically. So once that is in your lua folder you can go to the server and open the console in-game with ~. To execute a lua script type lua_openscript_cl file.lua. If it said it was executed you're in the green, else you're going to have to get a bypasser not too hard to find one on mpgh so yeah.

For console commands just execute them in console like you normally would eg for RunConsoleCommand( "shop", "buy", "Ak 47", 50 ):
Just type in console "shop buy shittytext -50"

I know this may not be clear and it is unorganized but the information is there, some people may get it most may not. I am sorry and no problem to anyone that appreciates it. PM me if you have any trouble or just want to ask some questions. - Peace
xoxo I is wannabe at best.
IMO, that's a better post to learn from.
Moved to correct section
Posts 1–5 of 5 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us