(Augoeides/Hidden Project) Bugs and Glitches

Posts 1–7 of 7 · Page 1 of 1
(Augoeides/Hidden Project) Bugs and Glitches
Since Its exceptionally hard to make a bot for augoeides/hidden project due to certain circumstances

Write down all the bugs and glitches you know that would help us players to playing the game easier
So far I'm running a security audit of augoeides and it has found a potential DOM-based XSS vulnerability in the weekly-update news and a potential SQL injection in the newsboard (so escape all inputs if you're using MySQL and/or MySQLi which is why I recommend PDO since it's much harder to mess up with PDO) and don't forget to use htmlspecialchars in the PHP to combat XSS vulnerabilities
Quote Originally Posted by kchoman View Post
So far I'm running a security audit of augoeides and it has found a potential DOM-based XSS vulnerability in the weekly-update news and a potential SQL injection in the newsboard (so escape all inputs if you're using MySQL and/or MySQLi which is why I recommend PDO since it's much harder to mess up with PDO) and don't forget to use htmlspecialchars in the PHP to combat XSS vulnerabilities
English explanation please? :s
Quote Originally Posted by MGanuslange View Post
English explanation please? :s
He is talking about website vulnerabilities, not related to the game. Unless of course, the exploitation of one of them allows you to access their databases or something along those lines
Yeah, I did not quite get the website talk though, but got a basic idea. I just did not see anything related to the game like glitches, but only exploiting vulnerabilities.
Quote Originally Posted by Biney View Post
He is talking about website vulnerabilities, not related to the game. Unless of course, the exploitation of one of them allows you to access their databases or something along those lines
Not just that, but I've already found sql injections in several AQW private servers because most people just recycle the same vulnerable code that's been around for years.

I've attempted to remedy this by modifying an existing AQW private server to accept PDO and Prepared Statements over MySQLi and Escaped Strings: https://github.com/KimChoJapFan/AQWPS
Quote Originally Posted by kchoman View Post
Not just that, but I've already found sql injections in several AQW private servers because most people just recycle the same vulnerable code that's been around for years.

I've attempted to remedy this by modifying an existing AQW private server to accept PDO and Prepared Statements over MySQLi and Escaped Strings: https://github.com/KimChoJapFan/AQWPSⓘ
This is actually really good tbh, these exploits have been there for like 6 years now.
Posts 1–7 of 7 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us