Welcome to AC Web.
Results 1 to 9 of 9
  1. #1

    Authentication bypass exploits for 1.12.1, 2.4.3 and 3.3.5a servers


    REGISTER! (FREE)
    Registered members see less ads
    and also gain access to other great features.
    In early November of 2016, I privately disclosed to any private server developer who would listen to me two different authentication bypass issues. One was discovered by Chaosvex, the other by Daemon. A week or two later, I pushed public fixes for these issues to cmangos.

    It is now the middle of March 2017 and some private servers have not fixed their servers. I have decided to release an open-source exploit for these issues. That exploit is here: GitHub - namreeb/wowned: Authentication bypass for outdated WoW emulation authentication servers

    There are pre-compiled binaries for this exploit under 'Releases' here: Releases * namreeb/wowned * GitHub

    Enjoy!

  2. #2
    Very interesting. As soon as I saw this im pretty sure the server I was playing on made a hot fix.

  3. #3
    Suprised people didn't see the flaw in the first place

  4. #4
    Hi
    i don't really understand how it works ! can you explain a bit more ?

  5. #5
    lol, I'm surprised that you didn't release this sooner.

    Only problem is there are a lot of NEW server owners who are unaware of the problem/fix maybe post the fix again with this? I mean just so some people who didn't see the thread and who don't have the knowledge to fix this them self could have a fighting chance.

  6. #6
    But what is the actually exploit allowing you to do?

  7. #7
    @DeadRage: The fix is easy: get latest revision of tc (mangos fixed this long time ago). If you use a repack for a public project and the repackcreator isn't updating it then now is the time to learn building a core yourself (meaning the new server owners)

    @hsoares: It allows you to login to every account on this server without knowing the password

  8. #8
    u dont know how fun is it.. i log ppl's account lol..

  9. #9


    Join Date
    Jan 2014
    Location
    https://www.cruel-wow.net
    Posts
    1,477

    REGISTER! (FREE)
    Registered members see less ads
    and also gain access to other great features.
    Quote Originally Posted by DeadRage ^.^ View Post
    lol, I'm surprised that you didn't release this sooner.

    Only problem is there are a lot of NEW server owners who are unaware of the problem/fix maybe post the fix again with this? I mean just so some people who didn't see the thread and who don't have the knowledge to fix this them self could have a fighting chance.
    https://github.com/cmangos/mangos-cl...6e7473cb8e2601 - Definetely the most advanced way
    https://github.com/cmangos/mangos-cl...daba5121467383 - Easiest / Fastest


 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •