SWGEmu account hacking?

Researching, Proof of Concepts, Hacking, Console Modding and Hacking and more. No game hacking / modding here.
Post Reply
Thatguy
Newbie..
Newbie..
Posts: 5
Joined: Sun Oct 23, 2011 5:21 am

SWGEmu account hacking?

Post by Thatguy »

I am wanting to hack into this certain persons account on the site swgemu.com account name mym. Just wanting to fuck up his shit on SWGEmu the game. Thanks in advance if you post any tips tools links or anything else!
User avatar
Sethioz
Admin
Admin
Posts: 4762
Joined: Fri Jul 27, 2007 5:11 pm
Custom: Gaming YT > https://youtube.com/SethiozEntertainment
Game Hacking YT > https://youtube.com/sethioz
Game Hacks Store > https://sethioz.com/shopz
Location: unknown
Contact:

Re: SWGEmu account hacking?

Post by Sethioz »

by icon it seems like its vbulletin website systems. they are known to have very few vulnerabilites, don't think its that easy.
you should scan the site with some vulnerability scanners, such as acunetix, and see what comes up.

you can also try using cookie stealer, that way you can target specific ppl. here's a working cookie stealer tutorial:
http://sethioz.com/forum/viewtopic.php? ... 986&p=6230

however i doubt that vbulletin is vulnerable to such cookie stealing attacks, however it might be with their custom design and stuff.

best is to launch attack against website, get their database, then get password hash for the user and crack it. using CUDA GPU project you can easily do 10 million pass per second, which should be quite easy to get to 10 digit passwords.

this kind of site hacking is never that easy. specially with those known site systems, if there is vulnerability, they fix it and vbulletin been out there for years, fixing vulnerabilites that you are trying to find now.
you can always try to optain more details about that user and try sending him/her some trojans or keyloggers hidden inside other programs so they allow it by anti-virus thinking its false positive (program has to work obviously).
Thatguy
Newbie..
Newbie..
Posts: 5
Joined: Sun Oct 23, 2011 5:21 am

Re: SWGEmu account hacking?

Post by Thatguy »

Thanks m8. What does it mean to attack a website? It seems like this works so how do you attack a website? Ill try these asap


What is a cuda gpu project? I searched on website and google but so far all ive gotten is a tool reference is what it looked like from your website. And mostly nvidia graphics card stuff from google. Is any of that what I needed?


Been running the web vulnerability on the website for about 30 minutes... yeah this will take a while. running it over night i guess. nothing now.
User avatar
Sethioz
Admin
Admin
Posts: 4762
Joined: Fri Jul 27, 2007 5:11 pm
Custom: Gaming YT > https://youtube.com/SethiozEntertainment
Game Hacking YT > https://youtube.com/sethioz
Game Hacks Store > https://sethioz.com/shopz
Location: unknown
Contact:

Re: SWGEmu account hacking?

Post by Sethioz »

ffs dude .. this isnt your personal blog or chatroom ! post .. post .. post ... i merged them, but stop doing it !
first think through what you want to post, if you're not sure, use the "save draft" button and later when you're sure what you want to post, submit it.

i don't exactly know how can i even reply to your post, i don't see any questions really.
you can't just pop into it and say "i wanna hack".
first you gotta understand how websites run, based on what. how they use database, where they use it, why ...etc
what language websites use, why, how and other details.

Scan alone won't help you. you need to know how to launch the attack.
i don't think that vbulletin has any simple vulnerabilites tho, its quite good system. as i said, its been out there for years.
simple as that, you gotta read about stuff. like XSS, SQL injections, blind SQL injection, cookie stealing, cloning a page..etc

I would go for a clone page tho, it has good potential if you do it right.
1. you steal the page from official site
2. you modify it and put a keylogger in it
3. you host that keylogged page/site
4. use some freehosting and name the domain like swgemu.com.freehosting1.com
- noone ever looks the full link anyway, at least usually they don't.
5. send spoofed email to the victim (obviously you need his email)
- replicate one of the emails that SWG sends and replace the text saying like:
Hello, blabla1
Recently we have updated our servers and they are now located in two different places and are synchoronized
however we need you to verify your account before it can be synchronized with other server
To do so, please follow the link below and login using your game username and password.
Never give your password to anyone !

- just some general stuff that looks legit

now once your "victim" uses that link to login, your fake page should redirect them to a REAL page and log them in.
that way, he/she would never notice that something happend.
and once you get his/her login, you can send another spoofed email saying "thank you for confirimg blablabla"
so he/she would never suspect anything at all.

However DO NOT start asking me to make any of it, i only gave you the concept.
there are several details you need to work out, like making spoofed email proper and legit, so it wouldnt end up in junk or spam.
putting keylogger into a stolen page requires some php/html knowledge too + you need to get a php/html based keylogger first.
or more like form logger, logs whatever you input. and then also make it redirect and make it login in the real place.

nVidia CUDA project is something they started 1-2 years ago, its ability to use GPU as CPU, giving insane power in calculations.
first search i did on wiki and i found the article...how is it possible you didn't find it ?
Thatguy
Newbie..
Newbie..
Posts: 5
Joined: Sun Oct 23, 2011 5:21 am

Re: SWGEmu account hacking?

Post by Thatguy »

Im sorry im still new and dont know how this forum works. Ill figure it out

How do I clone the page? Does this just mean to copy what they have on the page to my freehosting site?

Shit I have everything figured out now but dont know his email... Ill figure it out. I think

Damnit you know I hate to be a quitter but I just dont know half this stuff. Ill need to research all this for a while sethoiz. Maybe ill get back to you one day if I figure it out. I like your site so ill use this account quite a bit for research. Thanks m8!
User avatar
Sethioz
Admin
Admin
Posts: 4762
Joined: Fri Jul 27, 2007 5:11 pm
Custom: Gaming YT > https://youtube.com/SethiozEntertainment
Game Hacking YT > https://youtube.com/sethioz
Game Hacks Store > https://sethioz.com/shopz
Location: unknown
Contact:

Re: SWGEmu account hacking?

Post by Sethioz »

it works the way that there is no need to please and thank you. if you want to thank > donate (or open a new thread to talk about yourself and website or me)
to me, saying thanks and please is just unneccesary and waste of space, i want to keep topic clean and clear, just in topic and nothing else.

clone a page = copy page
you just go to the page you want and in your browser you just click "save page as..."
in firefox, you can save page as complete, that includes all the images and stuff, while still being connected to original site.
then you just modify the code by adding a keylogger in it and then drop it on freehosting. note that you will get banned for this if freehosting notices it.
so better use some "shadow" account that you don't need anymore. ive had fake pages up for years and nothing happend, while some get deleted after few days.
ive also used formmail, it means it sends you an email whenever someone enters details on that fake page.

there is good topic about spoofed emailing here:
http://sethioz.com/forum/viewtopic.php?f=47&t=1077

this script allows you to spoof emails, it might need some tweaking tho.
Post Reply