[Plus Emulator] Exploit that nobody can fix...

Resubmitted

Member
Sep 13, 2015
51
4
I'm using the original PlusEMU build and I'm having an issue where people are able to access accounts without entering a password.
This is not the issue with the null check in SSOTicket.cs, as we already patched that.
I've also tried the method mentioned elsewhere of creating a separate table for tickets and deleting them upon login, however the people doing this are still able to.
Is there any other known exploit of this kind that is allowing them to do this?

Literally I've tried all day and night to fix this, but I can't find a solution at all and will be surprised if a solution is even found. Please can anyone tell me if they know how to fix this?

Thanks.
 
@Sledmore
 

Resubmitted

Member
Sep 13, 2015
51
4
I already spoke to the Owner about this.
He has patched the SSO exploit and changed CMS', it's neither of those. I believe it is probably code that a previous developer who originally added RP stuff to the emulator is aware of and knows how to exploit as it is not the CMS or base PlusEmu - but if anyone else has any ideas do share.

Basically what Haidyn said.
 

Joe

Well-Known Member
Jun 10, 2012
4,090
1,918
Without any code how can anybody possibly know, it's quite hard when you're basically not allowing anybody to access the server or see the code itself to search for exploits a previous developer could of added. What you're asking for is basically your thread title, nobody can fix it unless you allow them to.
 

Wickd

The first member of the Knights of the Pink Table
Jan 15, 2013
1,936
612
Without any code how can anybody possibly know, it's quite hard when you're basically not allowing anybody to access the server or see the code itself to search for exploits a previous developer could of added. What you're asking for is basically your thread title, nobody can fix it unless you allow them to.
Like finding a needle in a haystack.
 

Users who are viewing this thread

Top