Silkroad Online Forums

A community forum for the free online game Silkroad Online. Discuss Silkroad Online, read up on guides, and build your character and skills.

Faq Search Members Chat  Register Profile Login

All times are UTC




Post new topic Reply to topic  [ 28 posts ] 
Author Message
 Post subject: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:06 pm 
New Member
User avatar
Offline

Joined: Jul 2009
Posts: 29
Location: Blah
Credits to kaperucito >.>

http://i25.tinypic.com/s6ly15.png

They changed the IP's


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:18 pm 
Valued Member
User avatar
Offline

Joined: Jul 2006
Posts: 497
Location:
Alexander
You cant ping the gateways, never could.

_________________
Server: Alexander

-=IMPERIAL FOREVER=-

[Quit]


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:19 pm 
Advanced Member
User avatar
Offline

Joined: Aug 2007
Posts: 2153
Location:
Off Topic
I never used this anyways...but what was it>?

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:21 pm 
New Member
User avatar
Offline

Joined: Jul 2009
Posts: 29
Location: Blah
I know you can't ping them duh...

The point is to look at the NEW IP's


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:32 pm 
Regular Member
User avatar
Offline

Joined: Apr 2009
Posts: 316
Location: heaven and hell
lol, this will teach us something important... dk what but I think it's a lesson from JM xD

_________________
I'm lazy.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:37 pm 
Valued Member
User avatar
Offline

Joined: Apr 2009
Posts: 458
Location: Valhalla
:? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.

_________________
Are you so foolish as to not realize your own impotence? -Freya.
This ritual demands a sacrifice, and I can think of none more enticing than you...,Repent, for death is upon you -Arch Demon.


Last edited by TillTheEnd on Tue Jul 21, 2009 1:40 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:38 pm 
Active Member
User avatar
Offline

Joined: Jun 2008
Posts: 906
Location: Budapest, Hungary
Doomsday wrote:
lol, this will teach us something important... dk what but I think it's a lesson from JM xD

They are too lazy to look after their own game. Why would they give us lessons now?

_________________
Image
The best way out - is through.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:45 pm 
New Member
User avatar
Offline

Joined: Jul 2009
Posts: 29
Location: Blah
TillTheEnd wrote:
:? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.



OMFG theres still only 4 IP's but now they range from .28 to .30 which means youre back on the queue with goldbots.

They didnt add a new one at all, did you even look at the IP's in the ss?

gwgt1 : 121.128.133.29
gwgt2: 121.128.133.30
gwgt3: 121.128.133.28
gwgt4: 121.128.133.29


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:51 pm 
Active Member
User avatar
Offline

Joined: Oct 2006
Posts: 639
Location: Texas
As long as there is more than one login server to connect to, then you can use the login trick to go to a desired server.

gwgt1.joymax.com -> [121.128.133.29]
gwgt2.joymax.com -> [121.128.133.30]
gwgt3.joymax.com -> [121.128.133.28]
gwgt4.joymax.com -> [121.128.133.29] * Currently maps to gwgt1!

All they did is change the address the host names point to, which is the point of using a named address like "gwgt1.joymax.com" rather than a hard coded IP.

Instead of changing your hosts to go to 121.128.133.29, you would now change it to go to 121.128.133.28, since that is the address that will be least used, theoretically speaking.

All programs that only connect to the first two login servers, gwgt1.joymax.com and gwgt2.joymax.com, will now be connecting to the physical login servers .29 and .30, making .28 the "easy" one.

Since gwgt4 currently points to the physical server .29, which happens to be gwgt1, anyone that modded their hosts to use gwgt4/.29 as the Rev6 guide shows will now go to the main login server with everyone else.

So the correct new version should be (untested, but pretty simple):
121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com

Rather than the old version of:
121.128.133.29 gwgt1.joymax.com
121.128.133.29 gwgt2.joymax.com
121.128.133.29 gwgt3.joymax.com

Notice how since you are connecting to gwgt3 address, you skip that one and change the last octal of the routing address to it. of course, this mapping can change if a server goes down and is brought back up under a different address, so modifying your hosts file is not the best idea unless you how to fix it yourself.

As for any speculations of "getting banned" for this method, it's impossible. Just think about it, if they have their own client setup to connect to 1-4 login addresses based on some condition and you try to connect to one of those legitimate address using the legitimate client, how can they ban you?

The client contains code to detect when the server isn't available and you simply won't be able to login. They have a little dialog that pops up before the login box shows and you can only close the client. If you were using a clientless, then sure, they "could" devise a clever scheme to ban you if you are connecting to their server and you still connect after they send you a packet to not connect, but the game client isn't setup to work like that.

If the server is "up" it means it is connecting connections. Trying to setup a honeypot server to detect people using host file modification or clientless for that matter is not something Joymax would do. It's far easier detecting clientless a number of other ways in the world server and there's no risks of banning legitimate client users that way.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:54 pm 
New Member
User avatar
Offline

Joined: Jul 2009
Posts: 29
Location: Blah
Thanks Drew. My knowledge only went asfar as knowing the IP's changed.

Thanks. Copied and pasted to other forums too (With credits to you of course)


Last edited by lolololol on Tue Jul 21, 2009 1:57 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 1:56 pm 
Active Member
User avatar
Offline

Joined: Dec 2007
Posts: 998
Location: ♥ ♥ ♥ ♥ ♥
Drew_Benton wrote:
As long as there is more than one login server to connect to, then you can use the login trick to go to a desired server.

gwgt1.joymax.com -> [121.128.133.29]
gwgt2.joymax.com -> [121.128.133.30]
gwgt3.joymax.com -> [121.128.133.28]
gwgt4.joymax.com -> [121.128.133.29] * Currently maps to gwgt1!

All they did is change the address the host names point to, which is the point of using a named address like "gwgt1.joymax.com" rather than a hard coded IP.

Instead of changing your hosts to go to 121.128.133.29, you would now change it to go to 121.128.133.28, since that is the address that will be least used, theoretically speaking.

All programs that only connect to the first two login servers, gwgt1.joymax.com and gwgt2.joymax.com, will now be connecting to the physical login servers .29 and .30, making .28 the "easy" one.

Since gwgt4 currently points to the physical server .29, which happens to be gwgt1, anyone that modded their hosts to use gwgt4/.29 as the Rev6 guide shows will now go to the main login server with everyone else.

So the correct new version should be (untested, but pretty simple):
121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com

Rather than the old version of:
121.128.133.29 gwgt1.joymax.com
121.128.133.29 gwgt2.joymax.com
121.128.133.29 gwgt3.joymax.com

Notice how since you are connecting to gwgt3 address, you skip that one and change the last octal of the routing address to it. of course, this mapping can change if a server goes down and is brought back up under a different address, so modifying your hosts file is not the best idea unless you how to fix it yourself.

As for any speculations of "getting banned" for this method, it's impossible. Just think about it, if they have their own client setup to connect to 1-4 login addresses based on some condition and you try to connect to one of those legitimate address using the legitimate client, how can they ban you?

The client contains code to detect when the server isn't available and you simply won't be able to login. They have a little dialog that pops up before the login box shows and you can only close the client. If you were using a clientless, then sure, they "could" devise a clever scheme to ban you if you are connecting to their server and you still connect after they send you a packet to not connect, but the game client isn't setup to work like that.

If the server is "up" it means it is connecting connections. Trying to setup a honeypot server to detect people using host file modification or clientless for that matter is not something Joymax would do. It's far easier detecting clientless a number of other ways in the world server and there's no risks of banning legitimate client users that way.


so add this?, just asking to make sure.


121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com



instead of the .29 one? on the host file?

_________________
Image
Image
IGN - CrustyEars
level - 1000
guild - The_300


Last edited by KylieMinogue on Tue Jul 21, 2009 2:07 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 2:06 pm 
Valued Member
User avatar
Offline

Joined: Apr 2009
Posts: 458
Location: Valhalla
lolololol wrote:
TillTheEnd wrote:
:? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.



OMFG theres still only 4 IP's but now they range from .28 to .30 which means youre back on the queue with goldbots.

They didnt add a new one at all, did you even look at the IP's in the ss?

gwgt1 : 121.128.133.29
gwgt2: 121.128.133.30
gwgt3: 121.128.133.28
gwgt4: 121.128.133.29


.27 still appears if you check by netstat -n after opening the client, I get .26 .27 .28 .29 .30 ....

_________________
Are you so foolish as to not realize your own impotence? -Freya.
This ritual demands a sacrifice, and I can think of none more enticing than you...,Repent, for death is upon you -Arch Demon.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 2:51 pm 
Forum God
User avatar
Offline

Joined: Aug 2006
Posts: 8834
Location: Age of Wushu
Maybe gwgt5 lol
I've always wondered if the bots use host name to connect or IP to connect. Someone enlighten me?

_________________
Playing Age of Wushu, dota IMBA


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 2:56 pm 
Banned User
User avatar
Offline

Joined: Aug 2008
Posts: 308
Location: Spain
Thanks a lot Drew, so the exploit still works, I'm glad to hear it ^_^

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 3:14 pm 
Banned User
User avatar
Offline

Joined: Jan 2007
Posts: 151
Location:
Hercules
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg
netstats.joymax1.jpg [ 68.42 KiB | Viewed 6979 times ]

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 3:31 pm 
Senior Member
User avatar
Offline

Joined: Apr 2007
Posts: 4060
Location:
Uranus
NuclearSilo wrote:
Maybe gwgt5 lol
I've always wondered if the bots use host name to connect or IP to connect. Someone enlighten me?


im pretty sure they search server once they are in game. so it doesnt matter what the server is. just like ours.

they can change the host files and we just follow the location. bot just autoselects location i assume.
no need to configure

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 5:50 pm 
Banned User
User avatar
Offline

Joined: Aug 2008
Posts: 308
Location: Spain
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg


Only the bots connects to the .26 and .27 actually, both still exists, just Joymax quit the DNS on them, if you are still connected on them when you are login probably you are using a 3rd party program, because them connects to the IP's, not to the DNS. So self-pwned IMHO...

/ONTOPIC
So actually we have...
- gwgt1/4.joymax.com ------> .29
- gwgt2.joymax.com -------> .30
- gwgt3.joymax.com -------> .28

And gateways servers without DNS:

121.128.133.26 \
XXXXXXXXXXXXXX|-----> Used only by bots who connects to Silkroad via IP, not DNS.
121.128.133.27 /

Both of them are online when I send the ping, so are still working.

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 7:42 pm 
Casual Member
User avatar
Offline

Joined: May 2009
Posts: 74
Location: Far far away
So can anyone make a clean explanation about that?, i mean as simple as before just add 123.456.789 gwgc.blabla.com to hosts thats all. please? :oops:


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 7:49 pm 
New Member
User avatar
Offline

Joined: Mar 2009
Posts: 26
Location:
Xian
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^

_________________
100 Pure Int S/S
96 Warrior/Warlock
91 Wizard/Cleric


Last edited by ezos on Wed Jul 22, 2009 2:12 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 8:05 pm 
New Member
User avatar
Offline

Joined: Apr 2009
Posts: 39
Location: Canada
Selfpwn


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 8:37 pm 
Regular Member
User avatar
Offline

Joined: Apr 2009
Posts: 316
Location: heaven and hell
Thomas42 wrote:
Doomsday wrote:
lol, this will teach us something important... dk what but I think it's a lesson from JM xD

They are too lazy to look after their own game. Why would they give us lessons now?


That's why I said "dk what".
I think they just have changed the ip address.

_________________
I'm lazy.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Tue Jul 21, 2009 10:46 pm 
Active Member
User avatar
Offline

Joined: Feb 2008
Posts: 552
Location:
Persia
ezos wrote:
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg



running 4 clients? wheeee.


bayum


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Wed Jul 22, 2009 4:15 am 
Forum God
User avatar
Offline

Joined: Aug 2006
Posts: 8834
Location: Age of Wushu
kaperucito wrote:
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg


Only the bots connects to the .26 and .27 actually, both still exists, just Joymax quit the DNS on them, if you are still connected on them when you are login probably you are using a 3rd party program, because them connects to the IP's, not to the DNS. So self-pwned IMHO...

/ONTOPIC
So actually we have...
- gwgt1/4.joymax.com ------> .29
- gwgt2.joymax.com -------> .30
- gwgt3.joymax.com -------> .28

And gateways servers without DNS:

121.128.133.26 \
XXXXXXXXXXXXXX|-----> Used only by bots who connects to Silkroad via IP, not DNS.
121.128.133.27 /

Both of them are online when I send the ping, so are still working.

If that's true. Let's say bye bye to whoever connected to .26 and .27 in advance. :D

Edit: anyone's knows what's the IP of bot servers?

_________________
Playing Age of Wushu, dota IMBA


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Wed Jul 22, 2009 12:56 pm 
Active Member
User avatar
Offline

Joined: Mar 2009
Posts: 787
Location: Lupus
ezos wrote:
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^


You're an idiot for a number of reasons.
1. It wasn't 4
2. It wasn't 2, either. It was 3.
3. You got another great forum member banned.

EB ftw.

_________________
Someone make me an Aion-related sig and I will give you 5 dollhairs.


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Wed Jul 22, 2009 1:26 pm 
Senior Member
User avatar
Offline

Joined: Apr 2007
Posts: 4060
Location:
Uranus
a great forum member?
sorry a forum member that secretly bots is NOT a great forum member

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Wed Jul 22, 2009 1:33 pm 
Banned User
User avatar
Offline

Joined: Dec 2008
Posts: 122
Location: New Hampshire
penfold1992 wrote:
a great forum member?
sorry a forum member that secretly bots is NOT a great forum member



hahahahahha wow

_________________
Image


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Wed Jul 22, 2009 3:40 pm 
New Member
User avatar
Offline

Joined: Mar 2009
Posts: 26
Location:
Xian
zShared wrote:
ezos wrote:
dorkus wrote:
thread failure... i already connected to .26 and .27 today...

screenshot attatched.
Attachment:
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^


You're an idiot for a number of reasons.
1. It wasn't 4
2. It wasn't 2, either. It was 3.
3. You got another great forum member banned.

EB ftw.


You are a douchebag for a number of reasons...

1. Its actually 2. He has established connections to 121.128.113.27:15779 and 121.128.113.28:15779.
2. You should of put items 1 and 2 in the same sentence as they were related.
3. I didn't get anyone banned. I just LOL'ed at someones stupidity. I didn't report or any of that shit. I could give a rat's ass if he bots, multi-clients, runs his own gold farming business. This game is dead, who cares really?
4. You write stupid lists like this.
5. His screenshot was proof of multi-clienting only, it was not proof that he bots. So it should just be a 7 day ban.
6. You made ME write a stupid list like this.

Good Day Sir.

_________________
100 Pure Int S/S
96 Warrior/Warlock
91 Wizard/Cleric


Top
 Profile  
 
 Post subject: Re: No more login exploit.
PostPosted: Sun Aug 09, 2009 2:07 pm 
Casual Member
User avatar
Offline

Joined: Aug 2008
Posts: 84
Location:
Gaia
ezos wrote:
You are a douchebag for a number of reasons...

1. Its actually 2. He has established connections to 121.128.113.27:15779 and 121.128.113.28:15779.
2. You should of put items 1 and 2 in the same sentence as they were related.
3. I didn't get anyone banned. I just LOL'ed at someones stupidity. I didn't report or any of that shit. I could give a rat's ass if he bots, multi-clients, runs his own gold farming business. This game is dead, who cares really?
4. You write stupid lists like this.
5. His screenshot was proof of multi-clienting only, it was not proof that he bots. So it should just be a 7 day ban.
6. You made ME write a stupid list like this.

Good Day Sir.


ZOMG ZOMG LOL!!!!!!
YOU JUST OWNED EVERYONE IN LIVE HAHAHHAHA<3

_________________
Burn your wings.

5x Warlock/Cleric
Tribolt
Server Gaia
(Quite) Active!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 28 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users and 15 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group