No more login exploit.

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
Post Reply
User avatar
lolololol
New Member
Posts: 29
Joined: Mon Jul 20, 2009 11:37 am
Quick Reply: Yes
Location: Blah

No more login exploit.

Post by lolololol »

Credits to kaperucito >.>

http://i25.tinypic.com/s6ly15.png

They changed the IP's

User avatar
DotCom
Valued Member
Posts: 497
Joined: Thu Jul 20, 2006 1:44 am
Quick Reply: Yes
Location: Alexander

Re: No more login exploit.

Post by DotCom »

You cant ping the gateways, never could.
Server: Alexander

-=IMPERIAL FOREVER=-

[Quit]

User avatar
xKingpinx
Advanced Member
Posts: 2153
Joined: Wed Aug 29, 2007 8:12 pm
Quick Reply: Yes
Location: Off Topic

Re: No more login exploit.

Post by xKingpinx »

I never used this anyways...but what was it>?
Image

User avatar
lolololol
New Member
Posts: 29
Joined: Mon Jul 20, 2009 11:37 am
Quick Reply: Yes
Location: Blah

Re: No more login exploit.

Post by lolololol »

I know you can't ping them duh...

The point is to look at the NEW IP's

User avatar
Doomsday
Regular Member
Posts: 316
Joined: Sat Apr 04, 2009 5:37 am
Quick Reply: Yes
Location: heaven and hell

Re: No more login exploit.

Post by Doomsday »

lol, this will teach us something important... dk what but I think it's a lesson from JM xD
I'm lazy.

User avatar
TillTheEnd
Valued Member
Posts: 458
Joined: Sat Apr 04, 2009 3:21 pm
Quick Reply: Yes
Location: Valhalla

Re: No more login exploit.

Post by TillTheEnd »

:? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.
Last edited by TillTheEnd on Tue Jul 21, 2009 1:40 pm, edited 1 time in total.
Are you so foolish as to not realize your own impotence? -Freya.
This ritual demands a sacrifice, and I can think of none more enticing than you...,Repent, for death is upon you -Arch Demon.

User avatar
Thomas42
Active Member
Posts: 906
Joined: Wed Jun 18, 2008 6:30 am
Quick Reply: Yes
Location: Budapest, Hungary

Re: No more login exploit.

Post by Thomas42 »

Doomsday wrote:lol, this will teach us something important... dk what but I think it's a lesson from JM xD

They are too lazy to look after their own game. Why would they give us lessons now?
Image
The best way out - is through.

User avatar
lolololol
New Member
Posts: 29
Joined: Mon Jul 20, 2009 11:37 am
Quick Reply: Yes
Location: Blah

Re: No more login exploit.

Post by lolololol »

TillTheEnd wrote::? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.



OMFG theres still only 4 IP's but now they range from .28 to .30 which means youre back on the queue with goldbots.

They didnt add a new one at all, did you even look at the IP's in the ss?

gwgt1 : 121.128.133.29
gwgt2: 121.128.133.30
gwgt3: 121.128.133.28
gwgt4: 121.128.133.29

User avatar
Drew_Benton
Active Member
Posts: 639
Joined: Mon Oct 16, 2006 8:46 pm
Quick Reply: Yes
Location: Texas

Re: No more login exploit.

Post by Drew_Benton »

As long as there is more than one login server to connect to, then you can use the login trick to go to a desired server.

gwgt1.joymax.com -> [121.128.133.29]
gwgt2.joymax.com -> [121.128.133.30]
gwgt3.joymax.com -> [121.128.133.28]
gwgt4.joymax.com -> [121.128.133.29] * Currently maps to gwgt1!

All they did is change the address the host names point to, which is the point of using a named address like "gwgt1.joymax.com" rather than a hard coded IP.

Instead of changing your hosts to go to 121.128.133.29, you would now change it to go to 121.128.133.28, since that is the address that will be least used, theoretically speaking.

All programs that only connect to the first two login servers, gwgt1.joymax.com and gwgt2.joymax.com, will now be connecting to the physical login servers .29 and .30, making .28 the "easy" one.

Since gwgt4 currently points to the physical server .29, which happens to be gwgt1, anyone that modded their hosts to use gwgt4/.29 as the Rev6 guide shows will now go to the main login server with everyone else.

So the correct new version should be (untested, but pretty simple):
121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com

Rather than the old version of:
121.128.133.29 gwgt1.joymax.com
121.128.133.29 gwgt2.joymax.com
121.128.133.29 gwgt3.joymax.com

Notice how since you are connecting to gwgt3 address, you skip that one and change the last octal of the routing address to it. of course, this mapping can change if a server goes down and is brought back up under a different address, so modifying your hosts file is not the best idea unless you how to fix it yourself.

As for any speculations of "getting banned" for this method, it's impossible. Just think about it, if they have their own client setup to connect to 1-4 login addresses based on some condition and you try to connect to one of those legitimate address using the legitimate client, how can they ban you?

The client contains code to detect when the server isn't available and you simply won't be able to login. They have a little dialog that pops up before the login box shows and you can only close the client. If you were using a clientless, then sure, they "could" devise a clever scheme to ban you if you are connecting to their server and you still connect after they send you a packet to not connect, but the game client isn't setup to work like that.

If the server is "up" it means it is connecting connections. Trying to setup a honeypot server to detect people using host file modification or clientless for that matter is not something Joymax would do. It's far easier detecting clientless a number of other ways in the world server and there's no risks of banning legitimate client users that way.

User avatar
lolololol
New Member
Posts: 29
Joined: Mon Jul 20, 2009 11:37 am
Quick Reply: Yes
Location: Blah

Re: No more login exploit.

Post by lolololol »

Thanks Drew. My knowledge only went asfar as knowing the IP's changed.

Thanks. Copied and pasted to other forums too (With credits to you of course)
Last edited by lolololol on Tue Jul 21, 2009 1:57 pm, edited 1 time in total.

User avatar
KylieMinogue
Active Member
Posts: 998
Joined: Tue Dec 25, 2007 9:33 am
Quick Reply: Yes
Location: ♥ ♥ ♥ ♥ ♥

Re: No more login exploit.

Post by KylieMinogue »

Drew_Benton wrote:As long as there is more than one login server to connect to, then you can use the login trick to go to a desired server.

gwgt1.joymax.com -> [121.128.133.29]
gwgt2.joymax.com -> [121.128.133.30]
gwgt3.joymax.com -> [121.128.133.28]
gwgt4.joymax.com -> [121.128.133.29] * Currently maps to gwgt1!

All they did is change the address the host names point to, which is the point of using a named address like "gwgt1.joymax.com" rather than a hard coded IP.

Instead of changing your hosts to go to 121.128.133.29, you would now change it to go to 121.128.133.28, since that is the address that will be least used, theoretically speaking.

All programs that only connect to the first two login servers, gwgt1.joymax.com and gwgt2.joymax.com, will now be connecting to the physical login servers .29 and .30, making .28 the "easy" one.

Since gwgt4 currently points to the physical server .29, which happens to be gwgt1, anyone that modded their hosts to use gwgt4/.29 as the Rev6 guide shows will now go to the main login server with everyone else.

So the correct new version should be (untested, but pretty simple):
121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com

Rather than the old version of:
121.128.133.29 gwgt1.joymax.com
121.128.133.29 gwgt2.joymax.com
121.128.133.29 gwgt3.joymax.com

Notice how since you are connecting to gwgt3 address, you skip that one and change the last octal of the routing address to it. of course, this mapping can change if a server goes down and is brought back up under a different address, so modifying your hosts file is not the best idea unless you how to fix it yourself.

As for any speculations of "getting banned" for this method, it's impossible. Just think about it, if they have their own client setup to connect to 1-4 login addresses based on some condition and you try to connect to one of those legitimate address using the legitimate client, how can they ban you?

The client contains code to detect when the server isn't available and you simply won't be able to login. They have a little dialog that pops up before the login box shows and you can only close the client. If you were using a clientless, then sure, they "could" devise a clever scheme to ban you if you are connecting to their server and you still connect after they send you a packet to not connect, but the game client isn't setup to work like that.

If the server is "up" it means it is connecting connections. Trying to setup a honeypot server to detect people using host file modification or clientless for that matter is not something Joymax would do. It's far easier detecting clientless a number of other ways in the world server and there's no risks of banning legitimate client users that way.


so add this?, just asking to make sure.


121.128.133.28 gwgt1.joymax.com
121.128.133.28 gwgt2.joymax.com
121.128.133.28 gwgt4.joymax.com



instead of the .29 one? on the host file?
Last edited by KylieMinogue on Tue Jul 21, 2009 2:07 pm, edited 1 time in total.
Image
Image
IGN - CrustyEars
level - 1000
guild - The_300

User avatar
TillTheEnd
Valued Member
Posts: 458
Joined: Sat Apr 04, 2009 3:21 pm
Quick Reply: Yes
Location: Valhalla

Re: No more login exploit.

Post by TillTheEnd »

lolololol wrote:
TillTheEnd wrote::? I don't get it, if u were referring to the "exploit" where u can choose that login server, is still there lol, JM actually added a "NEN" login server .30 or replace it with an old 1 idk.



OMFG theres still only 4 IP's but now they range from .28 to .30 which means youre back on the queue with goldbots.

They didnt add a new one at all, did you even look at the IP's in the ss?

gwgt1 : 121.128.133.29
gwgt2: 121.128.133.30
gwgt3: 121.128.133.28
gwgt4: 121.128.133.29


.27 still appears if you check by netstat -n after opening the client, I get .26 .27 .28 .29 .30 ....
Are you so foolish as to not realize your own impotence? -Freya.
This ritual demands a sacrifice, and I can think of none more enticing than you...,Repent, for death is upon you -Arch Demon.

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Re: No more login exploit.

Post by NuclearSilo »

Maybe gwgt5 lol
I've always wondered if the bots use host name to connect or IP to connect. Someone enlighten me?
Playing Age of Wushu, dota IMBA

User avatar
kaperucito
Regular Member
Posts: 308
Joined: Sun Aug 24, 2008 2:30 am
Quick Reply: Yes
Location: Spain
Contact:

Re: No more login exploit.

Post by kaperucito »

Thanks a lot Drew, so the exploit still works, I'm glad to hear it ^_^
Image

User avatar
dorkus
Common Member
Posts: 151
Joined: Mon Jan 15, 2007 3:52 pm
Quick Reply: Yes
Location: Hercules

Re: No more login exploit.

Post by dorkus »

thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg
netstats.joymax1.jpg (68.42 KiB) Viewed 4938 times
Image

User avatar
penfold1992
Senior Member
Posts: 4059
Joined: Sun Apr 22, 2007 9:48 am
Quick Reply: Yes
Location: Uranus

Re: No more login exploit.

Post by penfold1992 »

NuclearSilo wrote:Maybe gwgt5 lol
I've always wondered if the bots use host name to connect or IP to connect. Someone enlighten me?


im pretty sure they search server once they are in game. so it doesnt matter what the server is. just like ours.

they can change the host files and we just follow the location. bot just autoselects location i assume.
no need to configure
Image

User avatar
kaperucito
Regular Member
Posts: 308
Joined: Sun Aug 24, 2008 2:30 am
Quick Reply: Yes
Location: Spain
Contact:

Re: No more login exploit.

Post by kaperucito »

dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg


Only the bots connects to the .26 and .27 actually, both still exists, just Joymax quit the DNS on them, if you are still connected on them when you are login probably you are using a 3rd party program, because them connects to the IP's, not to the DNS. So self-pwned IMHO...

/ONTOPIC
So actually we have...
- gwgt1/4.joymax.com ------> .29
- gwgt2.joymax.com -------> .30
- gwgt3.joymax.com -------> .28

And gateways servers without DNS:

121.128.133.26 \
XXXXXXXXXXXXXX|-----> Used only by bots who connects to Silkroad via IP, not DNS.
121.128.133.27 /

Both of them are online when I send the ping, so are still working.
Image

User avatar
cezzy
Casual Member
Posts: 74
Joined: Mon May 18, 2009 10:13 pm
Quick Reply: Yes
Location: Far far away

Re: No more login exploit.

Post by cezzy »

So can anyone make a clean explanation about that?, i mean as simple as before just add 123.456.789 gwgc.blabla.com to hosts thats all. please? :oops:

User avatar
ezos
New Member
Posts: 26
Joined: Sun Mar 01, 2009 9:43 pm
Quick Reply: Yes
Location: Xian

Re: No more login exploit.

Post by ezos »

dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^
Last edited by ezos on Wed Jul 22, 2009 2:12 am, edited 1 time in total.
100 Pure Int S/S
96 Warrior/Warlock
91 Wizard/Cleric

User avatar
HolyPrinter
New Member
Posts: 39
Joined: Wed Apr 15, 2009 7:59 pm
Quick Reply: Yes
Location: Canada

Re: No more login exploit.

Post by HolyPrinter »

Selfpwn

User avatar
Doomsday
Regular Member
Posts: 316
Joined: Sat Apr 04, 2009 5:37 am
Quick Reply: Yes
Location: heaven and hell

Re: No more login exploit.

Post by Doomsday »

Thomas42 wrote:
Doomsday wrote:lol, this will teach us something important... dk what but I think it's a lesson from JM xD

They are too lazy to look after their own game. Why would they give us lessons now?


That's why I said "dk what".
I think they just have changed the ip address.
I'm lazy.

User avatar
warfire6395
Active Member
Posts: 552
Joined: Fri Feb 08, 2008 5:10 am
Quick Reply: Yes
Location: Persia
Contact:

Re: No more login exploit.

Post by warfire6395 »

ezos wrote:
dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg



running 4 clients? wheeee.


bayum

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Re: No more login exploit.

Post by NuclearSilo »

kaperucito wrote:
dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg


Only the bots connects to the .26 and .27 actually, both still exists, just Joymax quit the DNS on them, if you are still connected on them when you are login probably you are using a 3rd party program, because them connects to the IP's, not to the DNS. So self-pwned IMHO...

/ONTOPIC
So actually we have...
- gwgt1/4.joymax.com ------> .29
- gwgt2.joymax.com -------> .30
- gwgt3.joymax.com -------> .28

And gateways servers without DNS:

121.128.133.26 \
XXXXXXXXXXXXXX|-----> Used only by bots who connects to Silkroad via IP, not DNS.
121.128.133.27 /

Both of them are online when I send the ping, so are still working.

If that's true. Let's say bye bye to whoever connected to .26 and .27 in advance. :D

Edit: anyone's knows what's the IP of bot servers?
Playing Age of Wushu, dota IMBA

User avatar
zShared
Active Member
Posts: 787
Joined: Wed Mar 04, 2009 8:43 pm
Quick Reply: Yes
Location: Lupus

Re: No more login exploit.

Post by zShared »

ezos wrote:
dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^


You're an idiot for a number of reasons.
1. It wasn't 4
2. It wasn't 2, either. It was 3.
3. You got another great forum member banned.

EB ftw.
Someone make me an Aion-related sig and I will give you 5 dollhairs.

User avatar
penfold1992
Senior Member
Posts: 4059
Joined: Sun Apr 22, 2007 9:48 am
Quick Reply: Yes
Location: Uranus

Re: No more login exploit.

Post by penfold1992 »

a great forum member?
sorry a forum member that secretly bots is NOT a great forum member
Image

User avatar
C1ockwork
Common Member
Posts: 122
Joined: Thu Dec 18, 2008 10:10 pm
Quick Reply: Yes
Location: New Hampshire

Re: No more login exploit.

Post by C1ockwork »

penfold1992 wrote:a great forum member?
sorry a forum member that secretly bots is NOT a great forum member



hahahahahha wow
Image

User avatar
ezos
New Member
Posts: 26
Joined: Sun Mar 01, 2009 9:43 pm
Quick Reply: Yes
Location: Xian

Re: No more login exploit.

Post by ezos »

zShared wrote:
ezos wrote:
dorkus wrote:thread failure... i already connected to .26 and .27 today...

screenshot attatched.
netstats.joymax1.jpg



running 4 clients? wheeee.

EDIT: Now that I look at it, it is actually only 2. Still. Nice One. ^^


You're an idiot for a number of reasons.
1. It wasn't 4
2. It wasn't 2, either. It was 3.
3. You got another great forum member banned.

EB ftw.


You are a douchebag for a number of reasons...

1. Its actually 2. He has established connections to 121.128.113.27:15779 and 121.128.113.28:15779.
2. You should of put items 1 and 2 in the same sentence as they were related.
3. I didn't get anyone banned. I just LOL'ed at someones stupidity. I didn't report or any of that shit. I could give a rat's ass if he bots, multi-clients, runs his own gold farming business. This game is dead, who cares really?
4. You write stupid lists like this.
5. His screenshot was proof of multi-clienting only, it was not proof that he bots. So it should just be a 7 day ban.
6. You made ME write a stupid list like this.

Good Day Sir.
100 Pure Int S/S
96 Warrior/Warlock
91 Wizard/Cleric

User avatar
Plovers
Casual Member
Posts: 84
Joined: Fri Aug 08, 2008 8:12 pm
Quick Reply: Yes
Location: Gaia

Re: No more login exploit.

Post by Plovers »

ezos wrote:You are a douchebag for a number of reasons...

1. Its actually 2. He has established connections to 121.128.113.27:15779 and 121.128.113.28:15779.
2. You should of put items 1 and 2 in the same sentence as they were related.
3. I didn't get anyone banned. I just LOL'ed at someones stupidity. I didn't report or any of that shit. I could give a rat's ass if he bots, multi-clients, runs his own gold farming business. This game is dead, who cares really?
4. You write stupid lists like this.
5. His screenshot was proof of multi-clienting only, it was not proof that he bots. So it should just be a 7 day ban.
6. You made ME write a stupid list like this.

Good Day Sir.


ZOMG ZOMG LOL!!!!!!
YOU JUST OWNED EVERYONE IN LIVE HAHAHHAHA<3
Burn your wings.

5x Warlock/Cleric
Tribolt
Server Gaia
(Quite) Active!

Post Reply

Return to “Silkroad General Discussion”