![]() |
|
Account Generator --DEAD-- - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: Visual Basic & .NET Framework (https://sinister.li/Forum-Visual-Basic-NET-Framework) +--- Thread: Account Generator --DEAD-- (/Thread-Account-Generator-DEAD) |
RE: Account Generator (Crack proof!) Need Testers! - Killpot - 11-06-2015 (11-06-2015, 01:35 AM)God Wrote: Just tested and started debugging and oh my, such bad, much stupid. Hmm, yeah I suppose I could do that, wouldn't be very hard, I don't see much of a flaw though, even though the password and username are stored in plain text on the client. So what? It's not compromising the server if someone gets his/her login from their own computer, like say a RAT, I'm not going to protect them from them selves. Really this isn't much, all you've done is just looked at the XML that's stored locally from settings, nothing groundbreaking. The only reason I can think of for encrypting the passwords client side, (Passwords are encrypted on the server), is to prevent Man in the middle attacks, but even then, that's going a little far. //Edit// Oh. I take that back. The password is hashed before it even leaves the client, I forgot about that. SSP3's client handling forces you to do so, it hashes the password with the keys, so eventually once users can specify their own keys it will be even more secure. I mean, I guess I could also make it so the client doesn't save the password, and they have to re-enter it every session, but again, it'd be more of an inconvenience than a security flaw. RE: Account Generator (Crack proof!) Need Testers! - Coefficient - 11-06-2015 TBH there isn't much to do except pentesting, not cracking. Since everything is stored server side, unless exploiting the requests and trying to request multiple accounts, I don't have the time to test that. RE: Account Generator (Crack proof!) Need Testers! - Killpot - 11-06-2015 (11-06-2015, 02:03 AM)God Wrote: TBH there isn't much to do except pentesting, not cracking. Since everything is stored server side, unless exploiting the requests and trying to request multiple accounts, I don't have the time to test that. Execute to get cracked another day. RE: Account Generator (Crack proof!) Need Testers! - TheTekBot - 11-10-2015 Very nice, Thanks a lot for this
RE: Account Generator (Crack proof!) Need Testers! - Killpot - 11-12-2015 (11-10-2015, 07:10 AM)TheTekBot Wrote: Very nice, Thanks a lot for this You're welcome, I hope you enjoy it! RE: Account Generator (Crack proof!) Need Testers! - Killpot - 11-15-2015 Testing stage is over, servers are shutting down. RE: Account Generator (Crack proof!) Need Testers! - Killpot - 01-29-2016 (01-29-2016, 11:12 PM)bilboquet Wrote: going to try this tool Not a thing anymore, servers aren't online. RE: Account Generator (Crack proof!) Need Testers! - Azzid - 01-29-2016 Isn't this the same one that people were Turing into a malware as well? RE: Account Generator (Crack proof!) Need Testers! - Killpot - 01-30-2016 (01-29-2016, 11:25 PM)Azzid Wrote: Isn't this the same one that people were Turing into a malware as well? Huh? Not sure what you're talking about but this isn't malware. It's just a client and server connection using LiteCode and SSP3 along with some custom dependencies, I use it for almost all of my projects that I sell. All it did was ask the server for account credentials and the server does a few simple checks like cooldown checks and multiple IP checks then just feeds the client a response. That's really it, not very complex. RE: Account Generator --DEAD-- - Azzid - 01-30-2016 (01-30-2016, 12:18 AM)Killpot Wrote:(01-29-2016, 11:25 PM)Azzid Wrote: Isn't this the same one that people were Turing into a malware as well? What I was saying is some one made something that looks just the same as this but instead of doing what you stated it was a rat and but still worked as a generator |