Ikarus Offline Shop Safebox Exploit Fix

  • Konbuyu başlatan Konbuyu başlatan Admin
  • Başlangıç tarihi Başlangıç tarihi
  • Cevaplar Cevaplar 0
  • Görüntüleme Görüntüleme 37

Admin

Metin2Lobby
Yönetici
Founder
Katılım
6 Mayıs 2022
Mesajlar
52,647
Ticaret : 1 / 0 / 0
Paylaşılan da mevcut mu bilmiyorum ama halen bazı oyunlarda exploit var diye artistlik yapanlar var.

Kod:
//dosya : new_offlineshop_manager.cpp //ARAT     bool CShopManager::RecvShopSafeboxGetValutesClientPacket(LPCHARACTER ch, const TValutesInfo& valutes)     {         if(!ch || !ch->GetShopSafebox())             return false; //EKLE:         //to fix amount exploit         if (valutes.illYang < 0)             return false; #ifdef __ENABLE_CHEQUE_SYSTEM__         if (valutes.iCheque < 0)             return false; #endif

Ikarus Offline Shop Safebox Exploit Fix


Metin2 özel sunucularında offline shop sistemleri, oyuncuların sunucu kapalıyken bile eşya alım-satımı yapabilmesini sağlar. Ancak bu sistemler bazen güvenlik açıklarına neden olabilir. Bu yazıda, Ikarus offline shop sisteminde bulunan 'Safebox exploit' sorununu nasıl düzelteceğimizi detaylıca ele alacağız.

Exploit Nedir?
Exploit, bir yazılımda bulunan güvenlik açığını istismar ederek istenmeyen işlemler yapılmasını sağlayan kod veya yöntemdir. Metin2 özel sunucularda bu tür açıklar genellikle eşya çoğaltma (duplication), yasadışı para basma veya güvenli kutudan (safebox) izinsiz eşya çekme gibi eylemlerde kullanılır.

Safebox Exploit Neye Benzer?
Ikarus offline shop sisteminde bazı kullanıcılar, safebox'a koyulan eşyaları doğrudan alım-satım yapmadan alabiliyor veya sistemde değişiklik yaparak kendi envanterlerine geri aktarıyorlardı. Bu durum sunucu sahipleri için ciddi bir ekonomik risk oluşturur.

Exploit Fix İçin Gerekli Adımlar
1. Sunucu Tarafı Kontrolleri[/COUNT]
Sunucu tarafında 'game' servisinde çalışan kodları incelemek gerekir. Özellikle offline shop ile ilgili fonksiyonlar, safebox işlemleri ile entegre olduğunda dikkatli bir kontrol yapılmalıdır. Örnek olarak:

Kod:
if (player->GetItemInShop(slot) == NULL && player->GetItemInSafebox(slot) != NULL)[BR][/BR]{[BR][/BR]    sys_log(0, 'EXPLOIT: Player %s tried to access safebox item through shop.', player->GetName());[BR][/BR]    return false;[BR][/BR]}


2. Safebox Erişim Kontrolü
Offline shop açıkken, oyuncunun safebox'a erişimini engellemek önemlidir. Bu işlem, 'input_main.cpp' veya benzeri dosyalarda 'EXCHANGE' veya 'SAFEBOX' komutları kontrol edilerek yapılabilir.

3. SQL Sorgusu Güvenliği
Günlük veritabanı işlemleri sırasında, özellikle eşya transferlerinde parametreli sorgular kullanılmalı. Bu sayede SQL injection gibi saldırılar da engellenmiş olur.

4. Paket Doğrulama
Oyuncudan gelen paketlerin içeriği mutlaka doğrulanmalıdır. Özellikle 'packet.warehouse_pos' gibi alanlar, pozitif değer kontrolü yapılmalıdır. Negatif ya da sınırların dışında olan değerler reddedilmelidir.

Sonuç
Ikarus offline shop sistemi, doğru şekilde yapılandırıldığında oldukça güçlü bir altyapı sunar. Ancak güvenlik açıkları zamanla ortaya çıkabilir. Bu nedenle sistem sürekli monitör edilmeli ve güncellemeler düzenli olarak yapılmalıdır. Metin2 özel sunucu geliştirme sürecinde güvenlik en önemli öncelik olmalıdır. Bu tür exploit'lerin önüne geçmek için hem C++ hem de Python seviyesinde kontroller yapılmalıdır. Daha fazla bilgi ve destek için Metin2Lobby topluluğuna katılabilirsiniz.


Ikarus Offline Shop Safebox Exploit Fix


Offline shop systems in Metin2 private servers allow players to trade items even when the server is offline. However, these systems can sometimes lead to security vulnerabilities. In this article, we will examine how to fix the 'Safebox exploit' issue found in the Ikarus offline shop system in detail.

What is an Exploit?
An exploit is code or a method that takes advantage of a vulnerability in software to perform unwanted actions. In Metin2 private servers, such vulnerabilities are often used for item duplication, illegal gold generation, or unauthorized retrieval of items from the safebox.

What Does Safebox Exploit Look Like?
In the Ikarus offline shop system, some users were able to retrieve items placed in the safebox without actually selling them or by manipulating the system to move items back to their inventory. This situation poses a serious economic risk for server owners.

Steps to Fix the Exploit
1. Server-Side Checks
The code running on the 'game' service must be reviewed, especially functions related to offline shops. Since they are integrated with safebox operations, careful checks are required. For example:

Kod:
if (player->GetItemInShop(slot) == NULL && player->GetItemInSafebox(slot) != NULL)[BR][/BR]{[BR][/BR]    sys_log(0, 'EXPLOIT: Player %s tried to access safebox item through shop.', player->GetName());[BR][/BR]    return false;[BR][/BR]}


2. Safebox Access Control
While the offline shop is active, access to the safebox should be blocked for the player. This can be done by checking 'EXCHANGE' or 'SAFEBOX' commands in files like 'input_main.cpp'.

3. SQL Query Security
During daily database operations, especially during item transfers, parameterized queries must be used to prevent attacks such as SQL injection.

4. Packet Verification
Packets sent by the player must be validated. Fields like 'packet.warehouse_pos' should be checked for positive values. Negative or out-of-bounds values should be rejected.

Conclusion
When properly configured, the Ikarus offline shop system offers a robust infrastructure. However, security vulnerabilities may emerge over time. Therefore, the system should be continuously monitored and updated regularly. Security must always be the top priority in Metin2 private server development. To prevent such exploits, checks must be performed at both C++ and Python levels. For more information and support, you can join the Metin2Lobby community.
 

Şuan Bu Konuyu Görüntüleyen Kullanıcılar (Toplam : 0, Üye : 0, Misafir : 0)

Benzer konular

Geri
Üst Alt