Mig33 Server Bug (Invisible Entry in chatrooms)

Post new topic   Reply to topic

View previous topic View next topic Go down

Mig33 Server Bug (Invisible Entry in chatrooms)

Post by h4v0c- on Fri 4 Jul 2008 - 7:08

This is one of the problems in mig33 server
Its an incorrect validation problem in mig33 server software
Its mostly known as invisible entry
I am sharing this because it dosent harms anyone in anyway and it is being fixed within next 2,3 days
Till then you can test it yourself
Detail:
When we send login packet to mig33 server, server sends two alphanumeric keys.
First key is used as a session id for opening links like profile, scrapbook, etc
Second one is for making hash with password
Then our mig33 client application joins second key with the password provided by us and after passing it through a hash making algorithm, it sends a four bytes long hash to mig33 server
Mig33 server then creates the same hash on the server with the user's password stored in database and matches it with the hash sent by our client mig33 application
If both the hashes are matched, server checks whether the username is active or inactive
If the username is active, it is logged in and the server then sends login success packet to the mig33 client in order to notify it about the successful login
Otherwise it sends the "Account not active" message
After successful login, if we send the hash again to the mig33 server, the server returns an error message "Session already exists"
Then we send the login packet again, mig33 server will again send keys
(Bug: When the login packet is sent to the server with the same connection, the server resets users details and remains logged in - I am not sure about this!)
Now if someone sends a private message to your id, it will say "User not online" (i wanted this bug as a feature in mig33 - Auto Block)
And if you enter a chatroom, your entry will not be appeared but when you leave the room it will show other users that you have left the chatroom
Fix:
mig33 coders have to make some change in login packet and the join chatroom packet
POC:
You cant do all this using mobile phone, java emulators or the website,
To do that, you need WPE (Winsock Packet Editor)
This program edits the packets sent to the server and resends them
To use this tool, you need some information about packets
Or you can also accomplish this by making a client mig33 application as i did
Here is a link to an mig33 client application (written in vb) made by me
download http://rescue.gov.pk/presentation/dl.php?f=1&n=mig_bug.zip
it does all the above with only 2,3 clicks
You must have the following files in your system:
1- msvbvm60.dll (download from www.dll-files.com)
2- mswinsck.ocx (download from www.dll-files.com)
3- hashgen.dll (included)

Good Luck!

h4v0c-
Logged in
Logged in

Gender:MaleAriesHorse
Posts : 6
Joined : 05 Sep 2007
Age : 18
Location : pakistani
mig33 nick : h4v0c-

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by r0mz on Fri 4 Jul 2008 - 8:03

thanx allot for the info man Very Happy

r0mz
Member of the Month

Gender:MaleLeoBuffalo
Posts : 902
Joined : 10 Jun 2008
Age : 23
Location : Tanzania
mig33 nick : r0mz---relo4d3d

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by luv.inspecta on Fri 4 Jul 2008 - 14:17

gud info bro ... thx for this informativ post ... ! ...


† ╔╩╬╩╣ Ç└εrïC ▬ Θƒ ▬ C┼┼αΘ§ ╠╩╬╩╗ †

luv.inspecta
Legendary
Legendary

Gender:MaleAriesTiger
Posts : 1643
Joined : 19 May 2008
Age : 22
Location : saudi arabia
mig33 nick : luv.inspecta

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by Giga on Fri 4 Jul 2008 - 14:30

Ahem!

Thanks for the info!  :yahoo:

Giga
Senior member
Senior member

Gender:MaleGeminiSnake
Posts : 932
Joined : 12 Jun 2008
Age : 19
Location : There is Place like Hell / Haunted House
mig33 nick : nigahiga-giga

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by hang_me_up on Fri 4 Jul 2008 - 16:19

thanks for the more detailed info broo laughing
posting from my mobile browser please forgive and correct my mistake!
[Thank you]

hang_me_up
Hanging out
Hanging out

Gender:MaleCancerDragon
Posts : 56
Joined : 26 Jun 2008
Age : 20
Location : bangladesh
mig33 nick : rajibul143 and digital-mulla

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by ykanishka on Fri 4 Jul 2008 - 18:13

Thanx for information... Keep it up..

ykanishka
Regular
Regular

Gender:MaleScorpioHorse
Posts : 124
Joined : 06 Mar 2008
Age : 18
Location : Sri lanka
mig33 nick : ykanishka

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by Kanishka_max on Fri 4 Jul 2008 - 23:57

hay this is cool Smile
i hope mig33 team wil find a solution asap.
.:: Proud to be a Sri lankan ::.

Kanishka_max
Addicted
Addicted

Gender:MaleGeminiDragon
Posts : 240
Joined : 09 Mar 2008
Age : 20
Location : .:: Sri Lanka ::.
mig33 nick : kanishka_max

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by sajith.xp.pk on Sat 5 Jul 2008 - 3:06

very nice informations. . .  :yupp:
thanks bro
keep sharing. . .

♪....мίg33™ fяίεηюš....♣
....ς٥ммυηίτч....♪

sajith.xp.pk
VIP member
VIP member

Gender:MaleCapricornDragon
Posts : 1444
Joined : 07 Mar 2008
Age : 19
Location : Sri Lanka
mig33 nick : sajith.xp.pk

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by Nothingness on Sat 5 Jul 2008 - 8:52

Good information
Thanks for sharing.
Keep it up

Nothingness
Moderator
Moderator

Gender:FemalePiscesSnake
Posts : 1866
Joined : 24 Apr 2008
Age : 19
Location : Pakistan
mig33 nick : lunacy_reloaded

Back to top Go down

Re: Mig33 Server Bug (Invisible Entry in chatrooms)

Post by r0mz on Sat 5 Jul 2008 - 12:48

i think u should try and update the mig33 software engineers abt this Very Happy

r0mz
Member of the Month

Gender:MaleLeoBuffalo
Posts : 902
Joined : 10 Jun 2008
Age : 23
Location : Tanzania
mig33 nick : r0mz---relo4d3d

Back to top Go down

View previous topic View next topic Back to top


Post new topic   Reply to topic
Permissions of this forum:
You cannot reply to topics in this forum