Azerothcore-wotlk: Hack tool or exploit

Created on 11 Mar 2020  路  13Comments  路  Source: azerothcore/azerothcore-wotlk

Hack tool or exploit

SMALL DESCRIPTION:

I found a player in my server that uses the exploit to create coins and items.
Unfortunately, I have no way to get any information from that player
image
image

STEPS TO REPRODUCE THE PROBLEM:

I guess, there may be through the bank, businessman, mailbox?锛燂紵

BRANCH(ES):

All branches

AC HASH/COMMIT:

1c23bf4

OPERATING SYSTEM:

win2008r2 x64

MODULES:

no


Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

Priority - Critical

Most helpful comment

So far no player has been found with the hack tool. I will open the problem again when I find it锛孴here is also a possibility that, #2721 It fixed him up

All 13 comments

This is really interesting if anyone has any clue and can investigate I would try to help him or try to debug any packets exchange.

on reddit they usually talk about "gold dupe" or "item dupe", it's doing some actions in a specific order, cancelling events and causing weird packet issues (queue issue?) on the server

really can't help much more

I tried to find a way to use the vulnerability. This player, has been offline. T.T

maeby this can help https://github.com/azerothcore/azerothcore-wotlk/pull/2721/files#diff-436148f15b32dae9b7b512b232bc2350R121
with money dupe, i dont see any other obvious code fragments that allow money to be duplicated

@Viste I applied part of your PR, including email

image
There might be a parenthesis missing here

image
There might be a parenthesis missing here

yes thanks ))

Thank you very much for your help
While I waited for him to come online again and cheat,

So far no player has been found with the hack tool. I will open the problem again when I find it锛孴here is also a possibility that, #2721 It fixed him up

Do not close until it's merged, please

okay

There's a way to multiply items. It may not be a problem here, but it's a way the players use.

  1. Take a bag or casket, or a box, or a bag that contains multiple items and which have a selling price to the merchant, for example:
    https://wotlkdb.com/?item=34846#contains
    https://wotlkdb.com/?item=15902#contains
    https://wotlkdb.com/?item=45878#contains
    2020-07-22_19-15-39
    2020-07-22_19-15-52
    2020-07-22_19-16-09

  2. Take everything but one item out of this bag.

  3. Sell the sack to the merchant.
  4. We make a refund, a ransom from a merchant...
  5. The bag is full again!!!
  6. collect all items from the bag.
  7. we sell the received items to the merchant and get gold.

maybe the player's getting into the game, I don't know for sure.

I solved this problem on my server by removing the cost of such bags in the database, now they can not be sold to a merchant.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

CyberFoxHax picture CyberFoxHax  路  3Comments

Maurowin picture Maurowin  路  3Comments

wampirr picture wampirr  路  3Comments

lineagedr picture lineagedr  路  3Comments

PivanDepolo picture PivanDepolo  路  3Comments