• There is NO official Otland's Discord server and NO official Otland's server list. The Otland's Staff does not manage any Discord server or server list. Moderators or administrator of any Discord server or server lists have NO connection to the Otland's Staff. Do not get scammed!

Gesior acc. maker for TFS

Status
Not open for further replies.

Gesior.pl

Mega Noob&LOL 2012
Senator
Joined
Sep 18, 2007
Messages
2,966
Solutions
99
Reaction score
3,383
Location
Poland
GitHub
gesior
Last update: 10 May 2008 10:37
Newest version: 0.3.0 (not beta)
Layouts: tibia.com
Credits said:
Acc. scripts:
*Gesior
*FightingElf - Elf (good ideas and scripts)
*Kofel (signatures script)
POT 0.1.2 / 0.1.0 (updated!):
*Wrzasq
Layouts:
*Tibia.com - CipSoft Gmbh
*Rasta - Gesior layout (with Ronaldino pictures) based on Arcsin "dirtilicius" layout
*Dark Ritual - Arcsin
Gesior Account Maker 0.3.0 (not beta)
Features:
*Account manager:
-create account (account number random or custom, e-mail, verification image, show server rules from file)
-create character (accept names like RL tibia character names, diffrent outfit for male/female, COPY character from database and change name, id, sex, account..., you select character to copy in "admin panel" like.. vocation: Sorcerer, char to copy: Sorcerer Sample, work with unlimited number of vocations, work with new vocations like... ID 94, vocation name: Ninja)
-change password (like on tibia.com)
-change e-mail (like on tibia.com, user must wait before e-mail change, time configurable in "admin panel")
-register account (generate rec-key, will be used in next version in "lost account interface"
-change character "comment" and set character account information "visible" or "hidden" (like on tibia.com)
-change account public information (location, rl name)
*Spells:
-load spells from OTS spells file (in "admin panel", save informations from file in database)
-set spell hidden/visible(admin) on "spells list" in library, also hide all/visible all
-show list of spells with informations, user can sort from 0 or from highest value (name, sentence, mana, soul, level, maglvl)
-user can select spells only for one vocation (and sort them)
*Monsters:
-load monsters from OTS monsters files (in "admin panel", save informations from files in database)
-set monsters hidden/visible(admin) on "monsters list" in "library", also hide all/visible all
-show list of monsters with informations about every monster (hp, mana, summonable, race) and link to page about every monster
-on page about monster user see also monster "voices" and "immunities"
*Character search:
-show informations about searched player: name, vocation, level, magic level (show yes/no configurable in admin panel), guild, comment, residence (town), last login
-(if player is NOT HIDDEN)show information about his account: account status (pacc/facc), location, rl name, date when account has been created (like tibia.com)
-show list of player deaths (like tibia.com)
-(if player is NOT HIDDEN)show list of other characters from account and "online"/"offline" near every char
*Who is online:
-show list of players online
-user can sort list by name, level or vocation
*Highscores:
-show highscores of players (level, magic level and all skills)
-100 players/page, links to next and previous page
*Last Kills/Last Deaths:
-show list of 25 (number configurable in "admin panel") last deaths from database
-rl tibia "death list" format(in table..):
5. Qutor killed at level 25 by a dragon.
6. Teo killed at level 41 by Kent.
*Houses List:
-show list of houses on OTS and informations about: size, rent, city and "owner"
*Guild System:
-change "guild nick" (this showed in game when you look at someone)
-create guild
-show guilds list (like tibia.com)
-change rank of players with lower rank in guild
For "owner" of guild:
-change guild description
-change guild MOTD
-delete guild
-pass leadership to other mamber of guild
-upload new guild image (size limit in "admin panel")
-add rank
-change rank level (member[1], vice-leader[2], leader[3])
-change rank name
-all what players with lower ranks can
For leaders:
-kick player with lower rank from guild
-all what players with lower ranks can
For vice-leaders:
-invite new player to guild
-cancel invitation
-change rank of players with lower rank
*News System:
-show news icon, post date, text and author
-admin can give rights to write news to every player on server (tutor? gm?)
-add, edit, delete news
-if you use MySQL database (95%? :) ) you can use HTML in news!
-javascript scripts to add news
*Admin panel:
-add,edit,delete news, set limit of news
-edit site configuration (default layout and many options: show yes/no)
-set limits of characters per account, lines and chars in guild description and many other
-reload monsters and spells from OTS files
-reload list of vocations from OTS file and set what vocations will be available in "create character" and name of character to copy when player try to create character with selected vocation
-edit maaany other options of acc. maker configuration
*Lost Account Interface:
-player can request e-mail (send only 1 e-mail to one account every XX minutes- config) with link to activate new password
-player can set new e-mail and new password if has recovery key

What is new in this version:
-fixed bugs with: sqlite/mysql, installation errors, shopsystem bugs, TFS 0.3/0.2 - POT
-In this version added (from 0.2.1):
*Lost Account Interface
*E-mail sender work
*Gesior Shop System as a submenu in layout
*Gamemasters list
*Downloads page
*Server Info page
*Only names like RL tibia (a bit better :p )

Screens:
-account manager
Screen 1

KNOWN BUGS:
-dont copy skills of characters to new characters (all new chars have 10 skill, 0 tries [triggers])

OFFICIAL FAQ FOR GESIOR ACCOUNT MAKER

TODO list for version 0.4:
-ban manager [0%] (wait for stable TFS 0.3 with full working bans table in database)
-new legal layouts? :) [100%] (two legal layouts are ready)
-fix all reported bugs, like problem with IE [100%]

LINKs TO VERSION 0.3.0:
Gesior Acc. maker for TFS from 0.2.6 (0.2 rc 6) to 0.2.13 (0.2 rc 13)
Gesior Acc. maker for TFS from 0.3 pre-alpha
 

Attachments

  • Gesior acc. maker 0.3.0 for TFS 0.2.x.rar
    1.6 MB · Views: 4,455 · VirusTotal
  • Gesior acc. maker 0.3.0 for TFS 0.3.rar
    1.6 MB · Views: 4,996 · VirusTotal
Last edited:
TOTALY INSECURED SCRIPTING
Dont use these AAC ( Automatic Account Creator ) It got alot of vulnerabilitys.. Check yourself with SSS ( Shadow Security Scanner )...

These vulnerabilitys can cause destruction of your database or different things depends in which things its vulnerable!
 
TOTALY INSECURED SCRIPTING


These vulnerabilitys can cause destruction of your database or different things depends in which things its vulnerable!

You're INSECURED. POT = security.
 
nice,I like this one much more, good job!
 
TOTALY INSECURED SCRIPTING


These vulnerabilitys can cause destruction of your database or different things depends in which things its vulnerable!
Can anyone tell WHERE IS THE FCCKING SECURITY BUG?! I DID NOT FIND ANY PROBLEM WITH SECURITY! My scripts are more safer than in other acc. makers. Of course admin can destroy database (sql injection) or modify text on site (XSS attack), but if admin SPECIALY destroy his database I can't help him.. If your program show "insecure" in scripts it's problem with your program, not with my acc. maker... or maybe POT is not secure? Tell "Wrzasq" about it if you find any bug, not only raport from stupid program. Why players did not hack:
http://www.capernia.net/ (50-100 online all day from ~2 weeks)
Admin use my acc. script from 2-3 weeks and did not report about any problems with database.. as I see he actualized to 0.2.1 beta2 version and still not hacked? :>
Maybe your program is out of date and doesn't verify fine PHP5 code or my scripting "style" (lol&noob style).
Post in this thread information about every security bug. I'll fix every reported bug in few hours.
 
Last edited:
The website is invulnerable in xss attacks,i checked it.
 
Just be happy that he is making the d*mn aac! Some people don't even do that! and stop being so god d*mn negative!

Once again,Gesior , You're doing a great job, scr*w the another ones!
 
You should hide Account Maker from the list :p
 

So.. Is Capernia safe?
Those are 3 High Vulnerabilitys and I got the exploits ^^
 

So.. Is Capernia safe?
Those are 3 High Vulnerabilitys and I got the exploits ^^
Maybe you know how to make my acc. maker safer?
Can you create any character with level 200 on capernia or delete other character? Add any link/javascript to page?
 
Last edited:
I found 1 bug so far, in houses.php you have:
PHP:
$allhouses = new OTS_HousesList($config_ini['server_path']."data/world/".$server_config['serverName']."-house.xml");
But not everyone (including me) has their map named after their server.

Edit: Also the Who Is Online? isn't working. and the server status keeps standing on Loading...

Using TFS.
 
Last edited:

So.. Is Capernia safe?
Those are 3 High Vulnerabilitys and I got the exploits ^^

The Scripts of Gesior are vunerable for Cross Site Scripting (XSS Attack) and I test it on my PC and I fucked the Website!!!

U can use exploits, javascripts and UPLOAD bad files!!


Sorry for my English :p!!!
 
The Scripts of Gesior are vunerable for Cross Site Scripting (XSS Attack) and I test it on my PC and I fucked the Website!!!
U can use exploits, javascripts and UPLOAD bad files!!
Sorry for my English :p!!!
Can you tell me on what pages? Characters? Guilds? News or what? Comments of chars or where? I'll fix all bugs if anyone tell me on what page you can upload files or modify site with java.
I found 1 bug so far, in houses.php you have:
PHP:
$allhouses = new OTS_HousesList($config_ini['server_path']."data/world/".$server_config['serverName']."-house.xml");
But not everyone (including me) has their map named after their server.
Edit: Also the Who Is Online? isn't working. and the server status keeps standing on Loading...
Using TFS.
House, spells, monsters files path will be configurable in admin panel in next version. Actually I want fix security bugs...
Should be:
$server_config['mapName']
in place of:
$server_config['serverName']
but some players have "name-houses.xml" in place of "name-house.xml" so path will be configurable.
 
Last edited:
http://ots.wypas.eu/NEW/index.php?subtopic=news

Online players count doesn't load.


[[ Sorry for double post, please merge if possible ]]


EDIT: Try by yourself this for server_status.php:
<?php
header('Content-Type: text/xml');
echo '<?xml version="1.0" encoding="utf-8" standalone="yes"?>';
$config = parse_ini_file('../config/config.ini');
$server_config = parse_ini_file($config['server_path'].'config.lua');

$socket = @fsockopen($server_config['ip'], $server_config['port'], $errno, $errstr, 1);
if ($socket)
{
stream_set_timeout($socket, 1);
fwrite($socket, chr(6).chr(0).chr(255).chr(255).'info');
$data;
while (!feof($socket))
{
$data .= fread($socket, 128);
}
fclose($socket);

preg_match('/players online="(\d+)" max="(\d+)"/', $data, $matches);
echo '<response>'.$matches[1].'</response>';
}
else
echo '<response>OFF</response>';
?>
 
Last edited:
http://ots.wypas.eu/NEW/index.php?subtopic=news
Online players count doesn't load.
[[ Sorry for double post, please merge if possible ]]
EDIT: Try by yourself this for server_status.php:
I'll try to fix it when I'll be in home, but most important now is problem with security. Can anyone post here link to exploit/info about exploit or on what page you can upload "bad files"? Guild upload picture or where?
I don't want to create another not safe acc. maker.
 
How do I do that a player can change between Venore, Carlin, Ab'Dendriel and thais when they create their character? =(
Also, how do I do that a player starts on level 8? >.<

Sincerely,
Furstwin.
 
How do I do that a player can change between Venore, Carlin, Ab'Dendriel and thais when they create their character? =(
Also, how do I do that a player starts on level 8? >.<

Sincerely,
Furstwin.
New chars are COPYs of characters from database. "Sorcerer" - char: "Sorcerer Sample" if you change level of "Sorcerer Sample" in database every new sorcer will have same level and same city ID. It's not possible to select city. You can spawn player on special island with NPC to teleport to selected city or just with 4 teleports to cities.
 
EDIT: Try by yourself this for server_status.php:

This also doesn't work for me just keeps on giving me the loading message, and who is online just tells me there is no one currently playing.

And guys if you find any security leaks then please tell them to Gesior, he is doing an amazing job with the acc maker and we should all be grateful that he is willing to put his time and effort into this for all of us.
 
Last edited:
Status
Not open for further replies.
Back
Top