Three samples from one thread
now from the first three (A,B and C) I'll take away any um important info.Code:http://www.gaiaonline.com/tipping/give?post_id=85321813_1&n=998111099.1364523876.757250196 http://www.gaiaonline.com/tipping/give?post_id=85321813_2&n=1289954699.1364523876.1182158091 http://www.gaiaonline.com/tipping/give?post_id=85321813_3&n=683251226.1364523876.1579870454 ------------------------------------------------- Three samples from another thread http://www.gaiaonline.com/tipping/give?post_id=36828231_1&n=165075917.1364524013.261867015 http://www.gaiaonline.com/tipping/give?post_id=36828231_9&n=265989427.1364524013.88180486 this one is from a different page--- http://www.gaiaonline.com/tipping/give?post_id=36828231_16&n=1050888142.1364524056.459776189
1&n=998111099.1364523876.757250196
2&n=1289954699.1364523876.1182158091
3&n=683251226.1364523876.1579870454
The first number is the post number in the thread, I'm not sure what each string of numbers after that is, though...
The middle blue string is always the same on each page, though it varies from different pages even in the same thread.
here are the 3 different samples of blue string I took
D)1364523876
E)1364524013
F)1364524056
the variation is marked with dark orange, the E and F strings are from the same thread but different pages so only the last two numbers changed.
That's all the useless info I found.
Anyways here's the stupid trick.
1. make a post with your desired account.
2. Go onto a mule and right click tip post with that account, copy the link location.
3. link people to what you just copied and when they click they will automatically donate 25 gold to you
doesn't work![]()
Results 1 to 40 of 49
Hybrid View
- 29 Mar. 2013 02:37am #1
Tipping posts- also a stupid trick
Last edited by Use; 29 Mar. 2013 at 05:29am.
- 29 Mar. 2013 02:51am #2
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 0.25
The trick is a good idea o: Also, I can give you some more info on that number, haha.
683251226.1364523876.1579870454 = your session ID. It's randomly generated each time you visit a page, and I believe there's a GSI function you can use to fetch it o: Now, if we could figure out how they're GENERATED, that would be a whole nother thing.
EDIT: After some research, I believe the blue string could be a timestamp. It would make sense that the last digits change when changing pages, because the seconds and minutes may change.
EDIT2: I am correct about that assumption. Converting one of your blue strings into unix time produces this: "Fri, 29 Mar 2013 02:246 GMT" which would make sense, because you probably did this today, haha. Now to figure out how the other numbers are generated.
Last edited by 323; 29 Mar. 2013 at 02:54am.
- 29 Mar. 2013 02:56am #3
That is not your session ID, that is a nonce, which is basically just from my short time of looking at it basically a randomly generated sequence based off the current time. It depends on the part of the site it's on really. And once a Nonce is used it normally can't be used again, so linking to others might work for the first person to click it, but I don't think it would work for anyone else after unless the check for nonce is just broke.
There is a GSI page and another page to generate Nonces but they don't apply to forums or elsewhere.
Cryptographic nonce - Wikipedia, the free encyclopedia
- 29 Mar. 2013 03:14am #4
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.70
Whoops, you're right.
Also, what the fucking fuck, I just found a second differently-formatted nonce. PM me for more info.
Also, you could probably just remove the "?nonce=" part of the URL and have it be automatically populated by Gaia, submitted by your session or something of that sort.
- 29 Mar. 2013 03:30am #5
- 29 Mar. 2013 03:33am #6
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.05
- 29 Mar. 2013 02:56am #7
I have a function i can use in VB.NET to generate a timestamp but how would we convert it to the "blue" String?
EDIT: It could also have something to do with the page number? I say this because the nonce on that page doesn't change when re-visited correct?Last edited by Kitsune; 29 Mar. 2013 at 03:09am.
- 29 Mar. 2013 03:26am #8
Oh thanks for the info guys
So I guess I can't use that trick to steal peoples gold lol.
I was trying to find a way to change the amount of gold donated.
- 29 Mar. 2013 03:27am #9
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.35
- 29 Mar. 2013 03:33am #10
@Above post, LOL
Yeah nonce must be submitted it's a part of the security an incorrect nonce will not receive action/grant/login/whatever.
- 29 Mar. 2013 03:56am #11
Is it in the same format? If so, I'm guessing all they'd change is the key. In either case, the particular snippet I released was tested on the forums, and I simply assumed it would work elsewhere.
- 29 Mar. 2013 04:08am #12
They never directly tried to sue us, it was just the same process of sending cease and desist letters, DMCA infringement notices, demands to remove content etc. Either way, we stopped checking our inbox a while ago, and if they really want to pursue legal action now, they're 100% welcome to. It'd be an incredibly expensive process for them and because of how we're structured, ultimately wouldn't be worth it
- 29 Mar. 2013 04:13am #13
- 29 Mar. 2013 04:37am #14
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 2.96
Bulletproof hosting, like Cyberbunker!
(But seriously, Cyberbunker is a good choice, they're defending their customers with a 300 GIGABIT DDOS ATTACK RIGHT NOW. Largest Cyber War in history. Link to an article on it, it's caused a 1-2 megabit per second slowdown on tons of internet backbones and shit apparently. Biggest DDoS attack in history slows Internet, breaks record at 300 Gbps | Computerworld Blogs )
- 29 Mar. 2013 04:41am #15
That cyberwar was on the news here this morning O_O
- 29 Mar. 2013 04:44am #16
I've been following that situation quite closely. It's fairly cloudy, and there's a bit of misinformation flying around. Either way though, I wouldn't want to associate with an organisation that actively protects those sort of clients. :p
- 29 Mar. 2013 05:15am #17
Going back to original topic, when i try to do above method i get this:
General Error
Sorry. No Hax.
Similar thing happened to me when i tried to hack HoC lol
- 29 Mar. 2013 05:19am #18
- 29 Mar. 2013 05:26am #19
- 29 Mar. 2013 05:28am #20
- 29 Mar. 2013 03:33pm #21
- 29 Mar. 2013 03:46pm #22
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 2.64
This.
You have to supply your own nonce if you want to use that, which would require programming I believe.
Hey wait, I just had an awesome idea!
What if you supplied a URL that directed to a website under your control, and that page uses Javascript or something to grab the nonce from your cookies or a Gaia page or something like that, using the person's session, and then can redirect them to a properly-formatted tip URL that has their nonce and everything so the tip works?
- 29 Mar. 2013 04:06pm #23
The nonce isn't store in your cookies, it is generated for each page. It is account independent, you can use the nonce from the generate nonce pages I linked to, and use that nonce on any other account in any store. So with tipping, each tip has it's own nonce generated by the server. A nonce is almost definitely never account dependent. All you would have to do if you really want to make a tip bot is just make a page scraper to get the nonce value for each tip or something, there is no need to complicate something as simple as a Nonce.
I think a lot of you are thinking waaaayyy too much into this nonce thing, when it's extremely simple.
- A nonce is not stored in your cookies, it has no reason to be.
- A nonce is generated on a per page basis, and often only works on a per section basis.
- A nonce is not your session it is just a randomly generated string, sometimes using keys, such as SID, time stamps etc to generate the nonce.
- A website cannot just grab cookies from any domain the user has been to, that would be an incredible security flaw. In order to do this, you would have to find an XSS which supplies the SID in the cookies, redirect to whatever script etc you want for cookie grabbing. However this is fairly useless in most scenarios, and as I said would have no bearing on a nonce.
- Why would you go so far as to wanting to cookie grab etc just to get people to tip your posts when it'd be a million times easier just to make a bot that uses the database my account gen makes, and have each account tip your post by scraping the HTML of the page for the nonce, and posting the tip?
- 29 Mar. 2013 04:47pm #24
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 2.54
Oh okay, I see what you mean. Also, random question, any idea how to go to a store by it's store #? I got an error: "Wrong store [Store: -store#-|Item: -itemID-]"
so, for example:
Wrong Store: [Store: 1|Item: 52051]
Would be for store 1 (The barton boutique) and Item # 52051, teh Easter Event 2010 Chickey.
I tried putting &store= in the URL and stuff, but that didn't work either. Any idea how to access stores by store number?
Lol just a random question.
- 29 Mar. 2013 05:36am #25
Indeed, sooooooo much easier to exploit back then.... the memories D:
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 29 Mar. 2013 05:36am #26
I had to make fake birthdates in 2003
>_>
<_<
- 29 Mar. 2013 05:42am #27
One of the exploits i liked was with the Daily Chance, you could just change the number at the end of the link as many times as you wanted.
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 29 Mar. 2013 05:45am #28
- 29 Mar. 2013 12:36pm #29
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.21
Just because this exploit doesn't work doesn't mean you should stop searching for more! :D find as many exploits as you can, we can make bots for them, and be the best Gaia hacking site again!
- 29 Mar. 2013 01:07pm #30
Best recent exploit was the one "To Give To You This Gun" found.
Ya Bish
__________Contributions-
[How to make a FMP] • [FLP Guide] • [Gaia Gold FLP] • [Exchanging Guide]
[My Store] • [My Forum]
- 29 Mar. 2013 01:28pm #31
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 0.94
- 29 Mar. 2013 05:34pm #32
What do you mean by store numbers?
In the url all's I see are the strings of letters
- 29 Mar. 2013 05:47pm #33
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.39
- 29 Mar. 2013 05:59pm #34
Oh, do you know if the http://www. gaiaonline.com /gaia/shopping.php?key=hbjdcjkygqwygbqw
if the blue has anything to do with anything? or if it's just random?
- 29 Mar. 2013 06:13pm #35
- 29 Mar. 2013 08:51pm #36
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 0.94