It was using method 120 in the GSI with a key I got friend like a year or two back, and the user ID of who you wanted to view.
It's patched, so don't get your hopes up. I put it here, since it's not really a release or anything.
README[/b]
https://github.com/elistrophy/Gaia-I...Viewer-PATCHEDJust the source to the now patched inventory viewer. This is what I was using, combined with flask to display user inventories. As you can see I was actually hiding some sections from the public, such as trade items, market items, storage, and housing.
Each section of the inventory would be a generator, so that the info grab for the items would only be performed on a per section basis. I was planning to rework it, but it got patched.
Required Requests: HTTP for Humans — Requests 1.1.0 documentation
This won't work anymore so don't try.
Results 1 to 40 of 41
- 30 Mar. 2013 12:23am #1
[Source] Since it was patched, Inventory Viewer source code.
Last edited by Tree; 01 Apr. 2013 at 03:47pm.
- 30 Mar. 2013 01:02am #2
- 30 Mar. 2013 01:03am #3
It took them forever to patch it though, and all they ended up doing was removing method 120. I'm not sure if they actually use it elsewhere on the site, but if so they probably just moved it. I'll probably end up scanning GSI later if I feel like it, though kinda boring to mess with Gaia.
- 30 Mar. 2013 01:07am #4
Yea we used to offer a public service (much like your site), and you could essentially skip right past that secret if you just passed through 'true' instead. When they patched that we figured it best to only grant a few people access using the key less they patch that as well.
- 30 Mar. 2013 01:09am #5
- 30 Mar. 2013 01:29am #6
- Join Date
- Apr. 2010
- Location
- When freedom is outlawed only outlaws will be free
- Posts
- 5,113
- Reputation
- 195
- LCash
- 1.53
- 30 Mar. 2013 01:33am #7
- 30 Mar. 2013 01:35am #8
Neat code.
When you guys refer to a key you used for this, wouldn't you have been able to access a lot more than just the inventory view GSI?
On top of that, why didn't Gaiaonline just invalidate the key being used instead of moving (or removing) the method?I don't get tired.
- 30 Mar. 2013 01:36am #9
- 30 Mar. 2013 01:38am #10
- 30 Mar. 2013 01:49am #11
So what you're saying is to patch the method, they simply moved the GSI. Meaning the key still could apply elsewhere?
I don't get tired.
- 30 Mar. 2013 01:53am #12
- 30 Mar. 2013 01:54am #13
- 30 Mar. 2013 01:56am #14
- 30 Mar. 2013 02:06am #15
- 30 Mar. 2013 02:22am #16
a common salt gaia used was something like "Go-Gaia 72 XD Squared" that may be off but it was something like that.
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 02:26am #17
- 30 Mar. 2013 02:28am #18
I remember when you could use GSI to login (idk if there is another method), You MD5 hashed your password with that salt to login.
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 02:31am #19
Last edited by Tree; 30 Mar. 2013 at 02:34am.
- 30 Mar. 2013 02:43am #20
Is method 107 a working way to login?
err i mean 108There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 02:44am #21
- 30 Mar. 2013 02:53am #22
I believe im looking at it.....
i have this
Code:http://gaiaonline.com/chat/gsi/index.php?v=json&m=[[108,[USER, PASS]]]
This is what it returns:
Code:[[0,false,[-5,"Nothing generated in response to the request."]]]
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 02:56am #23
Look at the source more. That's all I will say on that matter, I put it in there, and didn't outright say how to do it so people would have to read the source. also if it says Nothing was Generated it means you sent a malformed json string.
- 30 Mar. 2013 03:13am #24
okay so i think im getting, however i don't think you can use GSI to login still....
First Request:
Code:http://gaiaonline.com/chat/gsi/index.php?v=json&m=[[108,["USER","226f4e54a3a813c13d3fbd78be1441bfb0"]]]
Code:[["108",false,[-3,"Please use gaiaonline.com to login."]]]]
Code:http://gaiaonline.com/chat/gsi/index.php?v=json&m=[[108,["USER","226f4e54a3a813c13d3fbd78be1441bfb0", "True"]]]
Code:[["108",false,[-3,"failed-captcha"]]]
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 03:16am #25
Moderator Bachelor of Science in Virginity
- Age
- 31
- Join Date
- Nov. 2009
- Location
- Toronto
- Posts
- 5,421
- Reputation
- 546
- LCash (Rank 3)
- 1.96
- 30 Mar. 2013 03:18am #26
I SEEE NOW. I GOT IT RIGHT I JUST TYPED IN MY USERNAME WRONG
TY TREE +REP!
ill +Rep you too Stapled since you came in and tried to helpLast edited by Kitsune; 30 Mar. 2013 at 03:24am.
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 03:30am #27
- 30 Mar. 2013 03:32am #28
Moderator Bachelor of Science in Virginity
- Age
- 31
- Join Date
- Nov. 2009
- Location
- Toronto
- Posts
- 5,421
- Reputation
- 546
- LCash (Rank 3)
- 1.96
- 30 Mar. 2013 03:35am #29
This whole time when i thought logging in via GSI was no longer all i had to do was add "True" at the end of it >.>
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 03:35am #30
They've been actively banning any account I register, even if I don't do anything every day for the past week. Only reason I even keep releasing this stuff, is the last time Doc and me tried to help them fix their stuff, worked directly with a Dev etc, gave them some session grabbing exploits, ability to post announcements etc, and once they got that stuff they ran off. This was like a year or two back though, but they still refuse to actively do anything unless you force them to. They give me and others who can actually do stuff absolutely no reason to report any exploits to them at all.
- 30 Mar. 2013 03:37am #31
- 30 Mar. 2013 03:38am #32
Wow, also it seems that accounts made by your account creator (or whoever's account creator people are using) are getting banned fairly quickly just because they are being mass produced. Use tried to give me an account and it was banned, then he gave me a list and they were all banned xD (he used an account creator)
There's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 03:39am #33
Please what? I meant that if you login with the GSI method with an account that has been locked for being inactive for 6 months, it will reactivate it as opposed to having to go through the process of reactivation. It's literally the same as a normal login with the GSI.
- 30 Mar. 2013 03:44am #34
So i nearly shit myself because i re-activated a mule i had a while back just now.
I looked in the inventory and saw a nitemare sash and thought it was a scarf..... lolThere's nothing ideal about being real, there's so many flaws to cover and conceal.
- 30 Mar. 2013 03:46am #35
Moderator Bachelor of Science in Virginity
- Age
- 31
- Join Date
- Nov. 2009
- Location
- Toronto
- Posts
- 5,421
- Reputation
- 546
- LCash (Rank 3)
- 1.96
- 30 Mar. 2013 03:54am #36
Seems to me they've been carpet bomb banning anyone they even suspect isn't the original owner which is kind of a slippery slope.
I don't know if they fixed it or not, but with Towns 2 from what I looked at all you have to do in order to use mod powers is simply decompile, set the user_level variable to instead of accessing the server, simply set it to something above 85, and recompile. I'm not sure if they have a server side check or if it's just client sided for when these packets are sent though.
- 30 Mar. 2013 04:01am #37
They do check the forum, so if you release anything noteworthy to the public, it's going to get patched fairly quick
- 30 Mar. 2013 04:04am #38
- 30 Mar. 2013 04:18am #39
- 30 Mar. 2013 04:20am #40