Jump to content

Liderluigi

Senior Member
  • Posts

    137
  • Joined

  • Last visited

Everything posted by Liderluigi

  1. I know, not gonna release it. I just will fill their requests
  2. Still not patched after last update... Well, I have been investigating a bit on how Bullet Force works and I posted it here: https://iosgods.com/topic/41759-bullet-force-vulnerabilities-exploits-gold-hack/ But now I have decided I could make a simple tool on VB and allow people hack their on accounts. What does the tool offer? Features: - Read player's data automatically (on real time): credits, xp, gold, kills, etc. - Add Credits to your account. - Get XP (Slow process as it simulates kills). [Hidden Content] Have a nice day!
  3. he doesnt know to to do the sql injection lol I'll upload a tool soon ^^
  4. Lol you didnt even look for it... Here it is: Class: Chartboost Method: (id) getDeviceIdentifier Return value: NULL That way you wont send your device ID to their servers... Your welcome
  5. I looked into the game database and theres a "device ID" stored in "accounts" table. I supose yours is banned so try changing your device id with Flex or something... Then you will be allowed to play again...
  6. Hi guys! This game: Bullet Force, recently appeared on App Store and has become somehow a little bit famous, so I decided to take a look at it in any form to get exploits or vulnerabilities. I always prefer hacking in my own way which is no memory search or debugging at all, but inspecting packets going through server-client. And I found some interesting stuff! First of all, when you register a new account, the app access the database DIRECTLY to store the new user and some data, which is a very BAD idea indeed. Here is some proof: Therefore, ANYONE can access the database with just some newbie SQL-Injection, modify values, and even steal accounts! Heres an account email, but I won't show the password: I successfully had access to this account! I could even PLAY with it too! Proof of randomly chosen account password: Then, I stopped messing around with accounts, I wanted some currency! The same thing I did before, i did it now with MY account. I got some gold, some coins and cases too, BUT I could also add me unlocks, kills deaths, etc. Proof: Proof on device: PIC 1: http://i.epvpimg.com/drqdd.png PIC 2: http://i.epvpimg.com/4U0fh.png However, Gold hacks gets you instantly banned. I also noticed "accounts" TABLE on SQL had a variable called "unbanned" (Type: BOOL), therefore, anyone that gets banned can get unbanned so easily by just inserting a "TRUE"! Proof: All in all... This game is still in beta, thats why its so simple and bad written. So guys, be careful if you rgister using the same password and email than your own. Finally found out how to get gold without ban (08/12/16) GOLD HACK PIC 3 (Unlocks): http://i.epvpimg.com/a2add.png PIC 4 (Multiplayer):http://i.epvpimg.com/L4Fkb.jpg If you want a free account with tons of gold: https://iosgods.com/topic/41847-huge-giveaway-bullet-force-credits-cases-gold-and-lv80/#entry1359042 If you want Credits and XP: https://iosgods.com/topic/41811-tool-bullet-force-ios-android-credits-and-xp-hack/ Peace!
  7. Bump
  8. Name of app you want hacked: EveryCircuit Version of the app: 2.18 iTunes URL for the app: https://itunes.apple.com/es/app/everycircuit/id797157761?mt=8 Requested features: Full access (Premium user) Jailbroken or Non-Jailbroken: Any PD: I have tried using mobile substrate, saved files editing, packets requests on user status (premium or not)... But with no luck at all, I hope someone helps out !! It is kind of a hard app to mod... Thank you!
  9. Here you have: https://iosgods.com/topic/31098-angel-stone-multitool-210-all-versions/ ^^ I hope you like it!
  10. Here you have something: https://iosgods.com/topic/31098-angel-stone-multitool-210-all-versions/
  11. The app freezes haha, do you even know why are you typing "c"?
  12. Here: #include "writeData.h"
  13. You should recognize those tweaks you have installed, like "Activator" for example,. And those you don't know, look them up on Google to check if they are malware or not.
  14. Sure, with any file explorer (iFile, etc.) go to: /Library/MobileSubstrate/DynamicLibraries. There you will find 2 types of files (and even some folders), you should recognize those you have installed..
  15. Try to check if those tweaks created a .plist and .dylib file on mobileSubstrate so they access advertisements on springboard.
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines