Categories > Exploiting > Roblox >
âElium Hub â | Crack My Whitelist
Posted
Hello, I'm currently working on an upcoming hub for Roblox name Elium. So I figured I'd release a challenge. The whitelist is pretty easy to crack, if you crack it make sure to either reply with the solution, or DM me on Discord: Klem#8064
Here is an example of a successful whitelist:
getgenv().WhitelistKey = '89671c18-8c32-48fe-9e06-7c5eb4caecfd'
loadstring(game:HttpGet('https://elium-backend.herokuapp.com/api/v1/script'))()
Your goal is to get it to print 'Whitelisted!' with any key. Goodluck!
Replied
done /charsss
Cancel
Post
Replied
your wl isnt connected to a database also u can do a webhook to see who executes it if they wlisted or not
Cancel
Post
Replied
@6_7 I didn't hook it up to a DB just yet, but what does that have to do with it?
Cancel
Post
Shadow.lol Forum Admin
Bunni.lol Staff Lead
Xenon Founder & Developer
Replied
@Cyros The keys aren't stored in Lua, I'm not sure what you mean. Could you provide an example?
Cancel
Post
Replied
Thats not what I said, if you change the database local then its able to be cracked
if you use this
local DB = "https://www.thing.com/api/v1/database"
then its easily able to be changed using this
DB = "pastebin.com/raw/boblox"
then the getgenv().Whitelist = 'blah blah' would be modifed
even if it isnt connected to a DB it would be easy to crack using this method: key = "blah blah"
Cancel
Post
Shadow.lol Forum Admin
Bunni.lol Staff Lead
Xenon Founder & Developer
Replied
@Cyros The getgenv().WhitelistKey is the same as doing _G.WhitelistKey it is just how the script gets the input WhitelistKey and has nothing to do with authentication besides providing the key
Cancel
Post
Replied
@Klem oh and make sure when you make your hub that it supports all executors because I tested on fluxus and it failed which means you used an function which is undefined
Cancel
Post
Shadow.lol Forum Admin
Bunni.lol Staff Lead
Xenon Founder & Developer
Replied
Hooking the request does nothing because the whitelisted response is dynamic, there are EQ checks in place as well.
Cancel
Post
Added
@_realnickk I didn't mean to say that I stopped them entirely, just that there a checks to help prevent them. Anyone with enough time could crack any whitelist.
Cancel
Post
Added
Bumperoo.... /chars
Cancel
Post
Users viewing this thread:
( Members: 0, Guests: 3, Total: 3 )
Cancel
Post