I've got quite a bit of RS hacking experience having hacked around 5b in late 2011 which I sold as I decided to quit both RS and the RS hacking scene in general.
Decided it's about time I get back on board and take it more seriously this time. I've always been a bit of a lone wolf so this is the first time I've joined a community dedicated to this sort of thing. Hopefully I can make some useful contributions and learn a few new things myself
I was the first to get access to the runescapetips.dk database which was released on BA a month or two afterwards. What I'm most proud of though is getting read/write access to the SQL database of one of the largest RS gold sellers and creating 'fake' orders which they fulfilled. If anyone wants to know more just ask
Their site had an SQLi vulnerability which allowed me to get the information to one of their admin panels. From there I uploaded a shell onto their website and got the MySQL root password from one of their PHP files. This let me connect to their database on which they track and manage all their gold orders. Took me about a day to figure out how they tracked each order and what values were edited at what stage of the order and such. Once I'd worked that out it was easy to spoof gold orders I hadn't paid for
Managed to get around 1-1.5b from them before they realised what was going on and tightened up their website security and changed their password(s). They found and deleted my shell the day I was thinking about setting up a JDB on their Runescape order page. Given the amount of hits they get and the amount of gold they sell each day I estimate I've probably missed out on 1-2b or more depending on how long it took them to find it and take it down.
I still retain access to a few things of theirs however so now I'm back on the scene I'll get what I can out of them before I move onto other things :sunglasses_1: