PDA

View Full Version : habohut forums hacked



Pyroka
01-07-2009, 10:27 PM
basically if you had a username with the same pw as your habbo on habbohut forums then best changhe it, just got this through from habbohut:



GG HabboHut,

Owned by the JpK crew.

- Forum has been mysql injected
- administration has been logged
- forum database has been downloaded

GG

[JpK];;


FOR THE LULZ. i dont think anyone goes on habbohut so like what the hell lol. AND IT IS NEWS CUZ... NOBODY KNEW


Edited by Catzsy [Forum Super Moderator]: Moved from Habbo News to Habbo in General as it not actual news about the hotel. Thanks.

Kieeran
02-07-2009, 12:35 AM
habbohut was big like 4 years ago its not as big as it used to be i didnt even know it had a forum

Common
02-07-2009, 12:40 AM
Yeah the forums pretty dead beat anyway, but its a damn shame.

Immenseman
02-07-2009, 12:43 AM
didnt even know it was still open, lol.

lick
02-07-2009, 01:48 AM
yeah thought they closed last year lol?

Ardemax
02-07-2009, 05:37 AM
hackers r so cool these days

user130523
02-07-2009, 08:00 AM
habbohut is open? lmao

Kyle
02-07-2009, 08:58 AM
oh well everyone on there was obnoxious anyway

Axed
02-07-2009, 09:41 AM
Oh bless their cotton socks.


- Forum has been mysql injected
- administration has been logged
- forum database has been downloaded

vBulletin has no exploit in which you can MySQL inject, unless HabboHut have coded some rubbish. system which went vulnerable. Administration has been logged? The only way you can keylog through a website, is keylog the login box - which would mean, it's not the Administration being logged, it's the whole of the website's login? Forum Database, whoop de doop. They can do nothing with the database, due to the fact all your passwords are encrypted and they seem too nooby to decrypt passwords. :eusa_danc

My guess is, they somehow got access to the website (maybe an exploit on the actual fansite, not the forum) or something, uploaded a shell and kept it there. Went on the shell, got the configuration details, entered the MySQL password, made their user administrator and 'hack' the Forums. JpK? They're not hackers. SIMPLE.
Exploiting is not the same as hacking, idiots.

Jxhn
02-07-2009, 09:51 AM
Oh bless their cotton socks.



vBulletin has no exploit in which you can MySQL inject, unless HabboHut have coded some rubbish. system which went vulnerable. Administration has been logged? The only way you can keylog through a website, is keylog the login box - which would mean, it's not the Administration being logged, it's the whole of the website's login? Forum Database, whoop de doop. They can do nothing with the database, due to the fact all your passwords are encrypted and they seem too nooby to decrypt passwords. :eusa_danc

My guess is, they somehow got access to the website (maybe an exploit on the actual fansite, not the forum) or something, uploaded a shell and kept it there. Went on the shell, got the configuration details, entered the MySQL password, made their user administrator and 'hack' the Forums. JpK? They're not hackers. SIMPLE.
Exploiting is not the same as hacking, idiots.

Hacking is a loose term for many things today, including social engineering which is how access to the site was obtained.

Axed
02-07-2009, 10:00 AM
Hacking is a loose term for many things today, including social engineering which is how access to the site was obtained.

Lol. Are the Management that stupid to be fooled by Social Engineering?

Want to hide these adverts? Register an account for free!