View Full Version : [Bobba] WARNING: Javascript Hacking Via Links
Breeze
24-01-2012, 09:26 PM
People are using a new method which was a spin off to the last huge issue about "ClickJacking" in which an email address is leached to the victims Habbo ID. They use a website (won't name it) in which there's a tutorial on how to do it and all it takes is an account on this website and a small amount of know-how and boom you've got a Javascipt hacking method. Do not click any bit.ly or any other links which look dodgey or unsafe. I thought I'd warn some of you before someone maks a horrible mistake. Here's a screen shot of what some guy gained from it:
http://img7.imageshack.us/img7/7638/gdfgn.png
If a site ADMIN wants proof that this is legit and I am not causing a huge stir for attention I will gladly PM them 100% video proof that it works as someone posted a tutorial on youtube.
Hope I bailed someone out of making a big mistake, Breeze
Samantha
24-01-2012, 10:09 PM
Ooh maybe this is what hacked Normies, well all avatars on an id but luckily Normies was on another.
Chippiewill
24-01-2012, 10:16 PM
I don't believe this is a new exploit but it's certainly not a nice one either.
I would personally never click a link in the client and it's beyond me as to why they added that feature.
MKR&*42
24-01-2012, 10:24 PM
I don't click links in-client anyway ;L. I'm too scared to find out what the YouTube ones are, the bit.ly ones probs lead to *REMOVED* (not sure if I can name that aha - DON'T GOOGLE THAT SITE IF YOU DON'T KNOW WHAT IT IS) or some of that rubbish and the rest are just useless for me ._.
But yea, thx for warningx
Edited by SyrupyMonkey (Asssistant General Manager (Staff)): Please do not mention inappropriate sites.
Empired
24-01-2012, 10:30 PM
I don't click links because they lag me so very badly.. But I guess I can thank my lag in this case ^_^
Thanks for the warning, I think I've something something along those lines before, though :)
Succubus
25-01-2012, 08:11 AM
I don't click links unless there a site I know and fully trust.
Thanks for the warningthough!
FiftyCal
07-02-2012, 03:40 PM
I believe you breeze because thats how i get fake virus protection is through javascript via links
vito201-:D
10-02-2012, 07:07 AM
Sulake have locked up Habbo pretty damn effectively now - it means only small exploits like this can ever be found now-a-days... gone is the time when we'd find an exploit that allowed gain of hijacking the client.windows etc...
You basically actually have to fall for some sort of scam now... so if you just don't follow links you don't trust in regards to Habbo (So if anyone involved in Habbo sends you a link - make sure you know what it is/why they sent it before following it).
Simple.
Not like when you could use the client windowID to refresh into our own login version and then send the credentials back to the real client upon entry... so that the user barely knew anything was up... meant if you hacked a fansite you could expect hundreds of furni-hacks per day.
Good times, good times... but far, far, far away now... and replaced with this clickjacking method to add a secondary email to an Habbo account's ID.
Breeze
16-02-2012, 08:34 PM
Sulake have locked up Habbo pretty damn effectively now - it means only small exploits like this can ever be found now-a-days... gone is the time when we'd find an exploit that allowed gain of hijacking the client.windows etc...
You basically actually have to fall for some sort of scam now... so if you just don't follow links you don't trust in regards to Habbo (So if anyone involved in Habbo sends you a link - make sure you know what it is/why they sent it before following it).
Simple.
Not like when you could use the client windowID to refresh into our own login version and then send the credentials back to the real client upon entry... so that the user barely knew anything was up... meant if you hacked a fansite you could expect hundreds of furni-hacks per day.
Good times, good times... but far, far, far away now... and replaced with this clickjacking method to add a secondary email to an Habbo account's ID.
Alex you've not changed a bit man! I agree with you however the good times are long gone.
twinart
16-02-2012, 11:14 PM
Thanks for the advice. I'll take care.
Twista500
16-02-2012, 11:23 PM
I dont think these work I just tried a few old codes on my site And it would only go to the change email page, maybe there are new codes But i searched on google but didnt find
Cerys
17-02-2012, 11:59 AM
I don't click links because they lag me so very badly.. But I guess I can thank my lag in this case ^_^
Thanks for the warning, I think I've something something along those lines before, though :)
pfft you click my links you turnip. ;) ;)
OT: Unless it's a link from Charlie or a close friend, I never click them tbh. Thanks for the warning though :]
Empired
17-02-2012, 02:06 PM
pfft you click my links you turnip. ;) ;)
OT: Unless it's a link from Charlie or a close friend, I never click them tbh. Thanks for the warning though :]
Charlie OR a close friend? What am I cerys? :( the next-door neighbour?
And yeah I click your links :P
Sublayer
17-02-2012, 02:12 PM
Will do, cheers.
Plebings
17-02-2012, 04:45 PM
D: was normies hacked????
vito201-:D
23-02-2012, 11:55 PM
I dont think these work I just tried a few old codes on my site And it would only go to the change email page, maybe there are new codes But i searched on google but didnt find
There was a bran new method that was released a few days before this thread was created.
- Alex (Shenk).
I don't really click links unless its youtube/facebook etc
D: was normies hacked????
dno but interter was lol
iFlame
24-02-2012, 08:05 AM
Jesus, thanks for the heads up! x
xxMATTGxx
28-02-2012, 07:52 AM
Anyone aware of "fake youtube" links going around? And if they have any more information on it.
I dont think these work I just tried a few old codes on my site And it would only go to the change email page, maybe there are new codes But i searched on google but didnt find
what. i am confused. are you actively trying to use codes as a habbox staff member? are you taking the piss?!
thanks for the heads up :-)
Twista500
28-02-2012, 09:37 PM
what. i am confused. are you actively trying to use codes as a habbox staff member? are you taking the piss?!
No... Who Said I am, I said I Researched for a Code To test it out on MY Account To see if it works, I would not use it.
Breeze
28-02-2012, 09:47 PM
Anyone aware of "fake youtube" links going around? And if they have any more information on it.
Indeed, it's a youtube link which works as a clickjacker, I have a friend who is currently using the method, I'll update you if I find anything else about it.
Want to hide these adverts? Register an account for free!
Powered by vBulletin® Version 4.2.5 Copyright © 2025 vBulletin Solutions Inc. All rights reserved.