PDA

View Full Version : Fansite Hacks



GoldenMerc
27-04-2014, 10:18 PM
FlyHabbo, ThisHabbo,HabboHeights hacked, ThisHabbo's DB has been leaked.

THE GERMANS ARE HACKING AGAIN, LOCK YOUR HABBO HOTEL ROOMS (WITH PASSWORDS) SO NO ONE CAN GET IN

Chippiewill
27-04-2014, 10:21 PM
Recursion is rampaging.

Kardan
27-04-2014, 10:27 PM
Recursion told me that the server password was hunter2.

Storking
27-04-2014, 10:28 PM
I hope habbox has locked the back door

Accipiter
27-04-2014, 10:32 PM
Any idea on how its happening / how we can secure?

GoldenMerc
27-04-2014, 10:33 PM
Any idea on how its happening / how we can secure?
Some are on vb3

Accipiter
27-04-2014, 10:34 PM
Some are on vb3

Any more info on that haha, what is the vulnerability? ThisHabbo is a VB4 as well.

Chippiewill
27-04-2014, 10:36 PM
They probably don't block external MySQL connections.

Jurassic
27-04-2014, 10:37 PM
vBulletin released a security patch a week or so ago, maybe they didn't patch their installs? Could be a release to patch up that Heartbleed exploit.

sex
27-04-2014, 10:40 PM
everyone report them and have them removed from official

Yawn
27-04-2014, 10:50 PM
lets hope some more are hacked habbox gna be on top again :)

http://blog.vh1.com/files/2010/12/252_bball2_gif1.gif

Sian
27-04-2014, 11:03 PM
habbohut was hacked as well.

GoldenMerc
27-04-2014, 11:12 PM
I have db's for all of them :o

Storking
27-04-2014, 11:27 PM
rest in peace habbo fansites 28/4/14

Kyle
27-04-2014, 11:32 PM
I have db's for all of them :o
any pws not encrypted?

bloody dutch hackers i have locked my tubmaster in my room hopefully will be ok

GoldenMerc
27-04-2014, 11:33 PM
any pws not encrypted?

bloody dutch hackers i have locked my tubmaster in my room hopefully will be ok

All encrypted. Although you'd be silly not to use a total random password on those sites :P

Accipiter
27-04-2014, 11:35 PM
I can confirm breaches are being attempted on HFFM, however we don't believe it has been breached as of yet.

MKR&*42
27-04-2014, 11:35 PM
habbohut was hacked as well.

Beat me too it :P

Kyle
27-04-2014, 11:36 PM
I can confirm breaches are being attempted on HFFM, however we don't believe it has been breached as of yet.
"as of yet" sound very confident :P

anybody have any clue as to who is doing this? is it sierk?

GoldenMerc
27-04-2014, 11:37 PM
I can confirm breaches are being attempted on HFFM, however we don't believe it has been breached as of yet.


"as of yet" sound very confident :P

anybody have any clue as to who is doing this? is it sierk?
hffm will go down fast, Wonder what breach they are using...
Either way thanks for the emails hackers, I will use these for educational purposes only.
kyle expect an email x

Storking
27-04-2014, 11:39 PM
there should be a warning on HXF to change your password if you use it ... elsewhere

looks like almost every site has been hacked apart from Habbox and hffm

GoldenMerc
27-04-2014, 11:41 PM
there should be a warning on HXF to change your password if you use it ... elsewhere

looks like almost every site has been hacked apart from Habbox and hffm

no lol, maybe official but unofficial theres hundreds :P

Kyle
27-04-2014, 11:41 PM
hffm will go down fast, Wonder what breach they are using...
Either way thanks for the emails hackers, I will use these for educational purposes only.
kyle expect an email x
if only I knew what email I used for habbohut... probably my habboforum 1 that I can no longer access lol!!

Storking
27-04-2014, 11:42 PM
yeah I meant the official sites oops

God
27-04-2014, 11:43 PM
Has Habhome been breached?

GoldenMerc
27-04-2014, 11:43 PM
if only I knew what email I used for habbohut... probably my habboforum 1 that I can no longer access lol!!

is that the only one your registered to? :(

Kyle
27-04-2014, 11:44 PM
Accipiter; who is in charge of the backend of hffm forum?

- - - Updated - - -


is that the only one your registered to? :(
yes I make a point of not registering to other fansites because I know that if their security isn't awful then they're just as susceptible to socially engineered 'hacks' when they have like 20 admins per site. I'm only registered to habbohut cos I was events manager there way back when!

Accipiter
27-04-2014, 11:48 PM
hffm will go down fast, Wonder what breach they are using...
Either way thanks for the emails hackers, I will use these for educational purposes only.
kyle expect an email x

What makes you say this?

GoldenMerc
27-04-2014, 11:51 PM
What makes you say this?

Lots of admins, Lots of risks. You also have a ton of plugins. Can just see a injection or how ever they are doing it, taking place in the next hr or so.

Kyle
27-04-2014, 11:54 PM
Aside from poor management and terrible security, does anybody know what plugins these forums had in common?

GoldenMerc
27-04-2014, 11:55 PM
Aside from poor management and terrible security, does anybody know what plugins these forums had in common?

Potentially ajax thread update (which habbox were going to install on here)

Chippiewill
27-04-2014, 11:55 PM
Does anyone know if it was the thread ignore plugin, if it was then that'd be grand.

GoldenMerc
27-04-2014, 11:56 PM
Does anyone know if it was the thread ignore plugin, if it was then that'd be grand.

chippie u aint staff no more, I want to see ChippieJin become the boss on habbo

Chippiewill
27-04-2014, 11:57 PM
chippie u aint staff no more, I want to see ChippieJin become the boss on habbo

wat

Accipiter
28-04-2014, 12:03 AM
Lots of admins, Lots of risks. You also have a ton of plugins. Can just see a injection or how ever they are doing it, taking place in the next hr or so.

From what we have seen we are just being attacked by other database leaks at the moment

Deqqe
28-04-2014, 12:05 AM
Close down your forums! The hacker might be targeting you next!

GoldenMerc
28-04-2014, 12:06 AM
From what we have seen we are just being attacked by other database leaks at the moment
Id put this in the top of your config, Until the rough sea's are over and potentially vBulletin show some light to the matter;

// define('DISABLE_HOOKS', true);

Close down your forums! The hacker might be targeting you next!
er that aint gonna help no one

Absently
28-04-2014, 12:08 AM
Close down your forums! The hacker might be targeting you next!
love how you made an account just to post this, so cute

Accipiter
28-04-2014, 12:09 AM
Id put this in the top of your config, Until the rough sea's are over and potentially vBulletin show some light to the matter;

// define('DISABLE_HOOKS', true);

er that aint gonna help no one

Cheers I've fed it back!

Hidden
28-04-2014, 12:12 AM
They seem to be hacking the forum databases through the 'Like' plug-in feature. It seems they're searching through forums to find things to do with thanks and likes.

GoldenMerc
28-04-2014, 12:14 AM
They seem to be hacking the forum databases through the 'Like' plug-in feature. It seems they're searching through forums to find things to do with thanks and likes.

DragonByte Tech: Advanced Post Thanks / Like (Pro)

By any chance?

Hidden
28-04-2014, 12:18 AM
DragonByte Tech: Advanced Post Thanks / Like (Pro)

By any chance?

not sure they're scanning the files:
thankyoulike.php
tylsearch.php

I aint no expert, I'm not the brains.

GoldenMerc
28-04-2014, 12:19 AM
not sure they're scanning the files:
thankyoulike.php
tylsearch.php

I aint no expert, I'm not the brains.
tylsearch? Whats that

Hidden
28-04-2014, 12:20 AM
tylsearch? Whats that
thank you likes?

Daltron
28-04-2014, 12:23 AM
What exactly does it mean when a database is leaked/hacked?

GoldenMerc
28-04-2014, 12:24 AM
Okay just downloaded;
http://www.vbulletin.org/forum/showthread.php?t=231666&highlight=thank+you+likes

Its not that one.
http://www.vbulletin.org/forum/showthread.php?t=243510&highlight=thank+you+likes

Nor that one, They don't have the stuff you guys have searched for.

God knows ;l
HabboHut had stupid stuff installed like that silly facebook like thing that follows

- - - Updated - - -


From what we have seen we are just being attacked by other database leaks at the moment

Why do people on your site think im the hacker :(
http://tashload.com/Uploader/uploads//YNmtanY.png

Junox
28-04-2014, 12:35 AM
Okay just downloaded;
http://www.vbulletin.org/forum/showthread.php?t=231666&highlight=thank+you+likes

Its not that one.
http://www.vbulletin.org/forum/showthread.php?t=243510&highlight=thank+you+likes

Nor that one, They don't have the stuff you guys have searched for.

God knows ;l
HabboHut had stupid stuff installed like that silly facebook like thing that follows

- - - Updated - - -



Why do people on your site think im the hacker :(
http://tashload.com/Uploader/uploads//YNmtanY.png

He's on here too.

Wassap people anyways x

Accipiter
28-04-2014, 12:42 AM
Okay just downloaded;
http://www.vbulletin.org/forum/showthread.php?t=231666&highlight=thank+you+likes

Its not that one.
http://www.vbulletin.org/forum/showthread.php?t=243510&highlight=thank+you+likes

Nor that one, They don't have the stuff you guys have searched for.

God knows ;l
HabboHut had stupid stuff installed like that silly facebook like thing that follows

- - - Updated - - -



Why do people on your site think im the hacker :(
http://tashload.com/Uploader/uploads//YNmtanY.png

LMAO You most have that look ;/

They're a new member to us (i think he posted on here somewhere as well)

GoldenMerc
28-04-2014, 12:44 AM
LMAO You most have that look ;/

They're a new member to us (i think he posted on here somewhere as well)

Thats the second person ;(

http://tashload.com/Uploader/uploads//dKtAjJY.png

You're feeding them :(

- - - Updated - - -

3rd person;
http://tashload.com/Uploader/uploads//iDpFeYH.png

Accipiter
28-04-2014, 12:49 AM
LMAO Sonny is a troll he'll pull your leg, but i'll verify its not you on the forum!

Junox
28-04-2014, 12:51 AM
Lol oh sonny is funny

GoldenMerc
28-04-2014, 12:53 AM
I am being trolled by the HFFM community :(

Accipiter
28-04-2014, 12:56 AM
I am being trolled by the HFFM community :(

:( dw they even troll me :/

Kyle
28-04-2014, 12:57 AM
goldenmerc couldnt hack himself out of his mothers uterus

figured it would be the like system

GoldenMerc
28-04-2014, 12:57 AM
:( dw they even troll me :/

i should be vip to protect and have a body guard.

Did Habbohome or what ever get hacked too?

Accipiter
28-04-2014, 01:07 AM
i should be vip to protect and have a body guard.

Did Habbohome or what ever get hacked too?

I haven't had any notification of them being hacked, however their current security has proven faulty before so I would imagine they will be if they haven't yet

GoldenMerc
28-04-2014, 01:08 AM
I haven't had any notification of them being hacked, however their current security has proven faulty before so I would imagine they will be if they haven't yet

Aw, no point having a site with poor security.

Anyways im off to bed, NIGGHTTTT

Accipiter
28-04-2014, 01:09 AM
Night! Thanks for the help

loudu
28-04-2014, 01:50 AM
Hah - I just remembered my habboxforum pass. Damn crazy all the fan sites going down. I wonder how many people have the same email/pass as there habbo account... If you do I'd suggest you change your habbo account now

Rachel
28-04-2014, 02:05 AM
habbohut was hacked as well.

Really?!?! My cousin goes on Habbohut and she never heard it was hacked....hmm


People must be sad that they enjoy ruining other fansites...bunch of low lifes! But in the other hand the general managers at the other fansites needs to be more secure then this..come on!

HabboSwat
28-04-2014, 02:14 AM
http://habboswat.com has been hacked as well. And all users Passwords and Personal Info was shared on a redirect page. Some how they are redirecting our site. For now I have redirected our site to our twitter!

MKR&*42
28-04-2014, 02:15 AM
If it was due to the plugin system, HabHome *should* be fine as they disabled all plugins before anyone tried to target them.

RyRy
28-04-2014, 02:16 AM
http://habboswat.com has been hacked as well. And all users Passwords and Personal Info was shared on a redirect page. Some how they are redirecting our site. For now I have redirected our site to our twitter!

Did you have any encryption on passwords at all? O.O

HabboSwat
28-04-2014, 02:18 AM
Did you have any encryption on passwords at all? O.O

I am not the biggest geek. If IPB "The Forum Software We Use" Had one or not, I am not sure. All I know is I can't figure out how to Stop the redirect. BlueHost scanned our access and Databases and such and found nothing.


Update: Hacker has removed the ZIP Files from the redirect site.

RyRy
28-04-2014, 02:26 AM
I am not the biggest geek. If IPB "The Forum Software We Use" Had one or not, I am not sure. All I know is I can't figure out how to Stop the redirect. BlueHost scanned our access and Databases and such and found nothing.


Update: Hacker has removed the ZIP Files from the redirect site.

Noticed that the files were removed too, wonder why. IPB will have had encryption so that's alright.

HabboSwat
28-04-2014, 02:35 AM
Noticed that the files were removed too, wonder why. IPB will have had encryption so that's alright.

Thanks for saying this. I was feeling really low like a looser for a sec. Its weird that we even got attacked. As we are not official. We are how ever one of the most promoted via Social Media and Mobile App, that bing 1,000s to our site daily.

We ask that if you have any thoughts on, Swat's problem in finding away to stop the redirect, please let us *Me* know. I have dealt with Redirect erros before. I have done all that I know how to do. So please let me know, I don't see other fansites having the redirect problem.

RyRy
28-04-2014, 02:44 AM
Thanks for saying this. I was feeling really low like a looser for a sec. Its weird that we even got attacked. As we are not official. We are how ever one of the most promoted via Social Media and Mobile App, that bing 1,000s to our site daily.

We ask that if you have any thoughts on, Swat's problem in finding away to stop the redirect, please let us *Me* know. I have dealt with Redirect erros before. I have done all that I know how to do. So please let me know, I don't see other fansites having the redirect problem.

Could be they've embedded a PHP redirect in there seeing as you're saying htacess is clean, but I'm not clued up on Web tech really.

GoldenMerc
28-04-2014, 11:02 AM
Could be they've embedded a PHP redirect in there seeing as you're saying htacess is clean, but I'm not clued up on Web tech really.

Prob raw html redirect, will be something dead simple hah

Sent from my HTC One using Tapatalk

sex
28-04-2014, 12:31 PM
i've reported all sites which got hacked and they are in the process of being removed! success!

e5
28-04-2014, 03:05 PM
Really?!?! My cousin goes on Habbohut and she never heard it was hacked....hmm


People must be sad that they enjoy ruining other fansites...bunch of low lifes! But in the other hand the general managers at the other fansites needs to be more secure then this..come on!

Some people hack to show the security flaws on a site. They'll hack to prove a point and then email you on how to prevent it. Some touch nothing but others destroy sites!

habbox is clearly supa dupa safe

Tyrell
28-04-2014, 03:26 PM
So Habbox is safe? What will locking rooms do? IDGI

j0rd
28-04-2014, 03:27 PM
So Habbox is safe? What will locking rooms do? IDGI

that bit was a joke

james,
28-04-2014, 09:34 PM
what a load of ****, people needa grow up

xxMATTGxx
28-04-2014, 09:53 PM
I'm interested in what they actually did to take these sites down. Anyone have any more information?

yeshello
28-04-2014, 10:12 PM
yeshellothere

Mysterious hackur here: (proof - http://rofl.land/lol.txt)

You're all way off. And the majority of you suck ass.



that's all
thanks



<=3

lemons
28-04-2014, 10:15 PM
yeshellothere

Mysterious hackur here: (proof - http://rofl.land/lol.txt)

You're all way off. And the majority of you suck ass.



that's all
thanks



<=3

that link looks dodgy

GoldenMerc
28-04-2014, 10:17 PM
yeshellothere

Mysterious hackur here: (proof - http://rofl.land/lol.txt)

You're all way off. And the majority of you suck ass.



that's all
thanks



<=3

Shoot me a PM

Zak
28-04-2014, 10:21 PM
any pws not encrypted?

bloody dutch hackers i have locked my tubmaster in my room hopefully will be ok

lmao comment of the day

RyRy
28-04-2014, 10:27 PM
that link looks dodgy

Its a text file lol DODGYYYY

lemons
28-04-2014, 10:30 PM
Its a text file lol DODGYYYY

ok!

Suicune
29-04-2014, 01:03 AM
Really?!?! My cousin goes on Habbohut and she never heard it was hacked....hmm


People must be sad that they enjoy ruining other fansites...bunch of low lifes! But in the other hand the general managers at the other fansites needs to be more secure then this..come on!
Habbohut have posted a thread about it though at 9:25 am AEST yesterday.

TannerJP
29-04-2014, 01:18 AM
Interesting how quickly the hackers hopped from one site to another! Glad Habbox was safe!

Honestly the locking rooms comment made me LOL. I remember when I was a newb and thought that would keep my precious furni safe -eye roll-.

HabboSwat
29-04-2014, 01:40 AM
having hard time finding the hidden code that is redirecting our site.

RyRy
29-04-2014, 02:05 AM
Ctrl+F in Notepad or whatever you use

Type redirect.

Find redirect code in files. Likely done.

If you're using Linux just use grep to search inside files

HabboSwat
29-04-2014, 02:55 AM
Ctrl+F in Notepad or whatever you use

Type redirect.

Find redirect code in files. Likely done.

If you're using Linux just use grep to search inside files

Thanks, but this would not have helped as they used a Base69 Encryption, that made the line of code look like:


header(base64_decode('TG9jYXRpb246IGh0dHA6Ly9yb2Zs LmxhbmQv'));

Had to do a lot of digging. First I found out using a site, that Swat's site was being redirected via "Header Coder" Secondly I had to accept the fact that the code could be encrypted, thus causing me to use a website to search for base69 encryptions. The first file that came up, I searched and found that code, I used a decoder to find out what it means, and find out that the line is actually "Double Encrypted" so I take a leap of faith and delete the line. Test my site, and find that it is no longer being redirected! Wott! Wott!

Chippiewill
29-04-2014, 03:05 AM
Base69 Encryption

I just burst into hysterical laughter at the bastardisation of Base64 encoding.

Landon
29-04-2014, 05:52 AM
Hacking and finding vulnerabilities definitely isn't a good thing. Shows how selfish and self-centered you are. Can't think about anyone else.

Chippiewill
29-04-2014, 06:08 AM
Hacking and finding vulnerabilities definitely isn't a good thing.
Not true. Maliciously exploiting the vulnerabilities isn't a good thing. Finding them so they can be fixed is good.

lRhyss
29-04-2014, 08:09 AM
yeshellothere

Mysterious hackur here: (proof - http://rofl.land/lol.txt)

You're all way off. And the majority of you suck ass.



that's all
thanks



<=3

Shot in the dark here but...

$temp = unserialize($check);
add:
$temp = json_decode($check,true);

then running:

serialize($_POST) changed to json_encode($_POST)

PHP object injection?

Pretty sure that was a problem recently, if I remember correctly xxMATTGxx

yeshello
29-04-2014, 08:45 AM
Shot in the dark here but...

$temp = unserialize($check);
add:
$temp = json_decode($check,true);

then running:

serialize($_POST) changed to json_encode($_POST)

PHP object injection?

Pretty sure that was a problem recently, if I remember correctly xxMATTGxx

PHP object injection is literally useless in vanilla vBulletin. There's no exploitable magic methods. It only becomes a danger when you couple it with poorly made plugins.

Note how one forum was IPB and one was MyBB, too.

RyRy
29-04-2014, 10:38 AM
I just burst into hysterical laughter at the bastardisation of Base64 encoding.

I have an exam today on Base64 to binary conversion... Why did I see this today hahaha

lRhyss
29-04-2014, 12:21 PM
PHP object injection is literally useless in vanilla vBulletin. There's no exploitable magic methods. It only becomes a danger when you couple it with poorly made plugins.

Note how one forum was IPB and one was MyBB, too.

Ahh I see, I was just wondering about it seeing as vBulletin recently patched something simliar haha

lRhyss
29-04-2014, 01:04 PM
Hacking and finding vulnerabilities definitely isn't a good thing. Shows how selfish and self-centered you are. Can't think about anyone else.

Google Ethical Hacking

GoldenMerc
01-05-2014, 12:27 PM
Did anyone actually work out the cause?

Want to hide these adverts? Register an account for free!