Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 3 123 LastLast
Results 1 to 10 of 30
  1. #1
    Join Date
    Nov 2005
    Location
    Edinburgh
    Posts
    11,690
    Tokens
    0
    Habbo
    Pyroka

    Latest Awards:

    Default Regarding Security Notice

    When was this discovered, and do you know how long it's been on the forum? Plus, have you discovered a way to well uh, filter it from happening?

    I mean I haven't seen anything but then I haven't been online today.

  2. #2
    Join Date
    Jan 2008
    Location
    Wales
    Posts
    3,594
    Tokens
    1,387
    Habbo
    Skizzling

    Latest Awards:

    Default

    Quote Originally Posted by Pyroka View Post
    When was this discovered, and do you know how long it's been on the forum? Plus, have you discovered a way to well uh, filter it from happening?

    I mean I haven't seen anything but then I haven't been online today.
    A user had signed upto the forum not so long ago and when I was looking through threads a box popped up, luckily I told Matt before anyone else got fooled. One user accidently entered their details which Matt has dealt with.

    I don't think theres a filter because otherwise people won't be able to have signatures hosted from their website. THE ONLY PLACE HABBOXFORUM WILL ASK FOR YOUR PASSWORD IS IN THE LOGIN BOX ON THE FORUM, ANYWHERE ELSE THEN DO NOT ENTER YOUR PASSWORD, ALSO CHECK THE URL.

  3. #3
    Join Date
    Apr 2006
    Posts
    1,311
    Tokens
    1,347

    Latest Awards:

    Default

    What's happened? o.O Do I need to change my password?

  4. #4
    Join Date
    Jul 2004
    Location
    UK
    Posts
    23,590
    Tokens
    33,601
    Habbo
    xxMATTGxx

    Latest Awards:

    Default

    Quote Originally Posted by Pyroka View Post
    When was this discovered, and do you know how long it's been on the forum? Plus, have you discovered a way to well uh, filter it from happening?

    I mean I haven't seen anything but then I haven't been online today.
    I would say within the past 24 hours or so it was added into a users signature. This was spotted, the link hiding under the [IMG] tags was removed and the URL it is located on is also filtered. But in all means you should NEVER enter your details in any login prompt if they load when you go onto Habbox websites.

    You do not need to change your password unless you have entered them in a login prompt/window/dialog when you have gone into a thread. But if you may wish, you can change it anyway just to be safe as it's always ideal to change your password every now and then.


    Edit: Login Boxes look something like this: (This is not the one that was shown on HxF)

    Last edited by xxMATTGxx; 03-09-2010 at 12:10 AM.


    Previous Habbox Roles
    Co-Owner of Habbox | General Manager | Assistant General Manager (Staff) | Forum Manager | Super Moderator | Forum Moderator

  5. #5
    Join Date
    Apr 2006
    Posts
    1,311
    Tokens
    1,347

    Latest Awards:

    Default

    Ah ok! Thanks Matt.
    Did a user manage to bring something like this onto the forum? D:

  6. #6
    Join Date
    Jul 2004
    Location
    California
    Posts
    8,725
    Tokens
    3,789
    Habbo
    HotelUser

    Latest Awards:

    Default

    Ah, imagine all the credit cards filled with money said exploiter could get from stealing kid's passwords on a Habbo forum

    Anywho the IMG tags should atleast parse non image filetypes on the clientside of things. How strange.
    I'm not crazy, ask my toaster.

  7. #7
    Join Date
    Oct 2005
    Location
    Spain, Valencia
    Posts
    20,492
    Tokens
    3,575
    Habbo
    GoldenMerc

    Latest Awards:

    Default

    Yeh they put the link in the image tags n it does tht, rather annoying.

  8. #8
    Join Date
    Nov 2005
    Location
    Edinburgh
    Posts
    11,690
    Tokens
    0
    Habbo
    Pyroka

    Latest Awards:

    Default

    Wow, that's a pretty bad exploit on VBulletin's part. Cheers for that though, was pure curiosity on my behalf. Good job Calvin swooped in on that fast, else that could've gotten quite out of hand.

    But hang on, I would've thought it'd only let .JPG and all that sorta files to be hosted?

  9. #9
    Join Date
    Dec 2006
    Location
    Nottingham
    Posts
    7,752
    Tokens
    756
    Habbo
    katie.pricejorda

    Latest Awards:

    Default

    Why on earth some idiot would want to steal HabboxForum user details I don't know. Habbo accounts I can see why but HxF accounts I've no idea why anyone would want them.

  10. #10
    Join Date
    Nov 2005
    Location
    Edinburgh
    Posts
    11,690
    Tokens
    0
    Habbo
    Pyroka

    Latest Awards:

    Default

    I think it's because alot of (silly) users may use their HabboxForum passwords the same as their Habbo passwords. Of course, they'd need to know the email the account was linked too as well but that's not all THAT hard to discover if you think about it.

    Tis why I have a secret email linked to my Habbo, I don't even bloody know the password to it LOL.

Page 1 of 3 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •