Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Results 1 to 6 of 6
  1. #1
    Join Date
    Oct 2007
    Location
    Gloucester
    Posts
    44
    Tokens
    0

    Default HabboCPG & Cutenews = Unsecure bigtime!

    My friends owns a site.

    (rockhabbo.com)

    and last night someone hacked out cutenews and habbo cpg.

    cutenews via search.php and habbocpg via mysql injection

    he left this message:

    dunno if you got my msn messages matt but the news and events pages have I ****** this ***** *** system.. Big up to TheGrimz.NET ;] Wafers from Habbo UK E-mail: ** REMOVED **
    0 CommentsPosted on 31 Jan 2008 by Squally posted on them!!!!

    only us will know the email but if it happens to you.. Well theres your contact
    The Time Has Come...

  2. #2
    Join Date
    May 2007
    Location
    Brisbane, Australia
    Posts
    796
    Tokens
    0

    Default

    Uhhm whats Habbo CPG
    Thanks,
    Chris
    Free Image Uploading

    __________________


    [/url]

    [/FONT]

  3. #3
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    This exploit has been known for some time now.

  4. #4
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    Should have payed attention to cutephp forums...
    Coming and going...
    Highers are getting the better of me

  5. #5
    Join Date
    Jan 2008
    Posts
    287
    Tokens
    0

    Default

    Quite easy?

    Code:
    dosearch=yes;files_arch[]=./data/users.db.php;title=$username
    Just remove search.php or get the latest patch.

  6. #6

    Default

    Hello,
    The site was "hacked" through Cutenews (as earlier posts suggest, search.php).

    If HabboCPG was compromised, it is likely due to harvested login information being the same as on HabboCPG.

    We are constantly working to make HabboCPG a more secure, easier to use radio control panel, and would appreciate it if you could send us any server logs showing how you think HabboCPG was hacked; we will then check for security holes, and patch them up.

    -Alex
    Lineapp.net

    Edited by H0BJ0B (Forum Moderator): Please do not bump threads.
    Last edited by H0BJ0B; 06-03-2008 at 11:46 PM.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •