Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Urgent

  1. #1
    Join Date
    Jan 2007
    Posts
    16,195
    Tokens
    3,454

    Latest Awards:

    Default Urgent

    Does anyone know anything about habbostyles.com?


  2. #2
    Join Date
    Aug 2008
    Location
    Leeeeeeeds
    Posts
    4,594
    Tokens
    1,315

    Latest Awards:

    Default

    No idea what it is, why?

  3. #3
    Join Date
    Jan 2007
    Posts
    16,195
    Tokens
    3,454

    Latest Awards:

    Default

    Quote Originally Posted by dogboy123 View Post
    No idea what it is, why?
    Someone came in my room said it is a new rare values site in au, I went on it, then he asks if I prefer logging in with habbo id or username.

    Think I might have fallen for a trick.


  4. #4
    Join Date
    Aug 2009
    Location
    Glasgow
    Posts
    214
    Tokens
    0
    Habbo
    jj9090

    Default

    DO NOT GO ON THE SITE I think its session stealer so they can hack you. Make sure you log in with email i think that was safe way. NOT your hab name.

  5. #5
    Join Date
    Jun 2006
    Location
    Bristol
    Posts
    7,177
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by paramoreriot View Post
    DO NOT GO ON THE SITE I think its session stealer so they can hack you. Make sure you log in with email i think that was safe way. NOT your hab name.
    If it's asking for Habbo ID - you should avoid it at all costs even if it does offer an alternative login. DO NOT LOG IN WITH YOUR EMAIL as this is equally dangerous, they will probably use it to at least try to access your Habbo Account.
    Benedictus qui venit in nomine Domini

  6. #6
    Join Date
    Aug 2009
    Location
    Glasgow
    Posts
    214
    Tokens
    0
    Habbo
    jj9090

    Default

    Ironic, isn't it? The security check is vulnerable to Cross Site Scripting.

    It appears to try sanitise the URL, thus <script></script> tags are useless here, but alas, tags are not necessary to steal a session cookie via this URL.

    An XSS hole for Habbo Hotel has not been in the public domain for a long while, so this is our gift to you. It will not last so make the most of it while you can.

    If you are not aware, you do not need a user's Habbo name or password to get on their account if you have their session cookie. You can log into your account, sit on homepage, use Firefox's "Add n' Edit Cookies" add-on to set their JSESSIONID as your JSESSIONID, and then all that is required is a page refresh in Habbo Homes to be logged into their account.

    A full tutorial on how to steal another Habbo's session (and use it yourself) using the security_check XSS exploit has been compiled for you. For learning purposes only, of course ;]

    IMPORTANT: Safari 4 and IE8 with XSS filtering enabled are immune.
    Perhaps others also. Test alternative browsers and comment.
    Also, this will only work on users who logged in using their name and not email. (thanks Loget)
    So email is safe i am 99% sure. So basically for the next while don't go on any sites that you have never been on or simply look weird.
    BTW IM NOT ADVERTISING HACKING
    Just showing prevention etc
    Last edited by paramoreriot; 24-04-2010 at 11:34 AM.

  7. #7
    Join Date
    Jan 2007
    Posts
    16,195
    Tokens
    3,454

    Latest Awards:

    Default

    I haven't actully put anything onthat website, I went on the domain though.

    What do i do now?

    **** that makes sense o.O The guy said we have faults with IE and Safari users atm..
    Last edited by AgnesIO; 24-04-2010 at 11:42 AM.


  8. #8
    Join Date
    Jan 2007
    Posts
    16,195
    Tokens
    3,454

    Latest Awards:

    Default

    May I ask how long they will be able to get on my account for?

    Also I am now using Sfari but how do i enable XSS filtering?


  9. #9
    Join Date
    Aug 2005
    Location
    Wales
    Posts
    10,595
    Tokens
    25
    Habbo
    Catzsy

    Latest Awards:

    Default

    Quote Originally Posted by Android View Post
    May I ask how long they will be able to get on my account for?

    Also I am now using Sfari but how do i enable XSS filtering?
    Well he won't if you use your email to sign in as it says here.

    Also, this will only work on users who logged in using their name and not email. (thanks Loget)

  10. #10
    Join Date
    Jan 2007
    Posts
    16,195
    Tokens
    3,454

    Latest Awards:

    Default

    Quote Originally Posted by Catzsy View Post
    Well he won't if you use your email to sign in as it says here.
    Oh fantastic, it doesn't make sense though - I always go through my email now! Do you think habbo are plannin g on only letting you use your email soon, hence why they didn't think about session stealing?

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •