Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 9 of 10 FirstFirst ... 5678910 LastLast
Results 81 to 90 of 94

Thread: Fansite Hacks

  1. #81
    Join Date
    Oct 2013
    Location
    Victoria, Australia
    Posts
    104
    Tokens
    622
    Habbo
    Shenkuu

    Default

    Quote Originally Posted by XxZammyXx View Post
    Really?!?! My cousin goes on Habbohut and she never heard it was hacked....hmm


    People must be sad that they enjoy ruining other fansites...bunch of low lifes! But in the other hand the general managers at the other fansites needs to be more secure then this..come on!
    Habbohut have posted a thread about it though at 9:25 am AEST yesterday.

  2. #82
    Join Date
    Feb 2014
    Location
    Utah
    Posts
    15
    Tokens
    130
    Habbo
    SodaHero

    Default

    Interesting how quickly the hackers hopped from one site to another! Glad Habbox was safe!

    Honestly the locking rooms comment made me LOL. I remember when I was a newb and thought that would keep my precious furni safe -eye roll-.

  3. #83
    Join Date
    Dec 2012
    Location
    USA
    Posts
    78
    Tokens
    458
    Habbo
    Jmmey321

    Default

    having hard time finding the hidden code that is redirecting our site.

  4. #84
    Join Date
    Apr 2011
    Posts
    1,957
    Tokens
    3,649
    Habbo
    Pyroka

    Latest Awards:

    Default

    Ctrl+F in Notepad or whatever you use

    Type redirect.

    Find redirect code in files. Likely done.

    If you're using Linux just use grep to search inside files

  5. #85
    Join Date
    Dec 2012
    Location
    USA
    Posts
    78
    Tokens
    458
    Habbo
    Jmmey321

    Default

    Quote Originally Posted by RyRy View Post
    Ctrl+F in Notepad or whatever you use

    Type redirect.

    Find redirect code in files. Likely done.

    If you're using Linux just use grep to search inside files
    Thanks, but this would not have helped as they used a Base69 Encryption, that made the line of code look like:

    HTML Code:
    header(base64_decode('TG9jYXRpb246IGh0dHA6Ly9yb2ZsLmxhbmQv'));
    Had to do a lot of digging. First I found out using a site, that Swat's site was being redirected via "Header Coder" Secondly I had to accept the fact that the code could be encrypted, thus causing me to use a website to search for base69 encryptions. The first file that came up, I searched and found that code, I used a decoder to find out what it means, and find out that the line is actually "Double Encrypted" so I take a leap of faith and delete the line. Test my site, and find that it is no longer being redirected! Wott! Wott!

  6. #86
    Join Date
    May 2007
    Posts
    10,481
    Tokens
    3,140

    Latest Awards:

    Default

    Quote Originally Posted by HabboSwat View Post
    Base69 Encryption
    I just burst into hysterical laughter at the bastardisation of Base64 encoding.

  7. #87
    Join Date
    Jan 2014
    Location
    US
    Posts
    1,466
    Tokens
    11,451
    Habbo
    landonxd

    Latest Awards:

    Default

    Hacking and finding vulnerabilities definitely isn't a good thing. Shows how selfish and self-centered you are. Can't think about anyone else.

  8. #88
    Join Date
    May 2007
    Posts
    10,481
    Tokens
    3,140

    Latest Awards:

    Default

    Quote Originally Posted by !Landon View Post
    Hacking and finding vulnerabilities definitely isn't a good thing.
    Not true. Maliciously exploiting the vulnerabilities isn't a good thing. Finding them so they can be fixed is good.

  9. #89
    Join Date
    Jun 2009
    Location
    Newcastle Upon Tyne, UK
    Posts
    2,652
    Tokens
    1,389
    Habbo
    lRhyss

    Latest Awards:

    Default

    Quote Originally Posted by yeshello View Post
    yeshellothere

    Mysterious hackur here: (proof - http://rofl.land/lol.txt)

    You're all way off. And the majority of you suck ass.



    that's all
    thanks



    <=3
    Shot in the dark here but...

    $temp = unserialize($check);
    add:
    $temp = json_decode($check,true);

    then running:

    serialize($_POST) changed to json_encode($_POST)

    PHP object injection?

    Pretty sure that was a problem recently, if I remember correctly @xxMATTGxx

  10. #90
    Join Date
    Apr 2014
    Posts
    2
    Tokens
    11

    Default

    Quote Originally Posted by lRhyss View Post
    Shot in the dark here but...

    $temp = unserialize($check);
    add:
    $temp = json_decode($check,true);

    then running:

    serialize($_POST) changed to json_encode($_POST)

    PHP object injection?

    Pretty sure that was a problem recently, if I remember correctly @xxMATTGxx
    PHP object injection is literally useless in vanilla vBulletin. There's no exploitable magic methods. It only becomes a danger when you couple it with poorly made plugins.

    Note how one forum was IPB and one was MyBB, too.

Page 9 of 10 FirstFirst ... 5678910 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •