Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 21

Thread: Phised

  1. #11
    Join Date
    May 2005
    Location
    Yokohama (Japan)
    Posts
    6,499
    Tokens
    0

    Latest Awards:

    Default

    so was I?

    erm other thing is how u can normally tell if it is a fake window?
    phishing isn't done with a program like a keylogger, it is simply a copy of the webpage which sends the details to the owner, the easiest way to tell if it is a fake is to check the url.
    Last edited by Mr.Sam; 30-08-2008 at 01:38 PM.
    (゚Д゚≡゚Д゚)

    Roy: [singing] We don't need no education.
    Moss: Yes you do; you've just used a double negative

  2. #12
    Join Date
    Jun 2007
    Posts
    3,918
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Mr.Sam View Post
    so was I?
    sorry was directed at bef

    + thanks

    1 min after so didn't see ya post


    ta


    Now last question, can sum1 explain wot cookie stealing means?
    I don't accept pm's, instead leave a message on my profile aka vistor message thing.


    Rep means nothing to me, thats why I even say I dislike +reps.

    Cool List: Mario, dinasaw, buttons, Drlacero, flyingjesus,hitman paulmaac,
    jesus (forum name),today, hitman and last but not least beautiful. 8),

    if I forgot you sign my visitor page.

  3. #13
    Join Date
    Oct 2005
    Location
    Spain, Valencia
    Posts
    20,492
    Tokens
    3,575
    Habbo
    GoldenMerc

    Latest Awards:

    Default

    If you have noscripts on which is a firefox addon you can't be session stolen

  4. #14
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by msb. View Post
    sorry was directed at bef

    + thanks

    1 min after so didn't see ya post


    ta


    Now last question, can sum1 explain wot cookie stealing means?
    Cookie stealing. On each website you log in on you have a unique cookie to tell the website who you're logged in as. Some sites have simple cookies like "username=john; passw=1234" other sides use sessions such as "PHPSESSID=dhr8848neru09fjijkmm59trjmn4t59". Habbo uses sessions. The javascript: "document.cookie" is used to get this data - typing "javascript:alert(document.cookie)" in the adress bar will show you your cookies for the site you're on. If the website in question has an XSS vulnerability (people can place their own html and javascript code on it) then an attacker can use this to redirect you to a php script which will log the cookie information. They can then use your cookie information to either log in with if the cookies show username and password or they can hijack your session if the website uses cookies like habbo.

    I hope this makes it clearer to you.

  5. #15
    Join Date
    Jun 2004
    Location
    South England.
    Posts
    2,059
    Tokens
    1,508

    Latest Awards:

    Default

    I cba to read all the posts, the first 4 or so were wrong though :rolleyes:

    Phishing has been around before Habbo, you know..

    Here are a couple of examples:

    - When you create a fake-login like Ebays.com or PayPol.com and create it to look like the site...
    you trick people to going on it, they sign in (good phishers will now re-direct to the real site) and big-bang-bosh - you've got thier user details.

    - Phishing scams are VERY common in Spam emails such as:
    Hey, eBay has lost your users creditcard details in a recent update, please proceed to eBays.com/user_authenticate/Creditcard.php and re-enter your information.

    Basically, anything that requires a scam-site of some sort is usually considered phishing...
    Last edited by vito201-:D; 30-08-2008 at 05:43 PM.
    Apparently I am not allowed to advertise my site any longer. T_T
    - Alex (Shenk).

  6. #16
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Unhappyness View Post
    First of all it's called "phishing" not "phising". It is when a 'hacker' tells you to go on a website which is a fake version of another website. If you log in it will send the 'hacker' your login details.

    Cookie stealing is a completely different thing and can't be done effectivly without a vulnerability in the website it's targeting, whereas phishing can be done no matter how secure the website is.
    Quote Originally Posted by vito201-:D View Post
    I cba to read all the posts, the first 4 or so were wrong though :rolleyes:

    Phishing has been around before Habbo, you know..

    Here are a couple of examples:

    - When you create a fake-login like Ebays.com or PayPol.com and create it to look like the site...
    you trick people to going on it, they sign in (good phishers will now re-direct to the real site) and big-bang-bosh - you've got thier user details.

    - Phishing scams are VERY common in Spam emails such as:
    Hey, eBay has lost your users creditcard details in a recent update, please proceed to eBays.com/user_authenticate/Creditcard.php and re-enter your information.

    Basically, anything that requires a scam-site of some sort is usually considered phishing...
    How is that wrong? Where did I say that it's just for habbo. btw It's 'PayPal'

  7. #17
    Join Date
    Jun 2004
    Location
    South England.
    Posts
    2,059
    Tokens
    1,508

    Latest Awards:

    Default

    Quote Originally Posted by Unhappyness View Post
    How is that wrong? Where did I say that it's just for habbo. btw It's 'PayPal'
    No... PayPol.com was an old scam website... as way Ebays.com.

    And i swear it didn't say that the first time i read it >_> Pill-comedown bare with me... lol
    Apparently I am not allowed to advertise my site any longer. T_T
    - Alex (Shenk).

  8. #18
    Join Date
    Oct 2006
    Posts
    9,905
    Tokens
    26,858
    Habbo
    Zak

    Latest Awards:

    Default

    I go on them and type fake users n passwords.

  9. #19
    Join Date
    Jun 2007
    Posts
    3,918
    Tokens
    0

    Latest Awards:

    Default

    vito and unhappy
    dunno why ur debating each other LOL

    ur both actually right :S


    thanks very much, my knowledge is improving, brap.


    Quote Originally Posted by GoldenMerc View Post
    If you have noscripts on which is a firefox addon you can't be session stolen
    Cool so firefox, no scripts? so u can get an addon on firefox where it prevents you being hacked?

    directed @ unhappy... : So basically the safest way is to check the url pretty much or can people still steal ur cookies by say if u went on a site that isn't safe by mistake, then went on the REAL SITE, can they still change it some how?
    Last edited by msb.; 31-08-2008 at 12:03 AM.
    I don't accept pm's, instead leave a message on my profile aka vistor message thing.


    Rep means nothing to me, thats why I even say I dislike +reps.

    Cool List: Mario, dinasaw, buttons, Drlacero, flyingjesus,hitman paulmaac,
    jesus (forum name),today, hitman and last but not least beautiful. 8),

    if I forgot you sign my visitor page.

  10. #20
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by msb. View Post
    vito and unhappy
    dunno why ur debating each other LOL

    ur both actually right :S


    thanks very much, my knowledge is improving, brap.



    Cool so firefox, no scripts? so u can get an addon on firefox where it prevents you being hacked?

    directed @ unhappy... : So basically the safest way is to check the url pretty much or can people still steal ur cookies by say if u went on a site that isn't safe by mistake, then went on the REAL SITE, can they still change it some how?
    If you go on a site that has a script to steal your cookies as soon as you go on they get your cookies. It doesn't matter what you do afterwards. The best way to prevent this is to not go on sites you don't trust and if you think a site you went on might have had a cookie stealer then either log out and log back in if you think it stole your cookies from a website that uses sessions or change your password if you thing it stole your cookies from a website that uses the username and password in the cookies. If you don't know then do both. Another way to stop it (which I personally don't like but many other people do) is to use firefox's noscript addon which only executes javascript (needed for cookie stealing) from websites you have told it to.

Page 2 of 3 FirstFirst 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •