Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 45
  1. #21
    Join Date
    Feb 2006
    Posts
    24,818
    Tokens
    63,690
    Habbo
    FlyingJesus

    Latest Awards:

    Default

    Quote Originally Posted by Immenseman View Post
    It was sarcasm, I don't think people take GCSEs in hacking habbo fansites. I was merely highlighting they were hardly handling anyone serious just some deluded child who met his girlfriend through Habbo and learnt to read on Habbo and I am being deadly serious.
    omg it was Fry.

    In reply to the actual thread topic though - there was a security problem so you suggest giving out full admin access to more people? Unfortunately whilst people should really be more careful with their details (especially when it can involve other people as this case did) even those who do protect themselves properly as they are told to can find themselves at risk if someone really determined comes along. The benefit of potentially faster reaction doesn't come close to the problem of increased risk. If 4 people have admin access then adding even one more makes for a 25% bigger target
    | TWITTER |



    Blessed be
    + * + * + * +

  2. #22
    Join Date
    Sep 2007
    Location
    England
    Posts
    3,602
    Tokens
    500

    Latest Awards:

    Default

    Adam Welsh is Adzeh the ex agm lol o.O
    The other day I was in a toilet.
    A voice came from the cubicle next to me: "Hello mate, how are you doing?"
    I didn't want to be rude, so I said, "Not too bad, thanks."
    I heard the voice again. "So, what are you up to?"
    Again I answered, "Just having a quick ****... How about yourself?"
    Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."

  3. #23
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    I think really what this has shown is the lack of security shown amongst staff members, for example, I see in people's desktop screenshots they just leave ModCP passwords and things in text files, you may as well Digg it or something!

    These staff members should be somewhat clued up about how to treat sensitive data like that and how to NOT get keyloggers and to only download files from trusted sources, and perhaps this could be added to the application process.

    What I have seen though are quick reaction times from the staff members and I applaud them
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  4. #24
    Join Date
    Sep 2007
    Location
    England
    Posts
    3,602
    Tokens
    500

    Latest Awards:

    Default

    I still think Habbox should invest in SSL Certificates for MOD/ADMINCP + site admin
    The other day I was in a toilet.
    A voice came from the cubicle next to me: "Hello mate, how are you doing?"
    I didn't want to be rude, so I said, "Not too bad, thanks."
    I heard the voice again. "So, what are you up to?"
    Again I answered, "Just having a quick ****... How about yourself?"
    Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."

  5. #25
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Thats not going to help, especially in situations like this.
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  6. #26
    Join Date
    Sep 2007
    Location
    England
    Posts
    3,602
    Tokens
    500

    Latest Awards:

    Default

    Quote Originally Posted by Tawm View Post
    Thats not going to help, especially in situations like this.
    Why? Or if they set it so joomla admin can only be accessed by xxx ips
    The other day I was in a toilet.
    A voice came from the cubicle next to me: "Hello mate, how are you doing?"
    I didn't want to be rude, so I said, "Not too bad, thanks."
    I heard the voice again. "So, what are you up to?"
    Again I answered, "Just having a quick ****... How about yourself?"
    Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."

  7. #27
    Join Date
    Apr 2005
    Posts
    4,614
    Tokens
    90

    Latest Awards:

    Default

    Quote Originally Posted by Favourtism View Post
    Why? Or if they set it so joomla admin can only be accessed by xxx ips
    Dynamic IP's?

  8. #28
    Join Date
    Jun 2009
    Posts
    6
    Tokens
    0

    Default

    Quote Originally Posted by Favourtism View Post
    Why? Or if they set it so joomla admin can only be accessed by xxx ips
    Not everyone has a static IP... and SSL won't help if an mod is keylogged surely?

  9. #29
    Join Date
    Sep 2007
    Location
    England
    Posts
    3,602
    Tokens
    500

    Latest Awards:

    Default

    Quote Originally Posted by Robbie! View Post
    Dynamic IP's?
    Certificates again then? Not many people have dynamic IPs though???
    The other day I was in a toilet.
    A voice came from the cubicle next to me: "Hello mate, how are you doing?"
    I didn't want to be rude, so I said, "Not too bad, thanks."
    I heard the voice again. "So, what are you up to?"
    Again I answered, "Just having a quick ****... How about yourself?"
    Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."

  10. #30
    Join Date
    Aug 2004
    Location
    UK
    Posts
    11,283
    Tokens
    2,031

    Latest Awards:

    Default

    Most ISP will assign ips dynamically, static generally will cost extra.
    SSL wont help in the slightest since no direct hacking is occurring. If they have the pw, then the password will work whatever.

Page 3 of 5 FirstFirst 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •