Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 5 of 7 FirstFirst 1234567 LastLast
Results 41 to 50 of 66

Thread: Filter these

  1. #41
    Join Date
    Aug 2004
    Location
    USA
    Posts
    4,518
    Tokens
    3,536
    Habbo
    nvrspk4

    Latest Awards:

    Default

    Congrats while it lasted, quite ingenious honestly. We will be implementing a simple patch, hopefully tomorrow morning. (Credit to Pyroka)
    It costs nothing to be a good friend.

    American and Proud

    I also use the account nvrspk on other computers.


  2. #42
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by nvrspk4 View Post
    Congrats while it lasted, quite ingenious honestly. We will be implementing a simple patch, hopefully tomorrow morning. (Credit to Pyroka)
    Yes, very ingenious. I wonder who started it off.

    I'm pretty sure things like these are impossible to patch without adding a security token to each form.

    Look up CSRF/XSRF.

  3. #43
    Join Date
    Aug 2004
    Location
    USA
    Posts
    4,518
    Tokens
    3,536
    Habbo
    nvrspk4

    Latest Awards:

    Default

    Quote Originally Posted by Unhappyness View Post
    Yes, very ingenious. I wonder who started it off.

    I'm pretty sure things like these are impossible to patch without adding a security token to each form.

    Look up CSRF/XSRF.
    I would show you the simple patch however I feel like someone would find a workaround so we'll let them discover it without our help.
    It costs nothing to be a good friend.

    American and Proud

    I also use the account nvrspk on other computers.


  4. #44
    Join Date
    Dec 2006
    Posts
    3,970
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by nvrspk4 View Post
    I would show you the simple patch however I feel like someone would find a workaround so we'll let them discover it without our help.
    Im sure people will find a way arround it anyway
    Quote Originally Posted by Unhappyness View Post
    Yes, very ingenious. I wonder who started it off.

    I'm pretty sure things like these are impossible to patch without adding a security token to each form.

    Look up CSRF/XSRF.
    You could simply change the change style form at the bottom of the page to use $_POST then it cannot be changed unless someone submits it.
    Last edited by Decode; 15-08-2008 at 08:53 AM.
    Lets set the stage on fire, and hollywood will be jealous.

  5. #45
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Tom743 View Post
    You could simply change the change style form at the bottom of the page to use $_POST then it cannot be changed unless someone submits it.
    It is still possible, just harder. I won't explain how.

  6. #46
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Unhappyness View Post
    It is still possible, just harder. I won't explain how.
    EDIT: It's also possible to do this with Habbox's radio request system (I won't say how). I'm sure 300 of the same request from different people would piss off the DJs, although it might convince them to play some death metal.

    EDIT: I pressed quote instead of edit by accident.

    EDIT: I was past the edit limit anyway.
    Last edited by Jxhn; 15-08-2008 at 10:34 AM.

  7. #47
    Join Date
    Sep 2007
    Location
    England
    Posts
    3,602
    Tokens
    500

    Latest Awards:

    Default

    Quote Originally Posted by Swaydo View Post
    yes i know smart pants, i was just agreeing

    dont give me that
    I didnt mean the '-.-' at you, it was directed at the noobs who are doing it.

    Quote Originally Posted by Unhappyness View Post
    EDIT: It's also possible to do this with Habbox's radio request system (I won't say how). I'm sure 300 of the same request from different people would piss off the DJs, although it might convince them to play some death metal.

    EDIT: I pressed quote instead of edit by accident.

    EDIT: I was past the edit limit anyway.
    Yup. Me and Mecto were testingo n our forum and you can do that. its also is/was(?) possible to log users out and redirect them.

    Glad to see that is has/is being patched
    The other day I was in a toilet.
    A voice came from the cubicle next to me: "Hello mate, how are you doing?"
    I didn't want to be rude, so I said, "Not too bad, thanks."
    I heard the voice again. "So, what are you up to?"
    Again I answered, "Just having a quick ****... How about yourself?"
    Then I heard him say "Sorry, mate, I'll have to call you back. I've got some **** in the cubicle next to me answering everything I say."

  8. #48
    Join Date
    Feb 2006
    Location
    London
    Posts
    7,904
    Tokens
    197

    Latest Awards:

    Default

    Can't you just filter the styleid= or something?
    That's why we seize the moment, try to freeze it and own it, squeeze it and hold it cause we consider these minutes golden.


  9. #49
    Join Date
    Nov 2005
    Location
    Edinburgh
    Posts
    11,690
    Tokens
    0
    Habbo
    Pyroka

    Latest Awards:

    Default

    That's just filtering out one problem, there's many things they could do with the [IMG] tag. It's not limited to just changing styles on a forum so they needed something more generic. Either way, it's done now.

  10. #50
    Join Date
    Dec 2006
    Posts
    3,970
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Pyroka View Post
    That's just filtering out one problem, there's many things they could do with the [IMG] tag. It's not limited to just changing styles on a forum so they needed something more generic. Either way, it's done now.
    What changes have been made, I can still use image tags.

    Last edited by Decode; 15-08-2008 at 11:08 AM.
    Lets set the stage on fire, and hollywood will be jealous.

Page 5 of 7 FirstFirst 1234567 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •