and Heidster used some crap about a new quest starting so habbos security didn't look as crap as it actually is.

and Heidster used some crap about a new quest starting so habbos security didn't look as crap as it actually is.
Go on Habbo.co.uk, in the address bar paste: javascript:alert(document.cookie);
The "hacker" gets that sent to his email. He can use the JSSessionID to get into your account.
Last edited by Never; 02-06-2007 at 03:56 PM.
Left HabboxForum.
Some things in Habbo allow you to specify the data in say an input form by doing "?formname=">+javascript code" or something, lol.
Oh interesting...
How would Habbo patch this?
Left HabboxForum.
Both of those MOD's signed my guestbook.
habbo.co.uk/home/bill
It's very easy to patch, just filter the input for the GET variablesWhat I don't know is how the session ID is gonna help them to touch your account.
i used to be NintendoNews. visit my blog or add me on twitter.
need help with vista? i am a microsoft certified technology specialist in configuring windows vista and connected home integrator.. pm me for help!
"I am the way, the truth, and the life. No one comes to the Father except through me"
John 14:6 (NIV)
Want to hide these adverts? Register an account for free!