Page 7 of 9 FirstFirst ... 3456789 LastLast
Results 61 to 70 of 89
  1. #61
    Join Date
    Jul 2006
    Location
    system32
    Posts
    305
    Tokens
    0

    Default

    and Heidster used some crap about a new quest starting so habbos security didn't look as crap as it actually is.

  2. #62
    Join Date
    Nov 2006
    Location
    Bolton
    Posts
    3,564
    Tokens
    1,804

    Latest Awards:

    Default

    Quote Originally Posted by PenguinFluid View Post
    dont go on websites when your on habbo
    ..only Habbo addicts would do that. "/.

    Just to come on the net to use Habbo only, no other sites lmao. :S

    Habbo can fix the XSS flaw if they try..

  3. #63
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Go on Habbo.co.uk, in the address bar paste: javascript:alert(document.cookie);

    The "hacker" gets that sent to his email. He can use the JSSessionID to get into your account.

  4. #64
    Join Date
    May 2007
    Posts
    63
    Tokens
    0

    Default

    Quote Originally Posted by Invent View Post
    Go on Habbo.co.uk, in the address bar paste: javascript:alert(document.cookie);

    The "hacker" gets that sent to his email. He can use the JSSessionID to get into your account.
    How's that send it to his email?!

    edit: o ya dont matter.
    Last edited by Never; 02-06-2007 at 03:56 PM.
    Left HabboxForum.


  5. #65
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Some things in Habbo allow you to specify the data in say an input form by doing "?formname=">+javascript code" or something, lol.

  6. #66
    Join Date
    May 2007
    Posts
    63
    Tokens
    0

    Default

    Oh interesting...

    How would Habbo patch this?
    Left HabboxForum.


  7. #67
    Join Date
    Oct 2006
    Posts
    3,277
    Tokens
    1,758

    Latest Awards:

    Default

    Quote Originally Posted by Never View Post
    Oh interesting...

    How would Habbo patch this?
    bobba It Knowing Them! Lol, Nice Find.

  8. #68
    Join Date
    Sep 2005
    Location
    N. Ireland
    Posts
    7,754
    Tokens
    67

    Latest Awards:

    Default

    Quote Originally Posted by Black-Sheak View Post
    bobba It Knowing Them! Lol, Nice Find.
    LOLOLOL

    Im gonna be a little more carefull from now on

    But not be a habbo addict and not visit sites lolol


    Click the image.

  9. #69
    Join Date
    Oct 2005
    Posts
    62
    Tokens
    1,951
    Habbo
    bill

    Latest Awards:

    Default

    Both of those MOD's signed my guestbook.


    habbo.co.uk/home/bill

  10. #70
    Join Date
    Dec 2004
    Location
    Essex, UK
    Posts
    3,285
    Tokens
    0

    Latest Awards:

    Default

    It's very easy to patch, just filter the input for the GET variables What I don't know is how the session ID is gonna help them to touch your account.



    i used to be NintendoNews. visit my blog or add me on twitter.
    need help with vista? i am a microsoft certified technology specialist in configuring windows vista and connected home integrator.. pm me for help!


    "I am the way, the truth, and the life. No one comes to the Father except through me"
    John 14:6 (NIV)


Page 7 of 9 FirstFirst ... 3456789 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •