Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 15
  1. #1
    Join Date
    Feb 2007
    Location
    Manchester
    Posts
    7,556
    Tokens
    58

    Latest Awards:

    Default New Session Stealer Type Scam!

    Ok it seems there is a new session stealer type scam. Somebody will add you on messenger and make up some story eg, worked out a new program to do something on Habbo. They will say go to the Habbo homepage while your logged in and type in the Url ' javascript:alert(document.cookie);'.

    You will then get a pop-up and they will say 'tell me the code after JSESSIONID' if you tell them the code they will put it into a separate code on there URL which will then log them into your account so they can do what they want on it

    Be warned OK?

  2. #2
    Join Date
    Dec 2006
    Location
    Singapore
    Posts
    7,212
    Tokens
    0

    Latest Awards:

    Default

    Thanks for the info
    shawn

  3. #3
    MrCorny Guest

    Default

    Good find

  4. #4
    Join Date
    Apr 2007
    Posts
    2,431
    Tokens
    0

    Latest Awards:

    Default

    Yeah ive seen this before. Although i have read it only logs them into your homepage - if it is true they cannot do much.

    Good find though

    [X] [X] [X]

  5. #5
    Join Date
    Apr 2005
    Posts
    3,331
    Tokens
    75

    Latest Awards:

    Default

    This is old..
    well maybe new to this forum. but yeah..

    It lets you steal their homepage thing.. but its useless if you have been online for more then 10 minutes because it will say that you timed out.. and the person would need your password to get in..
    formerly liquidaciid

  6. #6
    Join Date
    Jul 2006
    Posts
    6,615
    Tokens
    0

    Latest Awards:

    Default

    Thanks for the info!

    Good find :]

  7. #7
    Join Date
    Feb 2007
    Location
    Rochester NY
    Posts
    1,932
    Tokens
    0

    Latest Awards:

    Default

    Habbo.co.uk/client
    When u go there (its actual hotel) it says in the link
    https://www.habbo.co.uk/account/logi...f74gh65df47g65 it says jessionid
    Last edited by Duck Hunt; 25-06-2007 at 04:23 PM.

  8. #8
    Join Date
    Dec 2004
    Location
    somewhere in the middle of now
    Posts
    258
    Tokens
    0

    Default

    Quote Originally Posted by cardboard-box View Post
    Ok it seems there is a new session stealer type scam. Somebody will add you on messenger and make up some story eg, worked out a new program to do something on Habbo. They will say go to the Habbo homepage while your logged in and type in the Url ' javascript:alert(document.cookie);'.

    You will then get a pop-up and they will say 'tell me the code after JSESSIONID' if you tell them the code they will put it into a separate code on there URL which will then log them into your account so they can do what they want on it

    Be warned OK?
    Well done for telling everyone how to steal someones session remove the URL so people don't know it as long as people dont give away their session id they are fine.
    Trusted
    AC-400

  9. #9
    Join Date
    May 2007
    Posts
    168
    Tokens
    0

    Default

    Quote Originally Posted by NeonLime View Post
    Habbo.co.uk/client
    When u go there (its actual hotel) it says in the link
    https://www.habbo.co.uk/account/logi...f74gh65df47g65 it says jessionid
    Thats just the login jsessionid Im pretty sure that it is the same for everyone but I may be wrong, however it is harmless as it is only leading to a non-logged in account. But when you are logged in your jsessionid changes and you can use programmes to edit your cookies to that (will not name the programmes and addons for safety reasons)

    Quote Originally Posted by 5970 View Post
    Well done for telling everyone how to steal someones session remove the URL so people don't know it as long as people dont give away their session id they are fine.
    Read above..
    My Active Habbo accounts:
    • Nom
    • Per
    Just Fr me if you need me urgently.

    Bulk normals for credits:
    http://www.habboxforum.com/showthrea...44#post4769444
    CHEAP!

  10. #10
    Join Date
    Apr 2006
    Location
    UK
    Posts
    4,830
    Tokens
    0

    Latest Awards:

    Default

    Thanks for the info.

    Need a domain but dont have paypal... not to worry. You can purchase a domain via text or home phone at XeoDomains.mobi.

    (X Moderator)
    AKA Cheekykarl

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •