Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 5 12345 LastLast
Results 1 to 10 of 47
  1. #1
    Join Date
    Dec 2006
    Posts
    3,970
    Tokens
    0

    Latest Awards:

    Default [IMG] tag exploit

    I have sent a PM to Joshuar but nothing has been done about it Heres a demo of how it works-

    If you go to http://tom743.awardspace.com/hxf/test.txt you will knotice your IP has been logged, its against the rules of the forum to post peoples IPs because its personal infomation, so in my oppinion this should be fixed as soon as possible. Anyone could figure out how to do the code, its only 7 lines long. If someone puts that code in there signature then they could get hundreds of ips if they post regualy.

    If someone has a computer with remote access enabled and they still have the default admin/administrator account that is on XP which has no password (maybe vista as well) you could connect to there computer and view files, delete files, copy files to there computer, copy files from there computer. Allthough thats a little far fetched it could happen.

    By the way you can delete your ip from the text file by clicking here.

    Thanks for reading this.
    Lets set the stage on fire, and hollywood will be jealous.

  2. #2
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Tom, it's not an exploit...

    You can do it secretly via any image, it'd be a waste of time trying to 'patch' it.

  3. #3
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Tom, it's not an exploit...

    You can do it secretly via any image, it'd be a waste of time trying to 'patch' it.

    Edit: Bloody lag >_<

  4. #4
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Wouldn't the person have to know port number to connect to your computer?

    On digitalpoint images that aren't really images just display as a link even if it's a dir called like orly.jpg or something. But nearly all forums are vulnerable to this, warez-bb is and they have much more members than HxF so they would more likely be targeted.

  5. #5
    Join Date
    Aug 2005
    Location
    London
    Posts
    9,773
    Tokens
    146

    Latest Awards:

    Default

    Cpanel automatically logs IP's anyway so I've got a few thousand ip's off several users on my Cpanel anyway, not like i'm going to do anything with them even if I could do anything .

  6. #6
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    Exactly, IPs are extremely easy to get, but you can't do anything with them apart from prevent them from visiting your website

  7. #7
    Join Date
    May 2006
    Location
    Hull
    Posts
    7,701
    Tokens
    2,430
    Habbo
    Moh

    Latest Awards:

    Default

    If logging ip's was such a risk, I'm sure they wouldn't allow you to log them

    But you can easily find out the location of the ip with them (Well, city).

  8. #8
    Join Date
    Dec 2006
    Location
    London
    Posts
    3,536
    Tokens
    170

    Latest Awards:

    Default

    Couldn't connect to mine.

    Remote Desktop is off. It's not on my exceptions list.

    2005: JOINED ; Radio DJ

    2006: Radio DJ ; Senior DJ

    2007: HxTV Flash Artist ; Productions Staff ; HxHD Staff ; Head DJ ; Events Organiser ; Productions Staff ; Competitions Staff ; Assistant Radio Manager

    2008: Senior Competitions Staff ; Forum Moderator ; HxHD Staff ; Competitions Manager ; Graphics Designer

    2009: LEFT ; Guest DJ

  9. #9
    Join Date
    Jun 2008
    Location
    England
    Posts
    467
    Tokens
    0

    Default

    have to admit these stupid scripts to get profile views and thread views is annoying as crap now

  10. #10
    Join Date
    Jun 2007
    Posts
    3,918
    Tokens
    0

    Latest Awards:

    Default

    this is why I think you should ban all signatures and just have text


    too many rule breaking, first that habbo log out crap

    now this. I agree tom743 its out of hand.


    P.s. How can you disable remote access I think i have but incase + don't u have our ip now cuz of the image, i never clicked link.
    I don't accept pm's, instead leave a message on my profile aka vistor message thing.


    Rep means nothing to me, thats why I even say I dislike +reps.

    Cool List: Mario, dinasaw, buttons, Drlacero, flyingjesus,hitman paulmaac,
    jesus (forum name),today, hitman and last but not least beautiful. 8),

    if I forgot you sign my visitor page.

Page 1 of 5 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •