Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 3 123 LastLast
Results 1 to 10 of 24
  1. #1
    Join Date
    Oct 2011
    Location
    Hell
    Posts
    196
    Tokens
    147
    Habbo
    Adnoun

    Default WARNING: Javascript Hacking Via Links

    People are using a new method which was a spin off to the last huge issue about "ClickJacking" in which an email address is leached to the victims Habbo ID. They use a website (won't name it) in which there's a tutorial on how to do it and all it takes is an account on this website and a small amount of know-how and boom you've got a Javascipt hacking method. Do not click any bit.ly or any other links which look dodgey or unsafe. I thought I'd warn some of you before someone maks a horrible mistake. Here's a screen shot of what some guy gained from it:



    If a site ADMIN wants proof that this is legit and I am not causing a huge stir for attention I will gladly PM them 100% video proof that it works as someone posted a tutorial on youtube.

    Hope I bailed someone out of making a big mistake, Breeze


  2. #2
    Join Date
    Feb 2010
    Posts
    21,020
    Tokens
    49,520
    Habbo
    Samanfa

    Latest Awards:

    Default

    Ooh maybe this is what hacked Normies, well all avatars on an id but luckily Normies was on another.

  3. #3
    Join Date
    May 2007
    Posts
    10,481
    Tokens
    3,140

    Latest Awards:

    Default

    I don't believe this is a new exploit but it's certainly not a nice one either.

    I would personally never click a link in the client and it's beyond me as to why they added that feature.
    Chippiewill.


  4. #4
    Join Date
    Aug 2011
    Posts
    14,107
    Tokens
    4,179

    Latest Awards:

    Default

    I don't click links in-client anyway ;L. I'm too scared to find out what the YouTube ones are, the bit.ly ones probs lead to *REMOVED* (not sure if I can name that aha - DON'T GOOGLE THAT SITE IF YOU DON'T KNOW WHAT IT IS) or some of that rubbish and the rest are just useless for me ._.

    But yea, thx for warningx

    moderator alert Edited by SyrupyMonkey (Asssistant General Manager (Staff)): Please do not mention inappropriate sites.
    Last edited by myke; 28-01-2012 at 08:52 AM.
    /

  5. #5
    Join Date
    Mar 2011
    Location
    England
    Posts
    7,427
    Tokens
    13,424
    Habbo
    Empired

    Latest Awards:

    Default

    I don't click links because they lag me so very badly.. But I guess I can thank my lag in this case ^_^

    Thanks for the warning, I think I've something something along those lines before, though

  6. #6
    Join Date
    Nov 2011
    Posts
    3,393
    Tokens
    881

    Latest Awards:

    Default

    I don't click links unless there a site I know and fully trust.
    Thanks for the warningthough!

    she's morphine, queen of my vaccine

  7. #7
    Join Date
    Nov 2011
    Location
    US of A
    Posts
    909
    Tokens
    108
    Habbo
    FiftyCal

    Latest Awards:

    Default

    I believe you breeze because thats how i get fake virus protection is through javascript via links
    Joined Habbox: 11-18-2011
    Became DJ At Habboxlive: 11-22-2011
    Promoted To Senior DJ: 2-3-2012
    Stepped Down to Regular DJ 5-19-12
    Resigned As DJ June 2012


  8. #8
    Join Date
    Jun 2004
    Location
    South England.
    Posts
    2,059
    Tokens
    1,508

    Latest Awards:

    Default

    Sulake have locked up Habbo pretty damn effectively now - it means only small exploits like this can ever be found now-a-days... gone is the time when we'd find an exploit that allowed gain of hijacking the client.windows etc...
    You basically actually have to fall for some sort of scam now... so if you just don't follow links you don't trust in regards to Habbo (So if anyone involved in Habbo sends you a link - make sure you know what it is/why they sent it before following it).

    Simple.

    Not like when you could use the client windowID to refresh into our own login version and then send the credentials back to the real client upon entry... so that the user barely knew anything was up... meant if you hacked a fansite you could expect hundreds of furni-hacks per day.
    Good times, good times... but far, far, far away now... and replaced with this clickjacking method to add a secondary email to an Habbo account's ID.
    Apparently I am not allowed to advertise my site any longer. T_T
    - Alex (Shenk).

  9. #9
    Join Date
    Oct 2011
    Location
    Hell
    Posts
    196
    Tokens
    147
    Habbo
    Adnoun

    Default

    Quote Originally Posted by vito201-:D View Post
    Sulake have locked up Habbo pretty damn effectively now - it means only small exploits like this can ever be found now-a-days... gone is the time when we'd find an exploit that allowed gain of hijacking the client.windows etc...
    You basically actually have to fall for some sort of scam now... so if you just don't follow links you don't trust in regards to Habbo (So if anyone involved in Habbo sends you a link - make sure you know what it is/why they sent it before following it).

    Simple.

    Not like when you could use the client windowID to refresh into our own login version and then send the credentials back to the real client upon entry... so that the user barely knew anything was up... meant if you hacked a fansite you could expect hundreds of furni-hacks per day.
    Good times, good times... but far, far, far away now... and replaced with this clickjacking method to add a secondary email to an Habbo account's ID.
    Alex you've not changed a bit man! I agree with you however the good times are long gone.


  10. #10
    Join Date
    Nov 2011
    Location
    Malaysia
    Posts
    611
    Tokens
    123
    Habbo
    twinart

    Latest Awards:

    Default

    Thanks for the advice. I'll take care.

Page 1 of 3 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •