Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 3 123 LastLast
Results 1 to 10 of 25
  1. #1
    Join Date
    Jun 2012
    Posts
    4,707
    Tokens
    8,368

    Latest Awards:

    Default 15 Year Old Dutch Boy Sued after discovering exploit in Habbo Help Tool!

    http://www.nu.nl/tech/3500845/online...tonen-lek.html

    Hans Schröder and a friend in 2011 discovered a weakness in the help system of Habbo Hotel. Who create an account at the hotel will automatically receive a login for the help system. But who is an account in the help system had been automatically as an employee of Habbo Hotel and was labeled with all information of users.
    "You could at data from 15,000 people who will help tickets had created. Then saw your username, email address, title of the message and the content," says Schröder to Nutech. "You could just export all information. Here you can properly abuse it and that had to be reported."
    it's in dutch and the translate is pretty sure so i won't post it all. i remember seeing this posted n another site where he was trying to sell it before a few years ago (if it was him) lol

  2. #2
    Join Date
    Aug 2011
    Posts
    14,107
    Tokens
    4,179

    Latest Awards:

    Default

    It's really worrying when even children can discover an exploit in such systems lmao.

    Good news about the sueing though.
    /

  3. #3

    Default

    Well, did not expect this at all. Been a while since that happened.

  4. #4
    Join Date
    Jul 2012
    Location
    UK
    Posts
    6,226
    Tokens
    325
    Habbo
    Zitrone

    Latest Awards:

    Default

    poor guy

    #CutForHans

  5. #5
    Join Date
    Mar 2011
    Location
    England
    Posts
    7,427
    Tokens
    13,424
    Habbo
    Empired

    Latest Awards:

    Default

    Didn't understand half the translate but sounds like Habbo ****** up... again... lol.... :|

  6. #6
    Join Date
    May 2006
    Posts
    4,514
    Tokens
    1,832

    Latest Awards:

    Default

    I think Sulake are playing with fire here. I was affected by the leak with personal info stolen. I had preliminary discussions about opening a legal case against Sulake which I won't discuss in detail. The information stolen here led to me being harassed at work, at home and over social media. I almost lost my job as a consequence of what people were able to do with my personal data. If I had lost my job, I would have undoubtedly taken decisive action.

    Anyway, under the Data Protection Act Sulake are expected to do the following:

    • Encrypt any personal information held electronically that would cause damage or distress if it were lost or stolen - they didn't.

    Therefore, the rights of the individual in the same act states that:

    • A right to claim compensation for damages caused by a breach of the Act.

    Essentially, Sulake are expected to take measures to keep their systems secure. Okay, so the obvious argument is that it is Zendesk and not Sulake. However, Sulake are still legally responsible. They chose to remove their internal system and out source it to Zendesk. This decision ensured that a 15 year old boy could access thousands upon thousands of emails, phone numbers and credit card information.

    They can sue people but they should have taken a lot more responsibility than they did. They never told me my information was stolen which also breaks the law. I had contact with Sulake staff in Finland who made it pretty clear they knew parts were stolen but did not know what, when or how. All of which I have email proof of.

    If this game wasn't played mostly by teenagers who don't understand how dangerous this loss of information could be then they would have been sued and fined as and when it happened.

  7. #7
    Join Date
    Jul 2006
    Location
    Leeds
    Posts
    17,006
    Tokens
    26,134
    Habbo
    e5

    Latest Awards:

    Default

    Was it just an exploit or did they get users passwords and stuff?

  8. #8
    Join Date
    Jun 2012
    Posts
    4,707
    Tokens
    8,368

    Latest Awards:

    Default

    Quote Originally Posted by e5 View Post
    Was it just an exploit or did they get users passwords and stuff?
    they got anything you submitted to the help tool lol. how didn't you hear of this!

  9. #9
    Join Date
    Jul 2006
    Location
    Leeds
    Posts
    17,006
    Tokens
    26,134
    Habbo
    e5

    Latest Awards:

    Default

    I did hear it but like I dunno if they got passwords or not
    Quote Originally Posted by sex View Post
    they got anything you submitted to the help tool lol. how didn't you hear of this!

  10. #10

    Default

    Quote Originally Posted by edible View Post
    I think Sulake are playing with fire here. I was affected by the leak with personal info stolen. I had preliminary discussions about opening a legal case against Sulake which I won't discuss in detail. The information stolen here led to me being harassed at work, at home and over social media. I almost lost my job as a consequence of what people were able to do with my personal data. If I had lost my job, I would have undoubtedly taken decisive action.

    Anyway, under the Data Protection Act Sulake are expected to do the following:

    • Encrypt any personal information held electronically that would cause damage or distress if it were lost or stolen - they didn't.

    Therefore, the rights of the individual in the same act states that:

    • A right to claim compensation for damages caused by a breach of the Act.

    Essentially, Sulake are expected to take measures to keep their systems secure. Okay, so the obvious argument is that it is Zendesk and not Sulake. However, Sulake are still legally responsible. They chose to remove their internal system and out source it to Zendesk. This decision ensured that a 15 year old boy could access thousands upon thousands of emails, phone numbers and credit card information.

    They can sue people but they should have taken a lot more responsibility than they did. They never told me my information was stolen which also breaks the law. I had contact with Sulake staff in Finland who made it pretty clear they knew parts were stolen but did not know what, when or how. All of which I have email proof of.

    If this game wasn't played mostly by teenagers who don't understand how dangerous this loss of information could be then they would have been sued and fined as and when it happened.
    This guy pretty much has it in the bag. They're aware that the leak happened, but are still unsure of what exactly was leaked. Similar incidents have happened before, and Sulake do have meetings over this.

    From a leaked presentation about a similar incident a number of years ago, it's apparent that they chose not to alert users as to not cause a ruckus and distress within the hotel, this itself is a poor choice as if they made the choice based on that this time, then they've broken laws.

    Sulake did a bad thing here!

Page 1 of 3 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •