Home | Partners | Legal Notice | About | Contact | IRC

#32 HabboTimes.de Dump SQL Injection 2008


12082010-2151DE/tn: main adress leaks_18.html

Back to the roots, Tunny and X-RibbiX found a critical SQL injection on the article page from HabboTimes two years ago. They worked over two hours for the injection. After trying lot of injections, they found one to list all databases from [HT]. From CMS to phpbb3. This database is inlcuded on an index backup, with listing all crypted passwords.

Release date: 08.08.2008, most of them does not work anymore!

URL: http://wiseowl.kunta.ch/habbotimes_de_dump_19k_passwords_08.08.2008.rar (txt, htm and images included)