Security Team Diary

alarm.thumb

THE TRUE STORY

"Thanksgiving weekend"

We don't celebrate Thanksgiving in Finland, but of course we've spent a lot of effort in making sure it's going to be an enjoyable holiday for our American users. No such luck. Some spoilsport was finding it more interesting to glitch photos and replace them with inappropriate pictures, so while we look for how they're doing that, we put photo servers offline so they can't upload more...

"The week before Thanksgiving"

A long development work is finally coming to an end. Over the last months, our development teams have worked diligently to bring Pixels to Habbo, putting all kinds of new code in to measure what users are doing and give Pixels at the right points, working on all the different Effects, testing that everything works together, that every user, old and new, will get the same amount of Pixels for the same things. It's finally done. We're really looking forward to seeing all the fun stuff Habbos come up with using Effects...


On Friday, instead of holiday cheers, we start hearing that in USA, Habbos are being scammed by an unknown attacker. We trace the complaints back to a few fun-killers we've seen making trouble before, and of course ban their new accounts as well. But more importantly, we start to work on figuring out how they're messing things up. Just to make sure no harm can be done to others, we turn off trading, room deletion and gifting.

By next Thursday morning, we've created and tested a new patch that fixes the bugs caused by the scripting, and can enable trading again. Next week, we'll finally be able to release Pixels everywhere. Let the fun continue!


That same weekend, someone decides to spoil other people's fun by finding a script that disconnects Habbos when they're in the same room. We find the hacking tool, of course, and discover that they're also messing with Snowstorm and Battleball game invites. A patch is made and all hotels get updated.

As part of our test and piloting work, we turn on Pixels in UK in preparation for the best Xmas season ever in Habbo. While doing that, we also find out that a new hacking tool is making rounds. What's sad about it is that it looks so easy to install, it makes hacking and scripting seem like a safe thing to do, which it never is.

hockeyref

And the lesson here is:

Scripting is always dangerous, even when it doesn't look like it from the outside. Because of the dangers, every time we see it happening, we have to protect other Habbos by all means possible, including finding out the people responsible in real life and seeking punishment even in the courts. And of course, they will be immediately banned from Habbo!

You can also help us to make Habbo a better place for everyone! Here's what you can do:

1. Never use unofficial (scripted) features. If you are unsure, ask!

2. If you notice something strange going on, inform our moderators and security staff about it.

Scripting and hacking is a serious issue! Read this true story and share your thoughts in the discussion forum!

ABOUT SCRIPTING AND HACKING

I'll be there in a sec, just have to finish this!

Latest Diary Entry: December 2008

hockeyref

Hey there!
Some of you might have noticed some strange scripting activities in Habbo in December. To show you just how serious an issue this is to us (and all Habbos) we would like to share the following excerpt from our security teams December diary.

"How the Grinch nearly stole Thanksgiving"