WARNING: Serious security problem in Haypi Support!
I would like to inform All players and Haypi support Team of a serious hole in they ingame Support system:
1. Everyone can read the support messages..
1.1. How? Simply by extracting the ID from a message, using your own system from
I censured the full link to prevent any abuse of this information...
1.2. I simply tapped on one of your links ingame and got the full link path of your Mailing system..
1.3. Prof? Here is few of the messages from a players: (I censured the full text for privacy of the player)
- Code:
From: support201
Date: 2014/01/10 05:26
Subject: Re:This kid keeps using inappropriate language
Dear ***Censured***, We have given him a ban. He cannot chat in the chat room in the next 48 hours. Thanks for your support very much. Enjoy your game. Teresa The Lost Tower Team
Blakk kept calling me names and swearing in world chat and all I tried to do was help him find a cygness. But he won't stop so I'm reporting here's some screen shots, Thank you
1.4. I will only inform the full steps of this bug to a support member on a private message service.. so donnot ask me to give you info for abusment or any kind of actions that are not safe for players or the game!
NOTE: I strongly advice you not to write any personal or billing information on the ingame Help -- Support system!
Insted use the haypi E-Mail: monstersupport@haypi.com
mltsupport@haypi.com
Haypi Team ... Please upgrade your system to prevent this for being abused!... This is a serius bug in your system not a HACK .... if i can do this then anyone can!!!
Please Conntact me ingame or on some message service so i can share full information about this issue! Till then i will not use your Help system at all!
Yours BlackCRO!
Thank you!
