June 30th, 2008
Hi readers,
All began the 29th of February 2008. BBHQ was present on test but not on open. I was waiting for a test account since a few years and I really wanted to visit BBHQ. My objective was : HAVE A FULL TEST ACCOUNT or LAUNCH BBHQ on the open server.
29h February, 02:00PM
I’m reading the log file trying to understand how the game is working, looking for some information about Toontown programming, downloading Panda3d…
29th February, 05:00PM
I’m able to launch the game on the open server with my own Toontown files but I still can’t launch the game with BBHQ on open. Here is the first picture I made that day.
29h February, 08:00PM
I’m still playing with that issue. For now, I’m only able to play with textures files.
01st March, 01:00AM
I finally forget about playing on open with BBHQ, it’s totally impossible because the gameserver can’t recognize it. I NEED to play on test if I want to visit it. I’m looking for another issue on test because the open one doesn’t work on test (in fact I didn’t find the test launcher).
01st March, 01:30AM
I GOT IT, I’m on test with a FULL account whereas I’m not a tester. I make a small toon, the faster I can to visit BBHQ. Here is my very first picture of BBHQ.
I have now a new objective, make a big toon and go defeat that CEO.
Tags: bbhq, hack, test, toontown
Posted in Uncategorized | 9 Comments »
June 30th, 2008
Princess Boo Boo was my main toon on test. Because test is really…..quiet, I needed help. I asked some non-tester friends if they wanted to join me on test with a new toon to help each others and have a big toon before BBHQ come out on open and for next releases.
One friend joined me on test, others was too scared to be banned so they stayed on open.
My friend was not online a lot, I needed another friend but can’t find one. I have two open accounts, an US one and an UK one. My new objective : PLAY ON TEST WITH A UK ACCOUNT.
5 minutes later, Miss Rosie was born
Miss Rosie is the first UK non-tester toon on test and she’ll be certainly the last one because Disney doesn’t want UK players on test.
I’m now ready to play on test, I have two toons online at the same time and they are playing a lot :). I only have one picture of them. Here it is, Miss Rosie was the cat and Princess Boo Boo the mouse.
Tags: test, toontown, uk
Posted in Uncategorized | No Comments »
June 30th, 2008
After two issues found in only a few days, I’m telling myself that there is certainly others one. I’m asking myself, which one I would like to find and here is the one I want to find : IS THERE A PRIVATE DEV SERVER ?
A day in march, 11:30AM
There was an update a few days before and just after that one, the name of the open server changed, I was like “huh ? There are two open servers”. With the non-tester issue, I was able to play on all servers with a full account so I logged on the hidden open server. It’s a server like the US/UK one with known districts like Nutty River, Kookyboro, Nutty Summit…. but it’s totally empty.
I was fishing when suddenly, a toon came back from nowhere, I knew he was not a player (because players was not able to log on that server) but a dev, I clicked on it and….it was a dev !
17st March 2008
I was still looking for a dev server when I found this page on the test server. It’s talking about a “QA” account server, that means there is a “QA” game server too ! I tried to log on the “QA” gameserver and it worked ! There are three districts in it and a toon named Sysadmin (sysadmin means Administrator System, the personn who is working on toontown servers). I was really happy when I found that server but I was less happy when I saw it was only a copy of the open server with updates a few days before open.
I was able to play on the japanese server with a full account too.
Tags: dev, qa, server, toontown
Posted in Uncategorized | 3 Comments »
June 30th, 2008
The more I searched, the more I found important issues. I had fun with it but it was too big to keep it secret, I needed to tell Disney they have problems before cheaters, bad hackers and others find this.
I sent an email to Disney with all what I found and………they answered me I didn’t have to worry about it….
I was really surprised about their answer so I sent a message to Fraulein Trixie and with the help of Trish The dish from Stratics, we find a way to send an email to Greg Wiatroski, a Toontown dev.
He fixed issues a few days later with an update of Toontown but it took me a few minutes to hack it again. After that, I was no more able to play on test or on Japanese but I’m still able to play on the QA server because I made two free accounts on it before
and I’m still able to modify Toontown phases files and that’s bad !
Posted in Uncategorized | No Comments »
June 30th, 2008
When I hacked the game again (that was really easy, the fix was really small), I sent an email to Trish and Fraulein but I didn’t have an answer so I sent an email to the Toontown support and 9 days later, they answered me I should ask the live chat support, I asked the live chat support and they told me to send a bug report, I sent a bug report and…..2 months later, nothing new.
I sent some PM to some big toontown fansite but they didn’t want to talk about it on their frontpage because hack is bad (yes it is!). My only solution was : MAKE MY OWN WEBSITE AND POST VIDEO ON YOUTUBE.
You can find my first video there.
Tags: answer, video
Posted in Uncategorized | 1 Comment »
June 30th, 2008
Here is the list of all what I can do now :
-I can steal cookies from a player if that player click on a malicious link (no worries, there is no malicious link on my blog).
-I can activate chat without the parental code on a full account where “Restricted True Friends” is selected as security control for chat.
-I can play on the US/UK QA, FR, JP, BR server. Fixed
Unfixed…
-I can modify toontown files and play with them.
-I can play alone when there is a maintenance (not hack but fun :D)
-I can have full accounts for free.
So Disney, FIX IT please !!!!!
Posted in Uncategorized | 3 Comments »
June 30th, 2008
As you certainly didn’t notice, there is in the log file a value which is :
:05-03-2008 13:05:36 ShowBase(info): __dev__ == 0
I think if it was :05-03-2008 13:05:36 ShowBase(info): __dev__ == 1 my account would have dev powers.
The question is how to fake that information on the account server to have dev powers, like I do for chat rights.
Posted in Uncategorized | 5 Comments »
July 2nd, 2008
No worries about that blog, when you’ll fix all leaks I’ll close that blog.
It’s not a blog to explain to everyone how to hack the game, it’s just a blog to inform you about Toontown’s problems, because it seems you don’t read my bug report, emails, chat…
Posted in Uncategorized | No Comments »
July 10th, 2008
I’m working a lot so I don’t have time to play, make videos or look for new issues but I hope I’ll have time this week-end.
Check out Youtube, there is a new video. It’s from the QA server, a dev server where only dev are (but I never saw one on).
If you want to see the QA server yourself, you can download the vista launcher and log-in with the word “mouse” as username and password.
It’s not really hack (nothing illegal, it’s an official launcher, an official game server and an official account, that’s why I share it) but it’s maybe a way to have a Disney reaction to fix issues.
Tags: dev, qa, server, video
Posted in Uncategorized | 3 Comments »
July 14th, 2008
Hi. Thanks for you interest in Toon Town Online. I’m sorry that it has taken a while to respond, but we have been working on a lot of secret stuff here at Toon Town. I was wondering if you could let me know a list of all of the active bugs and how to reproduce them so that my dev team and I can get cracking on fixing them. We wouldn’t want everyone else to exploit these issues like you have. Thank you for taking the time and showing interest in your favorite game, Toon Town Online. Without help from people like you, we would never succeed.
Sincerely,
Mr. Schott
Senior Dev Team
I really hope this is real.
Edit : That was a fake…..
Tags: dev, email, toontown
Posted in Uncategorized | 2 Comments »
July 15th, 2008
I stole a dev account on the QA server a few weeks ago (that’s bad but I try all what I can imagine to talk to a dev). The account name and account password was so easy to find. After that, I looked at the email of the owner, it looks like firstname.lastname.-ND@online.disney.com so I think it’s a dev email.
The problem is that the webiste http://online.disney.com doesn’t exist so the email can’t exist. I’ll try to send an email to firstname.lastname@disneyonline.com or firstname.lastname.-ND@disneyonline.com because http://disneyonline.com is real.
More good news soon I hope.
edit : It didn’t work !!! :’(
Tags: dev, email, toontown
Posted in Uncategorized | No Comments »
July 21st, 2008
The vista UK launcher came out a few days ago and with it, I found the QA UK server which is the same as the US QA server so nothing new there. You can find the QA UK launcher there. To make an account you need to create one there when it’s done, click on Play and when you see the download page, launch the QA UK launcher and enter your QA account informations into it.
The most interesting part is It gave me the possibility to log-on the French QA server. I found it a few months ago (with a scanner of all the disney network) but didn’t find a way to play on it. Now I can. What you need to do if you want to play on it is create an account and play on this website.
You can see a screenshot with some French dev names here.
Theere is a QA japanese server too (igameserver.qa.jp.toontown.com) but I can’t access to the log-in page.
Tags: french, qa, toontown
Posted in Uncategorized | 2 Comments »
July 21st, 2008
If someone has some knowledge about Rijndael-encrypted SPA packet I would be happy to talk with him/her. It’s only to talk about the Toontown playtoken.
Tags: encryption, playtoken, Rijndael, toontown
Posted in Uncategorized | 4 Comments »
July 22nd, 2008
Hi,
As you can see, you can post comments on this blog. Your comments need to be approved manually by me because I don’t want to see some illegal stuff on my blog. So if you don’t see your comment there that’s because it was a message for me or it was not allowed here.
Remember this is a blog to keep Toontown safe, not to hack it.
If I share account with you, it’s not only to give you the possibility to have fun, it’s a way for me to catch Disney’s eyes. Because I think the more account I share with you, the more you’ll tell your friend “Hey, I had got an account on this website for free, cool :). Go to see if you can have one too !” and the fastest Disney will contact me.
Hmm, and yes, to answer you, I don’t pay them, there are really free.
edit : posts with account names and passwords have been deleted and comments are allowed now but not links
Posted in Uncategorized | No Comments »
July 24th, 2008
Today, there was a maintenance with no updates.
When I logged on a few hours ago, after the maintenance (Restricted true friend hack activated), I tried to add a secret friend and it worked without to asking my parents informations like ever, but NOW, on the same account, when I want to add a secret friend, there is a pop-up which asks my parents informations.
Look at the screenshot
Totally normal to all account where “Restricted true friends” is on but not on my accounts where “Restricted true friends hack” is on.
Until now I was able to bypass it. The problem is…..i can click OK and it works, I still can add secret friends on an account where “Restricted secret friends” is on….
But there is a progress, I see the popup now xD
edit : I think I dreamed, just after I posted this, the popup went away again. So I’m still able to bypass the parental control again like before.
Posted in Uncategorized | 2 Comments »
July 27th, 2008
Princess Boo Boo found a dev on the test server
That was a long time ago (they deleted her when I said them I was not a tester) but it’s funny. He didn’t see I was with a full illegal account :).
Posted in Uncategorized | 2 Comments »
July 27th, 2008
It seems someone found the same issue and……..did a really great job !
I’m now looking for the hacked files, it looks so good in the video.
edit : Ok, program hacked in 10 minutes (I don’t want to pay 30$ for it ^^) I’m just downloading the hacked toontown files.
edit : Hmmm, it looks good for a beta version.
Posted in Uncategorized | 21 Comments »
July 29th, 2008
Disney changed password of all accounts I made on the QA server and they removed the possibility to create a new account ! Thanks guys, they’re maybe reading that blog with your help.
But if you still want to visit the QA server, you can read this. It still works and it’s the same server.
edit : They didn’t deleted account, they just suspended all of them
edit : accounts are back
Tags: qa, server, toontown, uk
Posted in Uncategorized | 3 Comments »
July 31st, 2008
Disney closed the UK QA website and if you made an account on it then it has been desactivated. That means, there is now no way to play on the QA server. The french QA server is closed too.
That’s good but that was not the more important to fix…
Posted in Uncategorized | No Comments »
August 1st, 2008
I needed :
-A full open account
-A free test account
First, I needed to update the test game so I played with my free test account and the game was updated.
Then I needed a valid playtoken from my open account. I launched the open game with the vista launcher and opened my last log file. In that log file, there was a playtoken value.
In the registry I entered my playtoken and the WEB_ACCT_PARAMS which is webAccountParams=secretsNeedsParentPassword=0&chatEligible=1&
Then I just had to launch the game with a CMD command like
“Toontown.exe” “-OO” “https://gameserver.test.toontown.com” “https://account.toontown.com” “1″ “-pickbestres
That means I was launching the test game with my full OPEN account instead of my free TEST account and it worked because when the game asked the open account server if my playtoken was valid, the open account server answered yes to the test game server.
That was really easy and fun to do it but when I told it to Greg Wiatroski, the dev, he fixed it. Now, the open account server only works with the open game server and the test account server only works with the test game server.
Note : That bug still worked with POTC a few weeks ago, I didn’t try recently. So if you’re a POTC fan then you can test it with a full account if you have a full open account on POTC.
But warning, you can be banned for that !
edit : it’s still working with POTC
Tags: account, hack, test, toontown
Posted in Uncategorized | 4 Comments »
August 18th, 2008
Disney reopened QA UK and US server.
I thought they closed them for ever but it seems no.
Posted in Uncategorized | 17 Comments »
August 18th, 2008
You will certainly don’t understand what I’ll write here but…….I hope dev will read.
A SSL issue has been detected on Debian servers recently, all https website with an older SSL key than May 13th 2008 can have big problems.
You can read technical informations here.
And you know what……….Disney didn’t updated all key (That’s strange because I thought Disney had only Red Hat servers and this is a Debian problem only). It’s on https://www.disney.fr/toontown/main.html https://staging.disney.fr/toontown/main.html and https://staging.disney.co.uk/toontown/main.html
It’s too big for me this time, I don’t have the skill. I read it can give SSH access that means control the Disney server !
Screenshot
Posted in Uncategorized | 2 Comments »
September 6th, 2008
Again, I sent a bug report to Toontown. It is my last try. If I don’t have an answer in the next two weeks, I think I’ll do a public realease of all hacks.
Here is my email.
Hi,
This is at least my fourth try to tell you that you have some security problems since march.
It’s my last try.
Your **************** are absolutely not secure. I can *****************.
Here is my ************************
Doing that I’m able to play with hacked phases files, to bypass the parental control **********, to play on the QA game server, to play when there is a maintenance…
Other problem, you have a small cross scripting issue on your website. Here is an example where I can steal a cookie from a player *************
I hope I’ll have an answer this time. You can ask me more informations if you need to know more.
Later.
PS : The screenshot isn’t an edit, it was in-game.
Tags: disney, email, hack, issue, toontown
Posted in Uncategorized | 2 Comments »
September 7th, 2008
Warning Firefox users !
I wanted to explore my hack where I can steal cookies and I found a way to use the cookies I stole that means I can access an account without to know the accountname and the password of my victim.
It seems the TT_R_ttClearSession value is the most important part of the cookie.
Here is what I did to test that issue :
I asked a friend to click on a trapped link (I tell her what I wanted to do). She did it.
I received her cookie on my website.
I logged on toontown.com with my account and edited my TT_R_ttClearSession value with her TT_R_ttClearSession value
I was on her account, was able to see her postal informations, name…
I changed her password to launch the game wih the vista launcher and played a few minutes with her toons
I gave her a full account for free and the new password to thanks her.
The victim has to use Firefox (maybe others browsers but not Internet Explorer 7), to be logged on the play.toontown.com website, to click on the hacker’s link.
Don’t click on any link in your mail box, on messenger or on a toontown fan website if you have a toontown.com page opened. It could be a malicious link and with only ONE click, it’s enough to be hacked.
Try to not use the parent password when you visit the toontown website. Doing that, you’ll be able to have your account back if someone hack it with my method.
Tags: cookies, toontown, xss
Posted in Uncategorized | 2 Comments »
September 13th, 2008
I’ll tell you how to play with your own phases files like I did.
Stay tooned.
Disney, I gave you a lot of chance to fix it. I’m bored.
Posted in Uncategorized | No Comments »
September 13th, 2008
IF YOU DON’T HAVE A LOT OF KNOWLEDGE IN COMPUTERS, IT’S NOT FOR YOU !
List of things needed :
-Panda3d (especially multify, pview, bam2egg, egg2bam)
-Md5summer
-Notepad
-To use the Vista launcher
-A dedicated server (or your computer where Apache is installed. You can use easyphp, it’s easier.)
-A lot of skill because I can’t tell each step, it would be tooooooo long
You first need to unpack the toontown phase you want to modify. The command is multify -x -f nameofthephase.mf. Make your modifications and pack your phase with multify -c -f phasename.mf foldername
Then copy past your new phase in the toontown folder. You need now to bypass the md5 and size file control. The file which looks if files are up-to-date is that one for the open server.
I’ll explain one of the line :
FILE_phase_1.mf.v1.25=30829629 0d44fefe596b5b9204f5ae966b70a907
That means the last update of phase_1 is available here and when it’s uncompressed, it has to be a 30829629 byts file and his md5 has to be 0d44fefe596b5b9204f5ae966b70a907 or the file will be updated.
The objective is to tell the launcher to look at your OWN patcher.ver file (with your own md5 and file size to skip the update) instead of the official one. Doing that, it will not update the phases files and it will launch the game with your own files ! For that, you need to make a copy on your apache server like I did here .
You can have the md5 of your new phase file with md5summer and you can have the size of your file with…….Windows and a right click :p. You then have to update your patcher.ver file with what you found.
The last step is to redirect the launcher to your patcher.ver file. A few months ago I was able to inject the url of my patcher.ver file in the launcher (it’s compressed with upx so I had to un-upx it, open it with an hexadecimal editor and change the url ;o)) but they fixed it. So now the easiest way is to modify your C:\Windows\System32\drivers\etc\hosts with a line like ‘x.x.x.x download.toontown.com’ where x.x.x.x is your IP (or the IP of your dedicated server). Your computer will then believe download.toontown.com is YOUR computer and will search the patcher.ver file on your computer.
Done.
To stop it, you just need to remove the line in your hosts file and launch the Toontown launcher, it’ll update the file again and your modifications will be erased.
As you can see on my patcher.ver file I changed the WEB_PAGE_LOGIN_RPC value with https://account.toontownhack.com/standaloneLauncherLogin.php. It’s a copy of the Disney account server. It’s using a mysql database where my playtokens are. That’s how I can bypass the parental control and play when there is a maintenance because my account server still returns a playtoken if it can with chat rights activated.
Don’t use it, it’s not secure for you (i’ll see your username and password and if someone hack me he’ll too) but you can make an account server on your computer or dedicated server if you want.
Anyway, you now have a lot of informations to try to have 999 laffs, to modify the pick-a-name game and a lot more ;o)
Posted in Uncategorized | 32 Comments »
September 21st, 2008
It took me 8 minutes to log-on the QA server with your new security. Cool, but you need to fix more…
Close the account server like you did with the download server (good thing, I had to use my open phases files to play) and I’ll be kicked out for ever ;o).
But as I said, close that server to the public is not the more important I think. The more important is to fix that XSS on your website ! Read my bug report guys !
EDIT : Woooot, I found a way to have a full account on the QA server xD
The account server show me this page but it’s working fine.
I had that idea a few weeks ago but didn’t have time to try. That’s bad it’s not working with the test server :’(
EDIT : I played on the mouse/mouse account today and saw he has at least 5 friends, someone know who they are ?
Posted in Uncategorized | 9 Comments »
September 28th, 2008
You have to be logged on the Toontown US website with a free account, don’t close your browser.
Then, click on the button below.
And if you want True Friends on that account, click on that second button (only works on an account which doesn’t have a parent password).
Your parent password will be “password”. Go to “Member Services”, “Preferences” to activate Chat with your parent password.
Don’t forget to change your parent email and parent password ! And remember to chat only with your REAL friends !
Tags: free, full account, make, play, toontown
Posted in Uncategorized | 218 Comments »
September 29th, 2008
Hi,
Since march I found a lot of security problems on Toontown and sent at least 3 emails to you, 3 bug reports and I chatted once with the live chat…….and your security problems are still here.
I can steal cookies from an user and use it (that means steal the account of that user), I can play on the QA server, I can modify phases files and play with them, I can play for free with a full account.
I’m fed up with helping you to fix your bugs.
Can you ask a dev to contact me ?
Later
Answer :
Dear Nicolas,
Thank you for your e-mail.
To further assist you with your inquiry, please call Customer Service at
(888) 332-1626 between the hours of 9 a.m. to 10 p.m. Eastern Time
Monday through Friday, and Saturday and Sunday, from 12 p.m. to 4 p.m.
Eastern Time.
We look forward to seeing you in Disney’s Toontown Online soon!
Thank You,
Julio
Disney’s Toontown Online Member Services
Grrr, i don’t live in the usa and i don’t speak english…..
My answer :
Hi,
Sorry but I don’t speak english and I don’t live in the USA so I can’t call the customer service. If a dev can’t contact me then my only solution will be to share exploits with everyone and it will be massed exploited. Then Disney will maybe contact me…
Help.
New answer :
Dear Nicolas,
Thank you for contacting us.
We recommend contacting Toontown Live Customer Support regarding this
issue. Toontown Live Customer Support is available during the hours of
10:00 a.m. and 7:00 p.m. Pacific Standard Time, Monday through Friday.
Service may be temporarily unavailable throughout the day, but please
continue to try.
- Go to http://play.toontown.com
- Select Help on the left side of page, then choose Report A Problem
- Select “Chat with Toontown Live Support”
- (If the link is not listed, Chat is currently unavailable)
Please have your Remark number and a brief description of this issue
ready when you login.
We hope to see you back in Disney’s Toontown Online soon!
Thank You,
Chris
Disney’s Toontown Online Member Services
I’m going to the live chat……
edit : Chat here
Posted in Uncategorized | 19 Comments »
October 5th, 2008
I don’t like POTC but if you do then, here is the same button as Toontown. Click on it once you are logged on the POTC website with a free account and you’ll be a full member.
If you want to play on the test server with your open full account, then install the test launcher, find your hosts file (C:\Windows\System32\drivers\etc\hosts), open it with notepad and add this new line :
91.121.158.68 download.test.piratesonline.com
Log-on with the test launcher and your open account (don’t use your real account but a special one you made with the button because you can be banned to play on test).
Tags: account, pirates, potc, test
Posted in Uncategorized | 12 Comments »
October 6th, 2008
My toons on the QA server
I’m now visiting LOM, HAAAAAAAAAAAAAAAAA !
My playtokens database
Each time I’m launching the game, it records the username, the password (md5 encrypted), the date. If I want to play again and if there is a maintenance, it takes a valid playtoken in that database and launch the game during the maintenance.
A list of all server I know, if you know more, tell me please.
#GAME_SERVER=https://gameserver.qa.toontown.com
#GAME_SERVER=https://gameserver-lv.toontown.com
#GAME_SERVER=https://gameserver.toontown.com
#GAME_SERVER=https://ukgameserver.toontown.com
#GAME_SERVER=https://gameserver.test.toontown.com
#GAME_SERVER=https://gameserver.wip.toontown.com
#GAME_SERVER=https://ukgameserver.wip.toontown.com
#GAME_SERVER=https://igameserver.jp.toontown.com
#GAME_SERVER=https://gameserver2.toontown.com
#https://igameserver.fr.toontown.com
#https://igameserver.french.toontown.com
#https://igameserver.qa.french.toontown.com
#https://igameserver.br.toontown.com
#https://igameserver.qa.br.toontown.com
Posted in Uncategorized | 4 Comments »
October 13th, 2008
I would be REALLY happy if it was possible to have that test account I’m waiting for a lot of years now with my Princess Boo Boo. She had 77lp (I think) and she was beginning Donald dreamlands. I miss her :’(
My other dream (but i don’t think that one will be possible) will be to play on a dev account to see what they see, to see what they can do in-game, etc…
What are your dreams on Toontown ?
Posted in Uncategorized | 8 Comments »
October 13th, 2008
I found a totally new way to write directly to a dev. I’m waiting for his answer. I really hope he’ll answer and fix all problems (or at least a big part of them).
Edit : I’m still waiting his answer 
Edit 11/14/20008 : still waiting
Posted in Uncategorized | 7 Comments »
October 19th, 2008
Shhhhhht, it’s a secret, gags level 7 and pigs are now on the QA french server and will be soon on the open french server.
My book on QA FR server
Vista launcher for french players will be out soon too.
edit : New update on QA FR, french translations added for gags.
Posted in Uncategorized | 48 Comments »
October 27th, 2008
And if you want to see what it will look like, you can watch this.
Mickey the vampire in a video
Mickey the vampire in a screenshot
He’ll have new animations but only TT can activate them for now so they are not in the video.
Edit : Mickey is now a vampire on open when it’s dark.
Posted in Uncategorized | 17 Comments »
November 1st, 2008
I made a small script which shows if game servers are really off or on when there is a maintenance.
Usually, when there is a maintenance, Disney stop servers, put the update, start servers and test the new update during at least 20 minutes so if you see on the main page a maintenance whereas my page shows a green circle, that means the game will be back really soon. I’ll do a better script soon.
Are servers online ?
Posted in Uncategorized | 8 Comments »
November 2nd, 2008
Hi toons,
As you know, Disney made a new protection to keep you out of the QA server….but hmmm, I’m still waiting them to read my bug reports and it seems they move faster when something is massed exploited (excepted making account for free it seems ^^)…
So here we go, you can download that new QA launcher and you’ll be able to play on QA again.
Download
Your account will be a free account for now, I need to approve them manually so wait a few hours and you’ll be able to play with a full account and TF activated.
Note : Save the launcher in a folder, not on your desktop or you’ll have a lot of files on your desktop.
Thanks to McBlack who helped me a lot with his script to make accounts.
Edit : And remember, I don’t do that for your fun, I do that to catch Disney’s eyes.
Tags: dev, launcher, qa, toontown
Posted in Uncategorized | 81 Comments »
November 8th, 2008
Yesterday, I had to stop the launcher for a few hours, I was doing my first update. Here is why :
Someone asked me if it is possible to translate Toontown in an other language, I didn’t know so I tried. I translated the sentence “Trick or Treat !” in “I am a dev !” just for fun and it worked !!!
So now, if you see my toons on QA (Princess Boo Boo, Prince Boo Boo, or Dippy…..) you’ll see them saying that (only if you’re using my launcher but you should :p)
Video
edit : Update with new HQ at Donald dock has been released on test so it’s now on QA but I forgot a texture so don’t worry if the HQ looks wierd, i’ll fix it tomorrow.
Posted in Uncategorized | 48 Comments »
November 8th, 2008
Hi,
I would like to have some news from my bugs reports #852987 and #788120. Did you lost them ?
I’m still able to steal accounts with your cross scripting problem, still able to play on your private server (QA server) and still able to modify and play with hacked phases files.
Is it possible than you ask Greg Wiatroski to contact me directly ?
When I first contacted him with the help of Trish from stratics.com who had his email, he fixed issues in less than one week. But Trish doesn’t want to contact him again for me this time.
Bye
edit : Rats, I forgot to talk about full free accounts <_<
edit : sent an email to Trish today
Posted in Uncategorized | 3 Comments »
November 8th, 2008
I was visiting youtube today and found a few videos :
-swtangel3131 made an awesome ad for me
-kllucky1993 wants to keep credit for herself, that’s not a problem, the problem is I don’t approve your asking username and password from user, kllucky1993. It can be dangerous for them… Some are giving account name and password in comments….
As Disney ever tell “Keep your passwords private, even from your best friend!”
-pavel111111111 made a video too, it seems he’s asking kllucky1993 to do memberships
-ydswyvds is trying to have a big toon for nothing :p
-Boyfan123 wants friend to tell other where to have one free year
-wally853 is showing in a video how he does to make a full account
Did you find others, on youtube (excepted mine) or somewhere else ?
Tags: account, ads, member, membership, toontownhack
Posted in Uncategorized | 3 Comments »
November 9th, 2008
Hi toons,
I just found a new issue on Toontown. As you know, I was able to play a few months ago on test and on japanese with a full account but when I told it to Greg Wiatroski, he fixed it.
A playtoken can only works if it has been created by the corresponding account server.
So here we go, when you play Toontown on a computer with Windows XP and with Internet Explorer, when the game starts, you can see a page like that. The blue value is the value which ask the account server to make a valid playtoken.
So if I edit the past link with something like this the blue value is still valid so it’ll make a valid playtoken for the japanese game and I’ll play on japanese with my french status (paid account with SF).
That’s sooooo bad the US open and test server are not using the same type of link or I would be back to test with a full account too !
Note : Links are exemple so it will not work with them
Info for japanese readers : Pigs and gags level 7 are on the QA japanese game
Edit : They are trying to fix it, QA FR website, QA UK website, QA BR website and QA JP website are now unavailable.
Posted in Uncategorized | 14 Comments »
November 15th, 2008
Hi toons,
I just uploaded a gallery with some screenshots. Some are from me, others are not. I’ll add more from now.
Visit the gallery
Posted in Uncategorized | 5 Comments »
November 16th, 2008
Hi,
I’m reporting myself for making full accounts for free (reportme5, reportme6, reportme7).
I’m using a form who is faking the paiement.
Thank you for suspending me.
PS : This report may look funny but I tried bug report, email, livechat and issues are still present so now i’m trying reports….
Tags: account, free, full, membership, report
Posted in Uncategorized | 3 Comments »
November 18th, 2008
Dear Nicholas,
Thank you for contacting us.
We appreciate your efforts to help us secure Toontown. Mr. Wiatroski is
not on the Toontown development team, but in the future you’re welcome
to submit bug reports and we can route them to the appropriate developer
as needed.
We’re aware that it’s possible to modify the Toontown content you see on
your own computer, and this is not considered to be a vulnerability
since it only affects the game exerience for you and not for other
players. We have secured entry to the QA server such that it’s no longer
possible to create new accounts from the outside. Unauthorized accounts
which were created before this change are being reviewed, and the
account database for the QA server will be cleaned out soon.
We are also aware of the cross-site scripting issue you discussed and
we’re always looking for better ways to make Toontown fun and secure.
Thank you for following up with us. As always, we look forward to seeing
you in Toontown soon!
Thank You,
Barry
Disney’s Toontown Online Member Services
_____________________________________
We have secured entry to the QA server such that it’s no longer
possible to create new accounts from the outside. Unauthorized accounts
which were created before this change are being reviewed, and the
account database for the QA server will be cleaned out soon.
That means they think it’s no more possible to make account and that means they can’t close the QA login page. So they think if they delete all accounts on QA, they’ll kick us out because we can’t make new accounts…….but we can….
So if you’re planning to make a big toon on QA, stop it, it will be deleted soon or later.
It seems they just need months to fix something easy
So I’ll send a bug report about free accounts and access to the QA server and that’s all.
My job is done, toontownhack.com will close soon !
Posted in Uncategorized | 13 Comments »
November 19th, 2008
I was making full account on QA for new players and saw this.
Screenshot from the QA website
It doesn’t seem it’s activated in-game because I didn’t see a difference with Speedchat plus activated or desactivated.
Posted in Uncategorized | 4 Comments »