7 Steps to Hi-Jack JibJab’s Sendables…
May 20th, 2008I ran into this little security hole when I got an email (SPAM *wink*) from JibJab asking me to use their Sendables service. I started to create one, but then I realized that I had to pay for it, so I stopped!
well being the hacker that I am I looked into circumventing their technology, so that I could use their “preview” version and host it some place else and it worked!!! (SORRY JIBJAB I really love your product, I just felt a little greedy today… plus 10 bucks for 100 credits come one man)
JibJab if you are reading here is how you can reproduce:
- Go to the sendables page http://www.jibjab.com/sendables/
- Select your favorte sendable, upload photos, save.
- Click on the preview button / Link
- Right click on the page and select view source
- Click CTRL+F and search for .swf
- Locate a string that looks liek this: %2Fsendables%2Fapi%2Fpreview%2FIxLyhHno2XoHrM4xbre6q4C5.xml
- Insert that string into the ##HERE## area below
<embed src=”http://llnw.jibjab.com/content/player.swf” width=”450″ height=”395″ flashVars=”content_url=http%3A//www.jibjab.com##HERE##” wmode=”transparent” pluginspage=”http://www.macromedia.com/go/getflashplayer” type=”application/x-shockwave-flash”> </embed>
So using the string above it should looke like this
<embed src=”http://llnw.jibjab.com/content/player.swf” width=”450″ height=”395″ flashVars=”content_url=http%3A//www.jibjab.com%2Fsendables%2Fapi%2Fpreview%2FIxLyhHno2XoHrM4xbre6q4C5.xmlwmode=”transparent” pluginspage=”http://www.macromedia.com/go/getflashplayer” type=”application/x-shockwave-flash”> </embed>
And to prove to you that I’m not lying here is a quick sample!
http://www.chrisdevbox.com/hacks/jib-jab-hack/
When you are done with that please check out what I did last night….

July 16th, 2008 at 6:03 am
[...] post, which explains step by step the process for hi-jacking JibJab’s site and get free stuff… http://www.chrisdevbox.com/blog/2008/05/20/7-steps-to-hi-hack-jibjabs-sendables/Read “RE: Why is Jibjab website down? - Yahoo! Answers” at News & Events ForumI tried checking [...]
September 19th, 2008 at 12:09 am
now they make you subscribe. Any ideas on this one?
Thanks
September 23rd, 2008 at 12:36 am
did you try the steps above?