First off... AFF has been hackable since the beginning. And many individuals and hacking groups have been having their way with them.
It is common knowledge in hacking back channels that it is very easy to signup as an affiliate, and then fake, crap traffic, then go into the database and find whales, now swap the affiliate id for your own. Now you too can live in mother Russia like a czar with all of your ill gotten gains.
I would posit that this is going on with almost all affiliate programs dealing with dating and cams.
Btw, doesn't matter if you lock down mysql by ip since the hacker has full control of a white listed box.
|