![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Apr 2007
Posts: 983
|
Kill Switch for Websites? Is it possible?
A guy who designed a couple websites for me is having some health issues so he provided all my website files and databases. I uploaded them perfectly fine with the help of a a new developer. The new developer pointed out a file buried deep in a folder called self_destruct.php. We can't open or delete it, says we don't have permission. When you visit the link directly, you're prompted for a user/pass.
I called the original developer and he said it's a kill switch he puts into every one of his websites. If the client doesn't pay or they try to resell the website, he runs that script and it deletes the database and some key config files. WTF!?!? I mean he's cool, we never had a problem. But knowing some dude could have gotten fucked up one night and totally destroy my website was pretty scary. GFY webheads...is this even possible or is he bullshitting me? Is it a common practice? It makes sense.
__________________
Skype: Triplexprint |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
it sounds like it could be done.
mabe its an off the shelf thing all programers use.
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jul 2008
Location: Los Angeles
Posts: 942
|
Sounds like a real developer to me
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Feb 2011
Location: La Isla Bonita Power Level: ❤❤❤❤❤❤❤❤❤❤
Posts: 886
|
I would never host any shit I don't know. You do? LOL
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
It's possible but the client would have to be either stupid or not very technically inclined to be sure it would work. Depending on how he coded things it would be trivial to remove or block access to it so it could not be executed. Regardless, I don't think I'd allow someone to do that. It's dangerous.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Feb 2011
Location: La Isla Bonita Power Level: ❤❤❤❤❤❤❤❤❤❤
Posts: 886
|
BTW it sounds kinda noobish solution to me I think I could defuse this mine in various ways, the question is what else he has hidden there that you don't know about it.
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Bullshit how it cant be deleted,maybe over ftp cant but over ssh with root access you can.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
One other thing. You'd think he would have more sense than to name it self_destruct.php.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Playa
Industry Role:
Join Date: Dec 2005
Location: Somewhere on the Earth
Posts: 8,439
|
lool interesting thing to screw the costumers :D he can blackmail you now!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Guest
Posts: n/a
|
your webhost could remove it.
But yeah, very possible, we used to call them "theif bombs" if someone tried to not pay, activate it and booom, site is corrupt!! Never heard of anyone having to use one though and i dont use them myself!! |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Pay It Forward
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 76,934
|
hahahaha!!!! sorry 4 laughing thats funny
__________________
TRUMP 2025 KEKAW!!! - Support The Laken Riley Act!!! END DACA - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
58008 53773
Industry Role:
Join Date: Jul 2005
Location: Australia
Posts: 9,864
|
you will be able to delete the file or chmod the file etc - easy enough to put an end to that one.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Mar 2002
Location: asia
Posts: 5,590
|
had a programmer once who put quotes from the bible in the comment tags
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Industry Role:
Join Date: Jan 2010
Posts: 296
|
Quote:
@TripleXPrint, get a new developer and make completely new site. You don't know when he (or any other experienced user) will use script.
__________________
Twistys Hot Babes |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
bored
Industry Role:
Join Date: Aug 2003
Location: Metaverse
Posts: 4,675
|
Quote:
ya as signupdamnit said, just block access to the file thru htaccess if u cant delete it. and if u cant delete it you should figure out why you dont have root access to your own servers.
__________________
# ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: May 2008
Location: Mexico and Midwest
Posts: 612
|
What does your agreement with him/them state?
If this is not disclosed or if there is no contract then you have the federal courts on your side. In 2004, on a mainstream project we had this happen. The developer used this "feature" to demand additional payment. Our attorney went to the federal court and asked for an emergency hearing which was granted. He was found to be in violation of numerous federal codes. The judge additionally considered this to be a potential extortion scheme and a cyber terrorism threat. I accompanied the federal marshals to his place of business and his home ( on the same day as the hearing). He was arrested and everything he owned that could have potentially been used to create or store code was confiscated. I mean everything down to Zip drives ( remember those? ) Ultimately he was forced by the federal courts to provide us a clean copy of the code and pay for an independent examination of the code to ensure there were no other instances of this or any other back doors or nefarious code. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
|
Quote:
![]() ![]()
__________________
Make Money
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jan 2004
Location: oddfuturewolfgangkillthemall!!!!!!!
Posts: 5,656
|
Doesn't sound too fucked up IMO, as long as it is removed after payment is sent?
Speaking of hidden things in scripts, if anyone is using babelogger trying going to yoursite.com/msgs.php?msg=beatles (in IE) ![]() http://www.13scripts.com/demos/babel...hp?msg=beatles |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Registered User
Industry Role:
Join Date: Mar 2011
Posts: 6
|
Try uploading everything onto a different server without the self destruct file to make sure it all functions right. If it were me I'd probably pay another developer to go through everything else to ensure that "self_destruct.php" isn't just a decoy and the real one is still there hidden under a different name. Sounds like some shady shit and I don't understand why you wouldn't have looked at the files in the first place and already seen it?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
there is so much wrong with that I don't know where to start. Another big concern is the fact there is now a huge backdoor that ANYONE can use to crash your whole site, and most people have at least weekly backups anyways so what the hell good does it do him when people will just restore from backup and still have the site anyways?
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
bored
Industry Role:
Join Date: Aug 2003
Location: Metaverse
Posts: 4,675
|
Quote:
![]()
__________________
# ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Las Vegas
Posts: 3,220
|
good thing you have files to upload. and the site should be transferable
__________________
Network Of Adult Blogs With Hardlink Rentals Available |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |||||
Monger Cash
Industry Role:
Join Date: Jul 2010
Posts: 2,773
|
Quote:
Quote:
Quote:
Quote:
Quote:
And, what is wrong with this exactly? If he has a reputation and wants to keep it, he'd never do something to intentionally harm a client. And instead of blaming the developer, why not blame all the scumbag fucking crooks out there that make such measures necessary? Personally, when I take on a 3rd party client, I find it easier to keep all work hosted and in my control until completed. Show the client a fully working demo and let him play around inside the backend with a non super user account. Then once in agreement regarding the end product, I receive payment first then transfer files. I also tell clients this up front so as not to give some loser a way to try and sue me because he's a dirtbag. Anyway, don't blame the dev, especially if he's legit and has a good reputation in his field. Blame your scum peers in this industry (and others) for making such things necessary. |
|||||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Industry Role:
Join Date: Nov 2009
Location: Heaven
Posts: 4,306
|
i would decode that php and/delete it, i dont like the idea of hosting something which isnt in my control.
or u could try brute-forcing that self-destruct.php after making backup, then ask him for his client list and boom, u delete every others site.,, |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed User
Industry Role:
Join Date: Jun 2006
Posts: 342
|
Quote:
Beer in one hand, excitable lady in the other and location setting under your avatar set to "beyond reach" You aren't exactly inspiring confidence or exuding professionalism with that look. As a client, encrypted code and/or kill switches are a deal breaker. I'll tolerate it from billers and TMM, because they come under their own category - when I use their products I'm buying their reputation to pass on to third parties - surfers and affiliates. - Surfers and affs hopefully get it that for better or for worse, I can't fuck with those systems, so they can trust them, even if they think I might be a scumbag. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
bored
Industry Role:
Join Date: Aug 2003
Location: Metaverse
Posts: 4,675
|
Quote:
there's no reason to attack my avatar here either. this is gfy and i get plenty of sales regardless of my avatar. your one sale was not needed last year, and you were a pain in the ass during PRESALE. we even had a ridiculous phone convo about how my cms was all wrong and you wanted it completely customized. thanks but no thanks.. by the way, does your brand new tour using your brand new cms still take 10 seconds to load?? it must be so much better than my fast, cheap and easy to use cms (-easy for hundreds of normal people-). note - a new cms sale just came in as i was typing this plus 2 sales for one of the sites i manage. thanks for playing tho Simon. ^^ simon's "professional" avatar ^^
__________________
# ![]() Last edited by plsureking; 03-17-2011 at 08:37 AM.. Reason: had to add simon's avatar since he's cooler than me/ |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Too lazy to set a custom title
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,912
|
First thing I would do is out his name and any URLs that he uses so no one else gets this shit.
__________________
PornGuy skype me pornguy_epic AmateurDough The Hottes Shemales online! TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2003
Location: icq: 71462500 Skype: Jupzchris
Posts: 27,880
|
Ive seent his done in software programs
but i think they need to let you know ahead of time they are putting stuff like this in
__________________
[email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
ICQ:649699063
Industry Role:
Join Date: Mar 2003
Posts: 27,763
|
I think that's fair. If the client doesn't pay, he/she doesn't get the product. The self destruct file is interesting. It's like saying, "you have 5 seconds to terminate this tape."
__________________
Send me an email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Oct 2003
Location: Atlanta
Posts: 2,840
|
I have a back door file I install on sites when I take side jobs (i.e. craigslist admin jobs) till the client pays then I remove it. I've only had to use it once. Was setting up a webhosting WHM server for a client and the guy was a total a-hole and kept delaying payment so I went back in and removed everything and crippled his server. needless to say the next day he was willing to pay. i alway remove the extra password or script once paid. i have zero desire to go back into someone's system once my job is complete.
anyway personally i wouldn't name the file self_destruct.php probably something like site_function.inc and the have anything site_proc.php reference that file. But anyway all dev's should have a way back in. its nothing personal, its just that a lot of people are a-holes and look to rip people off. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 | |
Guest
Posts: n/a
|
Quote:
A developer can spend, hours, weeks, hell even months programming and for someone to recieve the work and not pay is a huge kick in the teeth, i guess it's this guys way of saying, ok you screwed me, now i screw you and getting satisfaction that the site isnt online. It's awful when this happens as nobody will pay the freelancer for all his hours spent on that paticular project. ![]() |
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
It's 42
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Confirmed User
Industry Role:
Join Date: Jun 2006
Posts: 342
|
Quote:
My CMS is old, broken and nasty, but yes, I like images - I have somewhere in the region of 800 models, but because I shot them they all have both real names and model names. So I think in pictures. That's just how it is. I'm not a webmaster, I'm a photographer who shoots porn. Funnily enough I recommended pornCMS yesterday as one to look at. You might have thought my pre-sale questions were annoying, but you hid it well at the time. Moving from an existing platform to another when you have shitloads of stuff is a big commitment and the time to work stuff out is before the sale. No point buying a car when you need a truck. I am not attacking you, I am pointing out if you want people to put their entire business in your hands you have to realise you are in the big league and how you look online matters. FYI, my Avatar is Randy from "My name is Earl", chosen entirely because he's an idiot, just scrapping by in life, but then I don't have my finger on anyone's kill switch. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 | |
bored
Industry Role:
Join Date: Aug 2003
Location: Metaverse
Posts: 4,675
|
Quote:
Porn CMS does not have a "kill switch" similar to the one posted by the OP and I never claimed it did. You don't like to read so I will forgive you for misquoting me. There is no file on Porn CMS that will erase an entire website. In fact, when I remove a site I do it manually using the command line. I have a 20-second install script but I am overly cautious on removal. What I DID say is that Porn CMS has an encrypted license file, which is similar to every other reputable software on the market -- including NATS. The only people afraid of that are the ones that don't pay their bills.
__________________
# ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |