![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
![]() Anyone else have a guy botting a paysite pre-join 100 times a day with a username & password from the same IP coming through different affiliate links... all the passwords are the same "super123" and all IP's are from China, and there's never an attempt to use a credit card... just entering user/passes into the NATS DB. Since it's coming from different legit affiliate links on different sites, he's obviously crawling the web for join codes... totally nuts.
Am I the only one? Can anyone think of any point in doing this? This bot comes and goes every couple months for the past year, I just blocked all of China's IPs to get rid of him permanently, just curious as hell what the point is to do this for a year? Any insite appreciated... NATS 3 owners check your member's database for any user with the password "super123" I think you will be suprised.. found 3 others that had the same deal.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
MFBA
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
|
have you gotten the IP and then grep'd your apache logs to see what else he is doing on your servers?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
¯\_(ツ)_/¯
Industry Role:
Join Date: Aug 2004
Posts: 11,475
|
how you know his pass? i have been thinking it is crypted in nats, is it there plain? are you kidding me?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
webmaster passes are encrypted, surfers passes are encrypted in the DB, but not the admin
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Aug 2011
Location: Las Vegas
Posts: 1,086
|
Install mod_geoip
SetEnvIf GEOIP_COUNTRY_CODE CN BlockCountry Deny from env=BlockCountry Tons of problems instantly go away |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
¯\_(ツ)_/¯
Industry Role:
Join Date: Aug 2004
Posts: 11,475
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
yep, all of china is blocked now.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
If you catch him in the act, temporarily turn on post logging. Might be trying an evil null, sql infection or similar. Since it continues and since he's crawling for NATS links, he's obviously trying something.specific.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Noticing
Industry Role:
Join Date: Nov 2003
Location: Null
Posts: 30,209
|
we fixed this problem but we had to disable it to keep our liscense. /:
ds
__________________
My mother said, to get things done You'd better not mess with Major Tom |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
hmm, other than banning all of china, how can you fix?
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Posts: 264
|
Is it worth blocking over 1 Billion potential customers to slow(they could still find a way around) something that wasn't causing any real harm anyway?
Strange stuff it is, but would need some deeper analysis to figure out what they're trying to accomplish. Could be some kind of "smart" bot that tries to sign up to any site it finds, to do spamming or whatever. I found this: https://www.dlitz.net/blog/2011/10/m...mmon-losenord/ and it looks alot that it's the same guy/bot there too. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Industry Role:
Join Date: Jun 2005
Location: concrete jungle
Posts: 3,489
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Amateur Gynecologist
Industry Role:
Join Date: May 2009
Location: Medellin
Posts: 4,436
|
Same here, did the prejoin about a dozen times between November and today on various sites of mine, I also have a few legit surfers using that password lol.
Check out the comments here: http://whatismyipaddress.com/ip/117.41.184.199 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | ||
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
Quote:
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Amateur Gynecologist
Industry Role:
Join Date: May 2009
Location: Medellin
Posts: 4,436
|
Quote:
Maybe the bot is just looking for forms with a user/pass field and a submit button and either isn't smart enough to detect actual community sites or else just hoping to get lucky. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Mar 2008
Location: Miami
Posts: 5,527
|
Thanks, we did have him in our database, but had taken care of him last year.
He joined via the following IP if it helps. 99.62.117.195
__________________
| skype: getscorecash | ICQ: 59-271-063 |
New Sites: | SCORELAND2 | Roku Channel SCORETV.TV | 60PLUSMILFS | | Big Tit Hooker | Tits And Tugs | Big Boobs POV | Karla James | | Naughty Foot Jobs | Linsey's World | Busty Arianna Sinn | Get SCORE Cash | |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Noticing
Industry Role:
Join Date: Nov 2003
Location: Null
Posts: 30,209
|
hmm well I not allowed to speak about it /:
ds
__________________
My mother said, to get things done You'd better not mess with Major Tom |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Posts: 264
|
Yes I was just editing my last post to add something what pompousjohn just suggested, it looks quite obvious that the amount of "super123" passwords on that swedish board was caused by some kind of bot, and since the password is same here then it's probably same (spam) bot.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Monster Rain
Industry Role:
Join Date: Feb 2004
Location: Mongo
Posts: 4,978
|
Quote:
__________________
“My Free Cams Affiliate Program by CrakRevenue” |
|
![]() |
![]() ![]() ![]() ![]() ![]() |