Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-04-2012, 02:43 AM   #1
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
What is a Malware attack

After wasting a week of my life cleaning up from a Malware attack I have been told;

The happen by forcing the FTP password

Then by weakness in the web design (but no explanation on what exactly.

I would have thought is would be easy to defend against multiple attempts to log in...

I was also told that the attack could come from the uploading or home computer but but anti virus and Microsoft's malware program failed to detect anything.

If it is a password problem is it true that

usealongsentenceasaspasswordinbetterthan

HgtSd55^&8

that it is the length is the stronger PW?
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 04:04 AM   #2
ottopottomouse
She is ugly, bad luck.
 
ottopottomouse's Avatar
 
Industry Role:
Join Date: Jan 2010
Posts: 13,177
What FTP program do you use as some are quite easy to steal the password from?
__________________
↑ see post ↑
13101
ottopottomouse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 05:51 AM   #3
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Quote:
Originally Posted by ottopottomouse View Post
What FTP program do you use as some are quite easy to steal the password from?
Interesting...such as?
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 08:01 AM   #4
helterskelter808
So Fucking Banned
 
Industry Role:
Join Date: Sep 2010
Posts: 3,405
I hope you people are just using "FTP" as a generic term, and you really mean SFTP or SSH, because FTP went out with Gopher and Archie. If you really are using FTP then stop, because it's not secure.
helterskelter808 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 08:11 AM   #5
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by suesheboy View Post
Interesting...such as?
Filezilla stores all it's saved sites in an unencrypted xml file. I have a buddy who does german mainstream sites, and his computer got a virus. The virus sent out his filezilla xml file to some server and that server went in and added some iframe crap on every .html and .tpl file on all his client's servers. This happens less frequently on adult sites because the hosts in adult tend to firewall their shit, but there are other viruses and malware that log right in from your computer and do it - thus bypassing any firewall or anything.

It doesn't have to be *YOUR* computer that got virused - it could be a designer you hired, a programmer, a copywriter, an seo guy, or even a server admin who's computer was infected with soemthing and had your login data saved somewhere.

Last edited by k0nr4d; 11-04-2012 at 08:12 AM..
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 03:08 PM   #6
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
Grim news, the irony is that we were having problems uploading large files and our host recommended Filezilla, and Fillezilla does work very well.
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 04:21 PM   #7
Lace
Too lazy to set a custom title
 
Lace's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 16,116
__________________
Your Paysite Partner
Strength In Numbers!
StickyDollars | RadicalCash | KennysPennies | HomegrownCash
Lace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 04:26 PM   #8
grumpy
Too lazy to set a custom title
 
grumpy's Avatar
 
Join Date: Jan 2002
Location: Holland
Posts: 9,870
Quote:
Originally Posted by k0nr4d View Post
Filezilla stores all it's saved sites in an unencrypted xml file. I have a buddy who does german mainstream sites, and his computer got a virus. The virus sent out his filezilla xml file to some server and that server went in and added some iframe crap on every .html and .tpl file on all his client's servers. This happens less frequently on adult sites because the hosts in adult tend to firewall their shit, but there are other viruses and malware that log right in from your computer and do it - thus bypassing any firewall or anything.

It doesn't have to be *YOUR* computer that got virused - it could be a designer you hired, a programmer, a copywriter, an seo guy, or even a server admin who's computer was infected with soemthing and had your login data saved somewhere.
thats why i use ipswitch ws_ftp professional
__________________
Don't let greediness blur your vision | You gotta let some shit slide
icq - 441-456-888
grumpy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 04:43 PM   #9
SilentKnight
Megan Fox's fluffer
 
SilentKnight's Avatar
 
Industry Role:
Join Date: Oct 2005
Location: shooting pool in Elysium
Posts: 24,818
Quote:
Originally Posted by Cherry7 View Post
After wasting a week of my life cleaning up from a Malware attack I have been told;

The happen by forcing the FTP password

Then by weakness in the web design (but no explanation on what exactly.

I would have thought is would be easy to defend against multiple attempts to log in...

I was also told that the attack could come from the uploading or home computer but but anti virus and Microsoft's malware program failed to detect anything.

If it is a password problem is it true that

usealongsentenceasaspasswordinbetterthan

HgtSd55^&8

that it is the length is the stronger PW?

We had a major malware issue here recently also - but it had nothing to do with FTP. We got the Ukash virus, which seemed to mutate into various forms. It busted through both our anti-virus and firewall and literally locked the system up.

It took me three days to completely eliminate it. No permanent damage, just major annoying with the downtime.
SilentKnight is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 09:53 PM   #10
rock-reed
Confirmed User
 
Join Date: May 2005
Posts: 1,892
Try using Secure FTP (SFTP) to feel more secure.
__________________
---
Ethnic niche? Black-Asian-Latina ?
Contact me and lets talk traffic.

rockreed@ that thing they call the google mail

When you E-mail Me, PLZZZZ make the Subject Title:

>>>>>> GFY!

So I do not lose you in Spam.
rock-reed is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2012, 09:57 PM   #11
NaughtyRob
Two fresh affiliate progs
 
NaughtyRob's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Inside teen pussy
Posts: 29,602
The Internet....

NaughtyRob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-05-2012, 01:52 PM   #12
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
So it could be Filezilla, it could be our computer, it could be our site PW was hacked, it could be a weakness in our website...
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-05-2012, 01:57 PM   #13
alex.missyouth
Confirmed User
 
Industry Role:
Join Date: Sep 2012
Posts: 1,870
My advice is to use SFTP and a strong password with capitals and non capital letters, numbers and symbols.
__________________
skype: descargasweb
alex.missyouth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2012, 12:31 PM   #14
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
Quote:
Originally Posted by alex.missyouth View Post
My advice is to use SFTP and a strong password with capitals and non capital letters, numbers and symbols.
I was reading it is the length of the password that is more important and a password like

thisisreallyeasytorememberasapasswordforexample

is better than

TerD5$$&*H
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2012, 12:56 PM   #15
helterskelter808
So Fucking Banned
 
Industry Role:
Join Date: Sep 2010
Posts: 3,405
^ Why not just make the second one longer.
helterskelter808 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2012, 01:05 PM   #16
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
Quote:
Originally Posted by k0nr4d View Post
Filezilla stores all it's saved sites in an unencrypted xml file. I have a buddy who does german mainstream sites, and his computer got a virus. The virus sent out his filezilla xml file to some server and that server went in and added some iframe crap on every .html and .tpl file on all his client's servers. This happens less frequently on adult sites because the hosts in adult tend to firewall their shit, but there are other viruses and malware that log right in from your computer and do it - thus bypassing any firewall or anything.

It doesn't have to be *YOUR* computer that got virused - it could be a designer you hired, a programmer, a copywriter, an seo guy, or even a server admin who's computer was infected with soemthing and had your login data saved somewhere.
exactly...
so, the solution is

1. Use Total Commander because it has password encryption (versions > 7.5)

2. Use FileZilla portable edition from PortableApps.com because then the virus doesn't know where filezilla is installed. All those viruses scan "c:/Program Files/" folder for installed applications or search the registry...

So, by using Portable Applications you will hide from possible attacker information that you are using that software... You can also put that on USB drive and carry with you or store it on Dropbox and use it on any computer, wherever you are...
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:

Last edited by HomerSimpson; 11-06-2012 at 01:06 PM..
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2012, 01:10 PM   #17
johnny o
Confirmed User
 
johnny o's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: los angeles
Posts: 825
this link says your long password is better, see for yourself:
http://howsecureismypassword.net/
__________________
http://candydreams.com
info[at]candydreams[dot]com
johnny o is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2012, 05:11 AM   #18
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
Quote:
Originally Posted by johnny o View Post
this link says your long password is better, see for yourself:
http://howsecureismypassword.net/
The intersting thing about that is that it seems to be 99% about length....
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2012, 05:17 AM   #19
CurrentlySober
Too lazy to wipe my ass
 
CurrentlySober's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,536
Quote:
Originally Posted by Cherry7 View Post
The intersting thing about that is that it seems to be 99% about length....
Surprised?

Thats what all women really think, but simply wont admit...
__________________


👁️ 👍️ 💩
CurrentlySober is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2012, 05:31 AM   #20
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by Cherry7 View Post
The intersting thing about that is that it seems to be 99% about length....
With brute forcing longer passwords will take exponentially longer to crack.

A single password with uppercase letters only will require up to 26 attempts to crack, but increase that to two and we're now at 676 (26 x 26)... go up to 10 and it's a number I'd have difficulty comprehending... 141,167,095,653,376

Of course there's no point having a "good" password if you're transmitting it cleartext via FTP, or you have something on your desktop or server that is catching the password as it's used.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2012, 11:47 AM   #21
idolbucks
Confirmed User
 
idolbucks's Avatar
 
Join Date: Dec 2008
Posts: 914
Quote:
Originally Posted by Cherry7 View Post
The intersting thing about that is that it seems to be 99% about length....
This site explains it a bit more in depth

https://www.grc.com/haystack.htm

Example password I typically use 100 char + High ANSI characters

„2?“=ŠQƒH[}ƒš!mba͵RXDx…n†!MM‰HJް1k5‚;7b C$wV~V‡‡ͨ7K‹hYœ

Massive Cracking Array Scenario:
(Assuming one hundred trillion guesses per second) 1.81 hundred million trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion centuries
__________________
Idol Bucks - always more...
idolbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2012, 12:35 PM   #22
Cherry7
Confirmed User
 
Cherry7's Avatar
 
Join Date: Aug 2005
Location: UK
Posts: 3,564
Quote:
Originally Posted by idolbucks View Post
This site explains it a bit more in depth

https://www.grc.com/haystack.htm

Example password I typically use 100 char + High ANSI characters

?2??=?Q?H[}??!mba͵RXDx?n?!MM?HJް1k5?;7b C$wV~V??ͨ7K?hY?

Massive Cracking Array Scenario:
(Assuming one hundred trillion guesses per second) 1.81 hundred million trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion centuries
But try and remember that. If you paste it in or store it another problem.But password such as

Thisisveryeasytorememberasitisinwordsbutverylong

seems to be the way to go
Cherry7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright 2000- Jelsoft Enterprises Limited.