Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-13-2016, 09:57 AM   #1
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
AFF/Penthouse has been hacked, 400 millions accounts, largest hack in 2016

All customer data has been liiberated, as per:
https://www.leakedsource.com/blog/friendfinder

400 million accounts, even 'closed' accounts are still in their database, and apparently the passwords were mostly stored insecurely.

better go download them lists and get to mailing :x
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 10:05 AM   #2
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Wow! Thanks for the heads up
__________________


Skype: CallTomNow

Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:02 AM   #3
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
The bigger issue are the emailers that 'save' your mail list -- their compromising hacks are rarely reported -- ever notice how you get sudden bursts of Spam emails?
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:32 AM   #4
Brian mike
#Alberta51
 
Brian mike's Avatar
 
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,959
Thanks for the heads up
__________________
Tube - Cam - Escorts - Top List
Menu Tab - Banner - Header Link - Blog Post
DM me
Brian mike is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:44 AM   #5
Smack dat
So Fucking Banned
 
Industry Role:
Join Date: Jul 2016
Posts: 4,613
Not surprised.
Smack dat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:45 AM   #6
Feng-PD
www.PornDeals.com
 
Feng-PD's Avatar
 
Industry Role:
Join Date: Jul 2011
Location: Netherlands
Posts: 3,964
how to get that list lol dont see it on the site!
__________________

PornDeals.com - WebcamDeals.com - GayDeals.com - PornCoupons.comnew!


Skype : fengwu83
Email : feng{atter}porndeals{dotter}com
Feng-PD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:58 AM   #7
j3rkules
VIP
 
j3rkules's Avatar
 
Industry Role:
Join Date: Jul 2013
Posts: 22,111
Wow, it is really big...
j3rkules is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:09 PM   #8
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by Feng-PD View Post
how to get that list lol dont see it on the site!
its in the wild, just have to know the right people or the right places to look.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:11 PM   #9
NemesisEnforcer
Confirmed User
 
NemesisEnforcer's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Vegas and Los Angeles
Posts: 2,122
Quote:
Originally Posted by Why View Post
400 million accounts, even 'closed' accounts are still in their database, and apparently the passwords were mostly stored insecurely.
Nice piece of nugget
__________________
The Only Time When Success Comes Before Work Is In A Dictionary.

Did you ever notice: When you put the 2 words 'The' and 'IRS' together it spells 'Theirs.'
NemesisEnforcer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:14 PM   #10
NemesisEnforcer
Confirmed User
 
NemesisEnforcer's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Vegas and Los Angeles
Posts: 2,122
Quote:
Originally Posted by Feng-PD View Post
how to get that list lol dont see it on the site!
Try the dark web.
__________________
The Only Time When Success Comes Before Work Is In A Dictionary.

Did you ever notice: When you put the 2 words 'The' and 'IRS' together it spells 'Theirs.'
NemesisEnforcer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:21 PM   #11
NewNick
Confirmed User
 
NewNick's Avatar
 
Join Date: Mar 2009
Posts: 7,036
Old news.
__________________
"Americas Hitler" JD Vance.
“There isn’t really an upside to Trump.” Tucker Carlson.
“a convicted felon rapist is now your president” OneHungLow, gfy.com
NewNick is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:24 PM   #12
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by Barry-xlovecam View Post
The bigger issue are the emailers that 'save' your mail list -- their compromising hacks are rarely reported -- ever notice how you get sudden bursts of Spam emails?
or they just sell the older ones for a cash infusion.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:25 PM   #13
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by NewNick View Post
Old news.
not so much, this happened just a few weeks ago.

i think the old news you refer to was the last time they were hacked.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 12:26 PM   #14
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
the sad part to me is how inept AFFs tech talent appears to be. they were storing passwords in plain text and/or SHA1. its not hard to reverse SHA1 passwords, then take the whole lot and properly secure them.

anyone still doing this deserves any bad press they get.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 03:38 PM   #15
poncabare
Confirmed User
 
poncabare's Avatar
 
Industry Role:
Join Date: Jul 2007
Location: carmel
Posts: 2,553
Uh oh...
poncabare is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 04:18 PM   #16
RyuLion
 
RyuLion's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,185
Quote:
Originally Posted by jerkules View Post
Wow, it is really big...
That's what she said..
__________________

Adult Biz Consultant A tech head since 1995
RyuLion is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 04:50 PM   #17
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
year ago they have been hacked and now year later they still have passwords in plain and nobody have found that someone is downloading whole db? that is not like you download whole db every day, and one of first things is to limit any db operations for ips 400millions is 39x times more than all people in my country, and they have security like that?
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 05:57 PM   #18
babeterminal
Confirmed User
 
Industry Role:
Join Date: Jul 2010
Location: tits
Posts: 2,751
Quote:
Originally Posted by TeenCat View Post
year ago they have been hacked and now year later they still have passwords in plain and nobody have found that someone is downloading whole db? that is not like you download whole db every day, and one of first things is to limit any db operations for ips 400millions is 39x times more than all people in my country, and they have security like that?
teencat is 6bot finished now, no update for nearly 2 years?

password changed, on doing so there was some new tos i had to agree with before i could enter program, never read it anyone know the summary of the changes?
__________________
*SIG SPOT SEND MESSAGE IF INTERESTED*
babeterminal is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 07:10 PM   #19
HairyChick
Slowly dying
 
Industry Role:
Join Date: Sep 2012
Location: Padanaram
Posts: 3,091
Another story said iCams and cams.com were hit as well. Fifteen million accounts on AFF were old customers who didn't renew. One organization unencoded 99% of passwords. Hacked a year ago and then again. I'd not trust them with my info.
__________________
*****************************************
Anti-Semites have Small Penis Syndrome. The only known treatment is electroshock therapy combined with cerebellum removal. Fortunately, it’s a tiny procedure.
*****************************************
HairyChick is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 07:43 PM   #20
the Shemp
congrats to the winners
 
the Shemp's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: Echo Beach
Posts: 10,891
I used to be on a 35% payout for life, but aff hacked me down to 20%...
the Shemp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 08:12 PM   #21
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
400 mil emails wowza.
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:13 PM   #22
st0ned
Confirmed User
 
st0ned's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
Surprising that these individuals and/or groups even release the data unless they have already hit it and want to further hide themselves in the additional flood of emails.

I guess it is for fame outside of that? They could make a killing with that many emails that's for sure.
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts.
We will guarantee and beat your current EPC to win your dating traffic!
Skype: ConversionSharks || Email: info /@/ conversionsharks.com
st0ned is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-13-2016, 11:30 PM   #23
NALEM
Confirmed User
 
NALEM's Avatar
 
Industry Role:
Join Date: Nov 2010
Location: Where ever Delta flies
Posts: 3,134
Quote:
Originally Posted by Why View Post
the sad part to me is how inept AFFs tech talent appears to be. they were storing passwords in plain text and/or SHA1. its not hard to reverse SHA1 passwords, then take the whole lot and properly secure them.

anyone still doing this deserves any bad press they get.

We use SHA512, not SHA1, to hash our passwords. It's still not ideal. Any of you cyber experts wan't to chime in and make some suggestions.
__________________
"The time men spend in trying to impress others they could spend in doing the things by which others would be impressed."
NALEM is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 12:05 AM   #24
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
Use some variable, other than the user name, to salt the password before you hash it.

Emails are a big problem. Not only are they of great marketing value -- email and user data is an extortion bonanza. If you value your businesses reputation and brand goodwill you need to actively secure this data.

The email marketing is problematic. For a medium sized business, doing high volume mail outs, the Spam server rules create security gaps that you have to trust to others (mailers).

The other point is network, database server and script security -- how did the hackers breach the system's security?
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 12:56 AM   #25
itx
Confirmed User
 
Join Date: Aug 2007
Posts: 972
If we are FFN affiliates we dont need spread this info, my .
itx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 02:02 AM   #26
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,744
First off... AFF has been hackable since the beginning. And many individuals and hacking groups have been having their way with them.

It is common knowledge in hacking back channels that it is very easy to signup as an affiliate, and then fake, crap traffic, then go into the database and find whales, now swap the affiliate id for your own. Now you too can live in mother Russia like a czar with all of your ill gotten gains.

I would posit that this is going on with almost all affiliate programs dealing with dating and cams.

Btw, doesn't matter if you lock down mysql by ip since the hacker has full control of a white listed box.
__________________
Blog Posts - Contextual Links - Hardlinks on 600+ Blog Network
* Handwritten * 180 C Class IPs * Permanent! * Many Niches! * Bulk Discounts! GFYPosts /at/ J2Media.net
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 02:09 AM   #27
CAHEK
C.C.C.P.
 
Industry Role:
Join Date: Aug 2003
Location: Novorossiya
Posts: 6,809
400 million is huge base
__________________
Pharma from True-Meds. High converting shop in Europe and USA, fast payouts via BTC !!!
CAHEK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:11 AM   #28
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
Quote:
Originally Posted by st0ned View Post
Surprising that these individuals and/or groups even release the data unless they have already hit it and want to further hide themselves in the additional flood of emails.

I guess it is for fame outside of that? They could make a killing with that many emails that's for sure.
it is easy, if you are original hacker, you will no release, if you are someone lucky and dumb, you will release, but mostly it is because the hole have been already filled, so no reason to keep the datas somewhere on local
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:17 AM   #29
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
Quote:
Originally Posted by vvvvv View Post
Btw, doesn't matter if you lock down mysql by ip since the hacker has full control of a white listed box.
hm, not sure about this one, because if the db operations are active only for one or two ips, i mean ip of billing or script which is writing into the db, you cannot do anything except from those two ips, and if someone change the settins, then some warning systems have to be activated. but, i am not good in those redneck things but looks like aff security guys have also a bit to learn ... another thing is that every big target will always be under attack, so have luck everyone
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:21 AM   #30
itx
Confirmed User
 
Join Date: Aug 2007
Posts: 972
If FFN is under attack we need this thing get unnoticed, we can as a Webmasters, they dont give a fuck if trump wins and they dont use it as excuse. We need be the MAFIA.
itx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 08:49 AM   #31
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
Quote:
Originally Posted by babeterminal View Post
teencat is 6bot finished now, no update for nearly 2 years?

password changed, on doing so there was some new tos i had to agree with before i could enter program, never read it anyone know the summary of the changes?
yes man two years is a nice holidays, 6bot will be back at work very soon
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 11:18 AM   #32
Adnium_Ivana
Confirmed User
 
Adnium_Ivana's Avatar
 
Industry Role:
Join Date: Jun 2016
Location: Toronto
Posts: 1,094
It's approx 412 million user details (like passwords & account info) that have leaked. A) that is one massive and envy inducing user base and B) Any site with such a huge list needs top anti-hacking and anti-pirating security. I mean get more people on your Dev & Ops team and invest in top notch software, you've got the $$
__________________

Skype - ivana.gsmi
Email - [email protected]
[URL="https://adnium.com/ref/3168"]
Adnium_Ivana is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 11:31 AM   #33
Brian mike
#Alberta51
 
Brian mike's Avatar
 
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,959
Quote:
Originally Posted by Adnium_Ivana View Post
you've got the $$
Do they really have it or they get in the TINDER FREE APP storm too ?

I heard from many client of the Dating world that; they all have lose big at the arrival of the type of Tinder FREE APP Models .

Someone can put some intel on that ?
__________________
Tube - Cam - Escorts - Top List
Menu Tab - Banner - Header Link - Blog Post
DM me
Brian mike is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 11:54 AM   #34
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by TeenCat View Post
hm, not sure about this one, because if the db operations are active only for one or two ips, i mean ip of billing or script which is writing into the db, you cannot do anything except from those two ips, and if someone change the settins, then some warning systems have to be activated. but, i am not good in those redneck things but looks like aff security guys have also a bit to learn ... another thing is that every big target will always be under attack, so have luck everyone
his point was if you have access to the one of the servers owning the whitelisted IPs in the database server, there is no way to keep the data safe. Ip protecting your database when your code is insecure doesn't do much for you.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 12:10 PM   #35
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
Quote:
Originally Posted by Why View Post
his point was if you have access to the one of the servers owning the whitelisted IPs in the database server, there is no way to keep the data safe. Ip protecting your database when your code is insecure doesn't do much for you.
ok man got it, thanks for the explanation
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 12:21 PM   #36
Adnium_Ivana
Confirmed User
 
Adnium_Ivana's Avatar
 
Industry Role:
Join Date: Jun 2016
Location: Toronto
Posts: 1,094
Quote:
Originally Posted by Brian mike View Post
Do they really have it or they get in the TINDER FREE APP storm too ?

I heard from many client of the Dating world that; they all have lose big at the arrival of the type of Tinder FREE APP Models .

Someone can put some intel on that ?
If' they've got servers to run and support 400 mill user base + plus traffic in the 100+ millions I'm assuming such a company has got the dough for security
__________________

Skype - ivana.gsmi
Email - [email protected]
[URL="https://adnium.com/ref/3168"]
Adnium_Ivana is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 01:01 PM   #37
romeo22
你自己去他媽的
 
romeo22's Avatar
 
Industry Role:
Join Date: Mar 2008
Posts: 23,346
Wohoo nice !!!!
romeo22 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:05 PM   #38
rhon23
Rebel Girl
 
rhon23's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: The Island Of Misfit Toys
Posts: 3,264
In light of recent Friend Finder events we would like to share our statement from Penthouse.

“Prior to February 19th, 2016 Penthouse was a subsidiary of FriendFinder Networks, Inc. and subject to their controls and procedures. As of the close of the sale, Penthouse now operates independent of FriendFinder Networks, Inc.
We are aware of the data hack and we are waiting on FriendFinder to give us a detailed account of the scope of the breach and their remedial actions in regard to our data. Penthouse.com is a content site and does not collect data regarding our members sexual preferences. We take our members’ data and site security seriously. We assumed full control of Penthouse.com in May of 2016 and immediately adopted a blanket policy requiring all of our members to change their passcodes. At the time our members weren’t thrilled with the inconvenience but we remain committed to “best practices” in regard to keeping our members’ data secure.”
rhon23 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:13 PM   #39
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by rhon23 View Post
In light of recent Friend Finder events we would like to share our statement from Penthouse.

?Prior to February 19th, 2016 Penthouse was a subsidiary of FriendFinder Networks, Inc. and subject to their controls and procedures. As of the close of the sale, Penthouse now operates independent of FriendFinder Networks, Inc.
We are aware of the data hack and we are waiting on FriendFinder to give us a detailed account of the scope of the breach and their remedial actions in regard to our data. Penthouse.com is a content site and does not collect data regarding our members sexual preferences. We take our members? data and site security seriously. We assumed full control of Penthouse.com in May of 2016 and immediately adopted a blanket policy requiring all of our members to change their passcodes. At the time our members weren?t thrilled with the inconvenience but we remain committed to ?best practices? in regard to keeping our members? data secure.?
which begs the question, if the acquiring party noticed this huge issue with how passwords were being stored, why did AFF not, and/or why did they not fix at least that part of the situation long before this all happened?

incompetence or apathy?
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 03:16 PM   #40
rhon23
Rebel Girl
 
rhon23's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: The Island Of Misfit Toys
Posts: 3,264
Quote:
Originally Posted by Why View Post
which begs the question, if the acquiring party noticed this huge issue with how passwords were being stored, why did AFF not, and/or why did they not fix at least that part of the situation long before this all happened?

incompetence or apathy?
That is a friend finder question. We are now divorced from them.
rhon23 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-14-2016, 04:17 PM   #41
money biz
Confirmed User
 
Join Date: Jan 2003
Posts: 962
I bet 65% are from api dating db's that didn't really sign up cough cough
money biz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 01:02 AM   #42
itx
Confirmed User
 
Join Date: Aug 2007
Posts: 972
itx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 03:47 AM   #43
TheDA
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 4,665
__________________
Sharleen Spiteri - 1989 - In The Ass
TheDA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 04:06 AM   #44
Vendot
Confirmed User
 
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
Quote:
Originally Posted by Why View Post
incompetence or apathy?
They look asleep at the wheel as anyone trying to get a response from affiliate support will tell you.
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell
Vendot is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 07:21 AM   #45
marcop
Content Producer
 
marcop's Avatar
 
Industry Role:
Join Date: Nov 2005
Location: Los Angeles
Posts: 4,143
Quote:
Originally Posted by Why View Post
the sad part to me is how inept AFFs tech talent appears to be. they were storing passwords in plain text and/or SHA1. its not hard to reverse SHA1 passwords, then take the whole lot and properly secure them.

anyone still doing this deserves any bad press they get.
This....
marcop is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 09:14 AM   #46
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,744
Quote:
Originally Posted by TeenCat View Post
hm, not sure about this one, because if the db operations are active only for one or two ips, i mean ip of billing or script which is writing into the db, you cannot do anything except from those two ips, and if someone change the settins, then some warning systems have to be activated. but, i am not good in those redneck things but looks like aff security guys have also a bit to learn ... another thing is that every big target will always be under attack, so have luck everyone
True, except that you cannot process anything directly in your own database? You always have to use some billing tool to do it? Not!
__________________
Blog Posts - Contextual Links - Hardlinks on 600+ Blog Network
* Handwritten * 180 C Class IPs * Permanent! * Many Niches! * Bulk Discounts! GFYPosts /at/ J2Media.net
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 10:15 AM   #47
JFK
FUBAR the ORIGINATOR
 
JFK's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: FUBARLAND
Posts: 67,374
Quote:
Originally Posted by RyuLion View Post
That's what she said..
You wish !
__________________

FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX
For promo opps contact jfk at fubarwebmasters dot com
JFK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-15-2016, 10:21 AM   #48
romeo22
你自己去他媽的
 
romeo22's Avatar
 
Industry Role:
Join Date: Mar 2008
Posts: 23,346
Me gusta much
romeo22 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
accounts, insecurely, stored, apparently, passwords, mailing, lists, download, database, closed, customer, data, hack, hacked, millions, largest, liiberated, aff/penthouse, million



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.