![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
extreme-dm leaking user:pass in public referer stats
<img src="http://media.sensationcontent.com/rowan/extreme-pw-leak.gif">
Never seen this before - someone has clicked through to another site from a link in my members area, and it's been recorded in that site's extreme-dm stats. Several people have jumped on that URL in the past few minutes. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Guest
Posts: n/a
|
Yup. I've noticed that quite a few times in my stats as well. Pretty shitty.
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
So Fucking Banned
Join Date: Jul 2003
Posts: 1,595
|
Brutal. Looks like a bug.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
vip member
Join Date: Jan 2003
Posts: 17,798
|
Woud happen with any stats program
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jun 2003
Location: The Hood of Burquitlam, BC
Posts: 1,046
|
How does well do fark boobies convert?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Aug 2001
Location: New Orleans
Posts: 1,680
|
It's not the program revealing the username:password so much as it is alerting you to a compromised password.
Look at it this way, if someone accesses your site as http://yourdomain.com/ instead of http:// www.yourdomain.com and you use relative linking throughout, then their referers will always be of the form http://yourdomain.com/directory/page.html. Right? Now, keeping that in mind- the question is, when does a person access a membership area using http://username:[email protected]/members/?
__________________
<CENTER><A HREF="http://www.hot-off-bourbon.com/" target="_blank"><IMG SRC="http://www.hot-off-bourbon.com/images/hob-logosmall.jpg" border="0"></A> <FONT face="Comic Sans MS" SIZE="-1"><I>Mardi Gras, Spring Break, Wet-T, Night Club Action, UpSkirt, Oil Wrestling, Voyeur</I></FONT></CENTER> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Join Date: Jan 2003
Location: NYC
Posts: 3,493
|
fiveeyes is the only one with a clue, thats definetely a pw crack,
unless you have a bookmark script that adds them like that for your members.
__________________
Contact information - ICQ: 7.9.0.3.0.0 · AIM: no roach · E-Mail: roachito || @ || gmail || . || com [Friend Finder - Geo Targeting & Incredible Site Ratio] - [Credit Card Traffic - Make $65 Per Join] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Aug 2001
Location: New Orleans
Posts: 1,680
|
In fact, comng to think of it, go pull your referer log and find the first occurance of that usage. It'll will point back to the password site that has you hotlinked.
__________________
<CENTER><A HREF="http://www.hot-off-bourbon.com/" target="_blank"><IMG SRC="http://www.hot-off-bourbon.com/images/hob-logosmall.jpg" border="0"></A> <FONT face="Comic Sans MS" SIZE="-1"><I>Mardi Gras, Spring Break, Wet-T, Night Club Action, UpSkirt, Oil Wrestling, Voyeur</I></FONT></CENTER> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Join Date: Apr 2002
Location: Los Angeles
Posts: 6,102
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
I agree that it was probably a password crack that got the 'leaker' to my site, it was just unusual to see it carried through as-is... from checking my logs it looks like it's buried in quite a few other sites extreme-dm stats and has been for at least 2 weeks. My compromised account script didn't pick it up due to the URL being well hidden (for the most part), so there was hardly anyone using it until it hit the 'last 20 referers' of a site and got noticed.
|
![]() |
![]() ![]() ![]() ![]() ![]() |