![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Mar 2002
Location: CA
Posts: 3,218
|
Paysite owners
I need a solution quick. I have tons of passwords hacked on our system everyday and it is starting to eat at the bottomline because legitimate subscribers cannot access the accounts they pay for.
We have pennywize in place and it blocks the brute force guys and kills passwords that are being accessed from more than a certain number of subnets in a 24 hour period. How can i get something like this? http://members.hardcoretraining.com/?lang=en This seems to be the way to go. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Kingman AZ
Posts: 2,849
|
get .htscess installed
I had the problem, but not really bad with passwords floating around at the crack sites. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Live Hard - Die Hard
Join Date: Feb 2002
Location: Ready to leave...
Posts: 17,042
|
Quote:
__________________
PHAT SERVERS - Quality dedicated hosting at a quality price! sly AT phatservers DOT com - 147479144 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Mar 2002
Location: CA
Posts: 3,218
|
anyone with a solid idea please post here
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Industry Role:
Join Date: May 2002
Location: Toronto, Canada
Posts: 5,599
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jul 2003
Location: in yoOoo kitchen
Posts: 6,984
|
bizzzump for a good q
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Jun 2003
Posts: 317
|
ProxyPass does much better than Pennywize, but you still need to keep an eye if they get creative. It does block proxy attacks, and all the usual stuff pennywize does. Make sure your billing processors' software is the latest version. (Which processors?)
-doug
__________________
XYCash International Gay Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jul 2001
Location: az
Posts: 8,464
|
we have the same problem. after a certain level of members htaccess was crunched. so we set up a mysql db.... but now we are going to switch to generating the user/pass for the customer. this should help a lot against brute force attacks.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: North Carolina
Posts: 4,257
|
go with Password Sentry..it's better than Pennywize ...I've used it for 2 years now and wouldn't use anything else !
![]() Ivy |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Feb 2002
Location: Tampa Bay, FL
Posts: 1,843
|
I like that... I'd be interested in something like that for my sites.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Hardcore 4 Life™
Join Date: Mar 2003
Location: Everett, WA
Posts: 2,553
|
As already mentioned proxy pass is the way to go. I used to have pennywize and had a lot of problems, since I got proxie pass I haven't had a single break in in around 8 months.. with pennywize I was getting 1 a week.
Chris -- before you start randomly generating user/passes you should check out proxy pass.. will save your members a lot of hassle! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
lurker
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
|
We have both password sentry and proxypass (I am suspenders and belt type of guy) . They have both been excellent for us and the password sentry guy is one of the nicest guys in the world .
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Live Hard - Die Hard
Join Date: Feb 2002
Location: Ready to leave...
Posts: 17,042
|
You guys got a link for Proxy Pass?
Thanks.
__________________
PHAT SERVERS - Quality dedicated hosting at a quality price! sly AT phatservers DOT com - 147479144 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Join Date: Mar 2002
Location: CA
Posts: 3,218
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Mar 2002
Location: CA
Posts: 3,218
|
What makes proxypass so much better than pennywize?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Will code for food...
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
|
Quote:
- some of them use bruteforce attacks to guess the logins. - some of them find a backdoor to insert their own user logins into your user management system. pennywize is good for detecting multiple uses of the same login but you need a solution that blocks brute force attacks at the server connection level as well, so they dont even get to apache.
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
One small line will save ya tons of trouble.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Confirmed User
Join Date: Mar 2002
Location: CA
Posts: 3,218
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Will code for food...
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
|
Quote:
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Strongbox is a whole new approach that is WAY above and beyond
anything like Pennydumb. Not only does it keep the hurlers from getting in, but it discourages them from even continueing the attack and slowing your server. It protects from hurlers (brute force attacks), password sites, and various other evils. Unlike PennyWize, Password Sentry, or other old fashioned approaches, Strongbox is 100% compatible with the latest versions of Microsoft Media Player. That, and the price is definitely right. Several of the well know members of this board, TLA's, and GFY use it on all of their pay sites and swear by it. For more information, see: http://webmastersguide.com/?htaccess-cgi/strongbox/
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |