Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-17-2004, 04:58 PM   #1
angelsofporn
Confirmed User
 
Join Date: Mar 2002
Location: CA
Posts: 3,218
Paysite owners

I need a solution quick. I have tons of passwords hacked on our system everyday and it is starting to eat at the bottomline because legitimate subscribers cannot access the accounts they pay for.
We have pennywize in place and it blocks the brute force guys and kills passwords that are being accessed from more than a certain number of subnets in a 24 hour period.
How can i get something like this?
http://members.hardcoretraining.com/?lang=en
This seems to be the way to go.
angelsofporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 05:10 PM   #2
SlickRick
Confirmed User
 
Industry Role:
Join Date: Jan 2003
Location: Kingman AZ
Posts: 2,849
get .htscess installed
I had the problem, but not really bad with passwords floating around at the crack sites.
SlickRick is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 05:11 PM   #3
Sly_RJ
Live Hard - Die Hard
 
Join Date: Feb 2002
Location: Ready to leave...
Posts: 17,042
Quote:
Originally posted by SlickRick
get .htscess installed
I had the problem, but not really bad with passwords floating around at the crack sites.
Damn, why didn't we think of that!
__________________
PHAT SERVERS - Quality dedicated hosting at a quality price!
sly AT phatservers DOT com - 147479144
Sly_RJ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 05:22 PM   #4
angelsofporn
Confirmed User
 
Join Date: Mar 2002
Location: CA
Posts: 3,218
anyone with a solid idea please post here
angelsofporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 05:39 PM   #5
notjoe
Confirmed User
 
Industry Role:
Join Date: May 2002
Location: Toronto, Canada
Posts: 5,599
Quote:
Originally posted by angelsofporn
anyone with a solid idea please post here
Hit me up on ICQ @ 5956902
notjoe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 05:57 PM   #6
doober
Confirmed User
 
Join Date: Jul 2003
Location: in yoOoo kitchen
Posts: 6,984
bizzzump for a good q
doober is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 06:09 PM   #7
crescentx
Confirmed User
 
Join Date: Jun 2003
Posts: 317
ProxyPass does much better than Pennywize, but you still need to keep an eye if they get creative. It does block proxy attacks, and all the usual stuff pennywize does. Make sure your billing processors' software is the latest version. (Which processors?)

-doug
__________________
XYCash International Gay Affiliate Program
crescentx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 06:11 PM   #8
lagwagon
Confirmed User
 
lagwagon's Avatar
 
Join Date: Jul 2001
Location: az
Posts: 8,464
we have the same problem. after a certain level of members htaccess was crunched. so we set up a mysql db.... but now we are going to switch to generating the user/pass for the customer. this should help a lot against brute force attacks.
__________________

FTVGirls - FTVMilfs - DanielleFTV
lagwagon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 06:12 PM   #9
PrivateIvy
Confirmed User
 
Industry Role:
Join Date: Oct 2003
Location: North Carolina
Posts: 4,257
go with Password Sentry..it's better than Pennywize ...I've used it for 2 years now and wouldn't use anything else !



Ivy
PrivateIvy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 06:53 PM   #10
NaughtyAlysha
Confirmed User
 
NaughtyAlysha's Avatar
 
Join Date: Feb 2002
Location: Tampa Bay, FL
Posts: 1,843
I like that... I'd be interested in something like that for my sites.
__________________


ExtremeBank.com, the EXTREME program for NaughtyAlysha.com.
NaughtyAlysha is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 06:56 PM   #11
Hardcore J
Hardcore 4 Life™
 
Hardcore J's Avatar
 
Join Date: Mar 2003
Location: Everett, WA
Posts: 2,553
As already mentioned proxy pass is the way to go. I used to have pennywize and had a lot of problems, since I got proxie pass I haven't had a single break in in around 8 months.. with pennywize I was getting 1 a week.

Chris -- before you start randomly generating user/passes you should check out proxy pass.. will save your members a lot of hassle!
Hardcore J is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 07:04 PM   #12
tony286
lurker
 
tony286's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
We have both password sentry and proxypass (I am suspenders and belt type of guy) . They have both been excellent for us and the password sentry guy is one of the nicest guys in the world .
tony286 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 07:10 PM   #13
Sly_RJ
Live Hard - Die Hard
 
Join Date: Feb 2002
Location: Ready to leave...
Posts: 17,042
You guys got a link for Proxy Pass?

Thanks.
__________________
PHAT SERVERS - Quality dedicated hosting at a quality price!
sly AT phatservers DOT com - 147479144
Sly_RJ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 07:52 PM   #14
angelsofporn
Confirmed User
 
Join Date: Mar 2002
Location: CA
Posts: 3,218
Quote:
Originally posted by Hardcore J
As already mentioned proxy pass is the way to go. I used to have pennywize and had a lot of problems, since I got proxie pass I haven't had a single break in in around 8 months.. with pennywize I was getting 1 a week.

Chris -- before you start randomly generating user/passes you should check out proxy pass.. will save your members a lot of hassle!
None is 8 months? shit man..i have 60 hacked every day and i am am mysql and pennywize
angelsofporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 07:57 PM   #15
angelsofporn
Confirmed User
 
Join Date: Mar 2002
Location: CA
Posts: 3,218
What makes proxypass so much better than pennywize?
angelsofporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 08:01 PM   #16
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by angelsofporn
I need a solution quick. I have tons of passwords hacked on our system everyday and it is starting to eat at the bottomline because legitimate subscribers cannot access the accounts they pay for.
We have pennywize in place and it blocks the brute force guys and kills passwords that are being accessed from more than a certain number of subnets in a 24 hour period.
How can i get something like this?
http://members.hardcoretraining.com/?lang=en
This seems to be the way to go.
first you should identify how they get in the first place.

- some of them use bruteforce attacks to guess the logins.
- some of them find a backdoor to insert their own user logins into your user management system.

pennywize is good for detecting multiple uses of the same login but you need a solution that blocks brute force attacks at the server connection level as well, so they dont even get to apache.
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 08:14 PM   #17
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally posted by angelsofporn
None is 8 months? shit man..i have 60 hacked every day and i am am mysql and pennywize
I use pennywize and have anywhere from 20k-80k log-in attempts daily and I might have one leak a month. On your sign-up forms tell the visitor to use one uppercase and a number in their user/pass.

One small line will save ya tons of trouble.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 08:15 PM   #18
angelsofporn
Confirmed User
 
Join Date: Mar 2002
Location: CA
Posts: 3,218
Quote:
Originally posted by Lane
first you should identify how they get in the first place.

- some of them use bruteforce attacks to guess the logins.
- some of them find a backdoor to insert their own user logins into your user management system.

pennywize is good for detecting multiple uses of the same login but you need a solution that blocks brute force attacks at the server connection level as well, so they dont even get to apache.
does proxypass do this better than pennywize?
angelsofporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 08:16 PM   #19
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally posted by angelsofporn
does proxypass do this better than pennywize?
Proxypass doesn't do what he is talking about. His is server level and custom coded.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 09:01 PM   #20
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by angelsofporn
does proxypass do this better than pennywize?
national-net has a custom solution for what i have mentioned, but other than that i havent looked around for any alternatives
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-17-2004, 09:36 PM   #21
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Strongbox is a whole new approach that is WAY above and beyond
anything like Pennydumb.
Not only does it keep the hurlers from getting in, but it discourages
them from even continueing the attack and slowing your server.
It protects from hurlers (brute force attacks), password sites, and various
other evils.
Unlike PennyWize, Password Sentry, or other old fashioned approaches,
Strongbox is 100% compatible with the latest versions of Microsoft Media
Player.
That, and the price is definitely right.
Several of the well know members of this board, TLA's, and
GFY use it on all of their pay sites and swear by it.

For more information, see:
http://webmastersguide.com/?htaccess-cgi/strongbox/
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.