Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-05-2004, 06:32 AM   #51
William-Xfactor
Confirmed User
 
Join Date: Mar 2004
Location: Melbourne
Posts: 299
What you see there is typical of any password dump/ forum
No point wasting your time trying to close it down they will have several mirrors and will be back up in no time.

You will notice 99 percent of those logins are user defined ?simple to brute-force?
And ?simple to decrypt?

Crackers know that people in general are lazy and use the same passwords for every site they join.

You cannot run a pay site that allows your customers to choose their own logins and not expect to have major password issues.

If your billing company allows random passwords to be assigned to your customers, do it!
And use a good length, I recommend 15 char. That will stop passwords from being brute-forced. Also by having a good length ?say 15 char? even if they exploit your server or a script to locate your password file they will be flat out trying to decrypt it.

All that needs doing then is to install a script like password sentry and that will alert you to any password trading.
William-Xfactor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:30 AM   #52
Gator
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: Don't live on GFY
Posts: 1,119
Quote:
Originally posted by William-Xfactor
If your billing company allows random passwords to be assigned to your customers, do it!
And use a good length, I recommend 15 char. That will stop passwords from being brute-forced. Also by having a good length ?say 15 char? even if they exploit your server or a script to locate your password file they will be flat out trying to decrypt it.
I wouldn't do that. That's a pain in the ass for the customers. The simplest solution is a form login page like this one:

http://www.polishmyhelmet.com/members/
Gator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:37 AM   #53
William-Xfactor
Confirmed User
 
Join Date: Mar 2004
Location: Melbourne
Posts: 299
Those forms can be brute-forced as well.
There are some very skilled coders on the dark side
Mr. Gator
William-Xfactor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:40 AM   #54
cayne
My time is coming...
 
Join Date: Jan 2004
Location: Europe --- eMail: service(at)badasscompany.com --- ICQ: 60288510
Posts: 7,476
Quote:
Originally posted by Basic_man
Fuck, there's ton of damn free password!
that's the world of free porn...but if I take a look at my sign-ups many ppl don't know these kind of links.
__________________
If lesbian anal is wrong, I don't want to be right.
cayne is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:45 AM   #55
Adam-EB
Confirmed User
 
Join Date: Mar 2004
Location: Tampa Bay, FL
Posts: 393
None of ours there...
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.
Adam-EB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:47 AM   #56
Gator
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: Don't live on GFY
Posts: 1,119
Quote:
Originally posted by William-Xfactor
Those forms can be brute-forced as well.
There are some very skilled coders on the dark side
Mr. Gator
I'm sure they can, but I still think it's better than using the pop up box login that it much easier to brute force.
Gator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 08:56 AM   #57
William-Xfactor
Confirmed User
 
Join Date: Mar 2004
Location: Melbourne
Posts: 299
Yes agreed it is a more secure option, however you?re still inconveniencing your customers by typing in the image content.

We use 15 char random logins, the members get used to it "most people are familiar with copy and paste"

Anyway I?m out for the night
Cheers
William-Xfactor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 09:09 AM   #58
Gator
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: Don't live on GFY
Posts: 1,119
Quote:
Originally posted by William-Xfactor
Yes agreed it is a more secure option, however you?re still inconveniencing your customers by typing in the image content.

We use 15 char random logins, the members get used to it "most people are familiar with copy and paste"

Anyway I?m out for the night
Cheers
Well the only thing they have to type is the image content because they can save their u/p on the page and not have to type that or copy and paste it.

Anyway, I'm sure your system works well. I was just saying the form login page was simpler than having a user and pass like Ug834nfoGodkt5j/Risjt35Fks53GW.
Gator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 10:05 AM   #59
Desperate Andy
Confirmed User
 
Industry Role:
Join Date: Mar 2003
Location: Europe
Posts: 150
Quote:
Originally posted by William-Xfactor
Yes agreed it is a more secure option, however youhaha8217;re still inconveniencing your customers by typing in the image content.

We use 15 char random logins, the members get used to it "most people are familiar with copy and paste"

There is always the other side of the coin. From our experience adding more complicated rules for creating the username and password leads to increasing of issues with creating accounts.

And still there're many customers who don't use (or don't know how to use, huh?) copy-paste to insert the info to log-in window.
__________________
Serious Coin Partnership Program: 50+ exclusive niche sites.
Convert your Medical, Lesbian, Nude Sports, BDSM, Femdom, CFNM Fetish traffic!
Desperate Andy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 03:22 PM   #60
Matt 26z
So Fucking Banned
 
Industry Role:
Join Date: Apr 2002
Location: ¤ª"˜¨๑۩۞۩๑¨˜"ª¤
Posts: 18,481
Quote:
Originally posted by Gator
The simplest solution is a form login page like this one:

http://www.polishmyhelmet.com/members/
If done correctly, yes, this could put an end to brute force. Unfortunately images as simple as they are using can be very easily read by an image reader program.
Matt 26z is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 03:24 PM   #61
Goose
Confirmed User
 
Join Date: Mar 2004
Location: --------Europe-------
Posts: 5,725
wow, that's a fucking huge list!!
__________________
ICQ: 52410619
Goose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2004, 03:30 PM   #62
Mr Dickovitch
Confirmed User
 
Join Date: Jul 2004
Posts: 1,070
I'm surprised they are not shut down yet.
Mr Dickovitch is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.