Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-08-2006, 09:39 AM   #1
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Pass sharing sites - To all site owners

just stumpled upon this...
http://www.villainess.com/
isn't there anything that can be done about these pass sharing sites?

AFF, cams.com seem to be the main sponsors ....
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 10:40 AM   #2
bobby666
boots are my religion
 
bobby666's Avatar
 
Join Date: Nov 2005
Location: Heart of europe
Posts: 21,765
see the same sites hacked as 3 years ago, when i still was far away of becomming a webmaster

i think the webmasters of the sites recognice what has happened when they view their daily bandwith stats

so i ask for the reason why staceys dungeon for instance is an open site for three years?
__________________
bobby666 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 10:47 AM   #3
SiMpLe
Confirmed User
 
SiMpLe's Avatar
 
Join Date: Feb 2002
Location: Porn Central - California
Posts: 3,221
Quote:
Originally Posted by martinsc

AFF, cams.com seem to be the main sponsors ....


SURPRISE!!!
__________________
Sean Holland
Vice President
OrbitalPay / Global Electronic Technology (GET)
SKYPE: iam.sean ::: sholland at orbitalpay.com
888-775-1500
SiMpLe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 11:35 AM   #4
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by SiMpLe
SURPRISE!!!
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 01:16 PM   #5
Anar_j
Confirmed User
 
Anar_j's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: World
Posts: 430
__________________
Teencash.com - Top converting teen cash program, where 1000s of pic, movie, tube ready FHGs...

Top Sites: Babysitter Movies*Teen Lesbian Land*Girls Left Alone*Teen Sleep Over*Teen Emery

ICQ:176-922-400
Anar_j is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 01:26 PM   #6
Roald
SecretFriends.com
 
Roald's Avatar
 
Industry Role:
Join Date: May 2001
Location: IMC Headquarters
Posts: 27,885
same old shit
__________________


WE ARE BUYING PAY SITES! CONTACT ME



ClubSweethearts | ManUpFilms | SinfulXXX | HOT * AdultPrime * HOT


Paying webmasters since 1996! Contact: r.riepen @ sansylgroup.com | telegram: roaldr
Roald is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 02:14 PM   #7
Sinstar
Confirmed User
 
Join Date: Mar 2006
Posts: 1,206
Pass sharing sucks.
Sinstar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 02:34 PM   #8
scottybuzz
Too lazy to set a custom title
 
scottybuzz's Avatar
 
Industry Role:
Join Date: May 2006
Location: NY
Posts: 14,800
yeh truley sucks
scottybuzz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 08:40 PM   #9
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by Anar_j
what are you happy about?
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 08:45 PM   #10
tony286
lurker
 
tony286's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
Can we sue the sponsors for supporting people who steal?
tony286 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2006, 11:46 PM   #11
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by tony404
Can we sue the sponsors for supporting people who steal?
interesting question..
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 12:56 AM   #12
themanager
Confirmed User
 
Join Date: Apr 2006
Location: usa
Posts: 508
I don't think that is right we should think of a way to stop it.
themanager is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 08:49 AM   #13
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by themanager
I don't think that is right we should think of a way to stop it.
any ideas?
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 09:06 AM   #14
Matt 26z
So Fucking Banned
 
Industry Role:
Join Date: Apr 2002
Location: ¤ª"˜¨๑۩۞۩๑¨˜"ª¤
Posts: 18,481
Quote:
Originally Posted by themanager
I don't think that is right we should think of a way to stop it.
You are about 10 years too late on that one.
Matt 26z is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 09:14 AM   #15
Dirty Dane
Sick Fuck
 
Dirty Dane's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
Quote:
Originally Posted by martinsc
any ideas?
Organize it.
If the porn industry had something like the music industry. But I don't think it will happen
Dirty Dane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 09:17 AM   #16
shack
Confirmed User
 
Join Date: Oct 2004
Location: Oz
Posts: 539
It's how some paysites drive traffic, they leak a password, or give the webmaster one, get the site listed, get a few people in, then kill the password.

Gets impression on your members area, and further traffic to the front end once you kill the password.

It's only bandwidth

Last edited by shack; 07-09-2006 at 09:18 AM..
shack is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:00 AM   #17
rotterdammer
Confirmed User
 
Join Date: Feb 2006
Posts: 1,523
Thats pretty bullshit what you say, there are shit loads of wordlist in different niches that contain 10.000 passwords for bangbros. Sites like BB and Nastydollars dont even seem to care about their passes being cracked.

The only way paysite owners can stop this is to get as many wordlists as possible and ban all the words for people who want to signup.

Especially the following user:pass

december:januari
abcde:fghijk
username:password

Maybe bangbros doesnt care because of the promotion but i know that site you mention is only the top of the iceberg.

There are several password forums like passwordparadise.net that have 100.000 passes to paysites.
rotterdammer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:02 AM   #18
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
or make the passwords harder, people that pick their own are too simple
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:15 AM   #19
rotterdammer
Confirmed User
 
Join Date: Feb 2006
Posts: 1,523
Yeah thats also very true fris!
rotterdammer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:22 AM   #20
Pimpin_J
Confirmed User
 
Join Date: Jul 2006
Location: SplitInfinity.com
Posts: 3,637
The passwords arent the most weak point on an adultsite. Generated user/pass combinations are a good start but that doesnt protect you from so called "pass sharers".
The weakest point is the "human" webmaster!
They hack your site through any well known bug (adultcms/phpBB,whatever), place a shell (mostly .php / .gif / .jpg ) and search for your .htpass file or your sql details. Once your .htpass is stolen its easily decrypted with the right tools. (Generated user/pass combinations are also more hard to decrypt then normal combos like "user123 : 321user")
Bruteforcing was 1990...
So better keep your stuff updated and check for suspect files on your server.
__________________
Pimpin_J is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:47 PM   #21
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by Pimpin_J
The passwords arent the most weak point on an adultsite. Generated user/pass combinations are a good start but that doesnt protect you from so called "pass sharers".
The weakest point is the "human" webmaster!
They hack your site through any well known bug (adultcms/phpBB,whatever), place a shell (mostly .php / .gif / .jpg ) and search for your .htpass file or your sql details. Once your .htpass is stolen its easily decrypted with the right tools. (Generated user/pass combinations are also more hard to decrypt then normal combos like "user123 : 321user")
Bruteforcing was 1990...
So better keep your stuff updated and check for suspect files on your server.
couldn't agree more...
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:54 PM   #22
Beejeebers
Confirmed User
 
Join Date: Oct 2004
Posts: 290
How are generated user/pass combos harder to encrypt?

If you have a user/pass/id number combo, you would screw over 95% of the scripts that script kiddies use to hack the sites in the first place.
__________________
Beejeebers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 10:57 PM   #23
frakyou
Registered User
 
Join Date: Jun 2006
Posts: 2
Seems like it would be easy to prevent this. Different people logging in under the same account would have different ip adresses.
frakyou is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-09-2006, 11:05 PM   #24
CaptainHowdy
Too lazy to set a custom title
 
CaptainHowdy's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,492
Quote:
Originally Posted by Anar_j
Uh ??
__________________
Tjeezers.cam plus all sites $12.000,00.
Transfer within 24 hours.
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 08:16 AM   #25
Pimpin_J
Confirmed User
 
Join Date: Jul 2006
Location: SplitInfinity.com
Posts: 3,637
Quote:
Originally Posted by Beejeebers
How are generated user/pass combos harder to encrypt?

If you have a user/pass/id number combo, you would screw over 95% of the scripts that script kiddies use to hack the sites in the first place.
Its definatly harder to decrypt if its generated! Most sites use DES decryption and to decrypt it you need a good wordlist. Generated means more salts = takes much longer to decrypt. Now its getting to the math part where i have to pass course i always was stoned in math..
But i hope you get my point now, why its more usefull to use generated passwords to prevent hackers.


Easy example -> check the web for suze passes or for bangbros..youll find a shitload of passes. But try to get a pass for partyhardcore and/or perfect gonzo sites...
Youll see what i mean..
__________________

Last edited by Pimpin_J; 07-10-2006 at 08:18 AM..
Pimpin_J is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 09:59 PM   #26
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by Pimpin_J
Its definatly harder to decrypt if its generated! Most sites use DES decryption and to decrypt it you need a good wordlist. Generated means more salts = takes much longer to decrypt. Now its getting to the math part where i have to pass course i always was stoned in math..
But i hope you get my point now, why its more usefull to use generated passwords to prevent hackers.


Easy example -> check the web for suze passes or for bangbros..youll find a shitload of passes. But try to get a pass for partyhardcore and/or perfect gonzo sites...
Youll see what i mean..
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 10:41 PM   #27
czarina
Webmaster Extraordinaire
 
czarina's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: A beautiful beach...
Posts: 10,748
Just do passwords away and invent something else, yeah, like what?
czarina is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 10:44 PM   #28
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
everone should img src it to death or packet it offline
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:01 PM   #29
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
Those passwords suck.
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:10 PM   #30
BV
wtf
 
BV's Avatar
 
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
it's free traffic guys
it's free traffic guys

there i said it twice
BV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:19 PM   #31
germ
( o Y o )
 
Industry Role:
Join Date: Oct 2002
Posts: 3,108
i say we stop promoting the sponsors that pay the password sharing sites.

its always aff and cams.com. they know wtf is going on, but they dont do anything about it. if other people stopped promoting them because of it, it may make them sit up and take notice that keeping one affiliate is making them lose a hell of a lot more.
germ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:25 PM   #32
UtahSaints
Confirmed User
 
UtahSaints's Avatar
 
Industry Role:
Join Date: Jan 2005
Posts: 1,538
hmmm. fucked up...
__________________
Enjoy Bucks - Enjoy Bucks
UtahSaints is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:28 PM   #33
aico
Moo Moo Cow
 
Join Date: Mar 2004
Location: Washington State
Posts: 14,748
Stop it? No!!!!!! I get mad hits from "leaked" passwords.
aico is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-10-2006, 11:35 PM   #34
Bro Media - BANNED FOR LIFE
MOBILE PORN: IMOBILEPORN
 
Join Date: Jan 2004
Location: Tinseltown NL
Posts: 16,502
Quote:
Originally Posted by martinsc
Bro Media - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-12-2006, 03:26 AM   #35
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
Quote:
Originally Posted by LOL :D
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-12-2006, 03:41 AM   #36
fr0gman
Confirmed User
 
Join Date: Feb 2005
Posts: 2,093
Quote:
Originally Posted by martinsc
any ideas?
Unplug the Internet.
__________________
Earn up to $.03 per Visitor -> No Click Monetization!
"Because the World Wide Web is all about two things: horrifyingly stupid psychodrama, and naked chicks."
Wild College Videos | ICQ: 7746696
fr0gman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-20-2006, 05:15 AM   #37
martinsc
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
just another bump.
someone has to do something about this...
__________________
Make Money
martinsc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-20-2006, 05:23 AM   #38
bizarredollars
Confirmed User
 
Join Date: Mar 2006
Location: bizarredollars.com
Posts: 1,582
How often does this shit keep coming up?? Invest in a script, and profit from the traffic.. easy as... I tested this a few years back, I posted a password to one of my own sites, left it working for a couple of days, blocked it and made a shit load of sales thanks to a well designed 401 page.

Good scripts don't cost much.. the investment is well worth it.

Fuck, I wrote my own.. I might start selling it at $25 per pop, lol.
__________________

[email protected]
icq: 205-252-550
bizarredollars is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-20-2006, 05:30 AM   #39
bizarredollars
Confirmed User
 
Join Date: Mar 2006
Location: bizarredollars.com
Posts: 1,582
Quote:
Originally Posted by Pimpin_J
The passwords arent the most weak point on an adultsite. Generated user/pass combinations are a good start but that doesnt protect you from so called "pass sharers".
The weakest point is the "human" webmaster!
They hack your site through any well known bug (adultcms/phpBB,whatever), place a shell (mostly .php / .gif / .jpg ) and search for your .htpass file or your sql details. Once your .htpass is stolen its easily decrypted with the right tools. (Generated user/pass combinations are also more hard to decrypt then normal combos like "user123 : 321user")
Bruteforcing was 1990...
So better keep your stuff updated and check for suspect files on your server.
Very good points.. another good tip - alter your apache config to use a file other than .htaccess for access rights.. something more random. It is very easily done, and adds another lair of security.

The best thing to do is have a seperate server just for your members only section, random names for your htaccess file, and for your scripts.. only let your billing agent know where the real files are located.

Even then, there are scripts that can email/page you when bandwidth goes way beyond normal levels, so you are alerted when your bandwidth suddenly jumps to an unusually high level.

Keep your software up to date, use a tracker to monitor for advisories that are relevent to your setup. If in doubt, hire someone who knows what they are doing - they are worth their weight in gold.
__________________

[email protected]
icq: 205-252-550
bizarredollars is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-20-2006, 05:32 AM   #40
bizarredollars
Confirmed User
 
Join Date: Mar 2006
Location: bizarredollars.com
Posts: 1,582
Quote:
Originally Posted by germ
i say we stop promoting the sponsors that pay the password sharing sites.

its always aff and cams.com. they know wtf is going on, but they dont do anything about it. if other people stopped promoting them because of it, it may make them sit up and take notice that keeping one affiliate is making them lose a hell of a lot more.
Be careful with this tho.. I for one plan to setup some 'password sites', that feature only links to 'hacked' sites that I have made and host myself.. I will be exploiting the password site traffic.. and I don't want the people I am sending traffic to getting pissed off, when I am not doing anything to hurt anyone.

I will of course inform my sponsors of my plans before putting their links up.. and will mostly be sending traffic to my own sites.
__________________

[email protected]
icq: 205-252-550
bizarredollars is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-20-2006, 06:03 AM   #41
jayeff
Confirmed User
 
Join Date: May 2001
Posts: 2,944
Quote:
Originally Posted by tony404
Can we sue the sponsors for supporting people who steal?
Good question.

On content-stealing sites, "conspiracy to defraud" would apply, because breach of copyright is an established crime and the sponsors on those sites are (knowingly) profiting from the sites' activities. The practical problem in the UK (and therefore possibly in the US and elsewhere) is that this is a criminal offense and an interested party would have to convince the public prosecutor to pursue the case. Software companies have successfully gone this route, but porn operators...?

The additional issue with password sites is whether what they are doing is a criminal or a civil matter. AFAIK that hasn't been tested and given the state of this industry, I wouldn't hold your breath.

Quote:
Originally Posted by germ
i say we stop promoting the sponsors that pay the password sharing sites.
I'm in the middle of removing links to the sponsors who give TBP special discounts, but after seeing Lens' responses to the content-theft sites issue a couple of days ago, yes, when that is done I'm taking down my links to AFF and its associated sites. I have been promoting them since 1998 and I'm not under any illusion that my action, by itself, will make the slightest difference to AFF's policies. However, by promoting sponsors who support those who undermine this industry, we are also failing to back those who do work in an ethical manner. So in effect, that's score 2 for the bad guys each time we fail to act.
jayeff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2006, 09:29 AM   #42
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
Ohh noooess...
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.