![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Feb 2005
Location: WORLDW!DE
Posts: 724
|
![]() When you think someone has shared a password, do you email the person first and ask about the issue or do you just terminate him/her? I have strongbox and I can tell when a member has many different IPs have accessed the site. Some I have let slid, others I have flat out terminated. It depends on how I'm feeling that day. However, I really don't want to lose their business as these people could keep rebilling for 6 months as far as I know. Also, I know many of these people use the same login info on multiple sites, so haxorz can access sites using their info without the member knowing. So, what to do?
Thanks in advance! Eric |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Workin With The Devil
Industry Role:
Join Date: Oct 2004
Location: West Bloomfield, MI
Posts: 51,532
|
I let proxxypass block them for 10 days, if they email me and ask why they can't access we tell them why and ask them to change there un and pw, if it gets hacked again after then we know there sharing and leave them blocked
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
|
How many IPS per day - per week?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Sep 2002
Posts: 1,882
|
We use software to handle that as well.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Feb 2005
Location: WORLDW!DE
Posts: 724
|
Cool. Thanks. I'll let them know they need to change their username and password and keep an eye on them after that. It varies on the ISPs.. 3-10 in a week or day.
What about the issue of charge backs? Do you refund or have you not had a chargeback issue with password sharing people? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Feb 2001
Posts: 1,690
|
We just let iprotect do its job. If only a few people are sharing, it would still be worth it to me to keep getting the rebill.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() They are blocked as soon as they show up from different IP blocks. The system auto blocks them, and changes their password.
If it happens again, they then have to call or write and ask, "what up" personally. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Registered User
Join Date: Jan 2006
Posts: 44
|
I let proxypass block them too
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
proxypass, when 3ips are logged, block for 24hours, change pass to some d5FGfds1va6 and email to member, if it will continue do this three times and then say sorry to him cause his email or computer is hacked and that can be danger for your or your members security
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Sep 2006
Location: Ukraine/USA
Posts: 176
|
I think that banning paid members is a bad idea. First of all, the same person can log in from home, then from work, then from laptop via wi-fi. If you want, you can ban these members automatically. As a result, your site's reputation will fall down, and there will be someone why may post messages on various forums and blogs that you are scam. I think that notifying these members by email about changing and not sharing their passwords is the best solution.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Apr 2003
Posts: 6,023
|
If they bandwidth-suck, its termination time.
And don't let them tell you, "I'll be baaack" or let them convince you that you have to "Come with me if you want to live." Termination. T-1000 style. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Die With Your Boots On
Join Date: Oct 2003
Location: Hawaii
Posts: 22,872
|
Quote:
![]()
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Sep 2002
Posts: 1,065
|
If it walks like a duck and talks like a duck its probably not a chicken ...
If someone is just logging in from multiple ip's the downloads should be random, sporadic and average ... if a password has been shared or hacked you'll notice different movement in that account. I'm not sure if pennywize is still available for lease but it has a download counter for each user/pass that shows you who has downloaded what. Its not hard to spot the cheats if you have the right data. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
I use strongbox.. I check my logins all the time. With password leaks I first make sure the account should still be active (that does happen). If it's a leak I change the password and email the member a simply email that says we changed the password, and here is the new login details.
If the account re-leaks (very low %) and the account is a fresh cancel, I kill the access. If it's an old account I select a new hard password, from here if a re-leak happens again I cancel and close the account. I check all failed password logins, and email the member a notice on why they are having login problems. I email 80% to the 20% that ask for help. From here I check every login that takes place, since I can see every country/ip, anyone that has more than 2 logins from a different country/isp/ip I email a new password.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Registered User
Join Date: Feb 2003
Location: HeLL
Posts: 75
|
i just change the password to there street address on file if they think ya know where they live they aint likely to do any shit
email them with a nice email saying ya password was changed for security reasons blah blah
__________________
........ FuCkEn DiE -I- |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Join Date: Feb 2005
Location: WORLDW!DE
Posts: 724
|
Quote:
![]() I have a new password for the members. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,243
|
You can spend a lot of time looking for password share'ers..
They get a email after they get blocked to change it..after the third time and warnings..we ban them!
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Mar 2003
Location: www.footfetishsponsors.com
Posts: 1,319
|
it depends on how much they downloaded, how different their IPs are and also if the customer is and old one and might come back or rebill.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
I'd re-enable the user can change the password only, not the user name, once
and email them the new password, telling them to be sure to keep it safe. If the new password gets out on the password sites I'd probably cancel them. I might give them one more chance. If a total of three different passwords of theirs get out I'd figure they were giving it out and get rid of them. One thing to be aware of, though, is password file ripping. If a LOT of passwords get out at about the same time, a cracker probably found a hole in some PHP script and downloaded your whole password file. That happens a lot if you use the old DES encryption that was for so long the standard way to encrypt passwords. That's not the user's fault, of course. In that case I'd upgrade the encryption, which we can help you with, and assign new passwords to the affected users. Normally I wouldn't change someone's user name, only their password, so it's easy to see later if the same users password keeps getting out.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |