![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
k, my paysite security is breached, need help! $$
k, I have proxypass installed, have SQL Auth/htaccess and for over 6 months I have never had a pass shared, traffic to my member section is always where it should be, no spikes on the leased feeds, over the last couple days traffic has skyrocketed, can't find my site listed on password sharing sites, and even if it was proxypass woulda shut em down.
So I'm thinking I'm dealing with someone who is spoofing something to get in and send all his surfers through, but I'm not technical enough to figure it out, host is clueless and I'm eating 12x the normal bandwidth I should be. Can someone gimme a clue, point me in the right direction, anything?
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
So Fucking Banned
Join Date: Aug 2003
Location: ICQ #23642053
Posts: 19,593
|
Can't you see which IP(s) is(are) causing the spike? Can't you then associate that with a customer's account?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
well yes, if any more than 3 IP's uses a login they are automatically blocked by ProxyPass, so this is something else.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
So Fucking Banned
Join Date: Aug 2003
Location: ICQ #23642053
Posts: 19,593
|
But a jerk with a website could be running a proxy, logging in through the proxy, and umpteen users could be going through his website, through his proxy, and into your members area. It would only show the IP of the proxy. That's why I ask if there's any particular IP producing a lot of the activity. Can you check your logs?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Purveyor, Fine Asian Porn
Industry Role:
Join Date: Jul 2004
Location: San Francisco Bay Area
Posts: 38,323
|
Try putting a limit on bandwidth per IP address until you detect the offender. Set it high at first then start ratcheting it down and you should find him.
Other people more technical than I am should have other solutions too (so bump for that). Surprised that your ISP can't help more... Good luck, ADG Webmaster |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
hmmm.. I can't tell, I have access to apache server status, it all looks like normal http traffic
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
So Fucking Banned
Join Date: Aug 2003
Location: ICQ #23642053
Posts: 19,593
|
Can you see in your stats the referring URL?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Dec 2006
Posts: 127
|
I guess your system admin should look into your log files
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
nope, no reffering url is sending the traffic, it's like a ghost is in my paysite area eating up 12x the bandwidth it should
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Nov 2006
Posts: 1,090
|
I added you to ICQ. I think I know what your problem is. I ran into this same problem about a year ago with a customer of mine.
Get in touch with me ASAP, because it'll get worse if you don't deal with it trust me. Once someone finds out it works, it'll spread like crazy.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Not sure if you were looking for suggestions for other software but I really like Strongboxxx.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Jul 2002
Posts: 3,869
|
if you have a managed server then I would switch, because if a host can't figure something like this out it's kind of fucked up and they are probably just some reseller without expertise in actual server administration
__________________
Blog Themes, TGP Design, Writing Services, Grunt Work ICQ: 66871495 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
Quote:
![]()
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
they are friends of mine, so I'm not naming names.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Phoenix, Az
Posts: 3,112
|
how do you know your "security is breached"?
there are other ways to make your bandwidth go up, one is somoene could be hotlinking your images, they could be hotlinking a single large file in an attempt to screw with you. lots of reasons for this, check your log analyzer... you do have a log analyzer program correct? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
8.8.8.8
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
|
Quote:
or the host simply doesnt care or have the time
__________________
TAEMDLRMSKRJIXMRLSMRJ. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
Also I see the traffic going to my leased plugins, so they are in there surfing, not hotlinking, hotlinks woulda showed up easy
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Troll Patrol
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
|
Most likely getting spoofed, what is the site that is being exploited?
__________________
"WTF, on google you can find the answer to every question in human history, EXCEPT how to convert cams..
Its crazy..." VenusBlogger |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Phoenix, Az
Posts: 3,112
|
you would think this would show up easy as well...
what log analyzer are you using? wusage ? Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
www.RevengeTV.com I got bandwidth download limits on (thanks PHP-CODER-FOR-HIRE), doesn't catch it, IP traps, nothing, I'm done for the night, 5am here.. but I need some more help.. this is a good one.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
http://www.ya-moon.com/start.asp it's japanese, but the word "revenge" shows up, but when you click anything you get some sort of message, which I assume is a "you must login" message, so I have no clue. ![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
You people are clueless. Managed or not managed, host in these cases can do jack shit. It's obvious none of you dealt with hacking before..
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Join Date: Nov 2005
Location: Seattle, WA
Posts: 510
|
You may want to remove the empty login & password from your passlist... i can just log right in with nothing -> thus why its not showing in proxypass i bet.
__________________
ICQ: 275335837 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Join Date: May 2006
Posts: 2,640
|
I tried to login with nothing.. can't get in though
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
gleem, feel free to hit me up on icq when you get back 157717888 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2006
Location: NY
Posts: 14,800
|
bump for help
__________________
$$$$$ MAKE HUGE MONEY IN CAMS - CLICK HERE $$$$$ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Join Date: Jun 2005
Posts: 1,786
|
nice site you have there, hope someone can help you out
__________________
http://www.highsociety.com http://www.playgirl.com http://www.cheri.com Jonathan "JC" Maldini ICQ: 223 643 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Haha.. don't be offended. I see you're flying hosting company in your sig, so that's probably why, but it's just how it is. Hosting companies are clueless. Which paysites host with you?
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
And yes the company I'm flying the sig for its one of them beeing run by hardcore sysadmins which over the years dealt with sites like ogrish,score-cash,webcams,spookycash,ebaumsworld and the list could go on. I'm also sure that companies like national-net,techiemedia, etc... know their shit as well. So your generalization its a bit biased. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
Anyway, which paysites does the company you're supporting currently host? I'd like to check something for you and educate you.
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
what type of firewall are you running? if it's anything decent like pf, then ask your host to look into the packet filter logs to see where the bandwidth is going.
Also get ntop installed asap - that'll tell you where all the traffic is going. If you need further help, hit me up on icq
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
I'm far from clueless, but fortunately I don't have to prove that to some nobody on a message board.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
sorry - forgot to include a link: nTOP
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
As i guessed. GG
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Just shows how clueless you are.
![]()
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
Confirmed User
Join Date: Nov 2006
Posts: 355
|
Parse the server logs and install additional logging, so you can track down the offending user.
__________________
![]() All the wallpapers you ever want http://www.wallpapers18.com And some cash to be made http://www.bucks18.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
well it sounds like you're just being spoofed via one of the leased plugins - how any plugin companies are still using referer method is beyond me.
are you seeing a spike in the numbers of your own files in the members area being downloaded? if not then no doubt it's just simple spoofing to get into the plugins. whick company leases these feeds http://www.revengetv.com/chop1/index2.php ?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
12x the normal bandwidth for the leased feeds or your own bandwidth?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
ok, turns out it was a " : " in the middle of the htaccess file that was indeed allowing anyone who entered blank u/p twice in.. so they never showed up as a user and it was all different IP's getting in not a proxy so it looked like legit traffic.
No the " : " wasn't there before in my htaccess, and I hadn't touched that file in months, the file had proper permissions, was like the server or someone else stuck it in there.. Sometimes I hate this biz, then again, it turns out to be something this simple that causes hours of frustration. crazy
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Thanks to "PHP-CODER-FOR-HIRE" for trouble shooting this for me for like 5 hours too!
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 |
Show Yer Tits!
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
|
Glad you got it all firgured out.
__________________
![]() Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
actually it was a " : " user inserted into my htpasswd file by paycom back before June 23rd since it created a backup of my htpasswd file automatically and that was the time stamp of the backup.
my brain is gonna explode...
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Phoenix, Az
Posts: 3,112
|
hlad you got it going... I was going to suggest the last ditch effor of manually looking though your log files to see if you can spot something strange.
If I have a problem, thats where I go... but now that all those people no longer have access you should keep that traffic by sending them to your join page, set your 401 error to go to a page, I made this one for people who do not have a valid password http://www.landofvenus.com/401.html .. converts great for me. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 |
Confirmed User
Join Date: Aug 2003
Location: Portland, Oregon
Posts: 4,541
|
![]() I don't mean to downplay anyone's efforts here; and I'm glad to hear this was taken care of however this should've taken your host or sysadmin much less than a half an hour to figgure out.
__________________
Real. Professional. Hosting. .:Expect Nothing Less:. 320-078-843 :: www.realprohosting.com :: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 |
making it rain
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,013
|
A couple of people have come to me this week and it turned out to be the same thing... I'm wondering if someone has figured out how to exploit paycoms postback system to add these.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
If it was an exploit someone figured out they did it to my file back in June, cause at the end of June I switched to SQL auth system and haven't used their postback since, 6/23 was the date that file was updated. guess I left the htpasswd file active cause it had a few members on it that were still active. anyways, if you have a "bandwidth ghost" in your members area and you can't pin it to any one login or IP address, look for user " : " in your htpasswd file! ![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 | |
Confirmed User
Industry Role:
Join Date: Nov 2006
Posts: 1,090
|
Quote:
On top of that, this was a server I had never logged into before, so going into someone else's territory isn't quite the same as if I'd been using the system for months and knew the workings of the entire thing. Thanks for the insult, though.
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |