![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#301 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
it is totally possible to take the concept of security way too far and thus make normal workings of any software totally unusable. Where do you stop? I'm sure you've patched plenty of apache or mysql installs after hearing of vulnerabilities via security newsgroups or mailinglists or are you the type that finds all of them on your own? Don't treat your mind to illusions of its own grandeur ladida, it is making you seem rather foolish.
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#302 | |
Confirmed User
Join Date: Sep 2003
Location: Los Angeles
Posts: 3,343
|
Quote:
![]()
__________________
HomemadeCash.com - Homemade & GF sites powered by NScash.com HomemadeVideoPass.com - The only all homemade mega site OurHomemadePorno.com - Real couples fucking on camera Contact ICQ: 400-786-531 Email: fade AT nscash.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#303 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
what holiday?
![]()
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#304 | |
Confirmed User
Industry Role:
Join Date: Jan 2006
Posts: 689
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#305 | |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Quote:
I have no false impressions about software but I do expect that when I pay for a software such as NATS and the developers of the software are aware of an issue that they will make it a priority to investigate the issue and make their clients aware of it and what they intend to do about it. I'm sure you can understand how i don't feel like this is too much to ask for. This vulnerability specifically targetted the NATS staff admin account and no others, as far as i can tell, which leads me to assume that it wasn't a brute force attack and if it were it was done because the nats staff account used the same username across multiple nats installations which is a total no-no in security 101 in and of itself.
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#306 |
Confirmed User
Join Date: May 2002
Location: Paying Webmasters Millions Since 1999
Posts: 4,044
|
People, keep in mind that the only admin account that has been compromised is the TMM admin account. For god's sake, delete this account immediately.
This breach would also explain the multiple waves of compromised user passwords that we have seen. User passwords are easy to see in NATS, affiliate passwords are not. My members area security software has reported dozens of compromised passwords logging in within less than 5 minutes. This only happens when there is a compiled list of valid passwords, not from passwords obtained by brute force. After over 20 hours, I finally got a response to my trouble ticket: TMM (3:55 PM): I'm sorry and it look like I have to get you an full upgrade to have this new feature TMM (3:56 PM): and we are currently develope on better security system on NATS and there will be release on Monday hopfully TMM (3:58 PM): can we do the update on Monday instead? Dirty D (3:59 PM): Keep in mind we are one of the MANY programs that the TMM admin login was compromised. Before I get pissed off, let me get this straight and make sure I understand. #1. The IP Log feature won't work until the next release comes out... maybe monday #2. NATS will not log the admin login info to a log file and the ONLY way to get admin login information is for me to WRITE A SCRIPT to accept a POST with info from NATS using these undocumented variables xxxxxx , xxxxxxx, xxxxxxxx, xxxxxxxx, xxxxxxx #3. Nothing has been accomplished to resolve this Trouble Ticket TMM (4:05 PM): #1 yes, we are currently develope on the security script on will try to get relase as soon as possble. #2 Currently no, but I will add this to the feature request. #3 I'm sorry about this, we are wokring on the relase, and will let you know as soon as it is ready. TMM (4:11 PM): I'm sorry for any inconvenience that cause on this issue, please change the ssh password and disable the nats admin login, one of us will contact you as soon as the new release is ready.
__________________
![]() Dirty D - ICQ #1326843 - $1 Million Dollars of Bonus Money - 8,000+ FHG! Glory Hole Girlz - Crack Whore Confessions - Tampa Bukkake - Slut Wife Training - Fuck a Fan Electricity Play - Porn Video Drive - Theater Sluts - Skunk Riley - Ukraine Amateurs - Strapon Sessions |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#307 |
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
WTF? They outsourcing to Russian programmers or something?
Thats some serious broken english. And certainly not the brightest of decisions.
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#308 |
So Fucking Banned
Join Date: Jul 2003
Posts: 1,623
|
Holy shit, this is huge
Imagine how much data was stolen through this NATS fuck up ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#309 | |
So Fucking Banned
Join Date: Jul 2003
Posts: 1,623
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#310 |
So Fucking Banned
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#311 | |
in a van by the river
Industry Role:
Join Date: May 2003
Posts: 76,806
|
Quote:
Real good choice you are taking there, ignoring not only the companies whom use your product, but also the affiliates whom promote those companies. So first we had pornograph fiasco and now this.. What was that old saying? Fool me once shame on me... Fool me twice??? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#312 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Actually the first time I have laughed at anything you've said.
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#313 | |
So Fucking Banned
Join Date: May 2006
Location: Seems To Be Here Now
Posts: 646
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#314 |
So Fucking Banned
Join Date: May 2006
Location: Seems To Be Here Now
Posts: 646
|
this thread should be a sticky.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#315 | |
Confirmed User
Industry Role:
Join Date: May 2004
Posts: 6,659
|
Quote:
__________________
![]() Skype: JohnA1078 Too Much Media - Makers of the Industry's Leading Payite Management Platform, NATS! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#316 | |
So Fucking Banned
Join Date: Jul 2003
Posts: 1,623
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#317 | |
So Fucking Banned
Join Date: May 2006
Location: Seems To Be Here Now
Posts: 646
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#318 |
So Fucking Banned
Join Date: May 2006
Location: Seems To Be Here Now
Posts: 646
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#319 |
Confirmed User
Industry Role:
Join Date: Nov 2007
Posts: 105
|
heres a band aid solution for those who have dynamic ips and absolutely cant 'lock down' their admins to a specific ip... at least until the problem is resolved fully.
have your coder code up a small script: w w w . d o m a i n . c o m /somesecretfile.php?key=somesecretkey if the key is correct have it make the changes to allow the ip accessing the script to log into admin. should take him about 15 minutes to code. and security wise, even if someone found this file AND your key it wouldn't be a major compromise... all it would do is allow his ip to enter admin, nothing more... they would still need the password of course. ciao. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#320 |
web
Join Date: Dec 2001
Location: On icq: 85-483-060
Posts: 9,533
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#321 |
So Fucking Banned
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#322 |
Marketing & Strategy
Industry Role:
Join Date: Jun 2001
Location: Former nomad
Posts: 14,293
|
__________________
Whitehat is for chumps If you don't do it, somebody else will - true story!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#323 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Here's the important question. Literally hundreds of people have evidence that they have had data stolen electronically.
When are the authorities contacted? When does the cyber crime unit step into this? If this is as big as it seems, action needs to be taken. There's no shortage of cash or backing to get this solved. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#324 | |
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
Quote:
The Bro squad is on the way to spin it, and this chapter will be swept under the carpet just like all the other dirty secrets in online adult. Merry Xmas Chumps you all got robbed.
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#325 |
Confirmed User
Join Date: Feb 2004
Location: Swamp
Posts: 5,201
|
This was definitely a breach on the NATS side as far as I can tell. All the programs I have talked to have had Fred's usernames be completely different from one another. This leads me to believe they kept a log/record of all user/passes on their side of things that got hacked/exploited/leaked/shared you take your pick of what happened.
If everyone getting exploited was being used by the same user/pass of an admin that would be one thing, but having them be so random and different from program to program shows quite clearly where the first issue started. We are lucky we host at swiftwill and have ip protection in place. Though Fred was able to login, we show zero evidence he was able to log into the actual admin since he was not allowed via ip protection. The only parts he was able to access was like an affiliate could, the ad tools and link codes. So for hosts like Swiftwill and others like it that demand IP protection on Nats, that is a positive. For others that don't require it, this is a major issue of all the data that could have been collected over the min 6 months this has been an issue based on the various evidence in this thread.
__________________
XXXRewards - Karups - Boyfun - Jawked. Paying on time since 1997. Contact me at brent [at] xxxrewards.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#326 | |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,405
|
Quote:
Move along novice. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#327 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,405
|
IP RESTRICTION...
But my IP address changes.... Bullshit. You make enough money to call your provider and request a PERMANENT one. But they don't provide one. What the fuck? Are you on Dialup because most Cable, DSL, Broadband providers WILL give you a permanent IP if you pay monthly for leasing. Usually $20. Consider it a cost of doing business and a tax write off. OK... But I AM ON DIALUP! So pay an admin here to setup a proxy on a dedicated server with a NON-ADULT hosting company picked at random. Have that proxy password protected. Case closed... The fact that a village idiot can get into this industry if he has $100,000 in inheritance money frightens me. It frightens me because when it comes to security you are all village idiots! Every last one of you! 90% of you have hackers on your boxes because they hacked your forum, your support system, your webcam software or by some other means. You don't know because all the hacker wants is your password DB and not the Emails. They trade those DB's like Pokemon cards. They give 1 account away to each person who asks for them on newsgroups and IRC channels. It NEVER trips your strongbox, pennywize, proxy pass, etc, because they give each requester a different account. So even if the real user and the fake one use it at the same time they fall with in the AOL threshold (5 IP's in 15 minutes). You all think.. Impossible because those previously mentioned programs shut this kinda shit down! No... They don't... Because each request gets a different account. This isn't password boards where 15,000 people get the same account. This is the designer version where everyone gets their own unique, free account. But bandwidth is so cheap I don't give a fuck!... I know.. But in one channel on the IRC alone you will have up to 1000 people receive a password in a day. You are pissing away $35,000 a day! Smaller programs a few thousand... Industry wide? About $800,000,000 a year is just pissed away... OK.. Back to your original programming where you just bury your heads in the sand. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#328 | |
Confirmed User
Industry Role:
Join Date: Sep 2001
Location: North America
Posts: 2,016
|
Quote:
Oh, and yes... you are the king. Whatever. I clicked your sig.
__________________
"There he goes. One of God's own prototypes. A high-powered mutant of some kind never even considered for mass production. Too weird to live, and too rare to die." -Hunter S. Thompson |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#329 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#330 | |
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
Quote:
http://www.alexa.com/data/details/tr...3y&size=Medium Saw it posted on another board. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#331 | |
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
This was sent to me last night and I was asked to post it without naming the source. I have no time to investigate it as I'm off out after checking the site.
Please draw your own conclusions from it. Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#332 | |
Confirmed User
Industry Role:
Join Date: May 2004
Posts: 6,659
|
Quote:
You're on my do not argue list and I'm heading to sleep anyway. Think as you wish, you always do.
__________________
![]() Skype: JohnA1078 Too Much Media - Makers of the Industry's Leading Payite Management Platform, NATS! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#333 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
Guess some people do realise how it is, but those are the same people that have either worked in security, or have had their boxes used as toys by hackers and have been awaken by the sad truth that their box is banned by google, listed on every blacklist known to man for spamming, their members sending 100 complaints, their databases beeing erased and indexes overwritten by kids etc etc. Then they realise that if it's at the point that your database is erased, the person that erased is not the hacker, hacker got in a long time ago. It's now to the point that he sold the access to turkish or who knows wannabes. Still long till time comes when people here take security seriously since so few understand it.
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#334 |
Too lazy to set a custom title
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
|
Just curious. Did you have the SAME user/pass for EVERY program?
I mean, that would be REALLY bad..... Also, if the 'hacker' had/had full admin access. He might have created a 2nd user with access to the affiliate info...Better check out ALL users with more access than a normal affiliate
__________________
Questions? ICQ: 125184542 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#335 | |
Confirmed User
Join Date: Sep 2002
Posts: 3,626
|
Quote:
i'm going to go dig back and see when this trend started, but i cant help but wonder if this is tied to when NATS and Segpay started their incestuous relationship, as i had never seen this kind if account compromising over the past 8 years, not so many simultaneously and then suddenly stoppping in a single wave. sounds way too close to what you describe above, *way* too close to me..
__________________
...promise her a defamation, tell her where the rain will fall.. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#336 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
it is not only nats there are public dumps of generated passwords from other programs and systems also, adult security experts are step behind hackers
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#337 |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Charleston, SC
Posts: 2,468
|
WOW this post got BIG fast.. Left it on Saturday on the first page, just read the rest now..
__________________
http://www.3dsex.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#338 |
Confirmed User
Join Date: Dec 2007
Location: Earth Planet
Posts: 213
|
popular topic, what you want.
we want to switch, so now we this twicely. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |