![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#201 | |
Yes that IS me. Bitch.
Industry Role:
Join Date: Nov 2001
Posts: 14,149
|
Quote:
He hasn't posted on that forum since august and then that freelance job thing in Sept. Hacker or whoever is using his name or whatever.. who fucking knows |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#202 |
Confirmed User
Join Date: Jan 2006
Location: The Valley
Posts: 7,412
|
Good luck to all parties involved in getting this matter sorted out.
__________________
-D. ICQ: 202-96-31 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#203 |
Too lazy to set a custom title
Industry Role:
Join Date: Jan 2001
Posts: 51,692
|
Did you hire a PR guy to answer all the previous questions too ?
Shit John, you're turning into a PR pro following all the rules (That's a compliment btw) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#204 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,405
|
I finally just saw where someone accused their lead programmer of being a smoking gun... Now that is funny.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#205 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Fred is the lead programmer of CARMA and NATS at TMM.
It's probably normal that admin accounts are under his name, it would be the most logical. I don't think you can conclude that it's Fred that's doing it, simply because that's the name on the admin account. As if you'd leave your full name on you own hack.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#206 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() ![]() i think that would be a bit premature of a guess as well , but its obvious his account was compromised. you would think as head programmer he might have built in some safeguard to keep his own account in check.. certainly not allowing it to login to multiple nats sponsors at the same time every few minutes and get data.
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#207 |
Confirmed User
Join Date: Jun 2006
Posts: 116
|
good to see NATS is finally doing something to fix this for everyone...
it's a bit overdue tho...
__________________
icq 236-802-704 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#208 |
aka K-Man
Industry Role:
Join Date: Oct 2001
Location: The Gutter
Posts: 29,290
|
i *may* have always been under the understanding that the processors sold off their email lists... i *may* have heard this from many webmasters that it *may* be an assumed occurence.. that's all i will say
*disclaim the above is not implying, implicating, suggesting or accusing anyone of doing anything uncuth or unlawful. the above is simply things one *may* have heard thru the 'grapevine'
__________________
Crypto HODLr Crypto mining Angel investor |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#209 |
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
Of course.
It was the lead admins account but it was not him and uhh uhh... How Convenient! If I knew that people were really that easy to pull one over on I would certainly be alot wealthier today. ROFLMAO! I mean NATS is a top notch crew it was just a glitch!
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#210 |
aka K-Man
Industry Role:
Join Date: Oct 2001
Location: The Gutter
Posts: 29,290
|
surely i cant the only one who may have hypothetically heard for years of the availablility of processor dbases for a hefty price?
__________________
Crypto HODLr Crypto mining Angel investor |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#211 | |
Making $$$$ w/ ClickCash
Industry Role:
Join Date: May 2003
Location: USA
Posts: 18,037
|
Quote:
One thing that surprised me was seeing that the guy was looking for side jobs on a rentacoder type site. I have 2 full time programmers i keep real busy. It just seemed odd to me that if he is the head guy he would have extra time on his hands to look for side jobs. Maybe I am the only one to think that but that was my opinion when i read that part.
__________________
ICQ: 86364801 Email: will [at] innovativeassets [dot] com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#212 |
Confirmed User
Join Date: Aug 2002
Location: Orlando, Florida
Posts: 2,051
|
Count me in too...
NATS was originally installed on my server in 2005. The account they created during the original install, is the one that got replaced by "Fred Schank". I won't go into details or opinions, but if i remember correctly it was a very generic username/password that was probably easily cracked. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#213 |
Too lazy to set a custom title
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,332
|
I nominate this thread for DRAMA of the year award.
__________________
ISeekGirls.com since 2005 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#214 | |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Quote:
Not everyone is a big of an arsehole as you are ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#215 |
Making $$$$ w/ ClickCash
Industry Role:
Join Date: May 2003
Location: USA
Posts: 18,037
|
2007 or 2008 ?
![]()
__________________
ICQ: 86364801 Email: will [at] innovativeassets [dot] com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#216 | |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
Quote:
![]() i can't believe so many people in this industry don't and refuse to believe that.
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#217 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
I was looking for a fake account to post under, then though what the fuck.
Here's where it stands. There are 2 scenarios: 1- Internal Job. Won't even speculate on this, I've got nothing to say. It's just an option. 2- Exploit. If it's an exploit, it'll be coming in via SQL injection attacks. I know this, because [as demonstrated] previously, NATS filtering of $_REQUEST variables has been incredibly poor. In what I've glimpsed of source code, and played with [I'm by no means a 'black hat', but I know an exploit when I see one] - they weren't even using mysql_real_escape_string for passing strings to the databases. 6-12 months ago I did a POC where I dropped an entire database by injecting the SQL through a NATS [or CARMA, can't remember] URL. I notified them via ticket. Have things improved? Not sure. So, if it's as above, it doesn't matter how good your sql restrictions are, because the SQL requests come from the localhost anyhow. It's easily conceivable that you can have full control over the database, hence the creation / deletion of accounts. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#218 |
Confirmed User
Join Date: Aug 2002
Location: Orlando, Florida
Posts: 2,051
|
3- Generic admin username/password created by installer. For example, if i remember correctly:
Username: (employee/installer name) Password: (i wont post on a public board, but also very generic) If this employee, used the same technique on several installs, i could see a problem... This could also explain why the problem is small scale. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#219 | |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Quote:
However people have pointed out in this thread that the account is reappearing after deletion. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#220 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
![]() Hit stats for a NATS sponser. 2006. Hmm. This is thin, thin 'evidence' though. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#221 | |
Too lazy to set a custom title
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,332
|
Quote:
Do you hear that? That is the sound of a company lawyering up!!! Follow the money....
__________________
ISeekGirls.com since 2005 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#222 |
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
Quantum I was being sarcastic above there fella.
I raged about some things regarding NATS I was even banned for it in the past. Do a history on John Albright here in GFY. Ya will know where I stand about all this. All I am saying now is, none of this surprises me in the least.
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#223 | |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
Quote:
so shouldn't all NATS program owners be checking their server stats now for that IP?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#224 |
Registered User
Join Date: Nov 2006
Posts: 65
|
theres no stopping this thread is there
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#225 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
If you reread the thread again, I think you'll find it's other, non-TMM IPs that are the problem.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#226 |
Confirmed User
Join Date: Apr 2003
Posts: 5,461
|
what you doing over these parts with all the yanks
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#227 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
owning a hosting company or affiliate software company would be about as stressful as it gets in this industry.
what if this isn't a hack of NATS but a new or even unknown exploit of mysql or apache - then NATS is just an innocent bystander and hosting companies are as much or more responsible?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#228 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
I'd say about 70% of the nats programs I sign up to (each with a very unique email address just for that program)... within about 3-5 weeks I start getting spam on that email address... Been mentioning it to some programs for a long time now but no one knows what to do about it... However... When I sgned up to topbucks as a member.. within 4 weeks I was getting spam on that unique email address.. processor Epoch... signed up to silvercash as a member.. within 4 weeks I was getting spam on that unique email address.. processor Epoch... I think the issue isn't just tied to 1 thing.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#229 |
Registered User
Join Date: Nov 2006
Posts: 65
|
Says u with 4000+ posts!
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#230 | |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#231 | |
Hello world!
Industry Role:
Join Date: Mar 2003
Posts: 12,508
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#232 | |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
Quote:
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#233 | |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Quote:
Furthermore, if it were a issue specific to mysql or apache then the internet itself would be ablaze with speculation about it in more than the adult affiliate sector. ...
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#234 | |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Quote:
If there is anyone that needs to think before they speak, it's you. You're sounding more of an idiot with each passing post. ...
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#235 | |
Confirmed User
Join Date: Sep 2002
Posts: 3,626
|
Quote:
![]()
__________________
...promise her a defamation, tell her where the rain will fall.. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#236 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Okay, it seems banning the account makes no difference as the person is still able to login:
67.19.188.250 - 2007-12-22 09:30:32 67.19.188.250 - 2007-12-22 03:30:31 67.19.188.250 - 2007-12-22 00:23:23 I submitted a ticket to TMM yesterday telling them I could not secure the admin via IP since i run on a dynamic IP. They said they couldn't help me till tomorrow. I said it was serious and they said if I had banned the account it would be fine. Obviously not the case. ...
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#237 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
Good luck to all
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#238 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
But then, when a program gets hacked through other means then nats, and their whole customer base with info gets stolen, and affilate data gets stolen, would they also need to issues such a statement? Informing all of the affiliates that the data might be breached and that they should change their passwords? Hmm.. Double standards? @RazorSharpe Buuuhuuu, did i burst your buble of the perfect world?
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#239 |
Confirmed User
Join Date: Oct 2002
Location: ICQ: 39-183769
Posts: 8,002
|
Change your own admin pass after you deleted the admin account used to get in (if you haven't already)
If the attacker was able to get in to gank emails etc. Chances are he has your username/pass as well. I've never used nats so I'm not sure if it's possible with the account they had but to be safe...
__________________
![]() ![]() ![]() ![]() I seo'd my hair yesterday and today it's pr7! RIP Texas Dreams ![]() Are you a content producer or program owner sick of tube sites? Contact me on ICQ: 39-183769
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#240 | |
Facit Omnia Voluntas
Industry Role:
Join Date: Apr 2003
Location: Offshore
Posts: 2,105
|
Quote:
Is it not possible to .htaccess protect the admin-area of NATS as well, as an added layer of security on top of limiting the User-IP NATS internally? Just an idea. I'm not running NATS as Admin so I wouldn't know, so this is just a suggestion.
__________________
Facilitation - BizDev - Traffic - Consulting - Marketing Skype: jokerempire | Silent Circle: joker |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#241 | |
Confirmed User
Join Date: Mar 2002
Location: Montreal Canada
Posts: 2,946
|
Quote:
__________________
![]() ~~♥~~♥~~♥~~♥~~♥~~♥~~♥~~♥~~ Patrizia COO - ♥ MassiveDollars Email: patrizia at MassiveDollars dot com ICQ: 465.826.441 Yahoo: trixxxia_me MSN: trixxxia at hotmail dot com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#242 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
No program has sent an email ever. That's the beauty. If you're at that stage that you receive email on the account, your data has already been traded. Hackers hack you and share info with their fellow hackers. Then spammers buy from hackers. So, when you start receiving spam on a dedicated email to a program, you're already few months behind the hackers.
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#243 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#244 | |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
|
Quote:
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#245 |
Confirmed User
Industry Role:
Join Date: May 2004
Posts: 6,659
|
The amount of wrong information, assumptions, and completely wrong accusations here is astounding.
This will be my last post in this thread and possibly on this board. I am tired of people running around saying whatever they want and there being no repercussions for it. It is ridiculous and I'm not going to sit here and argue with them. This fully appears to be a compromised password list. It is not an "exploit" in the software. It is not Fred spamming your members, etc. We have changed our policy so that we no longer maintain ANY passwords to ensure this does not happen via us ever in the future. We are also continuing to implement other protective measures. Those of you who have actual valid feedback and comments I appreciate them. Anyone is welcome to contact us regarding this with their questions or concerns and we will be further communicating directly with our clients about it. However as to dealing with the people who make their living making things up about other people, I'm done here.
__________________
![]() Skype: JohnA1078 Too Much Media - Makers of the Industry's Leading Payite Management Platform, NATS! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#246 |
Confirmed User
Industry Role:
Join Date: Feb 2005
Location: the 805
Posts: 4,290
|
Yep, threatened to sue me, and thats really all i am going to say here. OC3 has done a lot of work to help resolve this issue for our clients but our clients deserve most of the credit for helping us to find the problem. And for the record, when john said to me " I need yours and OC3's lawyers info, I twice told him that my cell number is in the thread about the issue, and invited him to call me. He never did.
__________________
Caz Thrush Head Honcho [email protected] http://thrushtech.com ICQ: 304883574 do people still icq? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#247 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Posts: 1,610
|
Just a simple statement that my momma taught me along time ago
Why does the farmer let the fox fix the whole in the fence? Im not IMPLYING ANYTHING here guys .... Just looking at the POSSIBILITY not any facts here at all and john why is it immediatly blame on all your customers servers and no blame at all on yourself? Im just looking at all this here and I see alot of people having a problem INCLUDING US ....... And im seeing you blaming us and our servers/hosting its easy to point a finger..... ANYWAYS THAT IS ALL I HAVE TO SAY.... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#248 | |
Registered User
Join Date: Nov 2006
Posts: 65
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#249 | ||
Hello world!
Industry Role:
Join Date: Mar 2003
Posts: 12,508
|
Quote:
Quickbuck uses Nats and they said this? wtf |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#250 | |
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |