![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Apr 2009
Posts: 327
|
Backdoor into Paysites!
I found a place where they explain how to access paysites for free!
It works when they got a URL from the membersection and copy paste into their browser, when the passwordbox pops up, you just click ok and you get access, they posted a list and I tried some and it's in fact possible to do so. Just wanted to bring this under your attention so you can check your sites for this backdoor.
__________________
Webcamsex Girlz I Host With AmeriNOC(Old Phatservers) Convert your BE/NL traffic: 18Pluscash ICQ: 87248392 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
useless without the list.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Apr 2009
Posts: 327
|
__________________
Webcamsex Girlz I Host With AmeriNOC(Old Phatservers) Convert your BE/NL traffic: 18Pluscash ICQ: 87248392 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
some work yeah.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Oct 2006
Posts: 1,763
|
![]() wow, not good. Just tested a few sites and was able to download full movies so its not creative marketing for sure. :\ In fact very well could rip alot of content thats getting sold currently here at gfy. Somebody is getting fired. lol |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Megan Fox's fluffer
Industry Role:
Join Date: Oct 2005
Location: shooting pool in Elysium
Posts: 24,818
|
Welcome to the interwebs.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
i don't understand how a blank username/password combo are letting people in some of those sites' members areas. anybody have an idea why that happens?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,020
|
Some work indeed. Most don't.
Platinum feeds is wide open in one link to 14 sites. Bryan better take a look at this. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
CjOverkill
Industry Role:
Join Date: Apr 2003
Location: Woldwide
Posts: 1,328
|
Quote:
Some don't even have videos at all. On some the "High Quality" videos were 480x360 ... that's not even 640x480 No wonder surfers are going to tubes. My tube sites content repository has 1500 full scenes licensed, and thats more that all these sites together, not to mention that they are not 320x240 size. At least I know what sponsors not to promote ![]()
__________________
CjOverkill Traffic Trading Script Free, secure and fast traffic trading script. Get your copy now ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,020
|
Some work indeed. Most don't.
Did you find that on exbii.com? Platinum feeds is wide open in one link to 14 sites without a user/pass. Bryan better take a look at this. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,058
|
Every one that I tried worked.
__________________
All cookies cleared! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
I am Amazing Content!
Industry Role:
Join Date: Feb 2004
Posts: 39,822
|
Quote:
and if i had to download 10 small clips to see one video i would cancel right away. very eye opening...
__________________
AmazingContent.com - providing only the best content and service since 2003 Monetize your content on Veegaz.com - one of Germanies largest VOD sites Got German traffic? We convert it into money for you! Skype: madalton02826 - Email: oltecconsult [at] gmail [dot] com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,020
|
Quote:
Some are really 1998 style and some take 9 seconds to load a video or more. CDN..use a CDN guys. Talk to your hosting companies. I googled some urls in the above .txt file and found the source. This guy posts free urls and user/passes on an Indian board just to get " reward points" for that board... Amazingly 70% still works of what he posts. Other posts on that board could have up to 10k(!) in replies and 4M(!) views. Since bandwith is expensive maybe all programs should double check their security stuff and double IP No.s on the same user/pass... I am now surfing ten.com's member area and platinumfeeds (I send Bryan a PM btw about this. People could lose LOTS of money if surfers can enter free and use up bandwith). |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
|
What's the reason that you get into some of those sites by pressing okay?
Even if ccbill closed their sites, the htaccess should still be intact.
__________________
--- ICQ 14-76-98 <-- I don't use this at all |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
Quote:
select count(*) from users where username='$username' and password='$password'; Then the pseudocode for the login/admin: .. if (count(result) > 0) ... If absolutely nothing/empty is passed, there's often an 'empty' account in there from testing or otherwise, and when it returns a valid result, they get access.
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
guess anyone can start a solo site with a couple non-exclusive pics and a couple videos huh?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
|
A couple of our sites that we're "phasing out" are in there. :/
Good thing we're switching up a lot of things in the next few weeks. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Apr 2009
Posts: 327
|
Quote:
Agreed! And that's not all they do, They post daily cracked passes to paysites too.. The faster they are deactivated, the more people get frustrated and pay to get access
__________________
Webcamsex Girlz I Host With AmeriNOC(Old Phatservers) Convert your BE/NL traffic: 18Pluscash ICQ: 87248392 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
CHECK MY SIG-AMAZING SITE
Join Date: May 2006
Location: ICQ: 210-874-419
Posts: 12,870
|
DAMN wtf is this
![]() I try few sites and it WOKS ![]()
__________________
![]() ![]() ![]() ![]() ![]() ICQ 210874419 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Feb 2005
Posts: 2,438
|
blank entries in members data?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,020
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Confirmed User
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
|
Quote:
![]() And what must be even more frustrating for them is that they can't fastforward through the movie and have to watch the whole load of crap. ![]()
__________________
--- ICQ 14-76-98 <-- I don't use this at all |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Apr 2009
Posts: 1,319
|
This is usually caused by a blank entry in the database or extra (empty) line in htaccess. Your security is complete shit if this happens on your site.
![]()
__________________
History will be kind to me for I intend to write it. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Join Date: Jul 2009
Location: In the City of Wonder
Posts: 613
|
Wow, some really pathetic members areas. No wonder sales suck.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Industry Role:
Join Date: Jan 2009
Location: EVERYWHERE
Posts: 1,541
|
Been going on for years...
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Confirmed User
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
|
You guys are dropping those sites all together or what?
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts. We will guarantee and beat your current EPC to win your dating traffic! Skype: ConversionSharks || Email: info /@/ conversionsharks.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Location: Los Angeles
Posts: 6,986
|
Wow, some great security.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Join Date: Feb 2002
Location: Third mall from the sun
Posts: 2,185
|
I checked about 5 sites and if I paid to see that crap I would never join another paysite ever again.
__________________
I was looking for a job, and then I found a job And heaven knows I'm miserable now |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
|
And people wonder why conversions are getting harder and harder? Actually giving the customer what he wants and getting him to stick around is harder than raping the fuck out of his card with cross sales when he joins I guess.
__________________
See sig... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Join The Royal Family
Join Date: Apr 2002
Posts: 25,463
|
Was thinking the same
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos. With TOP RATIO Sites like ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
We see this pretty often. Just recently, I had someone from a major program
hang up on me when I explained that his organization of files would cause this type of effect. He's rather be wide open than be told he's wrong, I guess.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Industry Role:
Join Date: Sep 2007
Location: Cheshire, UK
Posts: 454
|
I haven't checked if this works as the paysites I built don't require it, but this code should check for valid username and password and reject anyone without it:
Code:
<?php if(!$_SERVER[PHP_AUTH_USER] || !$_SERVER[PHP_AUTH_PW]) { //url to redirect to $url = "http://www.yourdomain.com"; header("Location: $url"); } ?> If anyone can verify this does help let other people know ![]()
__________________
David • 421-179-116 • support [@] adultnetworkuk [.] com
Website Development • Website Hosting • Model Index Software • Website Reviews and Links Hit me up for more information on everything I do. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Industry Pioneer
Industry Role:
Join Date: Oct 2002
Location: USA/EU/ASIA
Posts: 5,401
|
It's not a backdoor neither a CMS bug, just a problem in the .htaccess. Too bad the owners have not checked this. None of the ones mentioned are clients of ours.
Some are managed through ccbill, some are epoch's, so not sure if it is their overlooking or the sysadmins but clearly the owners should be notified in order to take action. I also agree with Raymors comment that often owners are told but dont do anything because they do not like being told they have done something wrong. ![]()
__________________
Around since 1997, and the company that introduced "Cascading Billing" in MPA3® Affiliate Management and Tracking Software ![]() Outsourcing With A Norwegian Twist - NordBits - Inquire within! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Holy shit some of those sites were last updated in 2007. Most of them worked for me
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,392
|
If you are on that list you were hacked at some point. The hack could have been remote server access like when you are SSH'ed into the server or a simpler one where you had an old ccbill, ibill, globill, etc script where someone can add a combo to the file without any kind of authentication.
On that last one, you might have a php script and an htaccess file that checks user/pass to the "admin script"... the check has: <limit get post> Which means you are only limited the get and post requests to the script... PHP doesn't care how it is called so I can craft a header with a method of V_RocKs and PHP will run it just the same... which renders your htaccess/htpasswd files useless... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Too lazy to wipe my ass
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,525
|
I blame Poppy Morgan..
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Registered User
Join Date: Jul 2009
Location: Canada
Posts: 92
|
You see a problem ... I see opportunity.
Redirect those blank fields to a page that makes them think they're in. Give them a tube site with previews and put "UPGRADE FOR ONLY $2.99" and sell a trial or something. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Quote:
the nonstandard $_SERVER[PHP_AUTH_USER], it'll work for any standard authentication method, past, present, or future. Plus it'll actually work. What's set in PHP_AUTH_USER is not necessarily a valid user name. REMOTE_USER is their authenticated user name. Also as XD2 mentioned, PHP_AUTH_USER is populated only for basic authentication, a system designed to be weak, and PHP weakens it further in the process of setting PHP_AUTH_PW. Not that a recommend jacking around with authentication at all within your content, that's the wrong place for it, but if you feel you must, use REMOTE_USER. 99% of the time if someone references PHP_AUTH_USER it's wrong and what they really want is REMOTE_USER. They may well be set differently. REMOTE_USER is their actual user name, authenticated by mod_auth, mod_auth_digest, Strongbox, ir whatever authentication you're using. PHP_AUTH_USER is whatever they set to be sent to the weakest possible authentication you could use - even if in fact you're using something much better.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
|
![]() |
![]() ![]() ![]() ![]() ![]() |