Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-25-2010, 01:38 PM   #1
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
OTHER BOARDS STEALING PASSWORDS: (read important)

There is a board out there VERY similar to this i am not going to mention names until i am 100% sure. lets say VERY VERY similar.

i tried to log in accidentally using my GFY password. the mod or admin from that board then proceeded to use my password to log into my GFY account and post as me.

i guess it is their policy to steal their users passwords and post as them.

i want to give you people the heads up and make sure you do not make the same mistake i did.

i emailed eric to see if he can match any IPs i will let you know what comes of it.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:06 PM   #2
JFK
FUBAR the ORIGINATOR
 
JFK's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: FUBARLAND
Posts: 67,374
it would be pretty LOW of them to do such thing
__________________

FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX
For promo opps contact jfk at fubarwebmasters dot com
JFK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:07 PM   #3
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
:2cents

Quote:
Originally Posted by JFK View Post
it would be pretty LOW of them to do such thing
Yes it would.

However, I can think of a few boards that could have done it.

Mental note to self, change all passwords.
__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:11 PM   #4
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
jez that is sick
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:14 PM   #5
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by JFK View Post
it would be pretty LOW of them to do such thing
yep. some people dont like me i understand that. i try to make people laugh and joke around but some people take boards very seriously.

i dish it and take it.

i would never go out of my way to actually harm someone that is not my style.

i know it is them because that is the only other place i have typed that password. i got an error message of 1 out of 5 tries. thus i know that vbulletin stores the log in attempts. so it was a mod from over there.

not to mention posters from this board were saying a nickname on their was a fake nic of mine. i have no need to use a fake nic i am always upfront. i have no need to hide. i guess they are cowards and do.

Quote:
Originally Posted by Barefootsies View Post
Yes it would.

However, I can think of a few boards that could have done it.

Mental note to self, change all passwords.
yep i never even thought of it before i am pretty good at keeping my passwords separate but i slipped up. i guess thats the way these people conduct business. you go to check out their board and they end up using your password against you.

i had to go through and change 10 log ins just incase.

----

i am waiting for eric to respond i already know who it is but i dont want to point fingers until i have 100% proof.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:22 PM   #6
digitaldivas
..I Heart Cannibal Corpse
 
digitaldivas's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: California
Posts: 4,328
Goddamn Motherfuckers, Please post when you get proof. I am on too many other boards. And that would pretty much fucking blow. And if you get the IP, they are already fucked.
__________________
...
digitaldivas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:24 PM   #7
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by digitaldivas View Post
Goddamn Motherfuckers, Please post when you get proof. I am on too many other boards. And that would pretty much fucking blow. And if you get the IP, they are already fucked.
Eric should have the IP i only emailed 15min ago i know he is very busy so i am waiting patiently.

I am in DC now so lets see if these guys were even smart enough to use a different IP. i am guessing not.

i caught it within 2min of it happening. they already posted as me and i caught it and edited. Vbulletin tracks IP login attempts as far as i know.

watch your passwords. i literally never even thought of this. but i guess when you deal with scum you cant expect anything less.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:28 PM   #8
danclips
Confirmed User
 
danclips's Avatar
 
Industry Role:
Join Date: Feb 2007
Location: Philadelphia pa!
Posts: 212
parked sig. Keep us posted, please.
__________________
Hotmovies and Clips.com affiliate programs!
icq: 241-169-479
[email protected]
800-500-2547
danclips is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:29 PM   #9
digitaldivas
..I Heart Cannibal Corpse
 
digitaldivas's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: California
Posts: 4,328
Yes Vbulletin does indeed track IP, if the Mod has it set as a "catch all" in his or her admin panel and redirects to his or hers database. It is clicked to "on" as a default.
__________________
...
digitaldivas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:31 PM   #10
2MuchMark
Videochat Solutions
 
2MuchMark's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Canada
Posts: 49,249
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
__________________

Custom Coding | Videochat Solutions | Age Verification | IT Help & Support
www.2Much.net
2MuchMark is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:31 PM   #11
security_man
So Fucking Banned
 
Join Date: Apr 2004
Location: Texas
Posts: 190
vb, phpbb, smf, every board is storing crypted password. owner of any board can not see your password, only its hash in sql db. if they want, they may use proggie to decrypt your hash, and if you have password 12345 its not that hard
security_man is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:32 PM   #12
spazlabz
Confirmed User
 
spazlabz's Avatar
 
Industry Role:
Join Date: Jul 2003
Location: Kentucky
Posts: 6,548
yes please, when you get proof out these people. I want to make sure that I never do business with anyone that would do or allow that type of behavior


spaz
spazlabz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:39 PM   #13
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by ********** View Post
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
how about the owner of the board? i am sure there is a way for them to see your password. even so it was not from my pass on that board. it was from a failed login attempt.

Quote:
Originally Posted by security_man View Post
vb, phpbb, smf, every board is storing crypted password. owner of any board can not see your password, only its hash in sql db. if they want, they may use proggie to decrypt your hash, and if you have password 12345 its not that hard
is was not a 12345, it is a combo of letters that only someone who knew it would be able to use it. the chances of even brute forcing my GFY pass vbulletin has protection.

and my computer is not hacked. i bought it 4 days ago.

i know it was them. i logged in with wrong info lastnight on this board. it was not my stored password on there. it was a FAILED LOGIN ATTEMPT.

i tried 3-4 different passes. i am pretty sure vbulletin stores the failed attempts. including which ip address it was from.

Last edited by MetaMan; 01-25-2010 at 02:40 PM..
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:40 PM   #14
shimmy2
Confirmed User
 
shimmy2's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Dominican Republic
Posts: 3,251
i at least hope they kept ur sig intact when they impersonate you seriously some folks have too much idle time on their hands to dabble in stuff like that. i have 3 computers running ftp, videocharge, and premiere at the same time and even when i leave the house or sleep there is always something processing on one of them. it amazes me who has time for these games
__________________
Make $$$ with Toticos.com! | Email: 1bluemiata@gmail | Joutube: ShimmyCash | Faceberg: ShimmyCash
shimmy2 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:43 PM   #15
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by spazlabz View Post
yes please, when you get proof out these people. I want to make sure that I never do business with anyone that would do or allow that type of behavior


spaz
i will let everyone know. i am waiting to see if the IP matches a GFY user.

Quote:
Originally Posted by shimmy2 View Post
i at least hope they kept ur sig intact when they impersonate you seriously some folks have too much idle time on their hands to dabble in stuff like that. i have 3 computers running ftp, videocharge, and premiere at the same time and even when i leave the house or sleep there is always something processing on one of them. it amazes me who has time for these games
they did not keep anything intact they changed my info. avatar, city and posted as me. i just happened to catch each within the same minute and changed it back.

if they were smart they would have changed my pass first but i guess they are to big of idiots for that.

it may be funny to them but imo if you go and post on another board and they steal your pass it shows what extreme scum they are. if they are willing to use something as trusted as a password it shows me they are capable of doing anything.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:43 PM   #16
WiredGuy
Pounding Googlebot
 
Industry Role:
Join Date: Aug 2002
Location: Canada
Posts: 34,479
Quote:
Originally Posted by ********** View Post
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
I'm pretty sure this is in fact the case. I don't think admins can see the passwords, just change them.
WG
__________________
I play with Google.
WiredGuy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:47 PM   #17
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by WiredGuy View Post
I'm pretty sure this is in fact the case. I don't think admins can see the passwords, just change them.
WG
i should have been more clear in the original post.

this was NOT my password on the site.

it was a failed login attempt. you get 5 log in attempts and i am pretty sure vbulletin stores each FAILED attempt.

look i am not a rookie i know it was them it is just whether or not i can prove it. if i cannot so be it. at least i have peace of mind knowing it was them.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:52 PM   #18
Tjeezers
Webmaster
 
Tjeezers's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: BP4L - NL/RO
Posts: 16,572
where is the post that this dude made?
i`m curious how he made use of this, with what idea in mind he did this?

Lot of GFY users use a same postings name elsewhere and i am pretty pretty pretty sure a lot of passes are the same also.
__________________
Enroll in the SWAG Affiliate Asian Live Cam Program and get 9 free quality linkbacks from my network!
Wanna see how old school I am? Look at this! All my Cam Review Sites are here!
Tjeezers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:54 PM   #19
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by Tjeezers View Post
where is the post that this dude made?
i`m curious how he made use of this, with what idea in mind he did this?

Lot of GFY users use a same postings name elsewhere and i am pretty pretty pretty sure a lot of passes are the same also.
http://www.gfy.com/16781575-post28.html

this was the post. i edited it out, i reloaded the page and my info was changed. so around a minute before that the post was made and i still had enough time to edit.

---------

just got an email from eric no ip matches found. not much i can do. i appreciate the response anyway. just be careful people is all i am saying. this has taught me a lesson to be careful with my passwords.

Last edited by MetaMan; 01-25-2010 at 02:55 PM..
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:54 PM   #20
digitaldivas
..I Heart Cannibal Corpse
 
digitaldivas's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: California
Posts: 4,328
Jesus guys, really?
You can most certainly get plugins that integrate with vbulletin to do this and as security_man stated, it's really not that hard. Oh... you want examples? Well here ya go.

if (is_object($vbulletin->session) AND intval($vbulletin->session->vars['loggedin']) == 2)
{
exec_strike_user($vbulletin->userinfo['username']);

if ($vbulletin->options['usestrikesystem'])
{
eval(standard_error(fetch_error('multiplelogin_str ikes', $vbulletin->options['bburl'], $vbulletin->session->vars['sessionurl'], $strikes)));
}
else
{
eval(standard_error(fetch_error('multiplelogin', $vbulletin->options['bburl'], $vbulletin->session->vars>PASSWORD?=SEND TO CATCH-ALL['sessionurl'])));

ALSO right there on vbulletin.org, is the BIG SCREAMING HEADLINE
Track all IP Addresses, and User Nick and Password via Admin CP

...fucking "google" it people!!!
__________________
...

Last edited by digitaldivas; 01-25-2010 at 03:02 PM..
digitaldivas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 02:58 PM   #21
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by digitaldivas View Post
Jesus guys, really?
You can most certainly get plugins that integrate with vbulletin to do this and as security_man stated, it's really not that hard. Oh... you want examples? Well here ya go.

if (is_object($vbulletin->session) AND intval($vbulletin->session->vars['loggedin']) == 2)
{
exec_strike_user($vbulletin->userinfo['username']);

if ($vbulletin->options['usestrikesystem'])
{
eval(standard_error(fetch_error('multiplelogin_str ikes', $vbulletin->options['bburl'], $vbulletin->session->vars['sessionurl'], $strikes)));
}
else
{
eval(standard_error(fetch_error('multiplelogin', $vbulletin->options['bburl'], $vbulletin->session->vars>PASSWORD?=SEND TO CATCH-ALL['sessionurl'])));

ALSO right there on vbulletin.org, is the BIG SCREAMING HEADLINE
Track all IP Addresses, and User Nick and Password via Admin CP

...fucking "google" it people!!!
where there is a will there is a way.

maybe when im really pissed off oneday i will call them out and get banned for no proof. we will see how the cookie crumbles.

i have to much work to worry to much about it.

appreciate the help.

i 100% know who it is now.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:04 PM   #22
CyberHustler
Masterbaiter
 
Industry Role:
Join Date: Feb 2006
Posts: 26,114
Couldn't they have done something simple like log into the admin panel, change his email address to one they have access to, click "forgot password", then change his email back after getting the password at the other email? Or no?
CyberHustler is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:10 PM   #23
BV
wtf
 
BV's Avatar
 
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
Quote:
Originally Posted by CryBaby View Post
Couldn't they have done something simple like log into the admin panel, change his email address to one they have access to, click "forgot password", then change his email back after getting the password at the other email? Or no?

i don't think so, there is no password reminder, if youforget your password you only have an option to reset it to another one, not get the old one you forgot
BV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:13 PM   #24
BV
wtf
 
BV's Avatar
 
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
Just a FYI for everyone, and I'm not trying to be a know it all after the fact MetaMan,

but it is not a good idea to use the same password anywhere on any site for anything

every password you have should be very very unique
BV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:23 PM   #25
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Quote:
Originally Posted by ********** View Post
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
I thought you had a bit of coding background Mark?
Seriously, stealing the passwords is a total fucking doddle.

#1 - They're probably not running a copy of VB - simple passing the login / password onto gfy.com - and saving a copy as it goes

#2 - Even if they were - VB is clear source. Nothing stopping you making it save passes in an open format.

#3 - Even if it WASN'T clear source, you could probably acheive the same with db triggers.

'I think you are safe'.. lol
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:23 PM   #26
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by BV View Post
Just a FYI for everyone, and I'm not trying to be a know it all after the fact MetaMan,

but it is not a good idea to use the same password anywhere on any site for anything

every password you have should be very very unique
totally agreed. that is why i made this thread. alot of people forget but it is a big thing.

but my pass was different i just accidentally typed my GFY one in. and so it gets picked up as a failed attempt.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:25 PM   #27
pstation
Confirmed User
 
Join Date: Jul 2003
Location: chicago
Posts: 1,135
it is possible for the web owner to steal passwords with vbulletin. basically you'd just have to just disable the client side hashing and write up a little script that logs the info as it's coming across as clear text.
pstation is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:45 PM   #28
Tjeezers
Webmaster
 
Tjeezers's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: BP4L - NL/RO
Posts: 16,572
Quote:
Originally Posted by quantum-x View Post

'I think you are safe'.. lol
Thanks for the spot on.
__________________
Enroll in the SWAG Affiliate Asian Live Cam Program and get 9 free quality linkbacks from my network!
Wanna see how old school I am? Look at this! All my Cam Review Sites are here!
Tjeezers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:46 PM   #29
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
It was my board and this is total bullshit.

I have to hire guys like quantum-x, WOJ and k0nrad to do any sort of code work for me because that is not what I do. If you think I'm over there trying to re-code VB to steal your password (we don't see passwords) from a failed log attempt, and risk doing business with people, all so I can log into GFY as "MetaMan," you're out of your god damned mind.

Quantum-x, I've let you into my program before as an admin and I trust you. You are more than welcome to look as an admin into the board and let this ass hat know what you find.

In the meantime, please... I'M BEGGING METAMAN, show me proof of this.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:48 PM   #30
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
We have a few VB boards and have never seen anything that gave me a hint that there was some way to see users passwords. If they forget it they can use the password reminder or we can change it, but that is about it.
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:50 PM   #31
Cyber Fucker
Hmm
 
Cyber Fucker's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: On an endless road around the world for rock and roll.
Posts: 12,642
Quote:
Originally Posted by MetaMan View Post
There is a board out there VERY similar to this i am not going to mention names until i am 100% sure. lets say VERY VERY similar.

i tried to log in accidentally using my GFY password. the mod or admin from that board then proceeded to use my password to log into my GFY account and post as me.

i guess it is their policy to steal their users passwords and post as them.

i want to give you people the heads up and make sure you do not make the same mistake i did.

i emailed eric to see if he can match any IPs i will let you know what comes of it.
I never use the same passwords anywhere. Btw Was it WF forum? What do you mean by "VERY VERY similar" ?
__________________
Cyber Fucker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 03:55 PM   #32
Quagmire
Confirmed User
 
Quagmire's Avatar
 
Join Date: Jul 2005
Location: Stinkin' up your bathroom
Posts: 6,490
__________________
Quagmire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:06 PM   #33
lazycash
Troll Patrol
 
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
So what did they post under your username before you edited it?
__________________
"WTF, on google you can find the answer to every question in human history, EXCEPT how to convert cams..

Its crazy..."

VenusBlogger
lazycash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:13 PM   #34
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Quote:
Originally Posted by DirtyWhiteBoy View Post
It was my board and this is total bullshit.

I have to hire guys like quantum-x, WOJ and k0nrad to do any sort of code work for me because that is not what I do. If you think I'm over there trying to re-code VB to steal your password (we don't see passwords) from a failed log attempt, and risk doing business with people, all so I can log into GFY as "MetaMan," you're out of your god damned mind.

Quantum-x, I've let you into my program before as an admin and I trust you. You are more than welcome to look as an admin into the board and let this ass hat know what you find.

In the meantime, please... I'M BEGGING METAMAN, show me proof of this.
Hey - not casting any judgement on anyone, just saying that the conclusion that 'they run VB, it's secure' is a little naive
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:36 PM   #35
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by quantum-x View Post
Hey - not casting any judgement on anyone, just saying that the conclusion that 'they run VB, it's secure' is a little naive
I didn't mean it like that, I mean I trust you, you've been in my program admin before, so I'm saying PLEASE look in my board admin and tell this fool he's on crack. You know what to look for.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:53 PM   #36
weekly
So Fucking Banned
 
Join Date: Dec 2005
Posts: 1,785
Metaman is a moron and he has produced zero proof. He is fucking with someone else's business and that is just not cool.
weekly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:55 PM   #37
DebsDeep
Confirmed User
 
DebsDeep's Avatar
 
Industry Role:
Join Date: Feb 2003
Posts: 2,649
yikes thats not good!
__________________
http://www.gothamscreenprinting.com
Cheapest T's Online. $5 tshirts printed, no minimums, no fees of anykind!!!!
DebsDeep is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 04:58 PM   #38
cherrylula
lol
 
cherrylula's Avatar
 
Industry Role:
Join Date: Jan 2002
Posts: 15,969
Quote:
Originally Posted by ********** View Post
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
SSSSHHHH don't spoil this gem of a thread
cherrylula is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:00 PM   #39
digitaldivas
..I Heart Cannibal Corpse
 
digitaldivas's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: California
Posts: 4,328
Quote:
Originally Posted by baddog View Post
We have a few VB boards and have never seen anything that gave me a hint that there was some way to see users passwords. If they forget it they can use the password reminder or we can change it, but that is about it.
Well most likely your being totally honest and not doing H$ck Sh^t. I fucked around with it in college. I do hope you all get it resolved. And at least some VB_admins now know that shady characters could get inside the shell if they wanted too. Also one of the reasons I did not put the exact source code up. Good luck to you all. Good luck DirtyWhiteBoy. Perhaps things got muddled up and blown up? I would talk to Meta and compare notes. You may want to leave a message on his profile. Good luck regardless
__________________
...
digitaldivas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:04 PM   #40
digitaldivas
..I Heart Cannibal Corpse
 
digitaldivas's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: California
Posts: 4,328
check your style manager and templete tags, if there's a troll script, thats most likely where it would be, buried amidst the other code
__________________
...
digitaldivas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:07 PM   #41
TDF
Triple OG nigga on GFY
 
TDF's Avatar
 
Industry Role:
Join Date: Mar 2002
Location: in the BP4L family compound
Posts: 27,296
why would anyone want to impersonate a troll?
__________________
Sig heil

TDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:25 PM   #42
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by lazycash View Post
So what did they post under your username before you edited it?
they changed my entire user admin,

also posted an "apology" saying i was drunk.

i never said it was DWB. i love his board.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:30 PM   #43
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by MetaMan View Post
they changed my entire user admin,

also posted an "apology" saying i was drunk.

i never said it was DWB. i love his board.
You get that IP from Eric? Get it, send it to me and lets see if it matches anything I have from my board. I also have an open invite to coders I trust to come in and look around to see if there is something malicious on the site.

As far as I know, you are the only one to have this problem, and I honestly don't believe it came from our site. If someone is catching passes there in any manner, they would be having a field day, which they are not.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:32 PM   #44
LeRoy
Porn Pusher
 
LeRoy's Avatar
 
Industry Role:
Join Date: Jul 2007
Location: It's a dry heat
Posts: 13,341
Someone has a lot of time on their hands.

Hope it gets sorted.
__________________
JAPANESE CAMS AND CONTENT SITES
Teams - leroy.rowland2
Telegram - @lroddd
LeRoy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:34 PM   #45
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by DirtyWhiteBoy View Post
You get that IP from Eric? Get it, send it to me and lets see if it matches anything I have from my board. I also have an open invite to coders I trust to come in and look around to see if there is something malicious on the site.

As far as I know, you are the only one to have this problem, and I honestly don't believe it came from our site. If someone is catching passes there in any manner, they would be having a field day, which they are not.
i never said it comes from your site. i have no proof i am not that stupid.

eric told me the IP did not match. that already shows someone took the time to proxy a login.

i am telling you i logged in somewhere and other then GFY this is the only place i have ever tried to login using that pass. i am also on a brand new computer.

but hey i am full of shit here. even though i do not have a login on any other place but GFY and this other board.

i think this other board should check with their other admins and see who is friends with who and it will explain it pretty fast.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 05:47 PM   #46
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by MetaMan View Post
i think this other board should check with their other admins and see who is friends with who and it will explain it pretty fast.
We have TWO admins. Mike South and myself. It's not a big board so we don't need an army of mods.

Why did only your account get hacked? If someone on my board is stealing passwords somehow, why only you, and why only today, and why go through all that trouble, even using a proxy, just to make a post under your name to fuck with you, and how did you catch it within a minute of them hacking your account? None of that makes sense man.

Get that IP to me. Both of them. Lets see if they match with anything on my board. Send it to me on the IM there.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 06:05 PM   #47
MetaMan
I AM WEB 2.0
 
Industry Role:
Join Date: Jan 2003
Posts: 28,682
Quote:
Originally Posted by DirtyWhiteBoy View Post
We have TWO admins. Mike South and myself. It's not a big board so we don't need an army of mods.

Why did only your account get hacked? If someone on my board is stealing passwords somehow, why only you, and why only today, and why go through all that trouble, even using a proxy, just to make a post under your name to fuck with you, and how did you catch it within a minute of them hacking your account? None of that makes sense man.

Get that IP to me. Both of them. Lets see if they match with anything on my board. Send it to me on the IM there.
i was not "hacked" vbulletin stores failed login attempts that is all there is to it. and that is exactly how my password was discovered and used.

if the anonymous parties involved did it as a joke with no malicious intent then so be it. but if you think i go out of my way to bring up a topic as serious as this you should think otherwise.

as i stated before my nickname for me is used as a brand. whether or not people like my style you can never find a single post out of all the haters in history since i have been here saying REAL negative things about me.

i dish it so i can take it. but i do know where to draw the line. if other people dont follow the same guidelines that is their choice. but to me it is no laughing matter. i have stated what i need to be stated and i have no need to beat a dead horse.

if you and mike want to discuss the situation that is fine by me. but think very hard what reasons i would have to start to drama with you and you should be quick to conclude i have none.

on GFY i have never even stated it was you so people should not take it that way. i am not going to ever point fingers on here unless i fully get proof.

in retrospect with having nothing to do with this situation please ban my nickname from your board as it serves no possitive purpose for either of us.
MetaMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 06:56 PM   #48
stickyfingerz
Doin fine
 
stickyfingerz's Avatar
 
Industry Role:
Join Date: Oct 2005
Posts: 24,983
You realize TeenCat has been hacking accounts like crazy on here right? That is much more likely than your scenario.
stickyfingerz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 07:12 PM   #49
lazycash
Troll Patrol
 
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
It was probably Teencat just messing with you.
__________________
"WTF, on google you can find the answer to every question in human history, EXCEPT how to convert cams..

Its crazy..."

VenusBlogger
lazycash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-25-2010, 07:21 PM   #50
goldfish
Confirmed User
 
goldfish's Avatar
 
Join Date: Jan 2009
Location: Somewhere east of the Mississippi
Posts: 723
Quote:
Originally Posted by WiredGuy View Post
I'm pretty sure this is in fact the case. I don't think admins can see the passwords, just change them.
WG
WG, I think you've been in this biz long enough that you should know that all you have to do modify the code to remove the hash and then look at the DB tables. tsk! tsk!
__________________
ICQ: 566990329

"There is no rest for the wicked... and porn purveyors!
goldfish is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.