![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Sponsors! check your member email DB, you prolly are hacked.
When was the last time you (affiliate program owners) have placed a virgin email address in your member database on your server to see if your member's email list has been compromised? Bet when you do it, you will see spam on those emails in 3 to 5 days ;)
Got some serious hackers selling off member's lists fresh from hot small to huge sponsor programs DB's and the ones who buys these lists are some of the biggest affiliates in the biz. Seed fake members in your DB and then thank me later for warning you. ![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Registered User
Join Date: May 2010
Posts: 90
|
Seconded.
Though, the less honest ones could be selling them... emails are worth a bit. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
nats or no nats ? i remember when nats got hacked by someone using their admin username and password , the hacker stole all the signup emails from each of the sponsors running nats that they compromised
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
hmm i see nats sites in sig , bad sign. NATS seemed to want nothing to do with finding/exposing/criminally charging the culprits last time. Kind of an open invitation for hackers to try the same hack, especially when they know their target isn't interested in finding them, charging them or exposing holes.
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
The spammer will not be shut down by program owners (tried that) because they are making huge money on basically the most valuable email list ever created in the history of porn spamming.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Behind the scenes
Posts: 5,190
|
if that's the case i would recommend seeding fake affiliate emails as well.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
My theory based on tests and collecting info on this problem is there is a group that is cracking program owners DB's by any means, including php exploits, apache/sql/smarty exploits, and then straight up brute force cracking DB's and affiliate software admins if that fails. This has been going on for over a year. Once they gain access they are selling the lists to the same group of affiliates, one gets it exclusively for about a week or two, then it's sold to another affiliate who gets semi-exclusive spam access, then it's sold to several other spammers.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
affiliate lists in my case were not touched through every test we had over the last year. Not valuable enough for em to bother with. These guys are only after paysite members email addresses, they don't take their logins, so they know what's worth $$ and don't bother with anything else.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
what is more valuable than lists of emails they have buyers for and the list being top tiered when it comes to spamming since every person is guaranteed (almost) to have a credit card and willing to join a porn site within the last few days. Stealing card data might be a bit riskier than just yanking email addresses from sponsors who will prolly not call the FBI for that crime. I don't keep CC data on any of my servers, but a crime like that brings a world of shit on your head.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
you do have a point there, although that risk hasn't stopped people before.
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
True, I don't keep CC data on my servers so I can't test if they were going after that as well other than I use my own CC's to do test joins all the time and they haven't been stolen, most sponsor other than huge programs leave the CC data at the gateways.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Feb 2006
Location: In a dream
Posts: 1,955
|
What kind of email are they sending?
I received one starting like that: ---- Here is your login information. Username: daWeXeve Password: xxxx Website Location : http://www.lifetimeadultpass.com/ ---- From: Customer Suport ([email protected]) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Behind the scenes
Posts: 5,190
|
theoretically, to be able to crack SQL DB's logins one would need to have server access in the first place as SQL servers are not open to receive connections from remote locations by default. I don't know inner workings of paysite scripts and billers how they're tied up together - but i highly doubt its required to have SQL DB access open for remote servers.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
MFBA
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
MFBA
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
|
Quote:
customer emails are one of the most valuable assets an adult affiliate program has.... they should protect them. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | ||
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Quote:
in to the database. This due to a widely held misconception about how the default account works. So default MySQL, not secured by someone who knows what they are doing + any popular PHP script = DB publicly available. Quote:
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Oct 2008
Location: xxweekxx mothers bed.
Posts: 2,017
|
Anyone after dating emails? I can acquire several million, im sure they would do well - sample available upon request.
__________________
GFY King? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Feb 2002
Posts: 2,527
|
there's no question some programs are either compromised, or are stupid enough selling emails. I've signed up with emails that have odd, hard to guess usernames and they get spam
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
these are very serious accusations about nats.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
welcome to yesterday
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
This isn't about nats, it about DB hacking and is happening to both NATS/Non nats & custom affiliate scripts.
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
you can register to public forums, where are hackers playing game like to have control over complete adult business. group of hackers, filling their list of hacked dbs. if there is new program, new job is started and program is hacked in few days. when the hack is compromissed for public, they just post the hole and then you wake up and say oooh i am hacked those bastards! some stupid ones are putting to your passfile also logins with ishere and similar passwords, but clever ones are only spamming and making big bucks with fake watches or viagra. and, there is not only one forum where they have control over almost everything ...
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
cant post and cant share, but not impossible to figure out, three forums in different languages, none of them is english. there is so much valuable informations to throw it out, sorry man ...
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Confirmed User
Industry Role:
Join Date: Jul 2008
Location: In your back seat with duck tape
Posts: 4,568
|
Quote:
![]()
__________________
High Performance Vps $10 Linode Manage your Digital Ocean, Linode, or Favorite Cloud Server. Simple, fast, and secure Server Pilot |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
Quote:
![]() ![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
Well I'd be interested, I'll even send thank you cards ![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
well man cant say for 100% but will try to remember your revengebucks when will be checking some of those places, but as i said it is wasting of time now so im doing it once per month or so, will let you know if i see you somewhere anyway ... now i can give you only vip access to saff forum, where most of the hacked passwords ended, so contact me at radimcillik at gmail if you are interested in this. security of your users and affiliates in the first place everyone!
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Industry Role:
Join Date: Jul 2008
Location: In your back seat with duck tape
Posts: 4,568
|
i like gleem and i like your program too. your always pretty level headed.
__________________
High Performance Vps $10 Linode Manage your Digital Ocean, Linode, or Favorite Cloud Server. Simple, fast, and secure Server Pilot |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 | ||
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
Email sent ![]() Quote:
![]()
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Behind the scenes
Posts: 5,190
|
lesson from this thread:
- restrict db access only to from known hosts (shut anonymous db access if you have that) - use complex generated passwords for db login and anything else - also should consider securing ssh/ftp access - for commonly used scripts - customize them, change admin url if possible, use strict passwords what else is missing?
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
Quote:
- do not send password through emails, do not store emails with passwords - put your own testing real looking combos in htpasswd so you can track the hacks easily - have all logins with captcha, not only popup 401 window maybe sounds easy and basic, but those are things how smart kid can take your datas even without knowing any programming language ![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Behind the scenes
Posts: 5,190
|
Quote:
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 | |
Confirmed User
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
|
Quote:
__________________
Contact me: \\// E: webmaster /at/ unprofessional.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |