Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-16-2010, 05:27 PM   #1
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
CCBill.com multiple vulnerabilities

Found this on the full disclosure mailing list:

Quote:
We want to warn you about security vulnerabilities in CCBILL.COM
Internet billing service.

CCBill is an Internet billing service. Established in 1998, the company
provides third-party billing, or turn-key solutions, for e-Merchants
requiring payments by way of credit card, debit card, or e-check,
European Debit/Direct Pay, and telephone payment.

Since Ccbill is a privately held company little is known about it's
finances however it is estimated that more than a billion dollars per
year in credit card charges are processed through Ccbill in the us and
abroad.

Time Table:
# 20/07/2010 We have found multiple Blind SQL injections.

# 30/07/2010 - Vendor notified. / no response
# 03/08/2010 - Vendor notified. / no response
# 10/08/2010 - Vendor notified. / no response

CCBILL.COM vulnerability:

Multiple blind SQL injections

It's possible to get all customers FULL personal details, server admins
etc...

Also is possible to read any file from ccbill.com and write to this
server too.

JPG sample tables proof:
http://www.ariko-security.com/images/ccbill_proof1.jpg

Credit:
# Discoverd By: MG / Ariko-Security 2010
# http://advisories.ariko-security.com...nstwa_719.html
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:10 PM   #2
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
It's possible to get all customers FULL personal details, server admins
etc...

Also is possible to read any file from ccbill.com and write to this
server too.


Pretty shitty vulnerability if you ask me.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:16 PM   #3
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Jesus, that is one hell of an vulnerability.
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:17 PM   #4
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
serious stuff...

# 30/07/2010 - Vendor notified. / no response
# 03/08/2010 - Vendor notified. / no response
# 10/08/2010 - Vendor notified. / no response

does that mean that it hasn't been patched up yet?
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:18 PM   #5
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Quote:
Originally Posted by woj View Post
serious stuff...

# 30/07/2010 - Vendor notified. / no response
# 03/08/2010 - Vendor notified. / no response
# 10/08/2010 - Vendor notified. / no response

does that mean that it hasn't been patched up yet?
Most likely...
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:19 PM   #6
NetHorse
Confirmed User
 
NetHorse's Avatar
 
Industry Role:
Join Date: Dec 2006
Location: Chicago
Posts: 3,526
Yeah, who knows...

I think a lot would agree that CCBILL needs to revamp EVERYTHING from the ground up. Especially considering they're the single biggest processor in adult. A lot of concerns have been brought up in the last 2-3 years, zero changes have happened though.
__________________
┌∩┐(◣_◢)┌∩┐
ICQ # 427013273
NetHorse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:20 PM   #7
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
They had so many, they stopped caring
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:24 PM   #8
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
In before the lock?

Get on it CCbill.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:33 PM   #9
BFT3K
Too lazy to set a custom title
 
BFT3K's Avatar
 
Industry Role:
Join Date: Dec 2005
Location: Narnia
Posts: 10,764
I am not defending CCBill here, and hopefully they have read this post, and are immediately working to correct these issues.

But I want to add, for whatever its worth, it appears EVERYTHING currently on the web is insecure nowadays - from major banks, to EVERY social network, to almost EVERY method of online processing, all the way up to Top Secret classified military documents!

It really is the fucking wild wild west out here...

Last edited by BFT3K; 08-16-2010 at 06:44 PM..
BFT3K is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:37 PM   #10
TheSenator
Too lazy to set a custom title
 
TheSenator's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,332
I bet this thread is gonna be locked down and thrown away.
__________________
ISeekGirls.com since 2005
TheSenator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:47 PM   #11
myneid
Confirmed User
 
myneid's Avatar
 
Industry Role:
Join Date: Jan 2003
Location: Los Angeles
Posts: 736
it is very serious business for any service provider or merchant to have ANY vulnerabilities as per pci dss.
every hole needs to be filled in somehow and quarterly scans are required.

now i have not verified this myself, but i'm guessing that its bogus.
__________________
Tanguy 0x7a69 inc. Programmer/President/CEO
http://www.0x7a69.com
A Leader in Programming since 1996
PHP, Ruby on Rails, MySQL, PCI DSS, and any Technical Consulting
myneid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 06:54 PM   #12
BittieBucks Eric
Confirmed User
 
Industry Role:
Join Date: Aug 2010
Posts: 457
Quote:
Originally Posted by NetHorse View Post
Yeah, who knows...

I think a lot would agree that CCBILL needs to revamp EVERYTHING from the ground up. Especially considering they're the single biggest processor in adult. A lot of concerns have been brought up in the last 2-3 years, zero changes have happened though.
Any idea how many bugs and vulnerabilities they'd create if they'd rebuild everything from the ground up?
__________________

Bittie Bucks - Upto 70% Revshare - CCBill Cascading Program - 10% Webmaster Referral
[email protected] - ICQ - 594415957


Need Content TRASHY CONTENT
BittieBucks Eric is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 07:00 PM   #13
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by myneid View Post
it is very serious business for any service provider or merchant to have ANY vulnerabilities as per pci dss.
every hole needs to be filled in somehow and quarterly scans are required.

now i have not verified this myself, but i'm guessing that its bogus.
bogus? Why would you think that?
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 07:04 PM   #14
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Quote:
Originally Posted by myneid View Post
now i have not verified this myself, but i'm guessing that its bogus.
Are all these other exploits they found bogus too?

http://www.ariko-security.com/index-7.html
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 07:28 PM   #15
SwirlsGirl
So Fucking Banned
 
Join Date: Feb 2006
Location: between east coast and vegas
Posts: 2,067
Hell I am no programmer, but I can attest that it appears that if they are not guilty of any fraud them selves, then some one has hacked them and been able to do a lot of things that have caused many webmasters to question the integrity of the data.

Of course for the past year and a half all ccbill has done was assure everyone that what they were seeing (Bizarre to say the least stats anomalies) was their imagination, and have there schills come into gfy and attack anyone raising serious questions!

Even if this post is found to be true, the majority of the industry is so brain washed and gullible, they will not believe or care that they could have been getting the fuzzy end of the lolipop
SwirlsGirl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 07:46 PM   #16
CCBill Paul
Confirmed User
 
CCBill Paul's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Cardinal Nation
Posts: 1,005
We are and have been looking into this.
__________________
Paulk @ CCBill.com | icq 248615940
CCBill Paul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 08:00 PM   #17
SwirlsGirl
So Fucking Banned
 
Join Date: Feb 2006
Location: between east coast and vegas
Posts: 2,067
Quote:
Originally Posted by CCBill Paul View Post
We are and have been looking into this.
Classic, but you would have others think I am just starting drama, tell me If this is found out to be true, will you come back in and apologize as an honorable person would?

I mean you guys at ccbill are so honorable, professional, and courteous. Something tells me not to hold my breath....


OH I KNOW.......................

ITS JUST A BUG!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! LOL
SwirlsGirl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 08:06 PM   #18
SwirlsGirl
So Fucking Banned
 
Join Date: Feb 2006
Location: between east coast and vegas
Posts: 2,067
Makes you start to wonder about some of those zero sales days really being zero sales days, especially when your back up processors are having sales flurries

SwirlsGirl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 08:45 PM   #19
BFT3K
Too lazy to set a custom title
 
BFT3K's Avatar
 
Industry Role:
Join Date: Dec 2005
Location: Narnia
Posts: 10,764
BFT3K is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 08:47 PM   #20
mmcfadden
So Fucking Banned
 
Join Date: Oct 2008
Location: philly
Posts: 5,099
Quote:
Originally Posted by CCBill Paul View Post
We are and have been looking into this.
Lmk when all is good ;). Lol
mmcfadden is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 09:07 PM   #21
NetHorse
Confirmed User
 
NetHorse's Avatar
 
Industry Role:
Join Date: Dec 2006
Location: Chicago
Posts: 3,526
Quote:
Originally Posted by BittieBucks Eric View Post
Any idea how many bugs and vulnerabilities they'd create if they'd rebuild everything from the ground up?
Good point. Not really sure what needs to be done, but something clearly needs addressing.

100s of affiliates/program owners have been creating thread after thread all with similar issues. Making a statement, "Everything is fine on our end" doesn't seem to be an amicable solution anymore.
__________________
┌∩┐(◣_◢)┌∩┐
ICQ # 427013273
NetHorse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 09:07 PM   #22
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
only thing I find odd is the 'proof' half a jpg screenshot with red underlines meaning "spelling errors" in most auto spellcheck applications....

and yet on the site that found the 'exploit' the bulk of their other finds have full text files as 'proof' (even with other msql exploit / injections)

I did notice that CCBILL is aware of the issue, but I still find the 'proof' a bit odd

-Loki-
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 09:21 PM   #23
The Ghost
IslandDollars.com
 
The Ghost's Avatar
 
Join Date: Oct 2004
Location: Icq: 176176
Posts: 12,188
Thread bookmarked.
__________________
ISLAND DOLLARS
1000's of Exclusive TS scenes / Constant Updates
Best TS Network your surfers will ever join
The Ghost is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 10:22 PM   #24
elitelist
So Fucking Banned
 
Join Date: Aug 2002
Posts: 210
Quote:
Originally Posted by Loki View Post
only thing I find odd is the 'proof' half a jpg screenshot with red underlines meaning "spelling errors" in most auto spellcheck applications....

and yet on the site that found the 'exploit' the bulk of their other finds have full text files as 'proof' (even with other msql exploit / injections)

I did notice that CCBILL is aware of the issue, but I still find the 'proof' a bit odd

-Loki-
Concatenated strings are not vocabulary.

I can also promise you that ccbill is owned beyond the owners.
elitelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 11:18 PM   #25
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 11:19 PM   #26
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by rowan View Post
I love that one
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 11:25 PM   #27
MrDeiz
 
MrDeiz's Avatar
 
Join Date: May 2008
Posts: 9,802
Quote:
Originally Posted by CCBill Paul View Post
We are and have been looking into this.
it doesn't make any sense = it's senseless
__________________
Make money with WEBC$MS
The only way to still make money in adult
MrDeiz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-16-2010, 11:30 PM   #28
LeRoy
Porn Pusher
 
LeRoy's Avatar
 
Industry Role:
Join Date: Jul 2007
Location: It's a dry heat
Posts: 13,337
Sounds like there's a few issues to deal with this week.

ugh!
__________________
JAPANESE CAMS AND CONTENT SITES
Skype - leroy.rowland2
LeRoy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 02:19 AM   #29
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by myneid View Post
every hole needs to be filled

DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 09:01 AM   #30
Beerbar
Confirmed User
 
Industry Role:
Join Date: Oct 2004
Posts: 145
Anything more from CCBill?
Beerbar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 12:56 PM   #31
NetHorse
Confirmed User
 
NetHorse's Avatar
 
Industry Role:
Join Date: Dec 2006
Location: Chicago
Posts: 3,526
If this is a real concern it should be forwarded to PCI. Request that a SAS 70 report be created.
__________________
┌∩┐(◣_◢)┌∩┐
ICQ # 427013273

Last edited by NetHorse; 08-17-2010 at 12:59 PM..
NetHorse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 01:01 PM   #32
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Not a new problem? From March 13th, 2009: http://blog.rstcenter.com/2009/03/13...-in-ccbillcom/
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 01:23 PM   #33
closer
Confirmed User
 
closer's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: ICQ :: 34739932 :: Les Pays-Bas
Posts: 1,707
Any site can be hacked/cracked,

a financial/banking site should be held up to much higher security standards, as this could potentially give yet another HUGE blow to the adult industry as a whole, which is already at its weakest point to date, if this becomes a CNN item, we're not talking facebook here.

In the end, the only real opinion that should matter in such cases is how fast that hacked site fixes the backdoors.

It's good to read that CCBill is looking into it and hope they'll update us with any news.
__________________

HOT DOMAIN NAMES FOR SALE:
EUROPEAN: MACHO.FRKINKY.ESSEXTOONS.CO.UKDOT COMS: DJSEX.COMFAQBOX.COMWEBCAMSTV.COMSEXTWEET.COMPORNVOUCHER.COMGAYBF.COM | GAYBFF.COMGAYSEXDATE.COM | GAYSEXDATING.COM
closer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 04:03 PM   #34
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by Ethersync View Post
Not a new problem? From March 13th, 2009: http://blog.rstcenter.com/2009/03/13...-in-ccbillcom/
I think this is a separate issue.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 05:58 PM   #35
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
bump for a serious issue.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:00 PM   #36
Shap
Confirmed User
 
Industry Role:
Join Date: May 2001
Posts: 8,313
Looking forward to hearing the reply.
Shap is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:10 PM   #37
cambaby
So Fucking Banned
 
Join Date: Feb 2003
Location: CR
Posts: 3,141
F.U.D.

Leave CCBill alone, NATS is shit
cambaby is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:11 PM   #38
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by cambaby View Post
F.U.D.

Leave CCBill alone, NATS is shit
So this isn't a serious vulnerability? How do you figure?
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:29 PM   #39
cambaby
So Fucking Banned
 
Join Date: Feb 2003
Location: CR
Posts: 3,141
Quote:
Originally Posted by CYF View Post
So this isn't a serious vulnerability? How do you figure?
There is a huge difference between "vulnerability" and actual cases of hacking. Every piece of software is "vulnerable".

Most likely you have to get social hacked into giving up some piece of information and then be on a certain domain at a certain time located at x,y gps coordinates and standing on your head sipping a glass of red wine while flatulating to actually exploit shit.
cambaby is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:32 PM   #40
Shap
Confirmed User
 
Industry Role:
Join Date: May 2001
Posts: 8,313
Quote:
Originally Posted by cambaby View Post
F.U.D.

Leave CCBill alone, NATS is shit
How does this have anything to do with Nats? It's one thing to discredit the claim it's another to bring in another company that has nothing to do with this topic.
Shap is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:35 PM   #41
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by cambaby View Post
There is a huge difference between "vulnerability" and actual cases of hacking. Every piece of software is "vulnerable".

Most likely you have to get social hacked into giving up some piece of information and then be on a certain domain at a certain time located at x,y gps coordinates and standing on your head sipping a glass of red wine while flatulating to actually exploit shit.
ROFL. god you're clueless
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:49 PM   #42
cambaby
So Fucking Banned
 
Join Date: Feb 2003
Location: CR
Posts: 3,141
...and out come the people who get paid to bash CCBill
cambaby is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 07:55 PM   #43
Shap
Confirmed User
 
Industry Role:
Join Date: May 2001
Posts: 8,313
Quote:
Originally Posted by cambaby View Post
...and out come the people who get paid to bash CCBill
LOL that really shows how clueless you are. How am I paid to bash Ccbill? I've used them for more than 10 years now.
Shap is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 08:02 PM   #44
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by cambaby View Post
There is a huge difference between "vulnerability" and actual cases of hacking. Every piece of software is "vulnerable".

Most likely you have to get social hacked into giving up some piece of information and then be on a certain domain at a certain time located at x,y gps coordinates and standing on your head sipping a glass of red wine while flatulating to actually exploit shit.
that's pretty clueless dude

and no, I'm not paid to bash CCBill.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-17-2010, 08:24 PM   #45
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by Ethersync View Post
Not a new problem? From March 13th, 2009: http://blog.rstcenter.com/2009/03/13...-in-ccbillcom/
This one looks like an SQL injection. See the cartoon I posted. Unbelievable that a multi-million dollar CC processing company would not sanitize input data to prevent what appears to be a relatively simple attack... especially on a non login required public knowledgebase. :
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-18-2010, 06:23 PM   #46
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by rowan View Post
This one looks like an SQL injection. See the cartoon I posted. Unbelievable that a multi-million dollar CC processing company would not sanitize input data to prevent what appears to be a relatively simple attack... especially on a non login required public knowledgebase. :
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-18-2010, 08:52 PM   #47
NinjaSteve
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2003
Posts: 11,089
Hopefully ccbill will finish looking into it and then come in and say "that shit is bananas!"
__________________
...
NinjaSteve is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-18-2010, 09:32 PM   #48
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by NinjaSteve View Post
Hopefully ccbill will finish looking into it and then come in and say "that shit is bananas!"
somehow I doubt it.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-18-2010, 09:52 PM   #49
Kelli58
Confirmed User
 
Kelli58's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Texas
Posts: 2,089
So bashing each other aside, did anyone from CCBill address the CCBill security issues yet?
__________________
Kandy AI 🍭🍬 Take a bite out of censorship 🍭🍬 We believe in empowering adults to use AI as they see fit. 👉 Get AI to write your scene descriptions for you 👈
Kelli58 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-18-2010, 10:23 PM   #50
The Porn Nerd
Living The Dream
 
The Porn Nerd's Avatar
 
Industry Role:
Join Date: Jun 2009
Location: Inside a Monitor
Posts: 19,536
Quote:
Originally Posted by Kelli58 View Post
So bashing each other aside, did anyone from CCBill address the CCBill security issues yet?
That would be a "no".
__________________
My Affiliate Programs:
Porn Nerd Cash | Porn Showcase | Aggressive Gold

Over 90 paysites to promote!
Now on Teams: peabodymedia
The Porn Nerd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.