GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Whats with the exoclick.com hack email? (https://gfy.com/showthread.php?t=1079331)

Feng-PD 08-27-2012 06:33 AM

Whats with the exoclick.com hack email?
 
wtf is this?

Barefootsies 08-27-2012 06:34 AM

It looks like you would hit the delete key, and move along with your day?

:helpme

Feng-PD 08-27-2012 06:36 AM

from what im reading is that this guy has a problem with exo for freezing his account. He hacked exoclicks and has ALL the info about all their affiliates. That means he also has all my information aswell.

Why would i want to move along when my information can get exposed?

wtf.

AnimeFevers 08-27-2012 06:37 AM

Feng is nub :1orglaugh

halfpint 08-27-2012 06:39 AM

Um it looks like the data base got hacked if you follow those links on that page

lucas131 08-27-2012 06:41 AM

sounds legit, have luck everyone :upsidedow

Feng-PD 08-27-2012 06:41 AM

Quote:

Originally Posted by halfpint (Post 19147296)
Um it looks like the data base got hacked if you follow those links on that page


yeap so ALL the affiliates their information (iban,swifty,paypal,paxum etc) is in the hands of this hacker....

~Ray 08-27-2012 06:42 AM

sounds like he's mad and looking for a little payback

Axel_Crak 08-27-2012 06:50 AM

Damn , i understand the guy is made, but what the point to make trouble to the other client

Hey Fengwu if your client like us, perhaps it would be better for all of us if you pulled out the link on the topic and just let people discuss...

halfpint 08-27-2012 06:54 AM

Quote:

Originally Posted by Axel_Crak (Post 19147327)
Damn , i understand the guy is made, but what the point to make trouble to the other client

Hey Fengwu if your client like us, perhaps it would be better for all of us if you pulled out the link on the topic and just let people discuss...

Dought it will make any diff as it looks like he has the users email addreses which he is using to send out this info

halfpint 08-27-2012 06:55 AM

Quote:

Originally Posted by fengwu83 (Post 19147307)
yeap so ALL the affiliates their information (iban,swifty,paypal,paxum etc) is in the hands of this hacker....

looks like it :Oh crap

Axel_Crak 08-27-2012 07:04 AM

Quote:

Originally Posted by halfpint (Post 19147339)
Dought it will make any diff as it looks like he has the users email addreses which he is using to send out this info

Well im concern about all GFY got access to this list..

halfpint 08-27-2012 07:07 AM

Quote:

Originally Posted by Axel_Crak (Post 19147361)
Well im concern about all GFY got access to this list..

Well all Exoclick members who get an email from him will have access to it and anybody else he wants to send the info to on the web, its a bit late to worry about it now and anyway looking at the passwords they are encoded

Axel_Crak 08-27-2012 07:15 AM

Quote:

Originally Posted by halfpint (Post 19147366)
Well all Exoclick members who get an email from him will have access to it and anybody else he wants to send the info to on the web, its a bit late to worry about it now

Well that your opinion, certainly not mine. People on the list have no gain to publish that list.. anyway we cant stop all info to go on the web, but at least if we could avoid publish it here, you can avoid some potential problem...

halfpint 08-27-2012 07:21 AM

Quote:

Originally Posted by Axel_Crak (Post 19147377)
Well that your opinion, certainly not mine. People on the list have no gain to publish that list.. anyway we cant stop all info to go on the web, but at least if we could avoid publish it here, you can avoid some potential problem...

I just had a look at some of those screenshots and it does show user login names, thier real names, addresses the company ID's and tel no. I think Exoclick need to get in here quick smart

Lace 08-27-2012 07:48 AM

Why would you publicly post this?

LeRoy 08-27-2012 07:56 AM

I got that message too.

Wonder whats going on?

Konda 08-27-2012 08:14 AM

Exoclick got hacked.

The most interesting part is that he claims he has proof that Exoclick is cheating it's customers.

Quote:

Also in my hands is the information from the database ExoClick Ad Network, which refers to the uncontrolled cheat clicks and impressions!
I'll post the data later after tidy the dump logs and proof of the fact of cheating.
With all the info and database dumbs and screenshot he already posted there is no doubt that this guy hacked Exoclick and had full access to their databases and all info.

topsiteking 08-27-2012 08:16 AM

Quote:

Originally Posted by halfpint (Post 19147389)
I just had a look at some of those screenshots and it does show user login names, thier real names, addresses the company ID's and tel no. I think Exoclick need to get in here quick smart

Ugh.
Has this been taken care of yet?

halfpint 08-27-2012 08:22 AM

Quote:

Originally Posted by topsiteking (Post 19147502)
Ugh.
Has this been taken care of yet?

The OP removed the link but the guy has been sending out emails to Exoclick users with the link and he does have all the info up on a site. He also has a password to access info about credit cards, paypal ect on the site

Exoclick 08-27-2012 08:27 AM

Hi Everyone,

About 6 months ago, ExoClick has been under heavy attack, from pretty nasty DDOS to all sorts of attempts to hack our servers or take them down.

Fortunately, we have a very high performance infrastructure and these attacks never took us down.
Unfortunately, one of their blind SQL injection attack got successful and they were able to fetch encrypted passwords as well as other information we have in our database. During all this time, he has been trying to blackmail us in all sorts of ways.

It appears the last thing he could do is to hurt our reputation and contact our clients about it.

To all our clients, please, rest assured your account is 100% safe. We have taken all necessary measures to prevent this type of issues in the future and to protect ExoClick clients. After the incident, we also hired a company expert in online security to audit our platform and make sure there was no other possible flaws.

I sincerely and personally apologies for this. And I apologies for any inconvenience that this might have caused you. Believe me we are taking this very seriously.

If you have any questions or doubts, please don't hesitate to contact me personally.

Best,
Benjamin.

Konda 08-27-2012 08:27 AM

You can see the hacker used super simple SQL injections to get access, meaning that they were using non-escaped querystring in the SQL - which is like one of the most basic security measures these days... At least they did seed the user passwords.

Axel_Crak 08-27-2012 08:29 AM


To everyone, please support the companies victim of the hack and dont post the link with the info here.

Eric just removed it from the first post.

Thanks for your cooperation

Konda 08-27-2012 08:30 AM

Quote:

Originally Posted by Exoclick (Post 19147530)

To all our clients, please, rest assured your account is 100% safe. We have taken all necessary measures to prevent this type of issues in the future and to protect ExoClick clients.

Well all personal and bank information of all users is public already now...

halfpint 08-27-2012 08:30 AM

Quote:

Originally Posted by Exoclick (Post 19147530)
Hi Everyone,

About 6 months ago, ExoClick has been under heavy attack, from pretty nasty DDOS to all sorts of attempts to hack our servers or take them down.

Fortunately, we have a very high performance infrastructure and these attacks never took us down.
Unfortunately, one of their blind SQL injection attack got successful and they were able to fetch encrypted passwords as well as other information we have in our database. During all this time, he has been trying to blackmail us in all sorts of ways.

It appears the last thing he could do is to hurt our reputation and contact our clients about it.

To all our clients, please, rest assured your account is 100% safe. We have taken all necessary measures to prevent this type of issues in the future and to protect ExoClick clients. After the incident, we also hired a company expert in online security to audit our platform and make sure there was no other possible flaws.

I sincerely and personally apologies for this. And I apologies for any inconvenience that this might have caused you. Believe me we are taking this very seriously.

If you have any questions or doubts, please don't hesitate to contact me personally.

Best,
Benjamin.

Nice quick repsonce and I hope you can find the idiot who did it

Konda 08-27-2012 08:32 AM

Quote:

Originally Posted by Axel_Crak (Post 19147537)

To everyone, please support the companies victim of the hack and dont post the link with the info here.

Eric just removed it from the first post.

Thanks for your cooperation

That's not going to help anything, he emailed the link to 10,000s of users from the exoclick database already.

Konda 08-27-2012 08:34 AM

Quote:

Originally Posted by halfpint (Post 19147541)
Nice quick repsonce and I hope you can find the idiot who did it


Nice quick response??

6 months too late. They should have informed their users as soon as it happened. Especially because of the sensitive personal and bank info that has been compromised!!

halfpint 08-27-2012 08:34 AM

Quote:

Originally Posted by Konda (Post 19147539)
Well all personal and bank information of all users is public already now...

Not all of it is yet. He had the banking info for Exoclick users password protected and all the users passwords are encrypted anyway , but whos to say that he wont start pasting it all over the net if he doesent get want he wants and if they do give him what he wants whos to say he wont keep on doing it.

I hope Exoclick can find this idiot :2 cents:

halfpint 08-27-2012 08:36 AM

Quote:

Originally Posted by Konda (Post 19147557)
Nice quick response??

6 months too late. They should have informed their users as soon as it happened. Especially because of the sensitive personal and bank info that has been compromised!!

Im talking about a responce on the board

lucas131 08-27-2012 08:38 AM

Quote:

Originally Posted by Konda (Post 19147539)
Well all personal and bank information of all users is public already now...

exactly. how are all accounts safe when there is db dump online? come one exoclick, are you serious? you cannot hide the fact that all users info is out behind any words :2 cents:

lucas131 08-27-2012 08:39 AM

and please, how can someone who hacked 82k of users, be an idiot? :) :error

topsiteking 08-27-2012 08:40 AM

I have an Exoclick account and got no email...

halfpint 08-27-2012 08:46 AM

Quote:

Originally Posted by lucas131 (Post 19147574)
and please, how can someone who hacked 82k of users, be an idiot? :) :error

Because anybody who trys to blackmail a company by hacking into their users data base is an idiot

nextri 08-27-2012 08:49 AM

Are you doing anything to go after the guy behind this? Do you know who he is?

topsiteking 08-27-2012 08:55 AM

Quote:

Originally Posted by halfpint (Post 19147594)
Because anybody who trys to blackmail a company by hacking into their users data base is an idiot

:2 cents:

BIGTYMER 08-27-2012 09:03 AM

I didn't get the email. Where is the link?

Feng-PD 08-27-2012 09:04 AM

we need to know what exo is going to do about this.

topsiteking 08-27-2012 09:09 AM

Quote:

Originally Posted by BIGTYMER (Post 19147641)
I didn't get the email. Where is the link?

Same someone get it to me please.

Niktamer 08-27-2012 09:20 AM

PLEASE, dont spread the email, if you received it, please keep it for yourself.

Exoclick is a victim with all their clients, even if its long time ago and everyone concerned had their password changed, spreading this info wont do any good to anyone on top of the blackmailer and other hackers and scammers who will use it and potentially harm the people on the list, people that can be your friends, partners, affiliates or just part of our community.

fris 08-27-2012 09:25 AM

rogue email admin


All times are GMT -7. The time now is 07:11 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc