GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   extreme-dm leaking user:pass in public referer stats (https://gfy.com/showthread.php?t=154319)

rowan 07-18-2003 03:08 PM

extreme-dm leaking user:pass in public referer stats
 
<img src="http://media.sensationcontent.com/rowan/extreme-pw-leak.gif">

Never seen this before - someone has clicked through to another site from a link in my members area, and it's been recorded in that site's extreme-dm stats.

Several people have jumped on that URL in the past few minutes.

shermo 07-18-2003 03:09 PM

Yup. I've noticed that quite a few times in my stats as well. Pretty shitty.

teenjump 07-18-2003 03:09 PM

Brutal. Looks like a bug.

detoxed 07-18-2003 03:09 PM

Woud happen with any stats program

rowan 07-18-2003 03:11 PM

Quote:

Originally posted by detoxed
Woud happen with any stats program
Yep, but IE doesn't normally include this information in the referer line. It must have been another browser that did it.

thekebie 07-18-2003 03:12 PM

How does well do fark boobies convert?

fiveyes 07-18-2003 03:37 PM

It's not the program revealing the username:password so much as it is alerting you to a compromised password.

Look at it this way, if someone accesses your site as http://yourdomain.com/ instead of http:// www.yourdomain.com and you use relative linking throughout, then their referers will always be of the form http://yourdomain.com/directory/page.html. Right?

Now, keeping that in mind- the question is, when does a person access a membership area using http://username:[email protected]/members/?

rowan 07-18-2003 03:44 PM

Quote:

Originally posted by thekebie
How does well do fark boobies convert?
Aha, you've noticed my site there? :) 415k clicks since it was listed in October 2001, I can't complain. I don't have any direct stats but I usually get a few signups per week from the 600-800 uniques they still send each day.

Twe Russ 07-18-2003 03:49 PM

fiveeyes is the only one with a clue, thats definetely a pw crack,
unless you have a bookmark script that adds them like that for
your members.

fiveyes 07-18-2003 03:49 PM

In fact, comng to think of it, go pull your referer log and find the first occurance of that usage. It'll will point back to the password site that has you hotlinked.

zzgundamnzz 07-18-2003 03:51 PM

Quote:

Originally posted by Twe Russ
fiveeyes is the only one with a clue, thats definetely a pw crack,
unless you have a bookmark script that adds them like that for
your members.

Looks like it. Is Necrohiphop up again? :1orglaugh

rowan 07-18-2003 04:01 PM

I agree that it was probably a password crack that got the 'leaker' to my site, it was just unusual to see it carried through as-is... from checking my logs it looks like it's buried in quite a few other sites extreme-dm stats and has been for at least 2 weeks. My compromised account script didn't pick it up due to the URL being well hidden (for the most part), so there was hardly anyone using it until it hit the 'last 20 referers' of a site and got noticed.


All times are GMT -7. The time now is 04:58 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123