GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Fix to Spoofing Members Areas (https://gfy.com/showthread.php?t=541520)

bighitter 11-17-2005 01:03 PM

Fix to Spoofing Members Areas
 
Everybody,

Last month we noticed our hits/bandwidth to our members are increase by over 1,000+ users per day, costing us over $5,000+ in content bandwidth as a direct result of spoofing software that lets people into your members area for free!

Well congratulations to Mr. Brad Slavin, my head IT, who wrote a killer script that can be added to your .htaccess file that will not let spoofers in. If anybody is interested in how we did this....we will be happy to help you out on trade.

Since the new .htaccess file was uploaded, we have been 100% secure, knocking out over 900+ spoofers per day!

THANKS BRAD!!!

Fuckin Bill 11-17-2005 01:21 PM

1) "Spoofing" doesn't get you into anything. Passwords do.

2) htaccess does not run scripts.

4Pics 11-17-2005 01:26 PM

email me the script?

fuzebox 11-17-2005 01:27 PM

Were you only authenticating via HTTP_REFERER? This is all too common, I've helped a few people out with this...

Dirty F 11-17-2005 01:30 PM

Quote:

Originally Posted by Fuckin Bill
1) "Spoofing" doesn't get you into anything. Passwords do.

Wrong.

...

bighitter 11-17-2005 01:32 PM

using the .htaccess file
 
We were use the http_referrer method, and still are, only adding a jump page and a couple quick lines of script to the .htaccess file itself has knocked out those thieves.

When I visited a couple of the web sites providing the spoof software and a huge, huge, list of members' area urls, which were big.

Testing their software, I was able to get into tons of members areas from very big content providers, plus many of the referring urls were via somebody elses account, paying $$ to the content provider.

Dalai lama 11-17-2005 01:33 PM

Just use strongboxxx

latinasojourn 11-17-2005 01:55 PM

if you are an owner of a popular paysite(s) you need to go to <deganews.com> and put in the name of your site.

this will tell you if asswipes are trading info about how to spoof your members area.

the "tar=ref" spoof is very common, and can be fixed by beefing up your member area security.

if you are on ccbill they can show you how to do it.

also if you are hosting video files you should have <antihotlinking.com> in place and be redirecting your hotlink attempts to some sort of sales page.


All times are GMT -7. The time now is 03:52 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123