GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   I think a lot of Epassporte account hacks have been the result of NATS security holes (https://gfy.com/showthread.php?t=794328)

Jet - BANNED FOR LIFE 12-23-2007 05:16 AM

I think a lot of Epassporte account hacks have been the result of NATS security holes
 
Think about how many people reported money stolen from their Epass accounts, saying they had no spyware/trojans on their PC.

I think it could be because of the NATS security holes.

If people used same login/password for their affiliate program accounts and their Epassporte account, i can see how easily money could have been be stolen.

Epassporte didn't have anything to do with it, but a lot of people blamed them.

Oracle Porn 12-23-2007 05:53 AM

epass is to blame for the nats hack!

slavdogg 12-23-2007 05:57 AM

if you use epass
you're a scammer
simple as that.

and u'r one dumb motherfucker for trusting epass with your money.

v4 media 12-23-2007 06:08 AM

Blame Canada

Emil 12-23-2007 06:09 AM

If people used same login/password for their affiliate program accounts and their Epassporte account, they're fucking retarded and should have their money stolen.

:2 cents:

polish_aristocrat 12-23-2007 06:11 AM

Quote:

Originally Posted by slavdogg (Post 13554513)
if you use epass
you're a scammer
simple as that.

so 90% of the adult industry are scammers...

slavdogg 12-23-2007 06:15 AM

Quote:

Originally Posted by polish_aristocrat (Post 13554542)
so 90% of the adult industry are scammers...

the same 90% that controls 10% of all joins ??

yes if u use epass as your payout method, you're a scammer and should not be trusted.

slavdogg 12-23-2007 06:16 AM

Quote:

Originally Posted by Emil (Post 13554536)
If people used same login/password for their affiliate program accounts and their Epassporte account, they're fucking retarded and should have their money stolen.

:2 cents:

agreed

hope more money gets stolen out of people's epass accnts

Jet - BANNED FOR LIFE 12-23-2007 06:17 AM

Quote:

Originally Posted by slavdogg (Post 13554513)
if you use epass
you're a scammer

you're an idiot.

slavdogg 12-23-2007 06:19 AM

Quote:

Originally Posted by Jet (Post 13554554)
you're an idiot.

voice of an epass scammer ?

minusonebit 12-23-2007 06:23 AM

Man this is scary, you might be right. Maybe it was NATS.

marketsmart 12-23-2007 06:23 AM

Quote:

Originally Posted by slavdogg (Post 13554513)
if you use epass
you're a scammer
simple as that.

and u'r one dumb motherfucker for trusting epass with your money.

and you are a fucking noob.... shall i list all the companies that pay me by epass? i guarantee they are bigger that 90% of all the programs out there...

Ray@TastyDollars 12-23-2007 06:26 AM

Webmaster, Epass, Biller, Admin, ect. Passwords are not available within the NATS admin area, all they/we see is ********.

The ONLY passwords they would be able to get a hold of with Admin access are member passwords.

The only place the passwords are stored are in the DB and it is encrypted. So the chances that your pass has been decrypted is very slim.

I can't speak for all programs but I can speak for mine, our DB was NOT compromised. Heck neither was our admin area, thanks to my host!

Ray

Jet - BANNED FOR LIFE 12-23-2007 06:29 AM

Quote:

Originally Posted by Ray@TastyDollars (Post 13554571)
The only place the passwords are stored are in the DB and it is encrypted. So the chances that your pass has been decrypted is very slim.

Why are you so sure of that?

slavdogg 12-23-2007 06:29 AM

Quote:

Originally Posted by marketsmart (Post 13554570)
and you are a fucking noob.... shall i list all the companies that pay me by epass? i guarantee they are bigger that 90% of all the programs out there...

come suck my balls epass scammer

slavdogg
Registered User
Join Date: Jan 2001
Posts: 2,350

Jet - BANNED FOR LIFE 12-23-2007 06:34 AM

slavdog this is uncalled for.

I use epassporte for my sponsor payouts. And I am honest person.

Ray@TastyDollars 12-23-2007 06:34 AM

Quote:

Originally Posted by Jet (Post 13554575)
Why are you so sure of that?

Because when you log into nats admin you dont see them and the only place you can get them is in the DB. This hack targeted the admin area only. Again, i speak for my program when I say our DB's have deff. NOT been hacked and im pretty sure this is the case for most other programs as well.

Admin area does not mean DB, simple.

Ray

Jet - BANNED FOR LIFE 12-23-2007 06:37 AM

Quote:

Originally Posted by Ray@TastyDollars (Post 13554586)
Because when you log into nats admin you dont see them and the only place you can get them is in the DB. This hack targeted the admin area only. Again, i speak for my program when I say our DB's have deff. NOT been hacked and im pretty sure this is the case for most other programs as well.

Admin area does not mean DB, simple.

Ray

I meant why you were so sure that the DB can't be hacked.

Iven John has admitted it was very possible.

Ray@TastyDollars 12-23-2007 06:43 AM

Quote:

Originally Posted by Jet (Post 13554592)
I meant why you were so sure that the DB can't be hacked.

Iven John has admitted it was very possible.

Even the Pentagon is hackable right? In this particular case the admin area was compromised. I spoke to many program owners last night and they all confired with their hosts that their DB's had not been hacked.

In THIS particular case.

Jet - BANNED FOR LIFE 12-23-2007 06:48 AM

Quote:

Originally Posted by Ray@TastyDollars (Post 13554596)
I spoke to many program owners last night and they all confired with their hosts that their DB's had not been hacked.

In THIS particular case.

How do they know if their DBs were hacked or not?

There are sponsors who say that full DB dumps were made by the intruder.

There is no way for the sponsors to know what happened to the stolen DBs.

Ray@TastyDollars 12-23-2007 06:51 AM

Quote:

Originally Posted by Jet (Post 13554605)
Ho

There are sponsors who say that full DB dumps were made by the intruder.


wow im really sorry to hear that! If they indeed were able to get a db dump just by having admin access I really hope these sponsors get their hosts to secure there db's a little better. Its bad enough that they had admin access, but db access to, fuck! :(

Trixxxia 12-23-2007 07:15 AM

Jet - not every program was hacked or compromised.
Some hosts are very diligent with their security and what access they allow on their servers. We are amongst some mighty happy clients of Swiftwill today and very very very thankful of their diligence.

borked 12-23-2007 07:24 AM

Quote:

Originally Posted by Jet (Post 13554605)
How do they know if their DBs were hacked or not?

There are sponsors who say that full DB dumps were made by the intruder.

There is no way for the sponsors to know what happened to the stolen DBs.

Wow that sucks. The sponsors that had their databases wripped also had some serious security issues, unrelated to the current NATS security problem. They really do need to get their hosts to lock things down better :2 cents:

Iron Fist 12-23-2007 09:57 AM

Quote:

Originally Posted by v4 media (Post 13554533)
Blame Canada

:1orglaugh:1orglaugh:1orglaugh:helpme

HouseHead 12-23-2007 10:12 AM

lawsl you kids silly kids

notoldschool 12-23-2007 10:15 AM

Quote:

Originally Posted by slavdogg (Post 13554513)
if you use epass
you're a scammer
simple as that.

and u'r one dumb motherfucker for trusting epass with your money.

DING DING DING......Surfer alert.

fuckingfuck 12-23-2007 10:19 AM

Epass works perfectly for me. I guess it's a few dimwits who have their money stolen (by giving their epass passwords to "epass reps" on msn!)

patmccrotch 12-23-2007 10:58 AM

Quote:

Originally Posted by Jet (Post 13554554)
you're an idiot.

Funny coming from someone who started such an ignorant thread. Passwords are encrypted in nats as well as database information. The "hacker" who was snagging access via the nats admin couldn't even retrieve the encrpyted password string of an affiliate account to try and decrypt it.

Never the less, epassporte passwords are not even stored in nats.

dipshit.

MrVids 12-23-2007 11:14 AM

Quote:

Originally Posted by Jet (Post 13554605)
How do they know if their DBs were hacked or not?

There are sponsors who say that full DB dumps were made by the intruder.

There is no way for the sponsors to know what happened to the stolen DBs.

Because the database password is not configurable via the admin and the encrypted string for the database password isn't even available via the admin for the "hacker" to try and decrypt it. Plus 95% of the time mysql databases are either IP restricted for access _or_ restricted solely to localhost for access.

woj 12-23-2007 01:12 PM

Quote:

Originally Posted by patmccrotch (Post 13555097)
Funny coming from someone who started such an ignorant thread. Passwords are encrypted in nats as well as database information. The "hacker" who was snagging access via the nats admin couldn't even retrieve the encrpyted password string of an affiliate account to try and decrypt it.

Never the less, epassporte passwords are not even stored in nats.

dipshit.

A clever hacker could find at least a few ways to extract the passwords from the admin area. :2 cents:

The problem is, that some people may have used same password for nats as they used for epassporte. It's not very smart, but it's very possible that some users would actually do that.

slavdogg 12-23-2007 05:07 PM

Quote:

Originally Posted by woj (Post 13555491)
A clever hacker could find at least a few ways to extract the passwords from the admin area. :2 cents:

The problem is, that some people may have used same password for nats as they used for epassporte. It's not very smart, but it's very possible that some users would actually do that.

if that was the case i hope their epass accnts got cleaned out.

DamageX 12-23-2007 05:10 PM

Quote:

Originally Posted by Trixxxia (Post 13554638)
Jet - not every program was hacked or compromised.
Some hosts are very diligent with their security and what access they allow on their servers. We are amongst some mighty happy clients of Swiftwill today and very very very thankful of their diligence.

Stop hackers dead - use SwiftWill. :)

papill0n 12-23-2007 05:21 PM

Quote:

Originally Posted by slavdogg (Post 13554548)
yes if u use epass as your payout method, you're a scammer and should not be trusted.

yeah, everyone who uses epassporte is a scammer :1orglaugh :helpme :Oh crap

xentech 12-23-2007 05:32 PM

Very good point Jet

Pleasurepays 12-23-2007 09:09 PM

Quote:

Originally Posted by notoldschool (Post 13555027)
DING DING DING......Surfer alert.


hahah..

GFY is always entertaining. Now we have surfers calling out industry legends that they think are surfers


:1orglaugh:1orglaugh:1orglaugh


All times are GMT -7. The time now is 10:46 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc