GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   CCBill.com multiple vulnerabilities (https://gfy.com/showthread.php?t=982701)

Supz 10-15-2010 03:25 PM

Quote:

Originally Posted by closer (Post 17422331)
Any site can be hacked/cracked,

a financial/banking site should be held up to much higher security standards, as this could potentially give yet another HUGE blow to the adult industry as a whole, which is already at its weakest point to date, if this becomes a CNN item, we're not talking facebook here.

In the end, the only real opinion that should matter in such cases is how fast that hacked site fixes the backdoors.

It's good to read that CCBill is looking into it and hope they'll update us with any news.

They are held at a higher standard. CC processors have to be PCI (payment card industry) compliant. Which is a much higher standard beyond normal network security. Same thing with Banks, brokerage firms, hospitals. So on so forth.

signupdamnit 10-15-2010 03:38 PM

Quote:

Originally Posted by RonC (Post 17610294)
This report was a complete joke. This was just a variation of a Nigerian scam. We contacted the website and they responded via GMAIL if we would "Western Union" them 10k they would tell us what was wrong. LOL They create a fake security page and post stuff and hope companies will pay the blackmail money VIA WESTERN UNION (LOL)

But hey if it is on the Internet it MUST BE TRUE.

End of Story.


Ron C
_________
CEO

CCbill.com
Cavecreek.com

Interesting. I suppose we all should have researched this further before giving it credence.

I see where your team spoke about this months ago:

http://seclists.org/fulldisclosure/2010/Aug/193

Quote:

From: William Bell <williamb () cwie net>
Date: Tue, 17 Aug 2010 03:52:19 +0000

At CCBill we take web application security very seriously. I can assure you that no one in this organization received
any type of disclosure prior to the posting of the vulnerability to this list. It is very easy to reach our Information
Security team at security () ccbill com<mailto:security () ccbill com>. We are working hard to identify the issue in
question and a post will be made here once it is resolved. I ask that the researcher from ariko-security.com please
contact us at the email provided.

William Bell
Director of Information Security
CCBill.com

_______________
I had never heard of these guys before but now I will research them and see if they have tried this in the past with others. If so I will make sure more people know about them.

SwirlsGirl 10-15-2010 09:05 PM

Quote:

Originally Posted by RonC (Post 17610294)
This report was a complete joke. This was just a variation of a Nigerian scam. We contacted the website and they responded via GMAIL if we would "Western Union" them 10k they would tell us what was wrong. LOL They create a fake security page and post stuff and hope companies will pay the blackmail money VIA WESTERN UNION (LOL)

But hey if it is on the Internet it MUST BE TRUE.

End of Story.


Ron C
_________
CEO

CCbill.com
Cavecreek.com

Hey Ron nice of you to stop in...also nice to meet you by the way. I also know some individuals that have recently been scammed.

There seems to be plenty of that going around these days. If I am not mistaken one of the scammers were of Nigerian origin. Another seems to be of American origin.

I wonder if you would mind posting the contact info or the gmail email account so that some of us may give the nigerian scammers a piece of our mind as well.

You say they created a "fake" security page and tried to extort 10k from you guys for a fix? Man that is pretty crass.

It is also very reassuring to know that all of my data as a client is secure and that you guys take data integrity so seriously.

After all what is really being sold here is confidence and a processing companies success is only as good as its clients confidence in it of said "data integrity"

Please post the contact info for the scammers would love to communicate with them.

Also thanks for the "hey if its on the internet its true" comment, I am still chuckling uncontrollably from that one:)

epitome 10-15-2010 09:59 PM

Quote:

Originally Posted by SwirlsGirl (Post 17611975)
Hey Ron nice of you to stop in...also nice to meet you by the way. I also know some individuals that have recently been scammed.

There seems to be plenty of that going around these days. If I am not mistaken one of the scammers were of Nigerian origin. Another seems to be of American origin.

I wonder if you would mind posting the contact info or the gmail email account so that some of us may give the nigerian scammers a piece of our mind as well.

You say they created a "fake" security page and tried to extort 10k from you guys for a fix? Man that is pretty crass.

It is also very reassuring to know that all of my data as a client is secure and that you guys take data integrity so seriously.

After all what is really being sold here is confidence and a processing companies success is only as good as its clients confidence in it of said "data integrity"

Please post the contact info for the scammers would love to communicate with them.

Also thanks for the "hey if its on the internet its true" comment, I am still chuckling uncontrollably from that one:)

Dear Britney,

I am writing today to let you know how awesome you are. Your music is great and it always picks me up when I am down. My cousin is a singer but she is not as good as you.

Remember that one time they asked you in an interview if you were a virgin and you said you were but it turns out you weren't? Well, that was pretty rude of them. Please give me the email address of that interviewer. I'd love to give them a piece of my mind.

Hey Britney, would you mind mailing me back with your concert dates? I'd love to see one of your shows.

Anyway, I feel some sort of closeness with you after writing this. I hope that you'll send me an autographed picture.

Fondly,
Your #1 Fan

plsureking 10-15-2010 11:47 PM

Quote:

Originally Posted by RonC (Post 17610294)
This report was a complete joke. End of Story.

there's too many eager hackers in Russia & China for this to not be a joke..

redwhiteandblue 10-16-2010 03:11 AM

Quote:

Originally Posted by Supz (Post 17611254)
They are held at a higher standard. CC processors have to be PCI (payment card industry) compliant. Which is a much higher standard beyond normal network security. Same thing with Banks, brokerage firms, hospitals. So on so forth.

:2 cents:

I worked for an e-commerce company that went through PCI compliance for all its servers and it is extremely thorough, and as I understand it anything that stores CC data has to be PCI compliant.

AdultKing 10-16-2010 04:49 AM

Reading this thread had me shaking my head.

Why would you give credence to a company issuing an advisory when they have an about us page like this

Doing a WHOIS on the domain reveals Polish contact details with a hotmail email address. Very professional.

Look at the credibility of the web site - it was registered in 2009 and is obviously, I mean so scammer obviously, bogus.


All times are GMT -7. The time now is 04:06 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123