GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   attn: Reality Check Network (https://gfy.com/showthread.php?t=992770)

Abracadabra_nl 10-17-2010 12:52 AM

Quote:

Originally Posted by Roald (Post 17614580)
So whats the status now, I see Pichunter is back up.

They have been up like this for more than 12 hours. But the thumbs don't show up

Roald 10-17-2010 12:54 AM

Quote:

Originally Posted by Abracadabra_nl (Post 17614581)
They have been up like this for more than 12 hours. But the thumbs don't show up

Oops was too fast, saw it loading and thought they were up.

My bad.

Soo which paysite programs are affected? I would like to put their links on backup till all is fixed for obvious reasons.

Andy22 10-17-2010 12:56 AM

gl getting it sorted. im on a small server there but luckily dont have any big income producing sites anymore. RCN have been good over the years though, i hope they get this shit fixed.

sandman! 10-17-2010 01:14 AM

your an idiot.


Quote:

Originally Posted by Tippy (Post 17613954)
I'm seeing a lot of these sites/domains going nowhere, you should set something up and redirect your domains. Seems crazy to just leave your sites/domains dead for this amount of time.

Just wanted to add, as mentioned, do you think its a good idea to host a legit site on a server hosting illegal tubes, seems risky these days considering.


sandman! 10-17-2010 01:17 AM

if rcn was located near brad im sure he would lend a hand not all hosting companies work like vultures.


Quote:

Originally Posted by Machete_ (Post 17614202)
Nigga please. It's a PR stunt to woo the resident sheep and possibly lure the current RCN clients in.

Get real, no one is flying any techs anywhere.


Matyko 10-17-2010 01:40 AM

Quote:

Originally Posted by Jdoughs (Post 17613688)
I'd rep you but I can't. Solid offer.

+1 :pimp

Abbie 10-17-2010 01:40 AM

Quote:

Originally Posted by Roald (Post 17614587)
Oops was too fast, saw it loading and thought they were up.

My bad.

Soo which paysite programs are affected? I would like to put their links on backup till all is fixed for obvious reasons.

Here's a starting place: http://serversiders.com/as46652

madawgz 10-17-2010 01:50 AM

guys at rcn must be so stressed :\

tg989 10-17-2010 02:01 AM

One logical explanation is the following:

Somebody got ahold of the root ssh key, likely an ex employee or current employee.

They logged into all the machines, changed the root pass/keys or replaced the ssh server with a custom one and then systematically disabled apache/lighttpd/nginx/mysql/pgsql etc (you'll notice that the sites running apache show forbidden but the ones that were running lighttpd just time out), then they gave rcn an ultimatum, effectively holding them hostage for a calculated sum of money (somebody who knows what is at stake, again, likely an employee/ex-employee). They probably also had the insight to make sure backups were affected as this really don't seem like a heat-of-the-moment thing. This is premeditated. The servers are still online, they are still 'running' the dns is still working... nothing was 'corrupted' or trashed, RCN just doesn't have access any more, holding them in a tight position as the servers are spread out in multiple locations and they don't have anyone 'infront' of them to use the console or do mass operating system re-installs+backup recoveries.

This is the only situation that really makes sense, there is NO gain to be made from hacking RCN and deleting everything. There is always motive involved, almost always monetary. As such, I assume somebody is doing this for financial gain and they are likely holding it hostage until they get the money, which if it is a wire, would be quite a few days. :\ I know of a registrar that was in a very similar situation recently. This registrar was being ddosed by a disgruntled ex-customer who had their domains deleted or blocked and they basically kept ddossing the domain servers until the registrar finally gave in.

I really don't want this to turn into an epass drama thread/situation and incite pandemonium or mass exodus, but this is really the most probable situation as it stands now.

:2 cents:

Abracadabra_nl 10-17-2010 02:34 AM

Quote:

Originally Posted by tg989 (Post 17614685)
I really don't want this to turn into an epass drama thread/situation and incite pandemonium or mass exodus, but this is really the most probable situation as it stands now.

:2 cents:

Well, isn't this what you are doing right now? :winkwink:

carrion1928 10-17-2010 02:55 AM

Quote:

Originally Posted by tg989 (Post 17614685)
One logical explanation is the following:

Somebody got ahold of the root ssh key, likely an ex employee or current employee.

They logged into all the machines, changed the root pass/keys or replaced the ssh server with a custom one and then systematically disabled apache/lighttpd/nginx/mysql/pgsql etc (you'll notice that the sites running apache show forbidden but the ones that were running lighttpd just time out), then they gave rcn an ultimatum, effectively holding them hostage for a calculated sum of money (somebody who knows what is at stake, again, likely an employee/ex-employee). They probably also had the insight to make sure backups were affected as this really don't seem like a heat-of-the-moment thing. This is premeditated. The servers are still online, they are still 'running' the dns is still working... nothing was 'corrupted' or trashed, RCN just doesn't have access any more, holding them in a tight position as the servers are spread out in multiple locations and they don't have anyone 'infront' of them to use the console or do mass operating system re-installs+backup recoveries.

This is the only situation that really makes sense, there is NO gain to be made from hacking RCN and deleting everything. There is always motive involved, almost always monetary. As such, I assume somebody is doing this for financial gain and they are likely holding it hostage until they get the money, which if it is a wire, would be quite a few days. :\ I know of a registrar that was in a very similar situation recently. This registrar was being ddosed by a disgruntled ex-customer who had their domains deleted or blocked and they basically kept ddossing the domain servers until the registrar finally gave in.

I really don't want this to turn into an epass drama thread/situation and incite pandemonium or mass exodus, but this is really the most probable situation as it stands now.

:2 cents:

A DDOS is clearly not what's happening here and is a TOTALLY different situation.

No one is holding anything hostage. A common phrase in the networking world is there's no security without physical security. In other words, if you can access a box, you can't lock someone out of it. A company hosting as many large sites as RCN has physical access to the machine, either personally, or through their data center. You can reset the root password of a box in 5 minutes if you can actually get to it. So unless you're implying that their data centers are literally being held hostage, IE: with guns, then your just fear mongering.

Also, anger and revenge are plenty of motive. In fact, their some of the best motives and pretty damn common. It's definitely possible (even likely) that the hacker is a current or ex employee, though.

Tippy 10-17-2010 04:05 AM

Quote:

Originally Posted by sandman! (Post 17614605)
your an idiot.

Because... ? Dude you can do better then that can't you, elaborate on it.

Mike

Denny 10-17-2010 04:09 AM

many big sites are still down, that really sucks :Oh crap

b2kill 10-17-2010 05:18 AM

Last news from them:

"We are still in progress on restoring data and connectivity, we'll update you with more details as soon as possible."

:disgust

tg989 10-17-2010 05:49 AM

Quote:

Originally Posted by carrion1928 (Post 17614746)
A DDOS is clearly not what's happening here and is a TOTALLY different situation.

No one is holding anything hostage. A common phrase in the networking world is there's no security without physical security. In other words, if you can access a box, you can't lock someone out of it. A company hosting as many large sites as RCN has physical access to the machine, either personally, or through their data center. You can reset the root password of a box in 5 minutes if you can actually get to it. So unless you're implying that their data centers are literally being held hostage, IE: with guns, then your just fear mongering.

Also, anger and revenge are plenty of motive. In fact, their some of the best motives and pretty damn common. It's definitely possible (even likely) that the hacker is a current or ex employee, though.

If they could just boot into a shell and reset the root password for all the boxes in only 5 minutes then we'd be out of this already, wouldn't we?

I would be very surprised to see if this wasn't about money, somewhere along the line of motives.

Also, just to clarify, I wasn't implying that this was due to a ddos, just that the same effect would be achieved, a controllable lapse of service that somebody could use as leverage. Anyway, sure would be good to get a proper update with some details to put some worries to rest.

OneWhoKnows 10-17-2010 06:26 AM

Quote:

Originally Posted by tg989 (Post 17614685)
This is the only situation that really makes sense, there is NO gain to be made from hacking RCN and deleting everything. There is always motive involved...

Hmmm... Well, traffic on my biggest tube (legal, of course) increased by 7k overnight. Plus I'm making some mad sales during the last 1 1/2 days. And I hear the same from other webmasters and program owners.

Might just be a coincidence, but I definitely see some motives here. :winkwink:

AdultKing 10-17-2010 06:35 AM

I wonder when someone will claim responsibility.

These sites have been down for a while, but seriously, you'd expect RCN to be able to put a short explanation on their website which is now just 403 Forbidden.

I wonder if some security guys will be looking for a new job Monday ?

dodgeman 10-17-2010 06:37 AM

My traffic incrased, too.

Trax 10-17-2010 07:07 AM

with sales and traffic up i wouldnt mind xvideos staying down
screw them

CaptainHowdy 10-17-2010 08:07 AM

"I get up, I get downnnnnn..."

gleem 10-17-2010 08:13 AM

Still nothing other than canned responses from them this morning:

"We are doing our best to restore as fast a possible"

"We are creating processes to streamline reinstalls/backup restores"


:Oh crap

ThumbLord 10-17-2010 08:15 AM

yep traffic to my legal tubes went up, sales are the same.

OneWhoKnows 10-17-2010 08:20 AM

Quote:

Originally Posted by Trax (Post 17615108)
with sales and traffic up i wouldnt mind xvideos staying down
screw them

:thumbsup :thumbsup

However, I still feel for the legit people hosting with them, such as vidz.com or RevengeBucks. Good luck getting your sites up again asap - I still remember how I felt when I had a day downtime about a year ago.

rhizome 10-17-2010 08:26 AM

this is ridiculous

blablabla 10-17-2010 09:18 AM

rcn will send out official mail soon, they said

- LOL - 10-17-2010 09:20 AM

new update:

Quote:

We've been working on finalizing the restore process and automating it with scripts so that we can get the servers online as rapidly as possible. We are creating work queues and assigning servers to them therefore we will be able to provide a more concrete ETA for restores shortly.

We are also in the process of finalizing agreements that will allow us to increase manpower significantly as well as provide a stable infrastructure when the servers are restored.

In terms of the damage to the servers it was corruption of the MBR and initial sectors on the hard drive. For customers with large attached storage devices your content should be unaffected as it was not part of the primary RAID configuration.

As for the intrusion it was the result of an ex-employee who was with us for three years as a result he had intimate knowledge of our systems which is why the effects are so large.

We have made significant progress on the backend and we feel that we are reaching a point where the recovery process can begin ramping up full force. We will be sending another update soon, and thanks again to everyone for the outpouring of support - we're working as hard and smart as we can to get everyone back online.

Agent 488 10-17-2010 09:28 AM

damn i hope they keep their employees happier from now on, throw a bigger xmas party or something.

Machete_ 10-17-2010 09:35 AM

Wonder what the rogue employee was mad about.

OneWhoKnows 10-17-2010 09:40 AM

Quote:

Originally Posted by Machete_ (Post 17615477)
Wonder what the rogue employee was mad about.

Well, maybe there were just a few people, not liking some of the sites hosted at RCN that much, who made him an offer he couldn't refuse :2 cents:

willwank 10-17-2010 09:40 AM

Quote:

Originally Posted by - LOL - (Post 17615430)
new update:
it was the result of an ex-employee who was with us for three years

http://pornbundles.com/toast1.jpg

Ron2k1 10-17-2010 10:05 AM

Quote:

Originally Posted by Machete_ (Post 17615477)
Wonder what the rogue employee was mad about.

maybe it's just a lame excuse, you'll never know if it was really an ex-employee

pentae 10-17-2010 10:09 AM

I hope this ex-employee gets put in jail for a long time

Klaus.Shultse 10-17-2010 10:10 AM

good news :) hopefully the tubes like xnxx etc dont have any backups , look at your stats yesterday and today :) fucking unbelievable . i saw the same numbers about a year ago . thats perfect , the guy who made it is a REAL MAN.

Agent 488 10-17-2010 10:11 AM

seems like a lot of increased sales reports ...

Quence 10-17-2010 10:22 AM

I don't see what's all the fuss is about. The few tubes that went down don't even hold the top google positions.

Why don't you bitch about pornhub.com, redtube.com, youporn.com, tube8.com? These are the biggest and hold top 10 google spots.

Klaus.Shultse 10-17-2010 10:38 AM

Quote:

Originally Posted by Quence (Post 17615732)
I don't see what's all the fuss is about. The few tubes that went down don't even hold the top google positions.

Why don't you bitch about pornhub.com, redtube.com, youporn.com, tube8.com? These are the biggest and hold top 10 google spots.

Hopefully will be shut down soon too

Roald 10-17-2010 10:41 AM

Quote:

Originally Posted by Quence (Post 17615732)
I don't see what's all the fuss is about. The few tubes that went down don't even hold the top google positions.

Why don't you bitch about pornhub.com, redtube.com, youporn.com, tube8.com? These are the biggest and hold top 10 google spots.

Maybe it's time to start looking for a rogue ex employee at their hosting?

cosis 10-17-2010 10:44 AM

Quote:

Originally Posted by Klaus.Shultse (Post 17615663)
good news :) hopefully the tubes like xnxx etc dont have any backups , look at your stats yesterday and today :) fucking unbelievable . i saw the same numbers about a year ago . thats perfect , the guy who made it is a REAL MAN.

If xnxx or xvideos went down surfers know there are 10 other tubes to visit. I wouldn't look to deep into this.

Quence 10-17-2010 10:47 AM

Quote:

Originally Posted by Klaus.Shultse (Post 17615784)
Hopefully will be shut down soon too

i wouldnt hold the breath..

slowloris 10-17-2010 10:53 AM

Most people I know are unaware of tubes, until I show them whats available for free. And xvideos was the #55 site in the world, and accounts for 1.5% of all internet traffic. I'm not sure what percentage of all internet traffic is porn related, but if we imagine it's 20% then xvideos would account for 7.5% or all porn traffic. That in itself is a sizeable amount of surfers who are forced to go back to the search engines looking for porn, if they don't know of any other tubes - which is bound to impact sales (especially if you rate highly for some good keywords)

DWB 10-17-2010 11:03 AM

Quote:

Originally Posted by sandman! (Post 17614605)
your an idiot.

I never tire of the simple irony that usually comes from "your an idiot" posts. :1orglaugh

SNRProductions 10-17-2010 11:11 AM

Quote:

Originally Posted by pentae (Post 17615654)
I hope this ex-employee gets put in jail for a long time

Seriously...I hope they say who it is so we can personally sue him.

tehHinjew 10-17-2010 11:21 AM

could it be this kid?


JosephFM 10-17-2010 12:02 PM

I don't know if it related to this but the traffic to my sites has increased a lot in these past two days.

madawgz 10-17-2010 01:39 PM

hope there is an update soon...

madawgz 10-17-2010 02:46 PM

please post if your server has been fully restored...thanks!

cybermike 10-17-2010 03:14 PM

http://torrentfreak.com/major-torren...ovider-101017/

Domain Broker 10-17-2010 03:48 PM

Quote:

Originally Posted by Domain Broker (Post 17612943)
so every server suffered from the same vulnerability, or

every server had the same global administrator account/password, or

rogue employee.

which one is it?

http://imgur.com/E9EI4.jpg

Klen 10-17-2010 04:26 PM

Quote:

Originally Posted by cybermike (Post 17616411)

Interesting,apparently 4chan competitor is hosting as well there.

Doctor Dre 10-17-2010 04:44 PM

Quote:

Originally Posted by Machete_ (Post 17614202)
Nigga please. It's a PR stunt to woo the resident sheep and possibly lure the current RCN clients in.

Get real, no one is flying any techs anywhere.

hahahha
someone called him out on it, now he might have too.


All times are GMT -7. The time now is 06:35 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc