$100 reward to be won

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Gals4free
    Confirmed User
    • Apr 2003
    • 428

    #1

    $100 reward to be won

    Hey guys,

    Allright, i posted my problem a few days ago without to much usefull feedback to get the problem solved. So since i need this solved, im offering $100 to anyone who can permanently solve my problem.

    I run www.gals4free.net, and since about a week, when i click to see galleries i sometimes get www.mea-movies.com (NOTE: not the original mia-movies.com, but someone who is ripping that site). This is very odd, as:

    1. I dont trade with that site
    2. Its not gallery specific, as i checked this and got it even on my own galleries
    3. its not some other trade trying to fuck me
    4. its no spy/adware as i checked this from many different pc's by now.

    I had the more common stuff ruled out, ATX got checked twice and its for sure not that. My bet is on comus, but with Tony in hospital and someone else checking, who said its not comus, i cant be 100%. Apache got checked, and so did htaccess.

    So basicly, anyone who knows the permanent solution to this and it actually works, ill be more then happy to send $100.

    ICQ me if you think you know : 59661018

    Regards

    Steve

    Link to old topic incase you can pick up usefull info there : http://www.gofuckyourself.com/showthread.php?p=7518727
    At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!
  • FunForOne
    Confirmed User
    • Nov 2003
    • 8704

    #2
    Only help I can give you is a bump

    Comment

    • DamageX
      Marketing & Strategy
      • Jun 2001
      • 14293

      #3
      Originally posted by FunForOne
      Only help I can give you is a bump
      I second that, for now.
      Whitehat is for chumps

      If you don't do it, somebody else will - true story!

      Comment

      • xXxtreme2005
        Confirmed User
        • Feb 2005
        • 717

        #4
        strange but ill bump it for ya


        GOT TRAFFIC?.......
        I BUY TRAFFIC
        ICQ 318-368-640

        Comment

        • ssp
          Confirmed User
          • Jan 2005
          • 7990

          #5
          Are you using a free tradescript? Could it be that the 1% of your traffic is sent to a website of the tradescript owner? Perhaps you clicked too much and excessive clicks get sent to that site. Hope this helps you.

          Comment

          • Gals4free
            Confirmed User
            • Apr 2003
            • 428

            #6
            nope... clearly states in my first post i use ATX
            At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!

            Comment

            • klinton
              So Fucking Banned
              • Apr 2003
              • 8766

              #7
              Originally posted by Gals4free
              3. its not some other trade trying to fuck me
              are you 100 % sure that none of your trades doesn't redirect to mia-movies in any way ?

              anyway, bump for you.
              Last edited by klinton; 06-08-2005, 08:31 AM.

              Comment

              • brilsmurf
                Confirmed User
                • Feb 2005
                • 3405

                #8
                bump for you!
                The Best Adult Web Hosting of 2008 - http://www.adulthosting.com
                Affiliate Program – http://www.sxcash.com

                Comment

                • nosey
                  Talk Hard
                  • Feb 2003
                  • 14413

                  #9
                  add mea-movies.com to your trade script & disable it

                  | Domain whois privacy Free || GFY favored Hosting |
                  $Chaturbate || FpcTraffic FPCPlugs || PlugRush Traffic

                  Comment

                  • boner 2.0
                    Too lazy to set a custom title
                    • Jul 2004
                    • 10970

                    #10
                    Another bump... Very strange

                    Comment

                    • Gals4free
                      Confirmed User
                      • Apr 2003
                      • 428

                      #11
                      Originally posted by boner 2.0
                      Another bump... Very strange
                      Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.
                      At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!

                      Comment

                      • nosey
                        Talk Hard
                        • Feb 2003
                        • 14413

                        #12
                        Originally posted by Gals4free
                        Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.
                        yeah its not atx...

                        clear cache & cookies,
                        click here > http://www.gals4free.net/ct/cx.php?i=000&s=100&t=1
                        second click redirects to mea-movies.com

                        re-install comus, script is corrupt

                        | Domain whois privacy Free || GFY favored Hosting |
                        $Chaturbate || FpcTraffic FPCPlugs || PlugRush Traffic

                        Comment

                        • wdsguy
                          Ryde or Die
                          • Dec 2002
                          • 19568

                          #13
                          bump for ya

                          Comment

                          • tranza
                            ICQ: 197-556-237
                            • Jun 2003
                            • 57559

                            #14
                            Damn, that's a tough one... I have no idea...
                            I'm just a newbie.

                            Comment

                            • taibo
                              Confirmed User
                              • May 2005
                              • 3720

                              #15
                              bump.. somebody in here should know

                              Comment

                              • sixzeros
                                Registered User
                                • Aug 2002
                                • 53

                                #16
                                Just took a look at Comus for you.

                                It looks like someone has stolen your FTP account and has placed their own code on the system, and have removed comus.

                                They've renamed the main cx.php to ctx.php and they are using zend encoded PHP scripts, so it is hard to see exactly what they have dumped on there, but we know at least it is a simple script of less than 1000 bytes long.

                                It would appear that they have also dumped a trojan on the machine, because they appear to be able to change files that neither comus nor your FTP account would naturally have the ability/permissions to change.

                                One way someone can test if they might be infected is to check the file size of /ct/cx.php if it less than 10k then you have a very suspect situation.

                                I suggest you move everything to a new server, and be very selective about what PHP files you copy over, best bet is to reinstall comus and your trade scripts clean, and then import the data and templates only.

                                I thought I posted earlier but it didnt seem to take, I suggested using commview, its a packet sniffer that lets you see what headers are being generated, so you can see exactly what is happening in your browser.. You would have been able to see that clicks were bouncing from index page -> cx.php -> ctx.php -> ATX .. and by comparing the path to a non-hacked site you'd see the different path and the culprit files. ctx.php should not be there.

                                I've never actually seen anyone do this before, its a first, but now that it has happened, I'll make something in Comus that will run an auto integrity check of the main files, it should make it impossible for anyone to do this again.

                                I feel for ya bro, F@$@#$'n hackers suck

                                -----------------
                                sixzeros - Comus Thumbs Author
                                Last edited by sixzeros; 06-10-2005, 02:38 AM.
                                http://comusthumbs - TGP Thumbnailer - The Power and Support you need to grow your TGP site.

                                Comment

                                • Dirty F
                                  Too lazy to set a custom title
                                  • Jul 2001
                                  • 59204

                                  #17
                                  Well at least you know where to find the asswiper. Contact his host and shit.

                                  Comment

                                  • brilsmurf
                                    Confirmed User
                                    • Feb 2005
                                    • 3405

                                    #18
                                    franck, you still need a transfer? i can do it now
                                    The Best Adult Web Hosting of 2008 - http://www.adulthosting.com
                                    Affiliate Program – http://www.sxcash.com

                                    Comment

                                    Working...