What you missed ? Records of transactions, including customers names, ip #'s, addresses, phone numbers, etc.. Database usernames and passwords, source code in the open waiting to be exploited, traversable directory paths, etc.
Free Premium Domain Lists and Tools at Clickmojo.com
What you missed ? Records of transactions, including customers names, ip #'s, addresses, phone numbers, etc.. Database usernames and passwords, source code in the open waiting to be exploited, traversable directory paths, etc.
It boogles my mind. What sort of idiot programmer would put that sort of data way out there like that.. Asses need to be fired...
I reccomend ES strongly over any other affiliates script out there these days.
ialien has built and helped build several affiliates programs with Executive Stats.
Thats the core of my business.
Not just building tours. I build the whole fucking thing so I am speaking with experience when it comes to support issues, contact and customizations.
Just two cents, ALL SCRIPTS ARE VULNERABLE TO HAX.
Parlor tricks...
There are many reasons not to like competing scripts.
Nats was funded in a bad way. Tis true, ask around and when ya get the dirt ya would be shocked.
MPA. Nuff said of the bad press over the years though it is good and definatly better than NATS.
RiverStyx. Its just old.
That does it, any company that purchases a top banner spot on GFY has to be out of their fucking minds.
Whats worth more. 1 top banner spot in a rotation of 30+ banners?
Or
61,000 half page ads??
"We are told to let our light shine, and if it does, we won't need to tell anybody it does. Lighthouses don't fire cannons to call attention to their shining- they just shine."
It boogles my mind. What sort of idiot programmer would put that sort of data way out there like that.. Asses need to be fired...
Yep, log files with information that sensitive should've been encrypted. The programmer/admin's oversight was not setting their directory permissions correctly. Lucky for Brad, that is an error that only takes minutes to correct.
Yep, log files with information that sensitive should've been encrypted. The programmer/admin's oversight was not setting their directory permissions correctly. Lucky for Brad, that is an error that only takes minutes to correct.
yeah,too bad now mailers are going to hammer the shit out of the information leaked here
Yep, log files with information that sensitive should've been encrypted. The programmer/admin's oversight was not setting their directory permissions correctly. Lucky for Brad, that is an error that only takes minutes to correct.
true.. but you have to wonder about the quality/experience of the dev team behind it, if they're making mistakes this blatant..
would you drive a car after the mechanic who serviced it apologises for forgetting to inflate the tires?
Hi... wow.. this blew up out of no where.. was feeding my new 3 week old son.. and got the phone call from hell...
thank Fris... for pointing this out.. as I mentioned in Montreal.. we were looking for a security person to do work for us.... as the one person I had contacted was backed up for a few months with other clients... then the 2257 crap hit.. .
from what i understand.... our original apache set up on our personal servers allows pl files to be readable..something that our guys should have caught and fixed.. but didn't... this is not a software wide issue ... as much as it is a server security issue... and we are now currently working on correcting it...
as Fris mentioned every system has its weaknesses.. and they will all be found at some point.. unfortunately ours happened to be tonight...
lastly.. as for our ESclients... I do not know how our clients build their webservers. in most cases we do not have access to the client's web servers. If their severs are secured properly... (unlike ours.. as we found out) they should not have similar issues....
I'll post more info as I find out more... thank you to those who are supporting us and who took the time to contact us...
Comment