I think a lot of Epassporte account hacks have been the result of NATS security holes

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Jet - BANNED FOR LIFE
    So Fucking Banned
    • Sep 2002
    • 7515

    #1

    I think a lot of Epassporte account hacks have been the result of NATS security holes

    Think about how many people reported money stolen from their Epass accounts, saying they had no spyware/trojans on their PC.

    I think it could be because of the NATS security holes.

    If people used same login/password for their affiliate program accounts and their Epassporte account, i can see how easily money could have been be stolen.

    Epassporte didn't have anything to do with it, but a lot of people blamed them.
  • Oracle Porn
    Affiliate
    • Oct 2002
    • 24433

    #2
    epass is to blame for the nats hack!


    Comment

    • slavdogg
      Confirmed User
      • Jan 2001
      • 3570

      #3
      if you use epass
      you're a scammer
      simple as that.

      and u'r one dumb motherfucker for trusting epass with your money.
      Adult Traffic for Sale

      Comment

      • v4 media
        Confirmed User
        • Feb 2005
        • 2934

        #4
        Blame Canada

        Comment

        • Emil
          Confirmed User
          • Feb 2007
          • 5655

          #5
          If people used same login/password for their affiliate program accounts and their Epassporte account, they're fucking retarded and should have their money stolen.

          Free BTC! (Yes, really. Free ₿itcoins.)
          Signup with ONLY your Nickname, Email and Password. You can also refer people and get even more.

          Comment

          • polish_aristocrat
            Too lazy to set a custom title
            • Jul 2002
            • 40377

            #6
            Originally posted by slavdogg
            if you use epass
            you're a scammer
            simple as that.
            so 90% of the adult industry are scammers...
            I don't use ICQ anymore.

            Comment

            • slavdogg
              Confirmed User
              • Jan 2001
              • 3570

              #7
              Originally posted by polish_aristocrat
              so 90% of the adult industry are scammers...
              the same 90% that controls 10% of all joins ??

              yes if u use epass as your payout method, you're a scammer and should not be trusted.
              Adult Traffic for Sale

              Comment

              • slavdogg
                Confirmed User
                • Jan 2001
                • 3570

                #8
                Originally posted by Emil
                If people used same login/password for their affiliate program accounts and their Epassporte account, they're fucking retarded and should have their money stolen.

                agreed

                hope more money gets stolen out of people's epass accnts
                Adult Traffic for Sale

                Comment

                • Jet - BANNED FOR LIFE
                  So Fucking Banned
                  • Sep 2002
                  • 7515

                  #9
                  Originally posted by slavdogg
                  if you use epass
                  you're a scammer
                  you're an idiot.

                  Comment

                  • slavdogg
                    Confirmed User
                    • Jan 2001
                    • 3570

                    #10
                    Originally posted by Jet
                    you're an idiot.
                    voice of an epass scammer ?
                    Adult Traffic for Sale

                    Comment

                    • minusonebit
                      So Fucking Banned
                      • Feb 2006
                      • 7391

                      #11
                      Man this is scary, you might be right. Maybe it was NATS.

                      Comment

                      • marketsmart
                        HOMICIDAL TROLL KILLER
                        • Dec 2004
                        • 20419

                        #12
                        Originally posted by slavdogg
                        if you use epass
                        you're a scammer
                        simple as that.

                        and u'r one dumb motherfucker for trusting epass with your money.
                        and you are a fucking noob.... shall i list all the companies that pay me by epass? i guarantee they are bigger that 90% of all the programs out there...

                        Comment

                        • Ray@TastyDollars
                          • May 2002
                          • 6797

                          #13
                          Webmaster, Epass, Biller, Admin, ect. Passwords are not available within the NATS admin area, all they/we see is ********.

                          The ONLY passwords they would be able to get a hold of with Admin access are member passwords.

                          The only place the passwords are stored are in the DB and it is encrypted. So the chances that your pass has been decrypted is very slim.

                          I can't speak for all programs but I can speak for mine, our DB was NOT compromised. Heck neither was our admin area, thanks to my host!

                          Ray

                          Comment

                          • Jet - BANNED FOR LIFE
                            So Fucking Banned
                            • Sep 2002
                            • 7515

                            #14
                            Originally posted by Ray@TastyDollars
                            The only place the passwords are stored are in the DB and it is encrypted. So the chances that your pass has been decrypted is very slim.
                            Why are you so sure of that?

                            Comment

                            • slavdogg
                              Confirmed User
                              • Jan 2001
                              • 3570

                              #15
                              Originally posted by marketsmart
                              and you are a fucking noob.... shall i list all the companies that pay me by epass? i guarantee they are bigger that 90% of all the programs out there...
                              come suck my balls epass scammer

                              slavdogg
                              Registered User
                              Join Date: Jan 2001
                              Posts: 2,350
                              Adult Traffic for Sale

                              Comment

                              • Jet - BANNED FOR LIFE
                                So Fucking Banned
                                • Sep 2002
                                • 7515

                                #16
                                slavdog this is uncalled for.

                                I use epassporte for my sponsor payouts. And I am honest person.

                                Comment

                                • Ray@TastyDollars
                                  • May 2002
                                  • 6797

                                  #17
                                  Originally posted by Jet
                                  Why are you so sure of that?
                                  Because when you log into nats admin you dont see them and the only place you can get them is in the DB. This hack targeted the admin area only. Again, i speak for my program when I say our DB's have deff. NOT been hacked and im pretty sure this is the case for most other programs as well.

                                  Admin area does not mean DB, simple.

                                  Ray

                                  Comment

                                  • Jet - BANNED FOR LIFE
                                    So Fucking Banned
                                    • Sep 2002
                                    • 7515

                                    #18
                                    Originally posted by Ray@TastyDollars
                                    Because when you log into nats admin you dont see them and the only place you can get them is in the DB. This hack targeted the admin area only. Again, i speak for my program when I say our DB's have deff. NOT been hacked and im pretty sure this is the case for most other programs as well.

                                    Admin area does not mean DB, simple.

                                    Ray
                                    I meant why you were so sure that the DB can't be hacked.

                                    Iven John has admitted it was very possible.

                                    Comment

                                    • Ray@TastyDollars
                                      • May 2002
                                      • 6797

                                      #19
                                      Originally posted by Jet
                                      I meant why you were so sure that the DB can't be hacked.

                                      Iven John has admitted it was very possible.
                                      Even the Pentagon is hackable right? In this particular case the admin area was compromised. I spoke to many program owners last night and they all confired with their hosts that their DB's had not been hacked.

                                      In THIS particular case.

                                      Comment

                                      • Jet - BANNED FOR LIFE
                                        So Fucking Banned
                                        • Sep 2002
                                        • 7515

                                        #20
                                        Originally posted by Ray@TastyDollars
                                        I spoke to many program owners last night and they all confired with their hosts that their DB's had not been hacked.

                                        In THIS particular case.
                                        How do they know if their DBs were hacked or not?

                                        There are sponsors who say that full DB dumps were made by the intruder.

                                        There is no way for the sponsors to know what happened to the stolen DBs.

                                        Comment

                                        • Ray@TastyDollars
                                          • May 2002
                                          • 6797

                                          #21
                                          Originally posted by Jet
                                          Ho

                                          There are sponsors who say that full DB dumps were made by the intruder.

                                          wow im really sorry to hear that! If they indeed were able to get a db dump just by having admin access I really hope these sponsors get their hosts to secure there db's a little better. Its bad enough that they had admin access, but db access to, fuck!

                                          Comment

                                          • Trixxxia
                                            Confirmed User
                                            • Aug 2004
                                            • 5600

                                            #22
                                            Jet - not every program was hacked or compromised.
                                            Some hosts are very diligent with their security and what access they allow on their servers. We are amongst some mighty happy clients of Swiftwill today and very very very thankful of their diligence.

                                            Comment

                                            • borked
                                              Totally Borked
                                              • Feb 2005
                                              • 6284

                                              #23
                                              Originally posted by Jet
                                              How do they know if their DBs were hacked or not?

                                              There are sponsors who say that full DB dumps were made by the intruder.

                                              There is no way for the sponsors to know what happened to the stolen DBs.
                                              Wow that sucks. The sponsors that had their databases wripped also had some serious security issues, unrelated to the current NATS security problem. They really do need to get their hosts to lock things down better

                                              For coding work - hit me up on andy // borkedcoder // com
                                              (consider figuring out the email as test #1)



                                              All models are wrong, but some are useful. George E.P. Box. p202

                                              Comment

                                              • Iron Fist
                                                Too lazy to set a custom title
                                                • Dec 2006
                                                • 23400

                                                #24
                                                Originally posted by v4 media
                                                Blame Canada
                                                i like waffles

                                                Comment

                                                • HouseHead
                                                  Confirmed User
                                                  • Aug 2003
                                                  • 5539

                                                  #25
                                                  lawsl you kids silly kids
                                                  The Sexiest place to Buy & Sell Adult Ads - JuicyAds is where YOUR profits matter!

                                                  ---> SPOTS AVAILABLE
                                                  :|: SIGN UP RIGHT NOW <---

                                                  Comment

                                                  • notoldschool
                                                    Confirmed User
                                                    • Aug 2007
                                                    • 5687

                                                    #26
                                                    Originally posted by slavdogg
                                                    if you use epass
                                                    you're a scammer
                                                    simple as that.

                                                    and u'r one dumb motherfucker for trusting epass with your money.
                                                    DING DING DING......Surfer alert.
                                                    No doubt one may quote history to support any cause, as the devil quotes scripture.
                                                    -- Learned Hand

                                                    http://www.bjpenn.com

                                                    Comment

                                                    • fuckingfuck
                                                      Confirmed User
                                                      • May 2007
                                                      • 521

                                                      #27
                                                      Epass works perfectly for me. I guess it's a few dimwits who have their money stolen (by giving their epass passwords to "epass reps" on msn!)
                                                      AA

                                                      Comment

                                                      • patmccrotch
                                                        Confirmed User
                                                        • Oct 2002
                                                        • 655

                                                        #28
                                                        Originally posted by Jet
                                                        you're an idiot.
                                                        Funny coming from someone who started such an ignorant thread. Passwords are encrypted in nats as well as database information. The "hacker" who was snagging access via the nats admin couldn't even retrieve the encrpyted password string of an affiliate account to try and decrypt it.

                                                        Never the less, epassporte passwords are not even stored in nats.

                                                        dipshit.

                                                        Comment

                                                        • MrVids
                                                          i am a meat popsicle
                                                          • Jan 2005
                                                          • 1070

                                                          #29
                                                          Originally posted by Jet
                                                          How do they know if their DBs were hacked or not?

                                                          There are sponsors who say that full DB dumps were made by the intruder.

                                                          There is no way for the sponsors to know what happened to the stolen DBs.
                                                          Because the database password is not configurable via the admin and the encrypted string for the database password isn't even available via the admin for the "hacker" to try and decrypt it. Plus 95% of the time mysql databases are either IP restricted for access _or_ restricted solely to localhost for access.

                                                          Comment

                                                          • woj
                                                            <&(©¿©)&>
                                                            • Jul 2002
                                                            • 47880

                                                            #30
                                                            Originally posted by patmccrotch
                                                            Funny coming from someone who started such an ignorant thread. Passwords are encrypted in nats as well as database information. The "hacker" who was snagging access via the nats admin couldn't even retrieve the encrpyted password string of an affiliate account to try and decrypt it.

                                                            Never the less, epassporte passwords are not even stored in nats.

                                                            dipshit.
                                                            A clever hacker could find at least a few ways to extract the passwords from the admin area.

                                                            The problem is, that some people may have used same password for nats as they used for epassporte. It's not very smart, but it's very possible that some users would actually do that.
                                                            Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
                                                            Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
                                                            Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

                                                            Comment

                                                            • slavdogg
                                                              Confirmed User
                                                              • Jan 2001
                                                              • 3570

                                                              #31
                                                              Originally posted by woj
                                                              A clever hacker could find at least a few ways to extract the passwords from the admin area.

                                                              The problem is, that some people may have used same password for nats as they used for epassporte. It's not very smart, but it's very possible that some users would actually do that.
                                                              if that was the case i hope their epass accnts got cleaned out.
                                                              Adult Traffic for Sale

                                                              Comment

                                                              • DamageX
                                                                Marketing & Strategy
                                                                • Jun 2001
                                                                • 14293

                                                                #32
                                                                Originally posted by Trixxxia
                                                                Jet - not every program was hacked or compromised.
                                                                Some hosts are very diligent with their security and what access they allow on their servers. We are amongst some mighty happy clients of Swiftwill today and very very very thankful of their diligence.
                                                                Stop hackers dead - use SwiftWill.
                                                                Whitehat is for chumps

                                                                If you don't do it, somebody else will - true story!

                                                                Comment

                                                                • papill0n
                                                                  Unregistered Abuser
                                                                  • Oct 2007
                                                                  • 15547

                                                                  #33
                                                                  Originally posted by slavdogg
                                                                  yes if u use epass as your payout method, you're a scammer and should not be trusted.
                                                                  yeah, everyone who uses epassporte is a scammer

                                                                  Comment

                                                                  • xentech
                                                                    Confirmed User
                                                                    • Jan 2006
                                                                    • 1405

                                                                    #34
                                                                    Very good point Jet

                                                                    Comment

                                                                    • Pleasurepays
                                                                      BANNED - SUPPORTING TUBES
                                                                      • Aug 2002
                                                                      • 11913

                                                                      #35
                                                                      Originally posted by notoldschool
                                                                      DING DING DING......Surfer alert.

                                                                      hahah..

                                                                      GFY is always entertaining. Now we have surfers calling out industry legends that they think are surfers


                                                                      Comment

                                                                      Working...