password list back online again

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Easy
    Registered User
    • Feb 2002
    • 79

    #1

    password list back online again

    http://tmd.df.ru/private.html
  • Mr.Fiction
    Confirmed User
    • Feb 2002
    • 9484

    #2
    Thanks.
    Don't be lazy, protect free speech: ACLU | Free Speech Coalition | EFF | IMPA

    Comment

    • Easy
      Registered User
      • Feb 2002
      • 79

      #3
      hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

      They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...

      Comment

      • echo465
        Confirmed User
        • Mar 2001
        • 265

        #4
        Originally posted by Easy
        hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

        They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
        How about this:

        When you've detected that an attack is underway, always fail the first login from an IP, even if the password is correct.. a surfer will (hopefully) assume that they mistyped their password, and try again, while a brute forcer will just continue on.

        Anyone?
        Currently Promoting: Adult Movie Club

        Comment

        • pimpdog3
          So Fucking Banned
          • Aug 2002
          • 652

          #5
          god damn, that list would make a kick ass plugin!!

          Comment

          • Backov
            Confirmed User
            • Mar 2001
            • 1600

            #6
            Originally posted by Easy
            hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

            They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
            http://www.proxypass.com

            That will kick the shit out of basically all brute force attacks.

            Cheers,
            Backov
            <embed src="http://banners.spotbrokers.com/button.swf" FlashVars="clickURL=http://banners.spotbrokers.com" quality=high pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" type="application/x-shockwave-flash" width="120" height="60"></embed>

            Comment

            • Rictor
              Old Timer
              • Jan 2001
              • 12208

              #7
              Cool. Free porn. Cha ching.

              Comment

              • echo465
                Confirmed User
                • Mar 2001
                • 265

                #8
                Originally posted by Easy
                hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

                They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
                Another idea -- monitor the webpage for compromized accounts, and then redirect users with that username and password to that 'hey everyone, i'm looking at gay porn!!' page

                link to that website that YOU DO NOT WANT TO CLICK ON is http://d-m-s-1-0-0.org/worksucks (without the dashes) (i think, but i'm sure as hell not gonna go check).
                Currently Promoting: Adult Movie Club

                Comment

                • Mr.Fiction
                  Confirmed User
                  • Feb 2002
                  • 9484

                  #9
                  Originally posted by pimpdog3
                  god damn, that list would make a kick ass plugin!!
                  Don't be lazy, protect free speech: ACLU | Free Speech Coalition | EFF | IMPA

                  Comment

                  • kinkyplace
                    Confirmed User
                    • Mar 2002
                    • 217

                    #10
                    I checked out some of the sites from that list. Gee, I cannot believe people are actually paying for that...!
                    But maybe that was a collection of all the crappy sites?

                    Comment

                    • eru
                      Confirmed User
                      • Mar 2002
                      • 2612

                      #11
                      FREE PORN YES!!!!
                      <font color="#FFFFFF" size="2" face="Verdana">This thread will self-destruct in 5 seconds.</font><font color="#FFFFFF" face="Verdana"><br>
                      <br>
                      <font size="1">In the meantime, consider hosting with <a href="http://www.choopa.com"><font color="#00FF00">Choopa</font></a>
                      -- The only provider with 9 x 1000mbps Transit Redundancy</font></font>

                      Comment

                      • BrettJ
                        ol' timer
                        • Jan 2001
                        • 4715

                        #12
                        Originally posted by kinkyplace
                        I checked out some of the sites from that list. Gee, I cannot believe people are actually paying for that...!
                        But maybe that was a collection of all the crappy sites?
                        Hey Fag - my site was on that =)

                        well back to jerking off to lots of "FREE" Porn!!

                        ~Brett

                        Comment

                        • eru
                          Confirmed User
                          • Mar 2002
                          • 2612

                          #13
                          lindaoneil.com was on there! Nice! She's one hot mama!
                          <font color="#FFFFFF" size="2" face="Verdana">This thread will self-destruct in 5 seconds.</font><font color="#FFFFFF" face="Verdana"><br>
                          <br>
                          <font size="1">In the meantime, consider hosting with <a href="http://www.choopa.com"><font color="#00FF00">Choopa</font></a>
                          -- The only provider with 9 x 1000mbps Transit Redundancy</font></font>

                          Comment

                          • SetTheWorldonFire
                            Confirmed User
                            • Feb 2002
                            • 7444

                            #14
                            anyone got anymore lotion?
                            www.STWOFDesign.com
                            hit me up on icq 154206276 or Skype: JaimeGizzle

                            Comment

                            • mastamindz
                              Confirmed User
                              • Feb 2002
                              • 3547

                              #15
                              Originally posted by SetTheWorldonFire
                              anyone got anymore lotion?
                              The BBW sites are hot. I must have jerked it 12 times in the last half hour.
                              If you click here, you will make money.

                              Comment

                              • B40
                                Confirmed User
                                • Jul 2001
                                • 7020

                                #16
                                Originally posted by eru
                                FREE PORN YES!!!!
                                Time to jerk off!

                                Comment

                                • sherbert
                                  Confirmed User
                                  • Aug 2002
                                  • 470

                                  #17
                                  WOOHOO!
                                  sdfsdfsdvgf

                                  Comment

                                  • kinkyplace
                                    Confirmed User
                                    • Mar 2002
                                    • 217

                                    #18
                                    Originally posted by BrettJ


                                    Hey Fag - my site was on that =)

                                    well back to jerking off to lots of "FREE" Porn!!

                                    ~Brett
                                    Stop calling me names! I'm a Pervert and not a Fag!

                                    So which of the crappy sites was yours? Is the password still working? I have to check it out...

                                    Comment

                                    • PxG
                                      Confirmed User
                                      • Feb 2002
                                      • 105

                                      #19
                                      Originally posted by Easy
                                      hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

                                      They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...

                                      Thanks Backov,
                                      As a client of Proxypass, you know that we stop brute force attacks that are run through proxies. But I am sure many people out there haven't heard of our new ProxyPass product.

                                      If anyone has any questions, please feel free to post them and we will do our best to answer them.

                                      On a side note, pr0 posted a concern about non-standard port proxies and my response initially was that ProxyPass did not block them. I asked a programmer and he corrected me: we DO block most non-standard port proxies too. Not only are they extremely rare (only 1 in 8000 according to our counts), but we block most of them anyway. Sorry for the misinformation.
                                      You may also hit us up privately on ICQ: 153529369

                                      Fire away guys,

                                      The ProxyPass Team
                                      Kill Password Hackers Now!
                                      Kill Hit-Botters Now!
                                      _____________________________

                                      Comment

                                      • MaxDent
                                        Confirmed User
                                        • Apr 2002
                                        • 851

                                        #20
                                        That list must have just been updated because all the accounts they had for our site weren't suspended yet. Now they are :-)

                                        Comment

                                        • BVF
                                          Black Vagina Finder
                                          • Jan 2002
                                          • 13975

                                          #21
                                          Originally posted by MaxDent
                                          That list must have just been updated because all the accounts they had for our site weren't suspended yet. Now they are :-)
                                          no matter. they'll have a fresh batch of them by tomorrow..fucking russians!

                                          Black Pussy
                                          Click On Mr Cosby..CCbill, 60/40, 136 FHG's....The Cos Loves Black Ghetto Pussy!!

                                          Comment

                                          • salsbury
                                            Confirmed User
                                            • Feb 2002
                                            • 1070

                                            #22
                                            i wonder how many of the sites on this list use Epoch or Jettis for billing. no amount of password crack checking would work for them.

                                            Comment

                                            • JamesK
                                              hi
                                              • Jun 2002
                                              • 16731

                                              #23
                                              muhahaha u dix using bruteforce, i got adultbouncer passwords!
                                              M3Server - NATS Hosting

                                              Comment

                                              • JamesK
                                                hi
                                                • Jun 2002
                                                • 16731

                                                #24
                                                oh shit u got them too
                                                M3Server - NATS Hosting

                                                Comment

                                                • pink_in_the_middle
                                                  Confirmed User
                                                  • Aug 2002
                                                  • 4503

                                                  #25
                                                  my sites on that list !!! FUCKERS

                                                  LOL it's okay it's all fixed ;)
                                                  pinkysteph AT gmail DOT com

                                                  I'm a native english speaker from Canada with a firm ass, excellent grammar and punctuation skills. If you're in need of text for your: blog, paysite galleries, DVD covers, image cropping, content purchasing, content insertion or anything else along these lines, please feel free to give me a shout. And I’m female to boot

                                                  Comment

                                                  • TarPy
                                                    Confirmed User
                                                    • Mar 2002
                                                    • 758

                                                    #26
                                                    it's 403 now... LOL, back up, back down
                                                    Not Working

                                                    Comment

                                                    • gothweb
                                                      Confirmed User
                                                      • Jun 2002
                                                      • 8849

                                                      #27
                                                      Okay, now... How did they get a new login so fast? I cleared out the three they were using last week, and they already have them down and a new one back up.

                                                      Photos by Ian X.: Distinctive photos of goth babes.
                                                      Blood Money:Your traffic, my sites, our money.
                                                      MojoHost: Still the best.

                                                      Comment

                                                      • DrGuile
                                                        Confirmed User
                                                        • Jan 2002
                                                        • 2025

                                                        #28
                                                        Originally posted by gothweb
                                                        Okay, now... How did they get a new login so fast? I cleared out the three they were using last week, and they already have them down and a new one back up.

                                                        maybe you should fix the problem this time.

                                                        Last edited by DrGuile; 09-30-2002, 11:10 AM.
                                                        LiveBucks / Privatefeeds - Giving you money since 1999
                                                        Up to 50% Commission!
                                                        25% Webmaster Referal
                                                        Powered by Gamma

                                                        Comment

                                                        • gothweb
                                                          Confirmed User
                                                          • Jun 2002
                                                          • 8849

                                                          #29
                                                          Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?

                                                          Photos by Ian X.: Distinctive photos of goth babes.
                                                          Blood Money:Your traffic, my sites, our money.
                                                          MojoHost: Still the best.

                                                          Comment

                                                          • DrGuile
                                                            Confirmed User
                                                            • Jan 2002
                                                            • 2025

                                                            #30
                                                            Originally posted by gothweb
                                                            Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?
                                                            brute force attack most likely...

                                                            i.e.: dictionary attacks
                                                            LiveBucks / Privatefeeds - Giving you money since 1999
                                                            Up to 50% Commission!
                                                            25% Webmaster Referal
                                                            Powered by Gamma

                                                            Comment

                                                            • gothweb
                                                              Confirmed User
                                                              • Jun 2002
                                                              • 8849

                                                              #31
                                                              A brute force attack won't help them get passwords that aren't already there. The logins they have had have not been the result of paying members, or of me manually updating.

                                                              Photos by Ian X.: Distinctive photos of goth babes.
                                                              Blood Money:Your traffic, my sites, our money.
                                                              MojoHost: Still the best.

                                                              Comment

                                                              • salsbury
                                                                Confirmed User
                                                                • Feb 2002
                                                                • 1070

                                                                #32
                                                                if you use Epoch or Jettis they can add passwords to your site themselves. Paypal's script gives me a headache because it is obfuscated - but because it is obfuscated i strongly suspect it's vulnerable as well.

                                                                Comment

                                                                • JFK
                                                                  FUBAR the ORIGINATOR
                                                                  • Jan 2002
                                                                  • 67369

                                                                  #33
                                                                  the link you posted is coming up 404 for me !

                                                                  FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX
                                                                  For promo opps contact jfk at fubarwebmasters dot com

                                                                  Comment

                                                                  • Pornwolf
                                                                    Drunk and Unruly
                                                                    • Jan 2002
                                                                    • 22712

                                                                    #34
                                                                    Damnit, it's down! I was hoping to see some midget oil wrestling today.
                                                                    I've trusted my sites to them for over a decade...

                                                                    Webair, bitches.

                                                                    Comment

                                                                    • Massivecock
                                                                      Confirmed User
                                                                      • Mar 2002
                                                                      • 800

                                                                      #35
                                                                      Where did you get that link?
                                                                      What I mean is Where did you find it?
                                                                      --
                                                                      And can you get me the new one... it seems to have changed file names and is gone?

                                                                      Comment

                                                                      • Easy
                                                                        Registered User
                                                                        • Feb 2002
                                                                        • 79

                                                                        #36
                                                                        Originally posted by gothweb
                                                                        Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?
                                                                        sometimes ccbill fails to remove inactive accounts. So the pwd is still in the password file.. just check your active usernames, download the password file and compare


                                                                        and that's what the russians answered...

                                                                        Thanks for your report.

                                                                        We'd appreciate it if you direct this type of reports to [email protected]
                                                                        (rather than the webmaster) in the future.
                                                                        We aren't in a position to determine what legal and what isn't. We
                                                                        have an Acceptable Use Policy, which is a part of our customer agreement,
                                                                        and we enforce it whenever we determine or are notified of a violation.

                                                                        The particular AUP document that we use has been approved by OFISP, a
                                                                        Russian/CIS ISP forum, and is shared by many Russian ISPs.

                                                                        Hosting some form of content is not an AUP violation, with the only
                                                                        exception for "spam support services". "Bypassing server security"
                                                                        would be it, but only hosting content that enables to do so isn't.

                                                                        It's only due to the details of agreement with this particular customer
                                                                        that we can in fact ask and insist that they remove this content simply
                                                                        because "we don't like it".

                                                                        --
                                                                        Alexander Peslyak
                                                                        DataForce ISP

                                                                        Comment

                                                                        • SeRsH
                                                                          Confirmed User
                                                                          • Oct 2001
                                                                          • 15

                                                                          #37
                                                                          I belive the largest daily updated with hundreds of passwords password list is here - http://www.xxxhq.com/vb/ ( you need to register to view )

                                                                          Also I have see it here - http://www.sublimechat.com/phpBB/vie...hp?forum=7&674 ( the part of sublimedirectory )

                                                                          Comment

                                                                          • kÿ®ëë
                                                                            Registered User
                                                                            • Sep 2002
                                                                            • 41

                                                                            #38
                                                                            Originally posted by salsbury
                                                                            if you use Epoch or Jettis they can add passwords to your site themselves. Paypal's script gives me a headache because it is obfuscated - but because it is obfuscated i strongly suspect it's vulnerable as well.
                                                                            same goes for ibill's mastergate cgi easier than cracking them

                                                                            that's ALL ibill sites

                                                                            Comment

                                                                            Working...