Got feeds in your paysite? Check this.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • cafeaulait
    Confirmed User
    • Jun 2002
    • 587

    #1

    Got feeds in your paysite? Check this.

    You probably already know this, but I just found out so......

    Most paysite feeds use simple referer based security to say that the link actually came from your members area. I just downloaded this little ZSpoof tool and was able to access every single one of my feeds from outside my members area.

    Its fucking scary to think how many other people can do this, either guess or just sign-up to a site once, copy all the feed links into ZSpoof and then cancel and you've got access to all of the feeds for life!



    Why can't feeds providers put better security in place????
    Last edited by cafeaulait; 03-13-2003, 03:07 AM.
  • ServerGenius
    Confirmed User
    • Feb 2002
    • 9377

    #2
    Remove the link please......just mention the program, don´t ç
    actually give it to all the kiddies that lurk around here.

    Referrer protection sucks, it´s so easy to fake. In a 10 line
    perl/php script you can write a header that has fake referrer info

    DynaMite
    | http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |

    Comment

    • quiet
      we'll miss you our friend. RIP
      • Sep 2001
      • 25115

      #3
      Originally posted by DynaSpain
      Remove the link please......just mention the program, don´t ç
      actually give it to all the kiddies that lurk around here.

      Referrer protection sucks, it´s so easy to fake. In a 10 line
      perl/php script you can write a header that has fake referrer info

      DynaMite
      too late
      we'll miss you our friend. RIP

      Comment

      • ServerGenius
        Confirmed User
        • Feb 2002
        • 9377

        #4
        It´s something you should be very wary off. Most plugin providers
        bill you for bandwidth. If people start to use these kind of programs, and fake your referrer then you will get a fucking nice
        bill at the next pay period.

        DynaMite
        | http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |

        Comment

        • Hentaikid
          Confirmed User
          • Nov 2002
          • 1250

          #5
          Can't you combine both? A login page that can only be accessed from the referrer and a password displayed above the link in the referring paysite's member area.

          Comment

          • G Sharp
            So Fucking Banned
            • May 2002
            • 1343

            #6
            A particularly notorious spoofer P___________s has been around for awhile. You'd think that big feeds providers like holio, socal, etc would plug this revenue leak up?

            Comment

            • SNIPER
              Confirmed User
              • Mar 2001
              • 410

              #7
              Man that is SO OLD! Almost prehistoric lol GET IT ...
              Anyways...here is a smarter way of stopping his operations. I did it once before I would do it again, but I don?t have the time.

              All those programs he is promoting...I contacted....let them know that the yare sponsoring A THEIF ..and what ya know the boy doesn't have two pennies to rub together. The site goes down and eventually it comes back.

              WHY>

              Because some CONTENT PROVIDERS, decide to work with the fucker and get 1-1 shows and shit from him. SO YOU SEE A BANNER IN HIS PROGRAM and YOU WANT TO DO SOMETHING ABOUT IT..... Contact the rev share place and let them know that unless they remove him from their list that you will be posting their names in here! and everywhere else you post.

              WHEN YOU SUPPORT A THEIF YOU ARE A THEIF!




              Face Like and Angel, but Makes More Deals than the Devil }:-)

              Comment

              • ronaldo
                Confirmed User
                • Jan 2002
                • 5475

                #8
                Originally posted by cafeaulait
                You probably already know this, but I just found out so......

                Most paysite feeds use simple referer based security to say that the link actually came from your members area. I just downloaded this little ZSpoof tool and was able to access every single one of my feeds from outside my members area.

                Its fucking scary to think how many other people can do this, either guess or just sign-up to a site once, copy all the feed links into ZSpoof and then cancel and you've got access to all of the feeds for life!



                Why can't feeds providers put better security in place????
                Very interesting that someone should bring this up.

                We're in the process of developing a script that will protect against this. The problem will be convincing paysite owners that they have to put OUR script on their server.

                We're releasing 23 feeds on April 1, but we don't think the script will be ready until May 1.

                Comment

                • ronaldo
                  Confirmed User
                  • Jan 2002
                  • 5475

                  #9
                  Originally posted by DynaSpain
                  It´s something you should be very wary off. Most plugin providers
                  bill you for bandwidth. If people start to use these kind of programs, and fake your referrer then you will get a fucking nice
                  bill at the next pay period.

                  DynaMite
                  We have NEVER surprised anyone with a bill like this and NEVER would. That is the reason for my post above.

                  Worst case you would have had notification of a price jump the next month. If, of course you balked at the price, we would look further into your bandwidth usage.

                  All of that will be a moot point soon.

                  Comment

                  Working...