Verotel hacked passes?...

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • mattyboy
    Confirmed User
    • Mar 2003
    • 1070

    #1

    Verotel hacked passes?...

    We use Verotel on 4 of our paysites along with Pennywize and a few other billers.
    This morning we've have an unusually high amount of Pennywize emails informing us of abused accounts - all Verotel ID's and from all 4 different sites.
    We get a few abused accounts most days but as i say, today is getting a lot from only Verotel ID's - more than we've had in the last few months.
    Anyone else getting this?
  • nudecanada
    Confirmed User
    • Jan 2004
    • 793

    #2
    Hey, hey...

    Chances are it's Verotel. On their end.
    I dumped those cheeseheads last week.
    Or, it could be on your end. I know 100% for sure that mine were hacked, somehow, on their end.

    http://www.gofuckyourself.com/showth...hreadid=235941

    Comment

    • raymor
      Confirmed User
      • Oct 2002
      • 3745

      #3
      It is possible to hack the older version of Verotels' add/remove password
      scripts (verotelrum.pl). People do actively scan for that script,
      as evidenced by server logs of sites I have seen.
      It is quite possible that the breach occurred through
      verotelrum.pl on your server.

      Also, due to the way Vertoel chooses usernames, Verotel usernames
      and good targets for brute force attacks. Pennywize's
      brute force detection is broken in so far as it does not acount
      for open proxies, which most brute force attackers use nowadays.

      For optimal security, you should update verotelrum.pl
      to the latest version and have a security aware tech take a
      look at your script configuration and related items.
      Also you may wish to replace pennydumb's suckurity based
      on 1998 methods with something up to date and far more
      secure, such as Strongbox.
      For historical display only. This information is not current:
      support@bettercgi.com ICQ 7208627
      Strongbox - The next generation in site security
      Throttlebox - The next generation in bandwidth control
      Clonebox - Backup and disaster recovery on steroids

      Comment

      • mattyboy
        Confirmed User
        • Mar 2003
        • 1070

        #4
        Interesting link - thanks

        Comment

        • jawanda
          Confirmed User
          • Feb 2003
          • 6040

          #5
          Originally posted by raymor
          It is possible to hack the older version of Verotels' add/remove password
          scripts (verotelrum.pl). People do actively scan for that script,
          as evidenced by server logs of sites I have seen.
          It is quite possible that the breach occurred through
          verotelrum.pl on your server.

          Also, due to the way Vertoel chooses usernames, Verotel usernames
          and good targets for brute force attacks. Pennywize's
          brute force detection is broken in so far as it does not acount
          for open proxies, which most brute force attackers use nowadays.

          For optimal security, you should update verotelrum.pl
          to the latest version and have a security aware tech take a
          look at your script configuration and related items.
          Also you may wish to replace pennydumb's suckurity based
          on 1998 methods with something up to date and far more
          secure, such as Strongbox.
          Good post

          Comment

          Working...