CCBill .htaccess nightmare

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • TheSaint
    Confirmed User
    • Jun 2003
    • 991

    #1

    CCBill .htaccess nightmare

    I decided to reconcile my password files on some sites.

    Knowing how things work I assumed there would be some bogus users in there, and in fact I found about 10.

    Not bad, for a year, but more than I thought I would find.

    It's not really CCBill's fault in my view (shit happens) but they should provide a tool to help reconcile the file - I ended up spending hours extracting users from CCBill reports, loading into mysql, and joining on .htaccess.

    Way too much work, but I'm going to do it occasionally from now on.

    If you have a paysite there is a good chance you have some expired users also with lifetime free access; you might want to take a look.
    I have no signature
  • doober
    Confirmed User
    • Jul 2003
    • 6984

    #2
    im afraid to look

    Comment

    • Rictor
      Old Timer
      • Jan 2001
      • 12208

      #3
      Yes, a tool would be very nice.

      Comment

      • WebTitan
        Confirmed User
        • Mar 2003
        • 5114

        #4
        i had a nightmare with a client we jsut setup with them on that too. was liking jumping thru hoops to try and fix that shit

        Comment

        • Ray@TastyDollars
          • May 2002
          • 6797

          #5
          this may be a stupid question, but how did they get there.
          Hacks or other?

          Comment

          • Bigjohn
            Confirmed User
            • Feb 2003
            • 1118

            #6
            I had the same thing. Pennywize would disable a a username for multiple accesses/different IPs but when I checked in CCBill, they weren't listed as a member.

            Turns out that my CCBill script was sitting where it was easy to find and hackers were managing to hahahahahahaha the script and create fake accounts. The Tech on the phone had it fixed in like two seconds. Now my script is safely hidden in a randomly named directory that's about a billion characters long

            Comment

            • emmanuelle
              Confirmed User
              • Mar 2003
              • 3662

              #7
              Since they brought out the newer J scripts, everything works great. Make sure that the old password file isnt still in an accessable directory or you can be sure it will be found and all those usernames will be hammered.

              Comment

              • High Quality
                Confirmed User
                • Feb 2002
                • 5741

                #8
                Originally posted by emmanuelle
                Since they brought out the newer J scripts, everything works great. Make sure that the old password file isnt still in an accessable directory or you can be sure it will be found and all those usernames will be hammered.
                This is CCBILL? I have about a year old script, as far as I know...

                RecurCash.com - Averaging $38/sale with 60% revshare in the first 4 months alone!

                Convert your TEEN traffic today @ better than 1:500 guaranteed. ICQ me: 18287590!

                Comment

                • TheSaint
                  Confirmed User
                  • Jun 2003
                  • 991

                  #9
                  Everything on my server is as secure as you can get - the password file is not in the web tree, the ccbill script name is random, etc.

                  Be very afraid.
                  I have no signature

                  Comment

                  Working...