Okay, I'm stupid, I admit it. I have been trying to fight hackers for 4 years and have failed miserably. Please take pity on me and point me in the right direction...if there is one.
Here is my plight:
- I launched a website of my nudie pics and videos
- CCbill is my primary processor (Ibill is an alternate)
- I pay $50/mo. for hosting from a couple of yahoos
- I get hourly bandwidth reports of who logged in, from what ip address and how much they downloaded
- Every hour, I see valid usernames (ccbill members) entering from dozens of ip addresses
- My Pennywize script shuts the username down
- Now my valid user can't get in and bitches to ccbill and gets refunded
- In order to avoid customer service disasters, I hover over my email every hour and frantically create and distribute new usernames to my members.
- In addition to having valid usernames abused, I have hackers creating their own usernames directly in my password file. They were even brazen enough to create a script called add-passwd.cgi and put it on my server
- My hosting company is of course not helping me
- Pennywize's technical support is also non-existant
- CCbill is equally vague and unconcerned
- www.xxxhosting.com (www.reliablehosting.com) quoted me $200 for a dedicated server which I would gladly pay if I thought it would make a difference
- the tech at www.xxxhosting.com said to use Password Sentry from http://www.monster-submit.com/ for $80. I would gladly pay for this script if it would fix the problem.
Does a dedicated server eliminate the issue, improve the issue?
Do I need to switch billing companies, hosting companies or both?
Can I buy protection or have somebody manage this for me?
Is there a hosting company who will promise you no hackers and promise to deal with those hackers if they do get through?
Is there anyway to automatically generate new usernames for abused accounts and dispatch them out to users for reentry while killing the hacked version?
Is this the process you all go through, ie, a username gets hacked, the user gets blocked, complains to you, you issue/readd a new username? And then repeat over and over? Seems unprofessional to disclose my security failures to my member by way of a new password every week!
Please help my sorry ass figure out what the hell to do. I apologize for my complete ignorance. Please show me the way!
Here is my plight:
- I launched a website of my nudie pics and videos
- CCbill is my primary processor (Ibill is an alternate)
- I pay $50/mo. for hosting from a couple of yahoos
- I get hourly bandwidth reports of who logged in, from what ip address and how much they downloaded
- Every hour, I see valid usernames (ccbill members) entering from dozens of ip addresses
- My Pennywize script shuts the username down
- Now my valid user can't get in and bitches to ccbill and gets refunded
- In order to avoid customer service disasters, I hover over my email every hour and frantically create and distribute new usernames to my members.
- In addition to having valid usernames abused, I have hackers creating their own usernames directly in my password file. They were even brazen enough to create a script called add-passwd.cgi and put it on my server
- My hosting company is of course not helping me
- Pennywize's technical support is also non-existant
- CCbill is equally vague and unconcerned
- www.xxxhosting.com (www.reliablehosting.com) quoted me $200 for a dedicated server which I would gladly pay if I thought it would make a difference
- the tech at www.xxxhosting.com said to use Password Sentry from http://www.monster-submit.com/ for $80. I would gladly pay for this script if it would fix the problem.
Does a dedicated server eliminate the issue, improve the issue?
Do I need to switch billing companies, hosting companies or both?
Can I buy protection or have somebody manage this for me?
Is there a hosting company who will promise you no hackers and promise to deal with those hackers if they do get through?
Is there anyway to automatically generate new usernames for abused accounts and dispatch them out to users for reentry while killing the hacked version?
Is this the process you all go through, ie, a username gets hacked, the user gets blocked, complains to you, you issue/readd a new username? And then repeat over and over? Seems unprofessional to disclose my security failures to my member by way of a new password every week!
Please help my sorry ass figure out what the hell to do. I apologize for my complete ignorance. Please show me the way!




Comment