Idiot Model needs your help to fight hackers

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • caroline4551
    Registered User
    • Aug 2004
    • 5

    #1

    Idiot Model needs your help to fight hackers

    Okay, I'm stupid, I admit it. I have been trying to fight hackers for 4 years and have failed miserably. Please take pity on me and point me in the right direction...if there is one.

    Here is my plight:

    - I launched a website of my nudie pics and videos
    - CCbill is my primary processor (Ibill is an alternate)
    - I pay $50/mo. for hosting from a couple of yahoos
    - I get hourly bandwidth reports of who logged in, from what ip address and how much they downloaded
    - Every hour, I see valid usernames (ccbill members) entering from dozens of ip addresses
    - My Pennywize script shuts the username down
    - Now my valid user can't get in and bitches to ccbill and gets refunded
    - In order to avoid customer service disasters, I hover over my email every hour and frantically create and distribute new usernames to my members.
    - In addition to having valid usernames abused, I have hackers creating their own usernames directly in my password file. They were even brazen enough to create a script called add-passwd.cgi and put it on my server
    - My hosting company is of course not helping me
    - Pennywize's technical support is also non-existant
    - CCbill is equally vague and unconcerned
    - www.xxxhosting.com (www.reliablehosting.com) quoted me $200 for a dedicated server which I would gladly pay if I thought it would make a difference
    - the tech at www.xxxhosting.com said to use Password Sentry from http://www.monster-submit.com/ for $80. I would gladly pay for this script if it would fix the problem.

    Does a dedicated server eliminate the issue, improve the issue?

    Do I need to switch billing companies, hosting companies or both?

    Can I buy protection or have somebody manage this for me?

    Is there a hosting company who will promise you no hackers and promise to deal with those hackers if they do get through?

    Is there anyway to automatically generate new usernames for abused accounts and dispatch them out to users for reentry while killing the hacked version?

    Is this the process you all go through, ie, a username gets hacked, the user gets blocked, complains to you, you issue/readd a new username? And then repeat over and over? Seems unprofessional to disclose my security failures to my member by way of a new password every week!

    Please help my sorry ass figure out what the hell to do. I apologize for my complete ignorance. Please show me the way!
    Caroline
  • BadBrad
    Confirmed User
    • Feb 2004
    • 618

    #2
    Well I just happen to be a Systems Administrator that used to deal with the same items you are. Here's what I can offer for help.

    Definately move to a dedicated server if possible. With you being on the same server as other webmasters it allows them to upload their own scripts thus being able to take advantage of exploits like the latest PHP script exploit. Even if they run a chroot environment it is not always secure. With a dedicated server you can also have additional items installed like databases, image manipulators, etc. that a lot of shared servers will not install. I would also recommend a Linux server over a Windows server for several security reason's.

    As for who to host with. I don't have any recommendations.

    Good luck.
    Brad
    Your sig chose me!

    Comment

    • PowerCum
      CjOverkill
      • Apr 2003
      • 1328

      #3
      I can offer you secure hosting at cyberorion.com
      Also offer you free security review on all the scripts you use.
      ICQ me at 171216535 (I will be in front of my ICQ in a couple of hours, so leave me a message and I will reply asap).
      CjOverkill Traffic Trading Script
      Free, secure and fast traffic trading script. Get your copy now

      Comment

      • Buddah00
        Confirmed User
        • May 2004
        • 722

        #4
        Look into TechieMedia for your hosting, they are good people. Strongbox should be able to help with your password protection.

        Don't discount the idea that your members may be giving out their password info or posting it on free password sites.
        Last edited by Buddah00; 08-18-2004, 03:22 AM.
        I want what every other man wants, I just want it more.

        Comment

        • caroline4551
          Registered User
          • Aug 2004
          • 5

          #5
          Originally posted by Buddah00
          Look into TechieMedia for your hosting, they are good people. Strongbox should be able to help with your password protection.

          Don't discount the idea that your members may be giving out their password info or posting it on free password sites.

          I hear you...this has been posed by ccbill and my host. I however, point to the fact that I have invalid usernames being added to the password file directly in addition to the good usernames being abused. Is there a way to tell if somebody is a password trader or just an innocent victim? I would hate to accuse a paying member of password trading without proof.
          Caroline

          Comment

          • Altheon
            Confirmed User
            • May 2004
            • 506

            #6
            A dedicated server is a big step. Unless it is managed you will be responsible for everthing from regular system maitnence to security. If you don't have these skills or prefer a toe-in-the-water approach a managed VPS (Virtual Private Server) would be better choice.

            -A

            Comment

            • blackout
              Confirmed User
              • Jul 2004
              • 615

              #7
              What is the site in question?
              ICQ: 42777193

              Comment

              • Buddah00
                Confirmed User
                • May 2004
                • 722

                #8
                Originally posted by caroline4551
                I hear you...this has been posed by ccbill and my host. I however, point to the fact that I have invalid usernames being added to the password file directly in addition to the good usernames being abused. Is there a way to tell if somebody is a password trader or just an innocent victim? I would hate to accuse a paying member of password trading without proof.
                I have had several members post their passwords. I cancelled their account and never heard from them again. If they aren't guilty they will contact you. If the did give out the password they know they are wrong and that they got caught.
                I want what every other man wants, I just want it more.

                Comment

                • Wolfy
                  Confirmed User
                  • Dec 2003
                  • 3574

                  #9
                  I've been wondering about this very issue - I'm not sure if cc-bill will back this up or not, BUT...

                  isn't there a way to add a clause in your tTOS stating that a customer may only log in from one ip (or one computer), or even limit it to one ip per day to account for travelling business people, and any other ips logging in with your passord and username is grounds for cancelling said users account, and under these circumstances no refund will be issued.

                  Any ideas?

                  Comment

                  • caroline4551
                    Registered User
                    • Aug 2004
                    • 5

                    #10
                    Originally posted by Wolfy
                    I've been wondering about this very issue - I'm not sure if cc-bill will back this up or not, BUT...

                    isn't there a way to add a clause in your tTOS stating that a customer may only log in from one ip (or one computer), or even limit it to one ip per day to account for travelling business people, and any other ips logging in with your passord and username is grounds for cancelling said users account, and under these circumstances no refund will be issued.

                    Any ideas?
                    I think that it is the wrong supply/demand model for that type of rigid stance. I pride myself on being the type of customer service I like to receive. I'm not hot enough, raunchy enough or popular enough to place limitations on my members. And blocking people from entering the site is not really a problem. It's what to do with the actual customers after the hackers know their usernames. That's the problem.

                    I use Pennywize and no more bandwidth surprises and no more server crashes.

                    Because Pennywize is blocking that username from coming in again, the actual customer, with the right ip, is also blocked. Sucks for him. And sucks for me, if he calls ccbill and does a chargeback.

                    I have to add a new username to the password file and communicate this to my member, who will need to reenter it (after retreiving the email) to get back into the site with his pants around his ankles. I would like to make it as easy as possible for guys to get what they want from my site. Plus, if a webmaster emailed me and said, "uh, yeah, my server was hacked and 6 usernames where posted in cyberspace, one of them was yours." I wouldn't feel very good about that company having my credit card information.

                    Do you all have so much business that you are neutral about cancelling a paying customer you suspect of password trading? Perhaps I stress too much about customer service. But seriously, I wouldn't neccessarily think it would be a bad thing if my members shared their password with a couple people. A little bit of viral marking of the such as done well for me in the past. Especially with college boys in dorms They need a student discount. two for one. Obviously, I don't want hackers, and I don't want my members to miss out on the membership they paid for, but how to have both at the same time?
                    Caroline

                    Comment

                    • caroline4551
                      Registered User
                      • Aug 2004
                      • 5

                      #11
                      Hey, I just got an idea. I'll have to try to get in touch with Pennywize support, but it would be great if they could program it to allow only the one associated IP address (the one logged at the signup) once the tolerance is reached for the IP limit.

                      So say the threshold is set to 3 ip addresses. (the guy's home, the guy's work and the guy's buddy who wants to see the video he was talking about) Fine. But the next time that username hits the surfer, it has to be coming from the associated IP address. If the IP addresses don't match, then they are blocked.

                      Hey technical smart programmer types: is such a thing maybe possible? Seems like it would be plausible. You think?
                      Caroline

                      Comment

                      • ModelPerfect
                        Confirmed User
                        • Nov 2003
                        • 2862

                        #12
                        Originally posted by caroline4551
                        Hey, I just got an idea. I'll have to try to get in touch with Pennywize support, but it would be great if they could program it to allow only the one associated IP address (the one logged at the signup) once the tolerance is reached for the IP limit.

                        So say the threshold is set to 3 ip addresses. (the guy's home, the guy's work and the guy's buddy who wants to see the video he was talking about) Fine. But the next time that username hits the surfer, it has to be coming from the associated IP address. If the IP addresses don't match, then they are blocked.

                        Hey technical smart programmer types: is such a thing maybe possible? Seems like it would be plausible. You think?
                        I don't mean any offense, Caroline, but do you think it's a good business model to make special allocations to allow a customer to cheat you? In this post and the previous one, you are stating that password trading is acceptable to you. Even if it's just to one other college buddy, it's still password trading.

                        I would emphatically state in the TOS that password trading would result in immediate cancellation of the user/pass with no refunds given. Cite examples to make the realization: 2 logins at once, two IP logins in two geographical separated regions, etc. Even if you don't follow through and even if you can't stop a chargeback, you at least make them apprehensive to give it out. You won't alienate them, since it's an expected practice. But if you state, "ok...you can give it to one other person", there's nothing to stop him from giving it out to everyone.

                        Just my
                        Logan
                        modelperfect [at] gmail.com
                        http://www.modelperfect.com

                        (Proudly hosted at www.webair.com )

                        Comment

                        • prostock
                          On probation
                          • Jun 2002
                          • 4160

                          #13
                          Originally posted by caroline4551
                          I think that it is the wrong supply/demand model for that type of rigid stance. I pride myself on being the type of customer service I like to receive. I'm not hot enough, raunchy enough or popular enough to place limitations on my members. And blocking people from entering the site is not really a problem. It's what to do with the actual customers after the hackers know their usernames. That's the problem.

                          I use Pennywize and no more bandwidth surprises and no more server crashes.

                          Because Pennywize is blocking that username from coming in again, the actual customer, with the right ip, is also blocked. Sucks for him. And sucks for me, if he calls ccbill and does a chargeback.

                          I have to add a new username to the password file and communicate this to my member, who will need to reenter it (after retreiving the email) to get back into the site with his pants around his ankles. I would like to make it as easy as possible for guys to get what they want from my site. Plus, if a webmaster emailed me and said, "uh, yeah, my server was hacked and 6 usernames where posted in cyberspace, one of them was yours." I wouldn't feel very good about that company having my credit card information.

                          Do you all have so much business that you are neutral about cancelling a paying customer you suspect of password trading? Perhaps I stress too much about customer service. But seriously, I wouldn't neccessarily think it would be a bad thing if my members shared their password with a couple people. A little bit of viral marking of the such as done well for me in the past. Especially with college boys in dorms They need a student discount. two for one. Obviously, I don't want hackers, and I don't want my members to miss out on the membership they paid for, but how to have both at the same time?


                          the best way to tell if they are trading is look at the ips and what you do is see if the same user name is coming from more then one ip then you look at the ip of the clint that has paid you then send him a nice email telling that we killed your old name and pass for we see it is being used by many people this time and this time only we will give you a new one tho if we see this matter to be happing again we will then killer your memebership for we see that isnt wasnt a prob on our end yet what we thought it was we are right YOU ARE PASS WORD TRADING AND THAT BREAKS THE RULES , WE WILL SEND THIS TO THE BILLER SO NOT THINK OF CHARGE BACK !
                          every time we sent one of these letters out it stoped and never had a CB

                          ICQ # :158519717

                          Comment

                          • puremember
                            Registered User
                            • Jan 2004
                            • 3

                            #14
                            Originally posted by caroline4551
                            Hey technical smart programmer types: is such a thing maybe possible? Seems like it would be plausible. You think?
                            This will not work because many ISPs assign their users dynamic IP address, so the IP a user signs up with may not be the same IP they log in with the next day.

                            There is no way of knowing whether a user has deliberately released their login to the public. My advice would be to compromise, and put a "two strikes, you're out policy" in place. If a user's account is violated, issue them a new username/password combination no questions asked. However if the same user's account is violated again, cut them loose.

                            Shinjin
                            puremember.com

                            Comment

                            • eBoundary
                              Registered User
                              • Jun 2003
                              • 30

                              #15
                              Originally posted by puremember
                              This will not work because many ISPs assign their users dynamic IP address, so the IP a user signs up with may not be the same IP they log in with the next day.

                              True, but you could reduce the risk by limiting access to a specific subnet, say the same class C as the original signup. Should reduce at least some of the abuse
                              Danny
                              http://www.eBoundary.com - Fast, Reliable, Secure, hosting solutions.
                              http://www.adulthostingsolutions.com- Hosting, the way it should be!
                              AIM: eBoundaryTch | ICQ: 3090141

                              Comment

                              • PowerCum
                                CjOverkill
                                • Apr 2003
                                • 1328

                                #16
                                Reducing the allowed connections for some surfers to a given subnet is not a very good option. If your user is from Spain and he uses a DSL you will have to allow several non consecutive class A subnets.
                                Sessions is the way to go. It's simple and easy. You allow an uaser to be logged only once at a time. Once someone else logs (probably the same user because he got disconnected) all the sessions for that user are clened, so there can be ONLY ONE surfer using that login and password. Also you can put some session crean limit (IP changes) per day. Let's say you allow 10 IP changes per day per account. After that the account gets put on review. Anyways, it becomes useless to password traders because they will be unable to surf your site if they get disconnected every 5 minutes because others are using the same password at the same time.
                                CjOverkill Traffic Trading Script
                                Free, secure and fast traffic trading script. Get your copy now

                                Comment

                                • caroline4551
                                  Registered User
                                  • Aug 2004
                                  • 5

                                  #17
                                  Originally posted by PowerCum
                                  Reducing the allowed connections for some surfers to a given subnet is not a very good option. If your user is from Spain and he uses a DSL you will have to allow several non consecutive class A subnets.
                                  Sessions is the way to go. It's simple and easy. You allow an uaser to be logged only once at a time. Once someone else logs (probably the same user because he got disconnected) all the sessions for that user are clened, so there can be ONLY ONE surfer using that login and password. Also you can put some session crean limit (IP changes) per day. Let's say you allow 10 IP changes per day per account. After that the account gets put on review. Anyways, it becomes useless to password traders because they will be unable to surf your site if they get disconnected every 5 minutes because others are using the same password at the same time.

                                  this sounds like something I would want to look in to. How would I use/setup "sessions"?
                                  Caroline

                                  Comment

                                  • JackRoyal
                                    Registered User
                                    • Sep 2003
                                    • 65

                                    #18
                                    Originally posted by caroline4551
                                    this sounds like something I would want to look in to. How would I use/setup "sessions"?
                                    Yeah, except there is no such thing as a true "session" in HTTP. (the way there is with FTP, telnet, SSH, etc.) You would have to use cookies or some other kludge.

                                    Comment

                                    • Brinner
                                      Confirmed User
                                      • Jul 2004
                                      • 303

                                      #19
                                      How can I help you just let me know. 331483655

                                      Comment

                                      • chiefmojo
                                        Registered User
                                        • Feb 2004
                                        • 9

                                        #20
                                        hey,

                                        ill quote you the same $200 for a dedicated server and additionally solve all your problems.

                                        check my site http://www.myfirstporno.com

                                        email me at [email protected] if you want to know more.
                                        SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.

                                        Comment

                                        • Adam-EB
                                          Confirmed User
                                          • Mar 2004
                                          • 393

                                          #21
                                          Originally posted by caroline4551
                                          - www.xxxhosting.com (www.reliablehosting.com) quoted me $200 for a dedicated server which I would gladly pay if I thought it would make a difference

                                          Reliablehosting.com is the same as XXXWebHosting.com, not xxxhosting.com.
                                          Last edited by Adam-EB; 08-24-2004, 08:09 AM.
                                          SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.

                                          Comment

                                          • JosefG
                                            Registered User
                                            • Aug 2004
                                            • 1

                                            #22
                                            What's about a member login and registration, which does or requires:
                                            - First a member registers, he gets an automatically generated password by email (that prevents you a bit, as it's not easy to change the email address often)
                                            - Member login with name or email and password
                                            - member can modify password as often as they want
                                            - as after login with password the dsn is used for login-verifications, that works simple and reliable
                                            - If a member logout correctly, the used dns address is deleted, nobody can login this way without valid password

                                            Most simple way, no problems about all together. Try it out at
                                            http://trademile.com/cgi-bin/aalogin...ewform&conf=de

                                            please use the german version 'login Deutsch', I have not yet translated the english configuration version

                                            any coments?

                                            Comment

                                            • exposed
                                              Confirmed User
                                              • Aug 2004
                                              • 1449

                                              #23
                                              Originally posted by prostock
                                              the best way to tell if they are trading is look at the ips and what you do is see if the same user name is coming from more then one ip then you look at the ip of the clint that has paid you then send him a nice email telling that we killed your old name and pass for we see it is being used by many people this time and this time only we will give you a new one tho if we see this matter to be happing again we will then killer your memebership for we see that isnt wasnt a prob on our end yet what we thought it was we are right YOU ARE PASS WORD TRADING AND THAT BREAKS THE RULES , WE WILL SEND THIS TO THE BILLER SO NOT THINK OF CHARGE BACK !
                                              every time we sent one of these letters out it stoped and never had a CB

                                              definately makes sense! good suggestions
                                              "I felt victimized by the Ian Eisenbergs of the world" - Mary Burger

                                              Comment

                                              • zarghol2
                                                Registered User
                                                • Aug 2004
                                                • 4

                                                #24
                                                hi all,

                                                don't forget that AOL users have a different IP each time they connect (at least the french system does).

                                                http://www.Sexy-casting.org

                                                Comment

                                                • PowerCum
                                                  CjOverkill
                                                  • Apr 2003
                                                  • 1328

                                                  #25
                                                  Originally posted by caroline4551
                                                  this sounds like something I would want to look in to. How would I use/setup "sessions"?
                                                  PHP can handle sessions. I suggest you to use MySQL powered sessions. If you want you can borrow some code from phpnuke (www.phpnuke.org), but you will need to change it in order to allow session set on htaccess authentication... probably you will need to migrate all your athentication to mod_auth_mysql.
                                                  CjOverkill Traffic Trading Script
                                                  Free, secure and fast traffic trading script. Get your copy now

                                                  Comment

                                                  Working...