Who else think this is a security risk.....

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Machete_
    WINNING!
    • Oct 2002
    • 14579

    #1

    Who else think this is a security risk.....

    Many affiliate program's have their link-codes like this:
    http://domain.com/reftracler=ID
    and ID = username in 50-60% of the cases...

    I really don't feel good about people knowing my user-name..
    They can take a brute force script + word-list.. and its just a matter of time before they have access to my account = my money

    I like NATS because they encrypt the link - thanks guys... I wish more Programs would do the same
  • JoeMeca
    So Fucking Banned
    • Nov 2005
    • 2266

    #2
    Yup i agree or a number like 487475 byt nope ahha

    Comment

    • SmokeyTheBear
      ►SouthOfHeaven
      • Jun 2004
      • 28609

      #3
      Originally posted by ebus_dk
      Many affiliate program's have their link-codes like this:
      http://domain.com/reftracler=ID
      and ID = username in 50-60% of the cases...

      I really don't feel good about people knowing my user-name..
      They can take a brute force script + word-list.. and its just a matter of time before they have access to my account = my money

      I like NATS because they encrypt the link - thanks guys... I wish more Programs would do the same

      if someone is going to go thru the trouble of trying to brute force your affiliate account , they would just decrypt your username before they tried to crack it.. all the nats codes do for me is make it harder to add link codes.
      hatisblack at yahoo.com

      Comment

      • Tempest
        Too lazy to set a custom title
        • May 2004
        • 10217

        #4
        Perhaps you should generate a random 10+ digit password... Maybe even do the same for the username...

        Comment

        • Machete_
          WINNING!
          • Oct 2002
          • 14579

          #5
          Originally posted by SmokeyTheBear
          if someone is going to go thru the trouble of trying to brute force your affiliate account , they would just decrypt your username before they tried to crack it.. all the nats codes do for me is make it harder to add link codes.
          sure, but it could still make it a smaller risk

          Comment

          • Tempest
            Too lazy to set a custom title
            • May 2004
            • 10217

            #6
            Originally posted by SmokeyTheBear
            all the nats codes do for me is make it harder to add link codes.
            Yep.. pisses me off since I use scripts for all my links and sites so things like campaign codes and stuff can be done by the script... After ARS shutting down all their sites and then hawgcash, I don't hard code any freakin links anymore unless it's a gallery I have to submit...

            Comment

            • iwantchixx
              Too lazy to set a custom title
              • Oct 2002
              • 12860

              #7
              I agree with smokey on this one, it's much easier to play with codes.

              Comment

              • SmokeyTheBear
                ►SouthOfHeaven
                • Jun 2004
                • 28609

                #8
                Originally posted by ebus_dk
                sure, but it could still make it a smaller risk
                frankly i highly doubt it . if someone is determined to hack an affiliate account solely on a username they found , they would also be smart enough to decrypt the nats username that is very simply decoded.
                hatisblack at yahoo.com

                Comment

                • Machete_
                  WINNING!
                  • Oct 2002
                  • 14579

                  #9
                  Originally posted by Tempest
                  Perhaps you should generate a random 10+ digit password... Maybe even do the same for the username...
                  I keep 8 char strong passwords thats different from each site, but the username they can se in the code - that is the problem..

                  Just like I know Smokey uses "gfy" or "gfygfy" on many of his sites.. its fucked

                  Comment

                  • Machete_
                    WINNING!
                    • Oct 2002
                    • 14579

                    #10
                    Guess its just me then

                    Comment

                    • Hardlinks
                      Confirmed User
                      • May 2005
                      • 1333

                      #11
                      Originally posted by ebus_dk
                      Guess its just me then

                      Seeing my ref code gives me wood.
                      Find out how I make Fabulous Cash !!

                      Comment

                      • Tempest
                        Too lazy to set a custom title
                        • May 2004
                        • 10217

                        #12
                        Originally posted by Hardlinks
                        Seeing my ref code gives me wood.
                        Especially when it's showing up in the google serps.

                        Comment

                        • JD
                          Too lazy to set a custom title
                          • Sep 2003
                          • 22651

                          #13
                          Originally posted by Tempest
                          Especially when it's showing up in the google serps.
                          werd

                          Comment

                          Working...