I promised you OXEO drama (pics, ++)

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • SomeCreep
    :glugglug
    • Mar 2003
    • 26118

    #51
    50 sig views
    Last edited by SomeCreep; 11-20-2004, 04:23 PM.

    Webair Hosting

    I use and recommend Webair for hosting.

    Comment

    • AkiraSS
      Wemaxa.com
      • Jan 2003
      • 2989

      #52

      Comment

      • Theo
        HAL 9000
        • May 2001
        • 34515

        #53
        Originally posted by Soul_Rebel
        holy

        no wonder paysites mailing lists are getting stolen frequently
        im taking back that cause it would affect only virtual/shared accounts

        Comment

        • DamageX
          Marketing & Strategy
          • Jun 2001
          • 14293

          #54
          Interesting, to say the least. Waiting for Oxeo to reply to this.
          Whitehat is for chumps

          If you don't do it, somebody else will - true story!

          Comment

          • MaDalton
            I am Amazing Content!
            • Feb 2004
            • 39861

            #55
            i normally don't do that, but...

            AmazingContent.com - providing only the best content and service since 2003
            Monetize your content on Veegaz.com - one of Germanies largest VOD sites
            Got German traffic? We convert it into money for you!
            Email: oltecconsult [at] gmail [dot] com

            Comment

            • cayne
              My time is coming...
              • Jan 2004
              • 7475

              #56
              wow - that's indeed a big prob.
              If lesbian anal is wrong, I don't want to be right.

              Comment

              • SomeCreep
                :glugglug
                • Mar 2003
                • 26118

                #57
                Originally posted by juicylinks

                Webair Hosting

                I use and recommend Webair for hosting.

                Comment

                • IPK
                  Confirmed User
                  • Sep 2003
                  • 4209

                  #58
                  whoa that sucks
                  DomainerResource.com
                  strategies for monetizing and investing in domain names...

                  Comment

                  • Trent Edison
                    Too lazy to set a custom title
                    • Jun 2003
                    • 6132

                    #59
                    Awesome job Monkey. FBI can take a vacation.
                    And see sig off course...

                    Comment

                    • Theo
                      HAL 9000
                      • May 2001
                      • 34515

                      #60
                      www.dieselaction.com


                      contact me to maximize the earnings of your traffic

                      Comment

                      • Tam
                        Rude Bitch
                        • Jan 2001
                        • 8534

                        #61
                        Originally posted by woj
                        50
                        as usual, you shot off prematurely.....
                        Get in Touch on Telegram if you need a hardworker - (since 1999) - All About Me!

                        Comment

                        • swedguy
                          Confirmed User
                          • Jan 2002
                          • 7981

                          #62
                          <sarcasm>
                          I've heard it's good to bring on drama on weekends. Makes it so much easier for people to respond.
                          </sarcasm>

                          Comment

                          • bestwaysex
                            Confirmed User
                            • Jan 2004
                            • 154

                            #63
                            Please don't check my sig

                            Need a stable 50k/100k/150k+ TGP or MGP built?
                            We are the best in the industry, no competition
                            Hit me up on icq at: 16307149

                            Comment

                            • PlayaPlaya
                              Confirmed User
                              • Jul 2001
                              • 191

                              #64
                              At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.

                              866.ASK.OXEO,
                              212.812.9073
                              or ICQ 161954530

                              Thank you
                              Last edited by PlayaPlaya; 11-20-2004, 05:29 PM.
                              Best Regards,

                              Michael Volozin
                              Oxeo Hosting
                              www.oxeo.com
                              Direct: 212.812.9073 ext 901
                              ICQ: 150013894 | AIM: MikeOxeo

                              Comment

                              • Repetitive Monkey
                                Confirmed User
                                • Feb 2004
                                • 3505

                                #65
                                Originally posted by PlayaPlaya
                                At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.

                                866.ASK.OXEO,
                                212.812.9073
                                or ICQ 161954530

                                Thank you
                                What are you saying? Are you denying that I viewed root on one of your virtuals? Are you saying that the screenshots are doctored?

                                If you are, then let's contact the owners of the sites visited and hear from them if the info in the screenshots matches or not.

                                Comment

                                • Repetitive Monkey
                                  Confirmed User
                                  • Feb 2004
                                  • 3505

                                  #66
                                  Originally posted by PlayaPlaya
                                  At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.

                                  866.ASK.OXEO,
                                  212.812.9073
                                  or ICQ 161954530

                                  Thank you
                                  Btw,

                                  Last edited by Repetitive Monkey; 11-20-2004, 05:41 PM.

                                  Comment

                                  • QuaWee
                                    Confirmed User
                                    • Jul 2004
                                    • 5791

                                    #67
                                    i luv mainstream

                                    Comment

                                    • cosis
                                      Confirmed User
                                      • Aug 2001
                                      • 5292

                                      #68
                                      Originally posted by Repetitive Monkey
                                      Btw,

                                      I knew that was coming

                                      Comment

                                      • fris
                                        I have to go potty
                                        • Aug 2002
                                        • 55785

                                        #69
                                        what he is saying is they have clueless system admins on staff, and they dont know how to secure their products/servers and they will be back when they hire someone and get it fixed.

                                        aka buying time.
                                        Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


                                        Totally Free Templates

                                        Comment

                                        • Fatalspeed
                                          Confirmed User
                                          • Sep 2002
                                          • 2101

                                          #70
                                          and I used to have a site there ..

                                          the drama
                                          Faber est quisque fortunae suae

                                          Comment

                                          • volante
                                            Confirmed User
                                            • Mar 2002
                                            • 2940

                                            #71
                                            Am I too late to say

                                            ?

                                            Comment

                                            • Doctor Dre
                                              Too lazy to set a custom title
                                              • Jan 2001
                                              • 51692

                                              #72
                                              I missed the first page. This is gonna be funny
                                              Originally posted by rayadp05
                                              I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                                              Comment

                                              • juicylinks
                                                So Fucking Banned
                                                • Apr 2001
                                                • 122992

                                                #73
                                                Originally posted by volante
                                                Am I too late to say

                                                ?

                                                Comment

                                                • Superterrorizer
                                                  Confirmed User
                                                  • Sep 2003
                                                  • 509

                                                  #74
                                                  Originally posted by Magg
                                                  yes, they could, glad to say we're already protected against this little trick
                                                  You are in no position to be talking shit in threads about other hosts. It makes you look like an idiot, especially considering your shit was hacked twice in the same week. Retard.

                                                  Comment

                                                  • PlayaPlaya
                                                    Confirmed User
                                                    • Jul 2001
                                                    • 191

                                                    #75
                                                    From the look of it, your ServerGod webscript is using the apache user account to read user directories and files which have the wrong read/write permissions. We strongly suggest for customers not to use permissions like "chmod 777" on important directories or files to avoid any password or sensitive data leaking. The script did not compromise any of our servers or system accounts and will most likely be able to show "security problems" on every web host which allows the hosting of dynamic web scripts. If you are a customer or if you have general questions about the security risk running such a script on your website please contact us directly.
                                                    Best Regards,

                                                    Michael Volozin
                                                    Oxeo Hosting
                                                    www.oxeo.com
                                                    Direct: 212.812.9073 ext 901
                                                    ICQ: 150013894 | AIM: MikeOxeo

                                                    Comment

                                                    • Repetitive Monkey
                                                      Confirmed User
                                                      • Feb 2004
                                                      • 3505

                                                      #76
                                                      Originally posted by PlayaPlaya
                                                      From the look of it, your ServerGod webscript is using the apache user account to read user directories and files which have the wrong read/write permissions. We strongly suggest for customers not to use permissions like "chmod 777" on important directories or files to avoid any password or sensitive data leaking. The script did not compromise any of our servers or system accounts and will most likely be able to show "security problems" on every web host which allows the hosting of dynamic web scripts. If you are a customer or if you have general questions about the security risk running such a script on your website please contact us directly.
                                                      Hold on the doublespeak. Are you trying to say that the screenshots are fake and that Server God never visited any OXEO accounts, or that a script that can read the sources and passwords for all virtual accounts isn't considered by OXEO to be a threat?

                                                      The former is wrong and the latter is outrageous.

                                                      Comment

                                                      • bryany
                                                        Confirmed User
                                                        • Aug 2001
                                                        • 2037

                                                        #77
                                                        I wanna be in the Cool Kids Club Dammit!

                                                        ya ya, I'll fill this in later...

                                                        Comment

                                                        • Repetitive Monkey
                                                          Confirmed User
                                                          • Feb 2004
                                                          • 3505

                                                          #78
                                                          Originally posted by Repetitive Monkey
                                                          Hold on the doublespeak. Are you trying to say that the screenshots are fake and that Server God never visited any OXEO accounts, or that a script that can read the sources and passwords for all virtual accounts isn't considered by OXEO to be a threat?

                                                          The former is wrong and the latter is outrageous.
                                                          Let me reiterate my inquiry in a manner better suited to your obligement to answer: DO YOU, AS A REPRESENTATIVE OF OXEO, CONSIDER PUBLIC VIEWING OF YOUR CLIENTS' SOURCES AND PASSWORDS A THREAT OR NOT?

                                                          Comment

                                                          • rowan
                                                            Too lazy to set a custom title
                                                            • Mar 2002
                                                            • 17393

                                                            #79
                                                            This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.

                                                            If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.

                                                            I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.

                                                            This is why I use dedicated servers only.

                                                            Comment

                                                            • Repetitive Monkey
                                                              Confirmed User
                                                              • Feb 2004
                                                              • 3505

                                                              #80
                                                              Originally posted by rowan
                                                              This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.

                                                              If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.

                                                              I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.

                                                              This is why I use dedicated servers only.
                                                              No solution? I understand from this that you haven't read too much into the PHP configs.

                                                              Comment

                                                              • swedguy
                                                                Confirmed User
                                                                • Jan 2002
                                                                • 7981

                                                                #81
                                                                Originally posted by rowan
                                                                This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.

                                                                If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.

                                                                I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.

                                                                This is why I use dedicated servers only.
                                                                http://httpd.apache.org/docs/suexec.html

                                                                Comment

                                                                • garett
                                                                  Confirmed User
                                                                  • Mar 2004
                                                                  • 683

                                                                  #82
                                                                  Originally posted by Repetitive Monkey
                                                                  What are you saying? Are you denying that I viewed root on one of your virtuals? Are you saying that the screenshots are doctored?

                                                                  If you are, then let's contact the owners of the sites visited and hear from them if the info in the screenshots matches or not.
                                                                  Looking at the screenshots I don't see how this is 'hacking'. The most that could happen, with access to a user's home directory, is that info could be stolen. Passwords out of .htpasswd for paysites etc., content, whatever ...

                                                                  So you were able to browse directories, including /root .. you didn't demonstrate that you had root priveleges on their server. You didn't demostrate that you were able to remotely compromise a machine that you did not previously have any user-level access to etc.

                                                                  And I don't see what the 'trick' that someone else mentioned is. What this software does that is so '1337'. A simple 'cd' and 'ls' on the shell would work just as well... unless of course oxeo doesn't provide ssh access to it's customers.

                                                                  Comment

                                                                  • rowan
                                                                    Too lazy to set a custom title
                                                                    • Mar 2002
                                                                    • 17393

                                                                    #83
                                                                    Originally posted by Repetitive Monkey
                                                                    No solution? I understand from this that you haven't read too much into the PHP configs.
                                                                    You mean safe mode? That causes other problems. A script can create a dir and populate it with files, but the same script is unable to delete them.

                                                                    Comment

                                                                    • Repetitive Monkey
                                                                      Confirmed User
                                                                      • Feb 2004
                                                                      • 3505

                                                                      #84
                                                                      Originally posted by garett
                                                                      Looking at the screenshots I don't see how this is 'hacking'. The most that could happen, with access to a user's home directory, is that info could be stolen. Passwords out of .htpasswd for paysites etc., content, whatever ...

                                                                      So you were able to browse directories, including /root .. you didn't demonstrate that you had root priveleges on their server. You didn't demostrate that you were able to remotely compromise a machine that you did not previously have any user-level access to etc.

                                                                      And I don't see what the 'trick' that someone else mentioned is. What this software does that is so '1337'. A simple 'cd' and 'ls' on the shell would work just as well... unless of course oxeo doesn't provide ssh access to it's customers.
                                                                      You don't get it. The point is that ANYONE can read ANYONES source on OXEO virtuals. If this isn't a concern for OXEO then I am shocked, and curious as to what else they don't give a shit about in regards to security and confidentiality.

                                                                      Comment

                                                                      • PlayaPlaya
                                                                        Confirmed User
                                                                        • Jul 2001
                                                                        • 191

                                                                        #85
                                                                        We have never denied that your script had access to files and directories which had the wrong permissions. We take security very seriously and running such a script on any virtual servers is a big security risk and against our terms of service. We are investigating the account which was running the software and are taking further steps to secure our servers against such web scripts.
                                                                        Best Regards,

                                                                        Michael Volozin
                                                                        Oxeo Hosting
                                                                        www.oxeo.com
                                                                        Direct: 212.812.9073 ext 901
                                                                        ICQ: 150013894 | AIM: MikeOxeo

                                                                        Comment

                                                                        • Repetitive Monkey
                                                                          Confirmed User
                                                                          • Feb 2004
                                                                          • 3505

                                                                          #86
                                                                          Originally posted by PlayaPlaya
                                                                          We have never denied that your script had access to files and directories which had the wrong permissions. We take security very seriously and running such a script on any virtual servers is a big security risk and against our terms of service. We are investigating the account which was running the software and are taking further steps to secure our servers against such web scripts.
                                                                          Ok, good. Now answer me, why didn't you do this sooner?

                                                                          Comment

                                                                          • Magg
                                                                            Confirmed User
                                                                            • Feb 2004
                                                                            • 4467

                                                                            #87
                                                                            Originally posted by Superterrorizer
                                                                            You are in no position to be talking shit in threads about other hosts. It makes you look like an idiot, especially considering your shit was hacked twice in the same week. Retard.

                                                                            Who the hell is talking shit? I was ANSWERING A QUESTION.


                                                                            RETARD.

                                                                            Comment

                                                                            • netnut
                                                                              Confirmed User
                                                                              • Nov 2004
                                                                              • 280

                                                                              #88
                                                                              im probably too late for a sig placement, but here it is

                                                                              Comment

                                                                              • David!
                                                                                By the wrath of Agamemnon
                                                                                • Apr 2004
                                                                                • 6501

                                                                                #89
                                                                                .

                                                                                Comment

                                                                                • Evil Chris
                                                                                  OG
                                                                                  • Dec 2001
                                                                                  • 13248

                                                                                  #90
                                                                                  I have the best looking sig in this thread. I do.


                                                                                  It PAYZE to post on GFY

                                                                                  chris at payze.com | Skype chriswrp

                                                                                  Comment

                                                                                  • VeriSexy
                                                                                    Join The Royal Family
                                                                                    • Apr 2002
                                                                                    • 25463

                                                                                    #91
                                                                                    Originally posted by juicylinks
                                                                                    Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
                                                                                    Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos
                                                                                    .
                                                                                    With TOP RATIO Sites like


                                                                                    ATMovs.com | iTeenVideo.com |
                                                                                    TeenSexMovs.com | TeenSexMania.com


                                                                                    Comment

                                                                                    • Superterrorizer
                                                                                      Confirmed User
                                                                                      • Sep 2003
                                                                                      • 509

                                                                                      #92
                                                                                      Originally posted by Magg
                                                                                      Who the hell is talking shit? I was ANSWERING A QUESTION.


                                                                                      RETARD.
                                                                                      Blah blah blah. You are always in hosting threads promoting your shit, talking shit about other hosts in an attempt to make yourself look like you have a clue.

                                                                                      Promoting your hosting in a thread like this makes you look like a moron.

                                                                                      Comment

                                                                                      • Magg
                                                                                        Confirmed User
                                                                                        • Feb 2004
                                                                                        • 4467

                                                                                        #93
                                                                                        Youre a complete idiot, this is an open forum, my main interest is hosting, so fuck yes im going to be posting in hosting threads.


                                                                                        Whether Im wearing my sig or not, you'll still see my posting as I know what is going on. The sig is automatically attached to my posts, Im not going to take time and remember to unclick the button that attaches it for idiots like you who have nothing to do but criticize and hate.


                                                                                        I'll continue to be in hosting threads as long as there are ones being made. Sorry if you cant seem the grasp the idea of having a favorite subject.


                                                                                        Secondly, do you know how many hosts here on GFY are probably vulnerable to this exploit?

                                                                                        Installing PHP open_basedir tweak will stop users from browsing outside of their account DIR, thus negating the usefulness of this script.

                                                                                        Theres the easy fix.

                                                                                        Moron.
                                                                                        Last edited by Magg; 11-20-2004, 08:06 PM.

                                                                                        Comment

                                                                                        • Theo
                                                                                          HAL 9000
                                                                                          • May 2001
                                                                                          • 34515

                                                                                          #94
                                                                                          www.dieselaction.com

                                                                                          Comment

                                                                                          • Superterrorizer
                                                                                            Confirmed User
                                                                                            • Sep 2003
                                                                                            • 509

                                                                                            #95
                                                                                            Originally posted by Magg




                                                                                            MONKEY CHECK YOUR ICQ
                                                                                            Sorry, I apologize. You are right, there is nothing you can do about your sig. I am not sure why I thought you were trying to spam your resold Poopah bandwidth in this thread.

                                                                                            Let's be friends, maybe we can go to the homecoming dance together??

                                                                                            Comment

                                                                                            • TheEbonyFelony
                                                                                              Confirmed User
                                                                                              • Jun 2003
                                                                                              • 1964

                                                                                              #96
                                                                                              no you cannot know what im promoting you nosey fucks!

                                                                                              Comment

                                                                                              • emthree
                                                                                                Dialer Kingpin
                                                                                                • Jun 2003
                                                                                                • 10816

                                                                                                #97
                                                                                                You sale cheap stolen scripts?

                                                                                                Sell Patches & Pills

                                                                                                Comment

                                                                                                • Repetitive Monkey
                                                                                                  Confirmed User
                                                                                                  • Feb 2004
                                                                                                  • 3505

                                                                                                  #98
                                                                                                  Originally posted by emthree
                                                                                                  You sale cheap stolen scripts?
                                                                                                  Excuse me? This was written from scratch, by me.

                                                                                                  If you are asking whether you can buy it illegitimately then it must suck to be you.

                                                                                                  Comment

                                                                                                  • emthree
                                                                                                    Dialer Kingpin
                                                                                                    • Jun 2003
                                                                                                    • 10816

                                                                                                    #99
                                                                                                    Originally posted by Repetitive Monkey
                                                                                                    Excuse me? This was written from scratch, by me.

                                                                                                    If you are asking whether you can buy it illegitimately then it must suck to be you.
                                                                                                    No, that's not what I ment
                                                                                                    But seeing as you killed the joke in my head, never mind

                                                                                                    quick question:
                                                                                                    Would it be possible for you guys to create a bulk version of SEO Buddy? I need an application which can easily check 50k-100k phrases/lines per session with ease. (My needs have nothing to do with SEO btw.)

                                                                                                    Sell Patches & Pills

                                                                                                    Comment

                                                                                                    • Repetitive Monkey
                                                                                                      Confirmed User
                                                                                                      • Feb 2004
                                                                                                      • 3505

                                                                                                      #100
                                                                                                      Originally posted by emthree
                                                                                                      No, that's not what I ment
                                                                                                      But seeing as you killed the joke in my head, never mind

                                                                                                      quick question:
                                                                                                      Would it be possible for you guys to create a bulk version of SEO Buddy? I need an application which can easily check 50k-100k phrases/lines per session with ease. (My needs have nothing to do with SEO btw.)
                                                                                                      I still don't get what you tried to say. I must be stupid.

                                                                                                      But yes, such a SEO Buddy version is possible. I don't think there is much of a demand for it though. SEO Buddy standard has sold perhaps ten times.

                                                                                                      Comment

                                                                                                      Working...