Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-11-2012, 07:34 AM   #51
CyberHustler
So Fucking Banned
 
Industry Role:
Join Date: Feb 2006
Posts: 26,062
Aww man this is going to be a fun one... for me at least, since I don't use Paxum. 50+ people who don't learn from the past? We shall see.
CyberHustler is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:37 AM   #52
ZeroHero
So Fucking Banned
 
Industry Role:
Join Date: Nov 2007
Location: Westbahnhof
Posts: 15,336
Quote:
Originally Posted by RuthB View Post
No, we are simply upgrading our login security to a better system. Thanks for your concern, but everything is fine.
Thanks Ruth
ZeroHero is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:37 AM   #53
Rothstein
So Fucking Banned
 
Industry Role:
Join Date: Jan 2012
Location: Frostburg, MD
Posts: 682
Quote:
Originally Posted by Dirty F View Post
People actually pay you?
Rothstein is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:38 AM   #54
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
Join Date: Jan 2012



doing biz here for decade before you came along.

LOL
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:39 AM   #55
Rothstein
So Fucking Banned
 
Industry Role:
Join Date: Jan 2012
Location: Frostburg, MD
Posts: 682
Quote:
Originally Posted by Fletch XXX View Post
Join Date: Jan 2012



doing biz here for decade before you came along.

LOL
Had over 10 nicks before yours was registered.

Go sell some more $5 banners, banner boy.
Rothstein is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:41 AM   #56
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
Quote:
Originally Posted by Rothstein View Post
Had over 10 nicks before yours was registered.
hahaha

gotcha well thanks for the eyes.

I always appreciate the new business these threads bring.

I use paxum if anyone needs adult services and use this as payment just hit me up!
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 07:41 AM   #57
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
Quote:
Originally Posted by Rothstein View Post
Had over 10 nicks before yours was registered.

Go sell some more $5 banners, banner boy.
ooohh banner boy, havent heard that one inawhile, forgot who coined it.

Nonetheless, my banners are not $5.

prices here http://www.getbannersmade.com

but I will make any client who emails me a deal and do some $5 ones just because of this thread LOL

email me!
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:06 AM   #58
mafia_man
Confirmed User
 
mafia_man's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq#: 639544261
Posts: 1,965
Quote:
Originally Posted by k0nr4d View Post
They store it in an md5 hash, you can see it in the cookie named 'toplabs' that they store when you login:
a:3:{s:4:"user";s:25:"[email protected]";s:4:"pass";s :44:"passwordhashhere";s:2:"no";i:13;}

What they store in the cookie is what appears to be a base64-encoded md5 hash. It appears to be salted.
MD5 has been ripped to pieces a long time ago. As a financial institution they should be using bcrypt minimum.
__________________
I'm out.
mafia_man is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:16 AM   #59
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
Quote:
Originally Posted by mafia_man View Post
MD5 has been ripped to pieces a long time ago. As a financial institution they should be using bcrypt minimum.
They should be using their own algorithm...
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:20 AM   #60
facialfreak
Confirmed User
 
facialfreak's Avatar
 
Join Date: Feb 2005
Location: Montreal
Posts: 3,018


YOUR PASSWORDS ARE IN MOTION ... PLEASE REMAIN CALM!!

-----------------

So glad I do not have a horse in the PAXUM race ...

I learned my lesson with epassporte.
__________________

Managed Shared Hosting starting at $4.99/mo
Managed VPS starting at $29.99/mo


facialfreak is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:23 AM   #61
cherrylula
lol
 
cherrylula's Avatar
 
Industry Role:
Join Date: Jan 2002
Posts: 15,969
In case anyone missed the PAXUM response, they fixed the issue and were upgrading something.
cherrylula is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:25 AM   #62
Rothstein
So Fucking Banned
 
Industry Role:
Join Date: Jan 2012
Location: Frostburg, MD
Posts: 682
Quote:
Originally Posted by cherrylula View Post
In case anyone missed the PAXUM response, they fixed the issue and were upgrading something.
Idiot, this thread is about security.
Rothstein is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 08:29 AM   #63
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
Quote:
Originally Posted by cherrylula View Post
In case anyone missed the PAXUM response, they fixed the issue and were upgrading something.
That's the 'official' response... but anyone worth anything knows that a company doesn't take their site down without ample warning to perform upgrades. It's really that simple.

Had people been warned a week or more before they went down for their "upgrades" then there wouldn't be a problem... but considering they went down unexpectedly tells us something went wrong somewhere... and since they're saying they're down for "security upgrades" and have foolishly sent all of their clients plain text passwords via email... the whole thing screams "we were hacked and we're trying to make it look like we weren't".
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 09:27 AM   #64
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,200
Quote:
Originally Posted by RuthB View Post
everything is fine.

Money is in motion ...
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 09:38 AM   #65
mafia_man
Confirmed User
 
mafia_man's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq#: 639544261
Posts: 1,965
Quote:
Originally Posted by vdbucks View Post
They should be using their own algorithm...
Nonononono

Bad idea.
__________________
I'm out.
mafia_man is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 09:40 AM   #66
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
Quote:
Originally Posted by mafia_man View Post
Nonononono

Bad idea.
Why? if you don't know the algorithm then it's harder to crack.... assuming of course they have someone who knows wtf they are doing... which from the looks of it, they currently don't so you're probably right :P
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 09:53 AM   #67
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,200
Quote:
Originally Posted by vdbucks View Post
Why? if you don't know the algorithm then it's harder to crack.... assuming of course they have someone who knows wtf they are doing... which from the looks of it, they currently don't so you're probably right :P
you need to be a specialist in cryptography to create an algorithm.
Of course you could combine some solid algorithms together but not to use only one of your own.
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 09:55 AM   #68
anexsia
Confirmed User
 
anexsia's Avatar
 
Industry Role:
Join Date: May 2010
Posts: 5,735
Quote:
Originally Posted by pornmasta View Post
you need to be a specialist in cryptography to create an algorithm.
Of course you could combine some solid algorithms together but not to use only one of your own.
my theory is there will be a new movie out shortly about paxum.
anexsia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 10:20 AM   #69
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
1. Unscheduled downtime
2. Everyone's password reset and you can't use your old one that you had with paxum
3. Unable to transfer funds to mastercard.

It's pretty safe to say its not just a "login upgrade". Such actions are always a case when your site gets compromised. Seen it far too many times.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 11:55 AM   #70
AdultEUhost
ORLY?
 
AdultEUhost's Avatar
 
Industry Role:
Join Date: Oct 2005
Location: NL & US
Posts: 2,579
Something weird is happening here for sure.

When I login with the new password and try to set it back to what it was I get:

"The new password you have entered has been used in the past. Please select a password that has never been used on this account."

So Paxum does know our old passwords and still have them in their possession. Hence the fact they email a new password to everyone in plain text is just borderline ridiculous. They could have easily put up a page where you can login with your current password and set a new password after you have identified yourself by logging in.

I don't know about Canada but every financial institution should report any hacks. The fact that Paxum holds funds for a ton of account holders and thus probably millions makes it an interesting goal for people who need quick cash without having to buy a gun and rob a bank. It is probably targeted daily by hackers.

I am not saying Paxum got hacked but as an account holder I demand a better and more detailed explanation, my bullshit radar is reporting very high numbers currently.
__________________
ICQ: 267-443-722 / leon [at] adulteuhost [dotcom]

Nominated for an XBIZ Award as "Webhost of the Year" in 2007, 2012, 2013 and 2014
AdultEUhost is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 12:06 PM   #71
Best-In-BC
Confirmed User
 
Best-In-BC's Avatar
 
Join Date: Jun 2002
Posts: 9,506
Quote:
Originally Posted by CyberHustler View Post
Aww man this is going to be a fun one... for me at least, since I don't use Paxum. 50+ people who don't learn from the past? We shall see.
ROFL, under that logic we should all take our money outta the banks ;) if we are to learn something from epass it'd be not to leave insane amounts of money in your account.
__________________
Vacares - Web Hosting, Domains, O365, Security & More
Unparked domains burning a hole in your pocket? 5 Simple Ways to Make Easy $$$ from Unused Domains
Best-In-BC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 12:30 PM   #72
mafia_man
Confirmed User
 
mafia_man's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq#: 639544261
Posts: 1,965
Quote:
Originally Posted by AdultEUhost View Post
Something weird is happening here for sure.

When I login with the new password and try to set it back to what it was I get:

"The new password you have entered has been used in the past. Please select a password that has never been used on this account."

So Paxum does know our old passwords and still have them in their possession. Hence the fact they email a new password to everyone in plain text is just borderline ridiculous. They could have easily put up a page where you can login with your current password and set a new password after you have identified yourself by logging in.

I don't know about Canada but every financial institution should report any hacks. The fact that Paxum holds funds for a ton of account holders and thus probably millions makes it an interesting goal for people who need quick cash without having to buy a gun and rob a bank. It is probably targeted daily by hackers.

I am not saying Paxum got hacked but as an account holder I demand a better and more detailed explanation, my bullshit radar is reporting very high numbers currently.
This shocked me also. Paxum knew about my previous passwords which means they are being stored in the clear somewhere.
__________________
I'm out.
mafia_man is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 12:55 PM   #73
AdultEUhost
ORLY?
 
AdultEUhost's Avatar
 
Industry Role:
Join Date: Oct 2005
Location: NL & US
Posts: 2,579
Quote:
Originally Posted by mafia_man View Post
This shocked me also. Paxum knew about my previous passwords which means they are being stored in the clear somewhere.
That is not true and most unlikely
They can have it stored in their database as a md5 hash for example and just compare your entry after they md5 it.

The point is though that they do have the old passwords which makes this whole email with a clear text password in it not only unnecessary but from a security point a view also very stupid
__________________
ICQ: 267-443-722 / leon [at] adulteuhost [dotcom]

Nominated for an XBIZ Award as "Webhost of the Year" in 2007, 2012, 2013 and 2014

Last edited by AdultEUhost; 02-11-2012 at 12:56 PM..
AdultEUhost is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 01:14 PM   #74
epitome
So Fucking Lame
 
epitome's Avatar
 
Industry Role:
Join Date: Jun 2009
Location: St. Petersburg, FL
Posts: 12,156



TRUST US, EVERYTHING IS FINE!
epitome is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 01:42 PM   #75
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
It boggles my mind that people use unprotected services such as this and the insane amount of dishonesty and bullshit spewed out by them let alone actions that are lets just say not even professional for a company operating in the 90s on the internet.

Doesn't mater what will happen. The vast majority will continue to use service such as this. Once a fool always a fool.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 03:35 PM   #76
RuthB
Let's Get Paxumized!
 
RuthB's Avatar
 
Industry Role:
Join Date: May 2005
Location: Vancouver, Canada
Posts: 7,247
We initially anticipated this update to take approximately three hours. However, during our migration to the new and improved security login engine we encountered some difficulties porting the old passwords to the new system. Since we do not have access to the passwords ourselves we had to reset everyone's password during this process. Once reset we were able to continue implementation of the new login engine and complete our updates. Unfortunately our estimated downtime was much longer than we first thought and we sincerely apologize for the additional downtime.

In regards to the plain text emails; we took the necessary measures to protect the passwords. We activated approval codes (users can disable them), and we sent a separate authentication key, which greatly reduces the odds of having the information fall into the wrong hands. There have been several waves of phishing attempts targeting Paxum clients recently, and this is partly the reason we thought it wise to not include HTML in our notifications.

In response to the query regarding the 'password match' when resetting your password;

Paxum does not store passwords in clear text and never has. What we store is a crypt result based on an algorithm and not the actual password. When somebody logs into the system we apply the same crypt algorithm to the password entered by the user and compare the result with what we have stored on the client file. We do not know the actual password, that's why you cannot recover the password from the system when forgotten. You can only reset it.

Now as to how we knew you were trying to set the same password as before, that's easy. After you enter the password on the interface we create the crypt result based on the new engine and we also create the crypt result based on the old engine. Therefore, the comparison can be made between the crypt results from both engines.

Ultimately, the purpose of this new update is to create an even safer environment for our clients. We sincerely hope our intentions here are clear, and that is; to protect our clients.
__________________
Send & Receive Mass Global Payments - Mass P2P/Wire/EFT/SEPA - Adult Industry Friendly - Award Winning Payment Service - Fast, Reliable & Secure!
Paxum ...... Paxum Bank
Email: [email protected] ~ Telegram: PaxumRuth
RuthB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 03:50 PM   #77
mafia_man
Confirmed User
 
mafia_man's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq#: 639544261
Posts: 1,965
Quote:
Originally Posted by AdultEUhost View Post
That is not true and most unlikely
They can have it stored in their database as a md5 hash for example and just compare your entry after they md5 it.

The point is though that they do have the old passwords which makes this whole email with a clear text password in it not only unnecessary but from a security point a view also very stupid
Oops brain fart. Of course they are being hashed on the fly and compared. Although I'm not a big fan of companies storing my old passwords because they could still be in use elsewhere. Also nobody should use MD5 these days.

Edit: I remember why I said it was plaintext now. The site said that the password was too similar to one I've used before so it's not a hash that's being stored.
__________________
I'm out.

Last edited by mafia_man; 02-11-2012 at 03:57 PM..
mafia_man is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 03:53 PM   #78
epitome
So Fucking Lame
 
epitome's Avatar
 
Industry Role:
Join Date: Jun 2009
Location: St. Petersburg, FL
Posts: 12,156
Are there plans to not do feature upgrades on a Friday afternoon during regular business hours?

As a worldwide service provider its always regular business hours in some time zone, but upgrading during a weekend would be easier on customers.
epitome is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 04:02 PM   #79
CyberHustler
So Fucking Banned
 
Industry Role:
Join Date: Feb 2006
Posts: 26,062
What about the bitcoins thing? Just a timely coincidence?
CyberHustler is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 04:12 PM   #80
RuthB
Let's Get Paxumized!
 
RuthB's Avatar
 
Industry Role:
Join Date: May 2005
Location: Vancouver, Canada
Posts: 7,247
Quote:
Originally Posted by epitome View Post
Are there plans to not do feature upgrades on a Friday afternoon during regular business hours?

As a worldwide service provider its always regular business hours in some time zone, but upgrading during a weekend would be easier on customers.
Based on our knowledge of our customers activity, Friday afternoon is typically one of the least busy times at Paxum. This is the reason we chose the time we did to make the upgrade.

We will take your suggestion for weekend downtime into consideration for future upgrades though. Thank you for sharing your thoughts.
__________________
Send & Receive Mass Global Payments - Mass P2P/Wire/EFT/SEPA - Adult Industry Friendly - Award Winning Payment Service - Fast, Reliable & Secure!
Paxum ...... Paxum Bank
Email: [email protected] ~ Telegram: PaxumRuth
RuthB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 04:21 PM   #81
ThumbLord
Confirmed User
 
ThumbLord's Avatar
 
Industry Role:
Join Date: Jan 2009
Location: Aruba
Posts: 1,932
ticket #141539 could somebody please look into it.
would be great!
__________________
We Sell Domains | ThumbLords | ICQ 128106905 | TubeLords | Traffic Holder | eRoken
ThumbLord is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 04:55 PM   #82
RuthB
Let's Get Paxumized!
 
RuthB's Avatar
 
Industry Role:
Join Date: May 2005
Location: Vancouver, Canada
Posts: 7,247
Quote:
Originally Posted by ThumbLord View Post
ticket #141539 could somebody please look into it.
would be great!
Hi ThumbLord, Your request involves some manual changes. We estimate to have your request complete by Monday. Thanks
__________________
Send & Receive Mass Global Payments - Mass P2P/Wire/EFT/SEPA - Adult Industry Friendly - Award Winning Payment Service - Fast, Reliable & Secure!
Paxum ...... Paxum Bank
Email: [email protected] ~ Telegram: PaxumRuth
RuthB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-11-2012, 04:57 PM   #83
livexxx
Confirmed User
 
livexxx's Avatar
 
Industry Role:
Join Date: May 2005
Location: UK
Posts: 1,201
so if I'm an obnoxious sysadmin all I have to do is trawl all my employees emails and see if there are any paxum passwords in there? neat. Beats reading about secret office love affairs.
__________________
http://www.webcamalerts.com for auto tweets for web cam operators
livexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-12-2012, 04:58 AM   #84
ThumbLord
Confirmed User
 
ThumbLord's Avatar
 
Industry Role:
Join Date: Jan 2009
Location: Aruba
Posts: 1,932
Thanks Ruth.
__________________
We Sell Domains | ThumbLords | ICQ 128106905 | TubeLords | Traffic Holder | eRoken
ThumbLord is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-12-2012, 06:17 AM   #85
ZeroHero
So Fucking Banned
 
Industry Role:
Join Date: Nov 2007
Location: Westbahnhof
Posts: 15,336
changes are great , but not to often , btw Ruth you tha best Paxum should pay more for speaking in the ZOO with the monkeys
ZeroHero is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.