Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-13-2003, 04:39 PM   #1
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
PLEASE help asap, cheater question!

Okay, heres the situation, I'm going mad, guys are taking my site, using the following object tag and placing it on high traffic sites. I need to know asap how I can prevent this from happening, and prevent that counting as that page loading. Theres got to be some way to do this or to detect if the object tag is being used, I know if anyone will know you guys will know...

OBJECT data="http://www.yourwebsite.com/" HEIGHT=1 WIDTH=1 VSPACE=1 HSPACE=1>
/OBJECT>


Thanks so much guys, i'm going crazy,
C.
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:40 PM   #2
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
uh oh.
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:41 PM   #3
X37375787
Guest
 
Posts: n/a
Patrick?
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:42 PM   #4
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
Quote:
Originally posted by Equinox
Patrick?
I was thinking that too. :D
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:45 PM   #5
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
Never mind how to stop it - we want to know why they're doing it. We need the drama!
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:46 PM   #6
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
why are they doing it?

hehe

__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:47 PM   #7
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
better yet, <i>who</i> is doing it?

heheh
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:48 PM   #8
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
And are they bigger than you. Better still is their dad bigger than your dad. We need details!
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:52 PM   #9
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
It's one of my mainstream sites, not adult, huge site, tons of people love it, a few people hate it (as always), jealous people, assholes, what have you. So just recently this new object code starts being used and its the most annoying thing I've seen yet, and I cant figure out for the life of me a way to fix this but it's being used by a LOT of people.

If I'm fucked and theres nothing I can do about it, be straight forward about it and just give me the bad news, but if anyone knows of anything at all, please help me out here.

C.
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:55 PM   #10
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
bump...
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 04:58 PM   #11
X37375787
Guest
 
Posts: n/a
Contact his host, and tell them to shut him down for illegal activity.
That's about the only thing I can think of.
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:01 PM   #12
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
Quote:
Originally posted by Equinox
Contact his host, and tell them to shut him down for illegal activity.
That's about the only thing I can think of.
thats fine, but the problem is there's currently more than a few hundred websites doing this to us, and we only know of a tiny percentage of them. alot are on free hosts, while some are big traffic sites. can anyone help or give advice even?

i'm dying here...
C.
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:04 PM   #13
LiveDose
Show Yer Tits!
 
LiveDose's Avatar
 
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
So tell us what did you do to piss off so many. What's the URL?
__________________

Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
LiveDose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:08 PM   #14
Theo
HAL 9000
 
Industry Role:
Join Date: May 2001
Posts: 34,515
Quote:
Originally posted by greedinc


thats fine, but the problem is there's currently more than a few hundred websites doing this to us, and we only know of a tiny percentage of them. alot are on free hosts, while some are big traffic sites. can anyone help or give advice even?

i'm dying here...
C.
wtf did you do bro to have 100s websites iframing you? Don't tell me they just don't like your site
Theo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:10 PM   #15
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
Quote:
Originally posted by Soul_Rebel


wtf did you do bro to have 100s websites iframing you? Don't tell me they just don't like your site
not iframing man, my guys found a way to prevent against tracking the iframe exploit about a month ago, because that was the last big thing, its this new "object" one thats really fucking with me this time around...
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:13 PM   #16
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
bump, is there no answer on this or way of dealing with this?
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:14 PM   #17
Theo
HAL 9000
 
Industry Role:
Join Date: May 2001
Posts: 34,515
your enemies sound dedicated on what they do....Maybe some of the admins that post here will be able to help.
Theo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:16 PM   #18
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
what im more concerned about, and maybe this will help you guys comeup with an answer... i'm not concerned that much with them using the code and pulling my site. all i really want to know is how to tell that its a real visitor hitting the page, and not a user on a page with an "object" tag embeded into it. i know a way must exist, especially with hitbot prevention and things like that...

anyone???
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:23 PM   #19
MattO
The O is for Oohhh
 
Join Date: Feb 2003
Location: AUSTIN TEJAS
Posts: 10,861
One thing that you could do that won't neccessarily make it go away, but it would reduce bandwidth is change the exact page that they are loading to something else.
So if your site is index.html, make the index.html as small as possible with an ENTER button to a renamed page with your site on it.
Then you can keep changing the target page real easy and each time, they would have to change all their OBJECT tags and hopefully get sick of doing it.

As far as detecting if it's a surfer or a pulled OBJECT tag, there might be a way to query the CGI.HTTP type shit.
If you run a HTTP-REFER, you could tell where the surfers are coming from, and you could match it against a list of offending sites.

I don't really know that much... just kinda "typing outloud".
MattO is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:32 PM   #20
JFPdude
Confirmed User
 
Join Date: Jan 2002
Location: Mountains of Western North Carolina.
Posts: 4,027
It's called being image sourced.

You won't find much help on this board to prevent it because it will attract cheaters like cockroaches.

Most mainstream admins won't know how to prevent it because they have probably never seen it before.

My advice: Stop pissing people off so that they won't image source you.

and 2: Hire an admin that can keep you out of trouble if you can't keep yourself out of trouble.

Good Luck
JFPdude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 05:50 PM   #21
grumpy
Too lazy to set a custom title
 
grumpy's Avatar
 
Join Date: Jan 2002
Location: Holland
Posts: 9,870
Its easy but im not gonna tell you because you wont tell us where and why
__________________
Don't let greediness blur your vision | You gotta let some shit slide
icq - 441-456-888
grumpy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 06:04 PM   #22
XXXManager
So Fucking Banned
 
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
1. I cant see why hundrads of site would do that to you if they were not hosted by the same guys.
2. EVEN if hundrads of sites do that to you, probably most of them do not have traffic. So it shouldn't hurt you and therefore not a problem.
3. IF hundrads of site with a lot of traffic do that to you that means you pissed alot of different people cause its not probable that one person with hundrads of sites which all are big is attacking you like that.
4. If 3 is indeed the case, take action against this person. Alot of time, if its one person, the different sites are all hosted in the same place, or few different places.

IN ANY CASE, redirect the hit back to the referrer from all the sites that do that to you. You can do that with mod_rewrite and RewriteMap.
WARNING: Make sure that the sites (the hundrads you list there) are indeed hitting you, so you don't hit back on innocent sites.
Recommendtion: start from the bigger ones so your immediate problem is fixed fast.
XXXManager is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 07:10 PM   #24
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
Quote:
Originally posted by EscortBiz
What type of site, whats the URL im nosey
Yea, I'm constantly asked, and i apologize, but I keep pretty well quiet for the most part when it comes to that kind of stuff and but a handful of people on this board have any idea as to what i own, sorry guys, I do appreciate all the help, comments and suggestions though, you guys are always awesome when it comes to lending a quick hand.

I will tell you though that its not us, or our sites "pissing off" people, what happens is we find cheaters, or hackers, or spammers, and we ban them from our network, and they retaliate by doing things like this as well as constant DOS attacks and things of that nature. Which, we have measures in place to take care of just about anything but the object code is new news to us and we're just now trying to figure out how to deal with it. The site gets a around 50,000 + signups a day and we ban quite a few guys everyday, so we've built up quite a good group of guys that have nothing better to do than try and hack and take down our network.

Grumpy - If you actually genuinely have a clue as to how to help me on this and it is that "easy" then please email me and I will gladly speak with you if you'd be willing to help me out and I would certainly owe you.

Night guys,
C.
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 07:38 PM   #25
lustbin
Registered User
 
Join Date: Feb 2003
Location: minnesota
Posts: 83
if you're using apache, and if i remember right....

put this into an .htaccess file in the root

SetEnvIfNoCase Referer "^http://offending\.domain\.com/" bad_ref=1
Order Deny,Allow
Deny from env=bad_ref

replace offending.domaim.com with the domain hosting the object tag in their page. make sure you notate dots as \. and preserve the ^

this will block any hits with them as the referer.

hope that works for you.

`lb

ps. apache people does that sound right?

Quote:
Originally posted by greedinc


Yea, I'm constantly asked, and i apologize, but I keep pretty well quiet for the most part when it comes to that kind of stuff and but a handful of people on this board have any idea as to what i own, sorry guys, I do appreciate all the help, comments and suggestions though, you guys are always awesome when it comes to lending a quick hand.

I will tell you though that its not us, or our sites "pissing off" people, what happens is we find cheaters, or hackers, or spammers, and we ban them from our network, and they retaliate by doing things like this as well as constant DOS attacks and things of that nature. Which, we have measures in place to take care of just about anything but the object code is new news to us and we're just now trying to figure out how to deal with it. The site gets a around 50,000 + signups a day and we ban quite a few guys everyday, so we've built up quite a good group of guys that have nothing better to do than try and hack and take down our network.

Grumpy - If you actually genuinely have a clue as to how to help me on this and it is that "easy" then please email me and I will gladly speak with you if you'd be willing to help me out and I would certainly owe you.

Night guys,
C.
__________________
cube life got me down
icq# 21315507
lustbin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 08:45 PM   #26
Nbritte
Confirmed User
 
Join Date: Sep 2001
Location: Kentucky USA
Posts: 689
well you could just take the page they are hitting and remove all the html but a link to an alternate page then use
&lt script src="site url" language=something>&lt/script
if you only have a small page and it creates a loop (not sure if it will but it might) then both sites get hit hard with hits but you use less bandwidth.

Nbritt
__________________

SexyCityCash gets in Bed with PornoDan

Last edited by Nbritte; 02-13-2003 at 08:47 PM..
Nbritte is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 08:55 PM   #27
XXXManager
So Fucking Banned
 
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
Quote:
Originally posted by lustbin
if you're using apache, and if i remember right....
put this into an .htaccess file in the root
SetEnvIfNoCase Referer "^http://offending\.domain\.com/" bad_ref=1
Order Deny,Allow
Deny from env=bad_ref
ps. apache people does that sound right?
Nope. It will not be efficient and will not work really..
See what I suggested above and what greedinc wrote. He has hundrads of attacking domains (which sounds strange to me but anyway).. therefore what you wrote wont help him.

greedinc: I don't know why I am helping you with this since you are "saying" you are attacked by bad guys BUT you are not willing to say which URLs the attackers use and which URLs of yours they attack. I don't understand what you have to hide it you claim to be a legit player. Can you explain? Are you doing CP or other illegal stuff??
Well, I guess I am helping you because you MIGHT be telling the truth in a way and for the chance that this is the case - I am willing to help.

If you have 100s of domains attacking do this...
Create a map file with pairs of the attacking domains and the word NWJ (acronyms of "No Way Jose") ;)
like that...
http://www.attacker1.com NWJ
http://www.attacker2.com NWJ
etc..

Enable mod_rewrite it its not yet enabled on your webserver.
Set a "RewriteMap NWJMap txt:/path/to/NWJ.dat"

break down the %{HTTP_REFERER} with a REGEXP rewrite condition and get the first part up to the THIRD backslash (Not including) leaving you with the http://......com in $1

Do a "RewriteCond ${NWJMap:$1} ^NWJ$"

Do a rewrite rule to http:// so that the client will show 404 for the onject.

- Paypal donations will not be met with resistance LOL

I redraw from my prior suggestion. do NOT, I repeat - NOT, send the hit back to the attacker.
For 3 reasons:
1. The attacker/s can redirect the rediretion BACK to you and so you will be damaged once again
2. It is illegal - even when he attacks you
3. The attacker/s might be using a third party system or a free host - in that case you will be attacking that system and you will damage innocent people.
Do NOT redirect traffic back to the attackers!!

Hope it helps
XXXManager is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 09:03 PM   #28
XXXManager
So Fucking Banned
 
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
Quote:
Originally posted by Nbritte
well you could just take the page they are hitting and remove all the html but a link to an alternate page then use
&lt script src="site url" language=something>&lt/script
if you only have a small page and it creates a loop (not sure if it will but it might) then both sites get hit hard with hits but you use less bandwidth.
Nbritt
Hmm... What good is this??
The problem with the attack is hardly the BW or the size of the page. Its the process Apache creates for the serving of the page.
Your solution will not help at all for that problem.
saying the truth, my solution will not solve everything as well, but just half of the problem
Also - call to the server from an OBJECT does NOT run the JS and will not create a loop no matter what - so I dont see what you mean.

A solution to the httpd process creation is using a reverse proxy. That will expedite the creation of the responder by using threads instead of processes.
Using something like Squid in a rev-proxy/web-accelerator is a good choice
XXXManager is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 09:08 PM   #29
XXXManager
So Fucking Banned
 
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
BTW - greedinc
It seems strange to me...
Your attackers are amateurs and newbies. They are hardly hackers.
If they were smart they would be using spoofed IPs through loose source routing and fake packet parameters as well as manipulated protocol parameters and fake referer.
Since no newbie know what that means - its not really dangerous to say what I just did

DIE CHEATERS DIE
XXXManager is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2003, 10:02 PM   #30
greedinc
Confirmed User
 
Join Date: Oct 2002
Posts: 245
Quote:
Originally posted by XXXManager


greedinc: I don't know why I am helping you with this since you are "saying" you are attacked by bad guys BUT you are not willing to say which URLs the attackers use and which URLs of yours they attack. I don't understand what you have to hide it you claim to be a legit player. Can you explain? Are you doing CP or other illegal stuff??
Well, I guess I am helping you because you MIGHT be telling the truth in a way and for the chance that this is the case - I am willing to help.

Hey man, drop me an email with your aim s/n or icq #, thanks a ton for the help, we can chat, and i can redeem myself and let you check out some of my mainstream sites, so i'm not accused of CP or other crazy shit, haha, jeez man...

Take it easy, and thanks again,
C.
greedinc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-14-2003, 12:55 AM   #31
Nbritte
Confirmed User
 
Join Date: Sep 2001
Location: Kentucky USA
Posts: 689
Quote:
Originally posted by XXXManager

Hmm... What good is this??
The problem with the attack is hardly the BW or the size of the page. Its the process Apache creates for the serving of the page.
Your solution will not help at all for that problem.
saying the truth, my solution will not solve everything as well, but just half of the problem
Also - call to the server from an OBJECT does NOT run the JS and will not create a loop no matter what - so I dont see what you mean.

A solution to the httpd process creation is using a reverse proxy. That will expedite the creation of the responder by using threads instead of processes.
Using something like Squid in a rev-proxy/web-accelerator is a good choice
Ok I will take your word it would not work like I said I didnt know if it would or not. I t was just a thouhgt and I have lots of them just not always good ones

Nbritt
__________________

SexyCityCash gets in Bed with PornoDan
Nbritte is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.