Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-20-2003, 06:25 AM   #1
nevermind
Confirmed User
 
Join Date: Feb 2003
Posts: 276
Hacked Passwords Are Over, Let the Spoofs Begin

About a year ago I noticed this pirate program called Zspoof, which basically fakes the referring url on htaccess and gives total access to a site.

Well, it's all over the pirate boards now, and they love it because the spoofs last a lot longer than hacked passwords which, with a few exceptions, tend to die pretty quickly.

The scariest thing is --- as far as I know --- there is no fix for Zspoof whatsoever, except dumping htaccess. A real nightmare for the content providers, among others.

Last edited by nevermind; 02-20-2003 at 06:34 AM..
nevermind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:28 AM   #2
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
woo hoo !! free porn !!
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:30 AM   #3
nevermind
Confirmed User
 
Join Date: Feb 2003
Posts: 276
Quote:
Originally posted by DarkJedi
woo hoo !! free porn !!
Figures. Smart Ass. I'll delete the link then. Just thought some legit webmasters might want to check to see if their site is being spoofed.

But I forgot there are so many thieves here. Fuck it.

Last edited by nevermind; 02-20-2003 at 06:40 AM..
nevermind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:41 AM   #4
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
Nigga don't hate

http://users.pandora.be/R4v3n/spoofs...of/spoofs3.txt
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:43 AM   #5
BigFrog
Confirmed User
 
Join Date: Sep 2002
Posts: 2,057
spoofing and the progs to do it have been around for a while....and yes there is a way to prevent it.

basically someone needs to know their target in order to spoof....if you dont publish the target then you've made it a bit harder for anyone to spoof you.
if you publish a members login on the web then dont use a members location that is easy to guess.
eventually though, if someone really wants in they will get in....most likely by carding your site and finding your members url.
BigFrog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:45 AM   #6
J B
Confirmed User
 
Join Date: May 2002
Location: StatsRemote.com
Posts: 1,804
Programs like this have been out there for years... it's really easy to fake the referral URL...
__________________


A HUGE TIME SAVER FOR LESS THAN $1 PER DAY!



Contact: support A|T statsremote D|O|T com

J B is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:48 AM   #7
nevermind
Confirmed User
 
Join Date: Feb 2003
Posts: 276
Quote:
Originally posted by J B
Programs like this have been out there for years... it's really easy to fake the referral URL...
Yeah, I know. But I've been seeing the average Joe Blow using it more and more lately. They hardly bother with hacked passwords anymore. That was my only point.

Last edited by nevermind; 02-20-2003 at 06:51 AM..
nevermind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 06:50 AM   #8
nevermind
Confirmed User
 
Join Date: Feb 2003
Posts: 276
Edit
nevermind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 07:12 AM   #9
nevermind
Confirmed User
 
Join Date: Feb 2003
Posts: 276
Quote:
Originally posted by BigFrog
spoofing and the progs to do it have been around for a while....and yes there is a way to prevent it.

basically someone needs to know their target in order to spoof....if you dont publish the target then you've made it a bit harder for anyone to spoof you.
if you publish a members login on the web then dont use a members location that is easy to guess.
eventually though, if someone really wants in they will get in....most likely by carding your site and finding your members url.


It probably helps a little, but not much. I've seen pirates use a hacked password to get the members' location. Then, once they have the location for the spoof, it doesn't matter if the password dies quickly.

And, of course, once they post the spoof, no one needs to bother with a password again.
nevermind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2003, 07:19 AM   #10
Aus
Registered User
 
Join Date: Feb 2003
Posts: 3

Protecting on referer is a bad idea anyway imho.
Because the referer is sent from the client side, the client will always be able to spoof it.
You also saw this with formmail being abused by spammers, it only relied on the referer

I suggest content providers to move to some other form of authentication, unless the amount of spoofers is low enough to still make a good profit, however with this 'teqnique' getting more and more known the amount of spoofers will rise..
Aus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.