Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-06-2013, 05:19 AM   #1
Femjoy Michael
Confirmed User
 
Industry Role:
Join Date: Sep 2012
Posts: 171
Stolen Passwords How To Find Them and Prevent Them

I saw this thread:
https://gfy.com/showthread.php?p=19861288

and was rather surprised by the responses. If you run a paysite, it's important to prevent stolen accounts and password abuse. Bandwidth isn't as expensive, but server load can be deadlier. Paying customers want a site that loads fast and downloads faster.

The basic solution is to purchase specialized software or program your own to detect stolen accounts and block them. Strongbox https://www.bettercgi.com/strongbox/ is often recommended.

But what if you are just starting out and can't afford $269? Or you want more specific details? Or you do have a password solution but it isn't online yet and you need information NOW? I'll show you what I did on Femjoy / Joymii to detect stolen accounts. I've shared this with other program owners and I invite you to share your methods so we can all learn.

1. Install Google Analytics and Track Your Member Pages
I'm constantly surprised how many program owners do not track their members area. You should do it now. You get really useful insight into your member behavior. Once we did, something was obviously amiss. We had 15X the number of uniques per day, as we had members. For most paysites, your daily traffic should be 1/3 to 1/2 of your total member count.

2. Check Out Your Referrals.
There are two places:
Real-Time -> Overview -> Top Referrals.
Take this route instead of "traffic sources" because you can see the full urls of where the incoming traffic is from. You can see the exact pages where stolen passwords and logins are posted.

and

Acquisition -> All Referrals
Go here to catch the rest or the ones the previous days. Referrals with low bounce rates means working passes.

If at this point you can't afford strongbox or your solution isn't ready yet, you can easily catch 95% of the stolen accounts by manually finding them in this manner, and shutting them down. Most are reposts from the bigger forums so taking down the ones posted on the big sites usually does the trick.

When you first start doing this, you'll only find a couple of accounts. Taking them down gives you breathing room for days. But then the number of stolen accounts start increasing. If you are a medium size site, as you take down the stolen accounts, the hackers get more aggressive and post new accounts more frequently, to the point manually doing this requires checking at regular intervals during your day. That's inefficient. So do this:

3. Get Strongbox or Similar Solution
Get it. It's one of your best investments. You'll earn back the costs within a day if you are small-medium.

4. Google your site/domain
Open an incognito window/private window in your browser. Go to google and do a search of your site name and domain. If any pages with stolen passes for your site shows up within the first 2 pages of results, DMCA google immediately. Repeat the process for more refinement using "sitename.com passes", "sitename.com passwords", or something to that effect.

Here's what our member area traffic looked like before and after:



Finally, here are some of the big password sharing sites/forums

http://porn-w.org
http://dixvi.com
http://crackingforum.com
http://passlot.com
http://mygully.com
http://bugmenot.com

There is one other site, but I forgot the address because it uses "ganuurl.com" as the referral/redirect. I'll update this list once I remember. Pretty much taking down your stuff from these sites will do the trick, and any that show up as pastebin or similar.

SteveLightspeed had a comprehensive list from last year
https://gfy.com/showthread.php?t=1066323
but you don't have to go through them everyday. The most efficient way is to check where the majority of your traffic is coming from in analytics.

Best of luck
Femjoy Michael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 05:43 AM   #2
Sexier
Confirmed User
 
Sexier's Avatar
 
Industry Role:
Join Date: Sep 2010
Location: Celt-Iberia
Posts: 364
Excellent Michael
__________________
Webmasters Contact: | skype: jp_sexier
Sexier is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 05:53 AM   #3
Mutt
Too lazy to set a custom title
 
Mutt's Avatar
 
Industry Role:
Join Date: Sep 2002
Posts: 34,431
Quote:
Originally Posted by Femjoy Michael View Post
We had 15X the number of uniques per day, as we had members. For most paysites, your daily traffic should be 1/3 to 1/2 of your total member count.
If Femjoy's members area had 15X more visitors than its member count then it would seem Strongbox or whatever solution they are using isn't doing a very good job.

I don't have GA in members areas, good idea though and I will install it.
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
Mutt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 07:21 AM   #4
Femjoy Michael
Confirmed User
 
Industry Role:
Join Date: Sep 2012
Posts: 171
Quote:
Originally Posted by Mutt View Post
If Femjoy's members area had 15X more visitors than its member count then it would seem Strongbox or whatever solution they are using isn't doing a very good job.

I don't have GA in members areas, good idea though and I will install it.
I forgot what we had before, but it was the competitor to strongbox and it was not working for us at all. It had too many false positives so we turned it off entirely.
At the time, the programmers on our team were not analytics guys and not aware of the extent of the problem. They figured it was only only a handful of stolen accounts. After the bad experience with the previous software, the development team decided to program an in-house solution which was pushed back because it was deemed low priority.
__________________
Our sites:
Femjoy.com - Softcore Nude Art featuring 100% All natural models
Joymii.com - pioneers in cinematic erotica and passion
Promote some of the most-respected, and best-converting sites in the erotica niche (as proven by affiliates who have promoted our sites and others). Sign up at http://cash.femjoy.com
Femjoy Michael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 07:25 AM   #5
tony286
lurker
 
tony286's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
I like password sentry and his customer service is second to none.
tony286 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 07:45 AM   #6
SplatterMaster
Confirmed User
 
SplatterMaster's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
Quote:
Originally Posted by tony286 View Post
I like password sentry and his customer service is second to none.
I have to admit PS customer service is excellent.

Nice post Michael. If you’re a webmaster and have never looked at your server traffic logs, I highly suggest you do. What you see may surprise you. Not only will you see passwords being shared but you’ll also see brute force attacks of hackers/pirates trying to test known username and passwords.
SplatterMaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 07:48 AM   #7
johnuno11
Confirmed User
 
johnuno11's Avatar
 
Join Date: Nov 2007
Location: Tampa, FL
Posts: 692
thanks for the info.
__________________
Monetize With iStrippers Future VR Adult Technology 2021, I earn $200+ a month for the last 10 years. Simply by Promoting one brand in your signature link...
johnuno11 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 08:00 AM   #8
lucas131
¯\_(ツ)_/¯
 
Industry Role:
Join Date: Aug 2004
Posts: 11,475
Quote:
Originally Posted by SplatterMaster View Post
I have to admit PS customer service is excellent.

Nice post Michael. If you?re a webmaster and have never looked at your server traffic logs, I highly suggest you do. What you see may surprise you. Not only will you see passwords being shared but you?ll also see brute force attacks of hackers/pirates trying to test known username and passwords.
it is called combolist, combination of user:pass. fredh ones taken from unsecure paysite can make many logins to other sites, as many members use same combo everywhere. now, unsecure sites may be a damage for those whose owners care
lucas131 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 08:06 AM   #9
SplatterMaster
Confirmed User
 
SplatterMaster's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
Quote:
Originally Posted by lucas131 View Post
it is called combolist, combination of user:pass. fredh ones taken from unsecure paysite can make many logins to other sites, as many members use same combo everywhere. now, unsecure sites may be a damage for those whose owners care
Good to know the term Lucas. Thanks
SplatterMaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 08:19 AM   #10
WetandPuffy
Confirmed User
 
WetandPuffy's Avatar
 
Industry Role:
Join Date: Aug 2009
Location: UK
Posts: 551
Very interesting thread.

I definitly need to get GA into my members area.

I have been noticing high server loads recently and maybe this is the cause.

When you have time could you hit me up Michael , would love to talk some biz with you.

Regards
__________________
Wayne.

Our Sites: Puffynetwork.com - Wetandpuffy.com - Wetandpissy.com - Weliketosuck.com
Skype: wetandpuffy
E-mail: wayne@wetandpuffy,com
Icq: 449385285

Puffynetwork.com - "Porn the way it should be"
WetandPuffy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 08:28 AM   #11
AdultKing
Raise Your Weapon
 
AdultKing's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,601
Please report stolen password sites here also

https://copycontrol.org/report-piracy
AdultKing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 09:39 AM   #12
Nancy M00re
Pegas Productions
 
Nancy M00re's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: Montreal, Canada
Posts: 2,280
Another one with stolen U/P here:
http://www.box.wixvi.com/2013/
__________________
www.pegasmoney.com
www.chickpasscash.com
Telegram: @Nancym00re
Nancy M00re is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 10:03 AM   #13
Captain Kawaii
So Fucking Banned
 
Industry Role:
Join Date: Oct 2007
Posts: 6,748
Great thread. Thank youssssss to the OP.
Captain Kawaii is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 10:08 AM   #14
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
What do we do if we run our sites on nginx?
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 11:32 AM   #15
Femjoy Michael
Confirmed User
 
Industry Role:
Join Date: Sep 2012
Posts: 171
Quote:
Originally Posted by SplatterMaster View Post
Nice post Michael. If you?re a webmaster and have never looked at your server traffic logs, I highly suggest you do. What you see may surprise you. Not only will you see passwords being shared but you?ll also see brute force attacks of hackers/pirates trying to test known username and passwords.
Very good point SplatterMaster.
A properly written piece of software will not just look for multiple IPs, but also restrict login attempts. We do occasionally look at our server logs for abnormalities. For example, we discovered a backdoor was exploited a few months back. The hacker also attacked our friends at DDF so we shared the info and fixed the problem.
__________________
Our sites:
Femjoy.com - Softcore Nude Art featuring 100% All natural models
Joymii.com - pioneers in cinematic erotica and passion
Promote some of the most-respected, and best-converting sites in the erotica niche (as proven by affiliates who have promoted our sites and others). Sign up at http://cash.femjoy.com
Femjoy Michael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-06-2013, 04:50 PM   #16
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by Femjoy Michael View Post
For example, we discovered a backdoor was exploited a few months back. The hacker also attacked our friends at DDF so we shared the info and fixed the problem.
I'll bet you have not. If you had a breach, you still have it. 100% positive on this.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2013, 01:10 AM   #17
Femjoy Michael
Confirmed User
 
Industry Role:
Join Date: Sep 2012
Posts: 171
Quote:
Originally Posted by ladida View Post
I'll bet you have not. If you had a breach, you still have it. 100% positive on this.
LOL. Isn't that like saying, "I'm 100% the sky is blue"?
That particular exploit is fixed, as well as a few others when we had a tech security team in to service our servers.

So Ladida brings up a good point: by the time you reach 500 members, invest in backup systems immediately. Get them as soon as you can afford it, but at 500, you have no reason not to. But that is a topic for another thread with someone with more knowledge about that.
__________________
Our sites:
Femjoy.com - Softcore Nude Art featuring 100% All natural models
Joymii.com - pioneers in cinematic erotica and passion
Promote some of the most-respected, and best-converting sites in the erotica niche (as proven by affiliates who have promoted our sites and others). Sign up at http://cash.femjoy.com
Femjoy Michael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-07-2013, 01:15 AM   #18
bean-aid
So Fucking Banned
 
Industry Role:
Join Date: Jun 2011
Location: the land of woke sleuths
Posts: 16,493
Ask Teencat... he knows how to hack them, and how to prevent them.
bean-aid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.