Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-10-2003, 08:57 PM   #1
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
sponsor stats leaking your USERNAME and PASSWORD to other sites

I'm becoming increasingly concerned at how some sponsors authenticate their stats - with the user and pass in the URL.

For example...

https://stats.globill-systems.com/cgi-bin/stats.cgi?partnerid=xxxxxx&password=xxxxxx
http://wm.mtree.com/wm.cgi/stats?mtaseqid=xxxxxx&mtapasswd=xxxxxx

There's too much chance for a referer 'leak', either with a direct link (globill's stats link directly to external sites - my u/p will show up in their referer logs if I click on those links), or with MSIE's buggy sending of referer lines from two or three pages back. With the latter scenario, ANY site you load could end up with your sponsor's u/p in their referer logs.

Non https:// URLs may get logged by any proxies you're using too. Anyone with access at optus@home (my ISP) can clearly see my moneytree ID and password in their proxy logs. Here's an example from my local caching proxy:

<font size=1>1050032864.223 7761 xxxxxx.xxxxxx.com TCP_MISS/200 67721 GET http://wm.mtree.com/wm.cgi/stats?<font color="#ff0000">mtaseqid=xxxxxx&mtapasswd=xxxxxx</font> - DIRECT/wm.mtree.com text/html</font>

This entry is sitting in a log file on my home unix gateway.

Am I the only one worried about this?

Last edited by rowan; 04-10-2003 at 09:00 PM..
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:01 PM   #2
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
this whole industry, including the stats, are setup by a bunch of
bedroom idiots.

What do you expect?
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:05 PM   #3
p00p
Confirmed User
 
Join Date: Dec 2002
Location: CanaDUH
Posts: 5,125
How about packet sniffers? Even if you use the login box that pops up, your username and password is sent plain text....
__________________
ICQ: 316365783
<a href="http://www.hostultra.com/~p00p" target="_blank">TEST</a>
p00p is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:06 PM   #4
BRISK
Too lazy to set a custom title
 
Join Date: Feb 2003
Posts: 12,240
Yeah, kinda scary.
__________________
I post on GFY so that when people ask me what I do,
I can tell them that I work with the mentally retarded.
BRISK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:11 PM   #5
cluck
Confirmed User
 
Join Date: Dec 2002
Location: New Jersey
Posts: 5,248
If you're really concerned, don't click the links, copy them and paste them into your browser. That or you could make a custom login page that uses POST instead of GET. I'm sure it'd work if the scripts are using standard CGI libraries.
cluck is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:23 PM   #6
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally posted by p00p
How about packet sniffers? Even if you use the login box that pops up, your username and password is sent plain text....
Agreed, but that's actively seeking out the details. This particular issue involves passive/accidental discovery of the u/p.

cluck: I don't click on the links, except for last night. I clicked on one of my affiliate IDs as I thought that would take me to stats for that account... it actually loaded up the paysite. They now have my u/p in their referer logs.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:25 PM   #7
hyper
Confirmed User
 
Join Date: Mar 2002
Location: Mass Ass
Posts: 5,294
thats what happens when you hire 12 yr old programmers
__________________
hyper is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 09:51 PM   #8
Thrawn$
Confirmed User
 
Join Date: Apr 2002
Location: Mtl
Posts: 4,596
I think If someone stole your account, You have all the time you need to contact your sponsor before he got your money! specially if he stole your WSB account
Thrawn$ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-10-2003, 10:04 PM   #9
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
This is why you need to check your stats at least a hundred times per day... for EACH sponsor.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-11-2003, 01:26 AM   #10
BritishTwinks
Confirmed User
 
Join Date: Feb 2003
Location: UK
Posts: 357
Quote:
Originally posted by rowan
This is why you need to check your stats at least a hundred times per day... for EACH sponsor.
Ah, I knew there was a reason I did that!
__________________

British Twinks - Earn 60% commissions promoting this original site

Over 100,000 quality photos and videos • High conversions and retention

Weekly payments via CCBill
BritishTwinks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.