Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-24-2018, 05:54 AM   #1
thommy
Confirmed User
 
thommy's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
better check your namecheap accounts

today a 2 of my publishers had a similar problem with hacked namecheap accounts.

account owner and password have been changed and all domains transfered.
after that blackmail-mail was send to the original owners pay 5 bitcoins within 24 hours.

namecheap support seems to be not very helpful.
livesupport useless and dumb.

up to now I can not say how it was possible to hack this accounts as they are at 2-factor authentication. but i will post it here as soon I find out.

check your namecheap accounts and try to use every security they offer.

also make a cc forwarding for any emails you might get from namecheap to a second
mailaccount because none of my publisher found a mail from namecheap in their regular mailaccounts. so i assume that the hack starts with a hack on the email-account, than they confirm the change and delete the message after.
__________________
Open for handpicked publishers and advertisers:
www.trafficfabrik.com
thommy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 06:32 AM   #2
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Thanks for the heads up
__________________


Skype: CallTomNow

Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 06:34 AM   #3
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
Disturbing if 2 factor was enabled.. Hopefully namecheap helps the original owners get their shit back. Hopefully nothing is compromised on namecheaps end.
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 06:35 AM   #4
Brian mike
#Alberta51
 
Brian mike's Avatar
 
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 8,434
Thanks for the heads up
__________________
Tube - Cam - Escorts - Top List
Menu Tab - Banner - Header Link - Blog Post
DM me
Brian mike is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 07:22 AM   #5
thommy
Confirmed User
 
thommy's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
Quote:
Originally Posted by MrBottomTooth View Post
Disturbing if 2 factor was enabled.. Hopefully namecheap helps the original owners get their shit back. Hopefully nothing is compromised on namecheaps end.


update:
looks like this was caused by a local trojan with a keylogger (that´s why 2 way authentication wasn´t secure enough).

namecheap for now locked the accounts. hope also that there is nothing else compromised because both publishers are really big ones with a lot of good traffic.
hope that it will end up only in a lot of work to change everything and build better security.

my biggest wish is to have 5 minutes with such a guy in one room.
after this 5 minutes he would never do that again.
__________________
Open for handpicked publishers and advertisers:
www.trafficfabrik.com
thommy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 07:22 AM   #6
Ramp
Confirmed User
 
Industry Role:
Join Date: Nov 2006
Posts: 4,464
edited...... missed some info
Ramp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 07:27 AM   #7
Arnox
Confirmed User
 
Arnox's Avatar
 
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,163
I'm not sure how a local trojan would have made 2FA not secure enough. Can you reset 2FA on NameCheap and it won't alert the 2FA device?
__________________
Need Text? X Copywriters | Adult Writing Service - [email protected]
Arnox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 07:30 AM   #8
blackmonsters
Making PHP work
 
blackmonsters's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,542
Checking mine now.

__________________
Make Money with Porn
blackmonsters is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 07:51 AM   #9
Google Expert
Webmaster
 
Google Expert's Avatar
 
Industry Role:
Join Date: Jun 2004
Posts: 14,294
Quote:
Originally Posted by thommy View Post
up to now I can not say how it was possible to hack this accounts as they are at 2-factor authentication. but i will post it here as soon I find out.
Just accept the fact that you're a dumbass who shouldn't be allowed on the interwebs.

Google Expert is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 08:57 AM   #10
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by MrBottomTooth View Post
Disturbing if 2 factor was enabled.. Hopefully namecheap helps the original owners get their shit back. Hopefully nothing is compromised on namecheaps end.
Any 2fa can be broken if your ride on session, that was recently discovered.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 08:57 AM   #11
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Arnox View Post
I'm not sure how a local trojan would have made 2FA not secure enough. Can you reset 2FA on NameCheap and it won't alert the 2FA device?
By riding on session. And here is how it works: let's say i have trojan on your PC, and i have access to your browser cookies. So, you login into system, using the 2FA device, and then i copy your cookie into my browser,and i get instant access. This works only as long cookie is valid, so if you click logout it wont work anymore, but if you leave browser without deleting cookie, it will be compromised.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 04:35 PM   #12
thommy
Confirmed User
 
thommy's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
Quote:
Originally Posted by Google Expert View Post
Just accept the fact that you're a dumbass who shouldn't be allowed on the interwebs.

thanks for this comment what shows again what clueless idiot you are.
__________________
Open for handpicked publishers and advertisers:
www.trafficfabrik.com
thommy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-24-2018, 04:37 PM   #13
thommy
Confirmed User
 
thommy's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
Quote:
Originally Posted by KlenTelaris View Post
By riding on session. And here is how it works: let's say i have trojan on your PC, and i have access to your browser cookies. So, you login into system, using the 2FA device, and then i copy your cookie into my browser,and i get instant access. This works only as long cookie is valid, so if you click logout it wont work anymore, but if you leave browser without deleting cookie, it will be compromised.
with a keylogger in the trojan there are also a few other ways.
no matter on what device you receive the pin you have to type it into the website.
__________________
Open for handpicked publishers and advertisers:
www.trafficfabrik.com
thommy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 06:24 AM   #14
Arnox
Confirmed User
 
Arnox's Avatar
 
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,163
Quote:
Originally Posted by KlenTelaris View Post
By riding on session. And here is how it works: let's say i have trojan on your PC, and i have access to your browser cookies. So, you login into system, using the 2FA device, and then i copy your cookie into my browser,and i get instant access. This works only as long cookie is valid, so if you click logout it wont work anymore, but if you leave browser without deleting cookie, it will be compromised.
Yeah, that's a whole new level of compromised. It'd be nice if they did what crypto exchanges do with Google Auth: every transaction you need to use your 2FA. Logging in 2FA simply isn't enough.
__________________
Need Text? X Copywriters | Adult Writing Service - [email protected]
Arnox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 06:35 AM   #15
beerptrol
Confirmed Asshole
 
beerptrol's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: Half way between sobriety and fubar.
Posts: 12,722
Quote:
Originally Posted by Google Expert View Post
Just accept the fact that you're a dumbass who shouldn't be allowed on the interwebs.

Says the biggest dumbass! Stick with what you're good at...sucking dick!!
__________________
“If we are to have another contest in the near future of our national existence, I predict that the dividing line will not be Mason and Dixon's but between patriotism and intelligence on the one side, and superstition, ambition and ignorance on the other.”
-- Ulysses S. Grant
beerptrol is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 06:46 AM   #16
thommy
Confirmed User
 
thommy's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
Quote:
Originally Posted by Arnox View Post
Yeah, that's a whole new level of compromised. It'd be nice if they did what crypto exchanges do with Google Auth: every transaction you need to use your 2FA. Logging in 2FA simply isn't enough.
the point here was that it was the local computer what was infected.
it was a very good made DCMA mail with a link (what is in the original mail also like that).

so be aware of obvious DCMA complaints.

looks like this is a new trick what is targeting adult websites with content because they get this kind of stuff quite often.
__________________
Open for handpicked publishers and advertisers:
www.trafficfabrik.com
thommy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 06:55 AM   #17
Matyko
PsyHead
 
Matyko's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: Hungary
Posts: 8,671
Thanks for the heads up! However I left NC some time ago I still have a few domains there. Turned on Two-Factor Authentication.
__________________
-=- Register with our ref link and we help you with the setup! -=-
AdSpyglass.com - Double your profit from brokers
Matyko is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 07:09 AM   #18
shake
frc
 
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,663
Quote:
Originally Posted by Matyko View Post
Thanks for the heads up! However I left NC some time ago I still have a few domains there. Turned on Two-Factor Authentication.
What are you using these days?

I was mostly using enom, but they just doubled their prices on me

Looking for a new register to use.
shake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 09:22 AM   #19
OneMillionGirls
Confirmed User
 
Industry Role:
Join Date: Apr 2017
Posts: 949
oh no man
OneMillionGirls is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 09:25 AM   #20
Arnox
Confirmed User
 
Arnox's Avatar
 
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,163
Quote:
Originally Posted by shake View Post
What are you using these days?

I was mostly using enom, but they just doubled their prices on me

Looking for a new register to use.
Google Domains is fantastic. I'm willing to pay slightly more if it's a no-bullshit domain host. They give you just what you need and that's it. Light and clean. It's the 21 Naturals of registrars.
__________________
Need Text? X Copywriters | Adult Writing Service - [email protected]
Arnox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-25-2018, 09:34 AM   #21
Google Expert
Webmaster
 
Google Expert's Avatar
 
Industry Role:
Join Date: Jun 2004
Posts: 14,294
Quote:
Originally Posted by beerptrol View Post
Says the biggest dumbass! Stick with what you're good at...sucking dick!!
You've mistaken me for your boyfriend Bladewire.
Google Expert is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
namecheap, accounts, hack, check, offer, forwarding, post, emails, security, mailaccount, assume, starts, mailaccounts, regular, email-account, delete, change, confirm, message, authentication, mail, found, publisher, domains, changed
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.