![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
|
better check your namecheap accounts
today a 2 of my publishers had a similar problem with hacked namecheap accounts.
account owner and password have been changed and all domains transfered. after that blackmail-mail was send to the original owners pay 5 bitcoins within 24 hours. namecheap support seems to be not very helpful. livesupport useless and dumb. up to now I can not say how it was possible to hack this accounts as they are at 2-factor authentication. but i will post it here as soon I find out. check your namecheap accounts and try to use every security they offer. also make a cc forwarding for any emails you might get from namecheap to a second mailaccount because none of my publisher found a mail from namecheap in their regular mailaccounts. so i assume that the hack starts with a hack on the email-account, than they confirm the change and delete the message after. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
|
Thanks for the heads up
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Sep 2009
Posts: 5,795
|
Disturbing if 2 factor was enabled.. Hopefully namecheap helps the original owners get their shit back. Hopefully nothing is compromised on namecheaps end.
__________________
Get Paid Per Email Like The WEGCASH Days!!!! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 8,434
|
Thanks for the heads up
![]()
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
|
Quote:
update: looks like this was caused by a local trojan with a keylogger (that´s why 2 way authentication wasn´t secure enough). namecheap for now locked the accounts. hope also that there is nothing else compromised because both publishers are really big ones with a lot of good traffic. hope that it will end up only in a lot of work to change everything and build better security. my biggest wish is to have 5 minutes with such a guy in one room. after this 5 minutes he would never do that again. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Nov 2006
Posts: 4,464
|
edited...... missed some info
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,162
|
I'm not sure how a local trojan would have made 2FA not secure enough. Can you reset 2FA on NameCheap and it won't alert the 2FA device?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Making PHP work
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,542
|
Checking mine now.
![]()
__________________
Make Money with Porn |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Webmaster
Industry Role:
Join Date: Jun 2004
Posts: 14,294
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
By riding on session. And here is how it works: let's say i have trojan on your PC, and i have access to your browser cookies. So, you login into system, using the 2FA device, and then i copy your cookie into my browser,and i get instant access. This works only as long cookie is valid, so if you click logout it wont work anymore, but if you leave browser without deleting cookie, it will be compromised.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
|
thanks for this comment what shows again what clueless idiot you are.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
|
Quote:
no matter on what device you receive the pin you have to type it into the website. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,162
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed Asshole
Industry Role:
Join Date: Feb 2003
Location: Half way between sobriety and fubar.
Posts: 12,722
|
Says the biggest dumbass! Stick with what you're good at...sucking dick!!
__________________
“If we are to have another contest in the near future of our national existence, I predict that the dividing line will not be Mason and Dixon's but between patriotism and intelligence on the one side, and superstition, ambition and ignorance on the other.” -- Ulysses S. Grant |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Switzerland / Germany / Thailand
Posts: 5,469
|
Quote:
it was a very good made DCMA mail with a link (what is in the original mail also like that). so be aware of obvious DCMA complaints. looks like this is a new trick what is targeting adult websites with content because they get this kind of stuff quite often. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
PsyHead
Industry Role:
Join Date: Aug 2005
Location: Hungary
Posts: 8,671
|
Thanks for the heads up! However I left NC some time ago I still have a few domains there. Turned on Two-Factor Authentication.
__________________
-=- Register with our ref link and we help you with the setup! -=-
AdSpyglass.com - Double your profit from brokers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
frc
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,663
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Industry Role:
Join Date: Apr 2017
Posts: 949
|
oh no man
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,162
|
Google Domains is fantastic. I'm willing to pay slightly more if it's a no-bullshit domain host. They give you just what you need and that's it. Light and clean. It's the 21 Naturals of registrars.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Webmaster
Industry Role:
Join Date: Jun 2004
Posts: 14,294
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |