Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-25-2003, 03:17 PM   #1
loco12
Confirmed User
 
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
Spoofing. Best way to stop it.

I seem to have a problem with spoofers, who get past my .htaccess like it isn't there.

Whats the best method to stop them accessing the members area?

Serious answers please!

cheers
loco12 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:31 AM   #2
loco12
Confirmed User
 
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
bump.
no one know how to stop spoofing?
loco12 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:37 AM   #3
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Is it for an AVS site? I don't think there is really any other generic way to protect your members area - the AVS would need to pass control to a script on your site with some sort of key that validates the surfer. Authenticating by referer is a nice and clean way to do it as it's all done with a few lines of .htaccess without needing scripts on your side, but as you can see it's virtually useless these days.

If you control the login page then you could move to a form+cookie based login, or stick with good old HTTP basic auth.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:38 AM   #4
Juggernaut
Confirmed User
 
Join Date: Jan 2003
Location: Brisbane, Australia
Posts: 753
Look into cookies, something that checks that they have permission because they've already gone through your "gateway", if they dont, 403. Session management cookies might do it.
Juggernaut is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:50 AM   #5
loco12
Confirmed User
 
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
basically its all my remaining members that signed up through ACPay. There are only about 150 members left that go through the acpayscript to enter my site.

If I added all these remaining ACPay members to my CCBill password file and removed the acpay from my htaccess file would that stop the problem?

Of course I would have to remove the acpay members by hand as they cancelled, but if it stopped the problem its worth it.
loco12 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:51 AM   #6
konduct
Registered User
 
Join Date: Oct 2003
Location: NYC
Posts: 326
konduct is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:53 AM   #7
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Did acpay use referer based authentication? Ouch, that's a HUGE hole for a 'real' paysite!! Yes, you'll probably save more bw in the long run by using proper authentication, even if your members get a week or two extra.

If ccbill allows you to 'deep link' products then email your acpay members a hidden URL that gives them a special rate for defecting from acpay to ccbill.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-26-2003, 01:57 AM   #8
loco12
Confirmed User
 
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
Quote:
Originally posted by rowan
Did acpay use referer based authentication? Ouch, that's a HUGE hole for a 'real' paysite!! Yes, you'll probably save more bw in the long run by using proper authentication, even if your members get a week or two extra.

If ccbill allows you to 'deep link' products then email your acpay members a hidden URL that gives them a special rate for defecting from acpay to ccbill.
Personally I don't want to move the ACPay members to another processor, as it was the best processor out there for its short life.

Looks like I will have to get them to change the auth so that the hole is filled in. I wondered why my servers were getting a bit slow over the last 24 hours. It was filled up with fucking hahahahaing gate crashers!
loco12 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.