![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Jan 2003
Posts: 1,699
|
JUST GOT HACKED, paysite owners any ideas?
Hey guys
Just got up to 30 new accounts blocked by pennywize and all with prefixed usernames like p2e_974039 p2e_947721 p2e_924163 p2e_924148 etc etc etc We use Epoch, MPA2, Electracash & CCbill right now. & Pennywize to protect the usernames from abuse. And we just dropped PSWbilling last month. Any ideas if any of these processors are vunerable to hackers doing this with password files? We are looking into our servers being hacked as an option. Burning up the members area with mass bandwidth right now, a huge video archive like wildpass.com just burning it up with hacked accounts. Fun and games ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
I help you SUCCEED
Industry Role:
Join Date: Nov 2003
Location: The Pearl of the Orient Seas
Posts: 32,195
|
brute force pw extraction script?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Confirmed User
Join Date: Jan 2003
Posts: 1,699
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: May 2002
Location: Oslo, Norway
Posts: 748
|
Were there any transactions behind those usernames? Check if they're from checking, Electracash is open like a barn door.
__________________
<a href="http://www.homepageofthedead.com"><img src="http://board.gofuckyourself.com/images/globill_88x31.gif"></a> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Dec 2001
Posts: 7,952
|
means one of those scripts is creating the password.
You need to figure out what they are using (hopefully you have apache logs and can see where they are getting added) if you need help icq me |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
So Fucking Banned
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
|
You may want to look into your ccbill scripts.. DO NOT use common directory names with ccbill. There are huge lists that have all the common directory paths for ccbill and many other processors. Use something unique like %_--29AusmAW-_$ as the directory
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
So Fucking Banned
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
|
Quote:
matt AT jasonandalex DOT com please ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Feb 2002
Location: Las Vegas
Posts: 6,504
|
i've heard about some hackers being able to do what they like w/ ccbill, not sure how true it is though
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Join Date: Jan 2003
Posts: 1,699
|
Electracash, interesting. Could you send me some more info at
matt a_t wildcash.com Thanks guys. Oh and nope the accounts don't seem to have any processing behind them, just the passwords are being added somehow |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
So Fucking Banned
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Jan 2003
Posts: 1,699
|
We've ruled out CCbill as we are only just setting them up and they are not fully active yet.
the pricks added 140 passwords we just removed them, they were spread out threwout the password file, must of been adding them for awhile using a script or something. Then unleashed them today |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Industry Role:
Join Date: Apr 2001
Location: N.Y. -Long Island --
Posts: 122,992
|
Dude if you did get hacked dont mention it here. Alot of talented people here on and just reading that will just try to fuck with you now.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Mar 2002
Location: NY
Posts: 4,994
|
if you have any 777 files in your setup follow matt's advice, dont use common directory paths. otherwise hit up your processor and see if they have logged IPs for the usernames you mentioned, if its all from the same IP you can ask them to block it out.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Jan 2003
Posts: 1,699
|
Good advice Juicy, thanks for the help guys.
|
![]() |
![]() ![]() ![]() ![]() ![]() |