Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-14-2005, 04:43 AM   #1
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
password forums. if you run a pay site. read this

http://www.protectadult.com/forumsecurity.php

we have released the monster list.

and a bit of an update just to keep you updated
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 04:46 AM   #2
Juggernaut
Confirmed User
 
Join Date: Jan 2003
Location: Brisbane, Australia
Posts: 753
Adding these URL's to a blocklist, doesn't prevent people from copy and pasting the hacked URL directly into their browser.

You've just given free porn to all the surfers on GFY, by the way.
Juggernaut is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 04:52 AM   #3
nmcog
Confirmed User
 
Join Date: Sep 2004
Posts: 825
Just force all passwords to be randomly generated and let members pick their own username.
nmcog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 05:10 AM   #4
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
Quote:
Originally Posted by nmcog
Just force all passwords to be randomly generated and let members pick their own username.

useless

still crackable
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 05:20 AM   #5
SomeCreep
:glugglug
 
SomeCreep's Avatar
 
Join Date: Mar 2003
Location: Where the Wild Things Are
Posts: 26,118
Quote:
Originally Posted by fris
http://www.protectadult.com/forumsecurity.php

we have released the monster list.

and a bit of an update just to keep you updated
Uhm, use common sense. Dont post that list on this board.

Edit: Surfers will bookmark those urls.
__________________

Webair Hosting

I use and recommend Webair for hosting.

Last edited by SomeCreep; 04-14-2005 at 05:21 AM..
SomeCreep is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 05:52 AM   #6
Trax
[----------------------]
 
Join Date: Aug 2001
Posts: 14,486
useless...
Trax is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 06:18 AM   #7
goldman
Confirmed User
 
Join Date: Nov 2004
Location: nz
Posts: 212
CTRL-D....

hmmm.................................
http://pass.nejcpass.com/
this ones the best from what i can remember.........

there r a further 1000 password sites out there
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, you may use a 624x80 instead of a 120x60. Let me repeat... A 120 x 60 button and no more that 3 lines of DEFAULT SIZE AND COLOR text.
goldman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 06:20 AM   #8
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
The sufers here are going to love those forums...
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 06:56 AM   #9
Triple 6
Confirmed User
 
Join Date: Feb 2002
Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: Location: isN'T everything
Posts: 5,394
why the fuck is it so hard for these paysites to monitor IP's and grant access to no more then 2 uniques per day on each account? its fucking easy. wake up.
__________________
SIG TOO SMALL! Maximum 1200x600 button and no more than 30 text lines of ALL SIZES and COLORS. Unless your sig is for a GFY top banner sponsor, then you may use a 6240x4800 instead of a 1024x800.
Triple 6 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 06:57 AM   #10
nmcog
Confirmed User
 
Join Date: Sep 2004
Posts: 825
Quote:
Originally Posted by fris
useless

still crackable
I've lurked for a while on IRC password trading channels (from efnet to thundercity), everytime some paysites get requested, everyone says that one is impossible because they autogenerate the password.

I've also talked with some of the ops who've been doing it since 1999 and they say the only way is to actually crack the server and not bruteforce which turns into a whole different game.
nmcog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:06 AM   #11
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
Quote:
Originally Posted by nmcog
I've lurked for a while on IRC password trading channels (from efnet to thundercity), everytime some paysites get requested, everyone says that one is impossible because they autogenerate the password.

I've also talked with some of the ops who've been doing it since 1999 and they say the only way is to actually crack the server and not bruteforce which turns into a whole different game.
its actually all bruteforced.

htacess is really easy to crack.

have a good dictionary list. and big proxy list. run it through over 2 million times and you will crack it. some sites are being smart and doing form logins. which are the smart way to go. thats why people use proxy's to crack. because of course if they see more than 2 ips from the same host they will ban.

we shut down password trading channels on dalnet last december. that was where most of the trading was done.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:07 AM   #12
MandyBlake
The one and only!
 
MandyBlake's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: Atlanta, GA
Posts: 17,761
that's why we have password protection software.
__________________
Mandy's Playhouse
Her First Fat Girl
If you're interested in promoting my sites, ICQ me! 178411921
MandyBlake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:30 AM   #13
MGibson
So Fucking Banned
 
Join Date: Jan 2005
Posts: 772
Actually make a fake part of your site, put it on a password forum. Fill the fake part with upsells. Money does come in...
MGibson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:31 AM   #14
jMP
Registered User
 
Join Date: Jan 2003
Posts: 5
Quote:
Originally Posted by fris
http://www.protectadult.com/forumsecurity.php

we have released the monster list.

and a bit of an update just to keep you updated
Thanks for the laugh
Now go find the other 5 million sites and their mirrors


Your security team beat pennywise? OMG! How lame are these guys if that?s their claim to password security fame.
jMP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:34 AM   #15
VeriSexy
Join The Royal Family
 
VeriSexy's Avatar
 
Join Date: Apr 2002
Posts: 25,463
Quote:
Originally Posted by fris
http://www.protectadult.com/forumsecurity.php

we have released the monster list.

and a bit of an update just to keep you updated

Good job
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos
.
With TOP RATIO Sites like


ATMovs.com | iTeenVideo.com |
TeenSexMovs.com | TeenSexMania.com


VeriSexy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:35 AM   #16
Jake
Confirmed User
 
Jake's Avatar
 
Join Date: Dec 2001
Location: CO, US
Posts: 3,056
Quote:
Originally Posted by Triple 6
why the fuck is it so hard for these paysites to monitor IP's and grant access to no more then 2 uniques per day on each account? its fucking easy. wake up.
Yes and then you'll spend the entire day unblocking pissed off AOL users. Or worse, they'll just cancel or chargeback their membership because they can't get access to the site.
__________________
Jake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:48 AM   #17
jMP
Registered User
 
Join Date: Jan 2003
Posts: 5
Quote:
Originally Posted by fris
its actually all bruteforced.


"have a good dictionary list"

.
.
And where do you think the good wordlists come from?
If you?re going to handout security advice you might want to actually understand the game first.

I can?t believe I doubled my post count in one night

Last edited by jMP; 04-14-2005 at 07:50 AM..
jMP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 07:49 AM   #18
Cassie
Confirmed User
 
Join Date: Mar 2003
Location: NJ
Posts: 3,139
Quote:
Originally Posted by jMP
.

I can?t believe I doubled my post count in one night

__________________
ICQ: 309756847
]
Cassie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2005, 01:20 PM   #19
kyree666
Registered User
 
Join Date: Feb 2005
Posts: 30

Quote:
Originally Posted by jMP
.
And where do you think the good wordlists come from?
If you?re going to handout security advice you might want to actually understand the game first.

I can?t believe I doubled my post count in one night

lol been saying that for years...do I know you/of you jMP I believe I do

screw dealing with dictionary files...people are creatures of habit...get one passfile, you're into many other sites...

for people running pay sites your best bet is to make it as diffecult as possible, make it more trouble than it's worth...form login with visual your best bet....but even that's not uncrackable...lemme rephrase that...your best bet...learn wtf you are doing, quit leaving it up to your hosts to protect you...quit being so god damn lazy, quit worrying about making that quick buck...learn about server configurations,quit being button pushers, START caring about your memebrs and offer them some security...learn how to crack, and you will learn how to protect
there are many sites that crackers will not even bother touching...why ? because the owners went to the trouble of finding out how people are getting in, instead of sitting around crying about it happening...do you really think shutting down an irc channel, or a website is gonna keep people out? get a clue....this si the same old tired shit it hasa been for years...you find a way to keep crackers out...we build a better mousetrap....but look at the brite side....handing out passwords tends to weed out the competition, and break the asshats that run shitty sites


moral of this rant......get off your lazy fucking asses and learn wtf you're doing before you call yourself a pr0n webmaster

kyree
kyree666 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2005, 04:00 AM   #20
High_Times
Confirmed User
 
Join Date: Apr 2005
Posts: 115
This thread will show you how to make it difficult as possible:
http://www.gofuckyourself.com/showthread.php?t=459989
High_Times is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2005, 04:04 AM   #21
Johny Traffic
Confirmed User
 
Join Date: Apr 2003
Posts: 5,461
Quote:
Originally Posted by Triple 6
why the fuck is it so hard for these paysites to monitor IP's and grant access to no more then 2 uniques per day on each account? its fucking easy. wake up.
What about ISP's that dont give the user a fixed IP?
__________________


hosted flv's, hosted galleries, morphing rss feeds, free content, free sites, hosted blog
Johny Traffic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2005, 04:27 AM   #22
Mutt
Too lazy to set a custom title
 
Mutt's Avatar
 
Industry Role:
Join Date: Sep 2002
Posts: 34,431
Quote:
Originally Posted by kyree666
lol been saying that for years...do I know you/of you jMP I believe I do

screw dealing with dictionary files...people are creatures of habit...get one passfile, you're into many other sites...

for people running pay sites your best bet is to make it as diffecult as possible, make it more trouble than it's worth...form login with visual your best bet....but even that's not uncrackable...lemme rephrase that...your best bet...learn wtf you are doing, quit leaving it up to your hosts to protect you...quit being so god damn lazy, quit worrying about making that quick buck...learn about server configurations,quit being button pushers, START caring about your memebrs and offer them some security...learn how to crack, and you will learn how to protect
there are many sites that crackers will not even bother touching...why ? because the owners went to the trouble of finding out how people are getting in, instead of sitting around crying about it happening...do you really think shutting down an irc channel, or a website is gonna keep people out? get a clue....this si the same old tired shit it hasa been for years...you find a way to keep crackers out...we build a better mousetrap....but look at the brite side....handing out passwords tends to weed out the competition, and break the asshats that run shitty sites


moral of this rant......get off your lazy fucking asses and learn wtf you're doing before you call yourself a pr0n webmaster

kyree
why do you surfers hang out here? seems like there is a growing group of pr0n webmasters groupies. surfers who are fascinated by the behind the scenes machinery of the web porn machine.
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
Mutt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2005, 08:08 AM   #23
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
bringing up old threads

nice

glad i took that list down.

i still wanna do a security aduit on paysites running proxypass, strongbox, and writeup a review. on the products.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.