Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-01-2001, 11:05 AM   #1
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
If you own a paysite, READ THIS NOW

www.spoofer.de

If you use .htacccess to protect your members area, you had better take a look at this.

You are basically wide open to people downloading the program and getting access.
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:07 AM   #2
12clicks
Too lazy to set a custom title
 
12clicks's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: God's right hand
Posts: 19,791
YES!
now I don't need my credit card anymore.
12clicks is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:09 AM   #3
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by 12clicks:
YES!
now I don't need my credit card anymore.
You have a credit card?
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:11 AM   #4
ElvisManson
Looking California
 
ElvisManson's Avatar
 
Industry Role:
Join Date: Feb 2001
Posts: 5,476
Thanks KK,

My techies are downlaoding now to test.

Sure 12Clicks has a credit card...how do you think he pays for his cape and boots?



------------------
The All NEW www.PythonVideo.com Portal Page
Python
Dollar Machine
Naughty Mail Pay by click
Awesome Content
ElvisManson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:13 AM   #5
Wizzo
2011 GFY Hall of Fame!
 
Wizzo's Avatar
 
Industry Role:
Join Date: Nov 2000
Location: Back in Texas!
Posts: 15,224
He's talking about the ones that came with the "Tonka's Big Man Business Adventure Set"... He got for Christmas last year.
Wizzo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:13 AM   #6
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by ElvisManson:
Thanks KK,

My techies are downlaoding now to test.

Sure 12Clicks has a credit card...how do you think he pays for his cape and boots?

I thought he used the five finger discount on those.
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:14 AM   #7
ElvisManson
Looking California
 
ElvisManson's Avatar
 
Industry Role:
Join Date: Feb 2001
Posts: 5,476
Quote:
Originally posted by Kimmykim:
I thought he used the five finger discount on those.
He only does that for the Pink satin undies.



------------------
The All NEW www.PythonVideo.com Portal Page
Python
Dollar Machine
Naughty Mail Pay by click
Awesome Content
ElvisManson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:30 AM   #8
Osholio
Confirmed User
 
Join Date: Sep 2001
Location: UK
Posts: 99
Referrer spoofing? Good god that's utterly trivial to do. Hell I've written scripts to do it in perl to pull images off the ifriends site for my 'active banners'.

It's an inherent limitation of HTTP, using .htaccess files to prevent hotlinking based upon the http referrer header (or as it's used, 'referer') has always been vunerable to spoofing.

If you use this to protect your member's areas, then you're in trouble, and have always been in trouble. Basic realm protection should still be secure from this kind of spoofing, but the ultra paranoid should verify usernames and password via a secure (SSL) page and then setup a session cookie to allow access to the members content. That kind of setup will also protect the site from brute force crackers.

One day, I may use my powers for evil...

------------------
ClickCash - Better than 1:99 and $50 for signing up
Lightspeed Cash - Converts like crazy
Osholio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:33 AM   #9
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
Quote:
Originally posted by Osholio:
One day, I may use my powers for evil...
If you do, call me up... I'd like to submit a resume for the evil hunch-backed sidekick position.

Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:38 AM   #10
Osholio
Confirmed User
 
Join Date: Sep 2001
Location: UK
Posts: 99
Quote:
Originally posted by Amputate Your Head:
Quote:
Originally posted by Osholio:
One day, I may use my powers for evil...
If you do, call me up... I'd like to submit a resume for the evil hunch-backed sidekick position.

I'll keep you in mind.. Do you prefer to be called ee-gore or eye-gore?


------------------
ClickCash - Better than 1:99 and $50 for signing up
Lightspeed Cash - Converts like crazy
Osholio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:39 AM   #11
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
Quote:
Originally posted by Osholio:
Do you prefer to be called ee-gore or eye-gore?
"Lumpy" is fine...

Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:45 AM   #12
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Osholio -- are you from Holio by any chance?
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:47 AM   #13
Osholio
Confirmed User
 
Join Date: Sep 2001
Location: UK
Posts: 99
Tonight, Lumpy, we take over the WORLD!


------------------
ClickCash - Better than 1:99 and $50 for signing up
Lightspeed Cash - Converts like crazy
Osholio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:51 AM   #14
erotictrance
Confirmed User
 
Join Date: Nov 2001
Location: Southern California
Posts: 328
This was mentioned on Netpond yesterday ...

Some people said they tested it, and it worked pretty well ...

------------------
erotictrance
erotictrance is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:52 AM   #15
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
I need TP for my bunghole! BUUUUUNGHOLIO!! yea! yea...! nnngngngghhhaaAAAH!
Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:52 AM   #16
Osholio
Confirmed User
 
Join Date: Sep 2001
Location: UK
Posts: 99
Quote:
Originally posted by Kimmykim:
Osholio -- are you from Holio by any chance?
I have no idea where Holio is. My usual nickname is 'Os' but most sites think it's too short and tells me to fuck off when I try to register, so I expanded it after seeing an episode of Beavis and Butthead.

"I am Osholio! I need tcp/ip for my bunghole!"

Sorry, I shouldn't drink during the day.


[This message has been edited by Osholio (edited 11-01-2001).]
Osholio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:52 AM   #17
ElvisManson
Looking California
 
ElvisManson's Avatar
 
Industry Role:
Join Date: Feb 2001
Posts: 5,476
Quote:
Originally posted by Osholio:
Tonight, Lumpy, we take over the WORLD!


I think Pinky and The Brain already have that line



------------------
The All NEW www.PythonVideo.com Portal Page
Python
Dollar Machine
Naughty Mail Pay by click
Awesome Content
ElvisManson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 11:54 AM   #18
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by erotictrance:
This was mentioned on Netpond yesterday ...

Some people said they tested it, and it worked pretty well ...

Unfortunately I agree.

Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:00 PM   #19
rollin
Confirmed User
 
Join Date: Oct 2001
Posts: 436
password protecting all areas
is the best solution
content providers should password protect their content
rollin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:00 PM   #20
awechen
Confirmed User
 
Join Date: Oct 2001
Location: LA
Posts: 162
1. use SSL
2. use cookies
3. use session ID's
4. use radom links.
5. use layer's
6. use javascrip
if u have all this and a cool scripting setup .. u dont have problems with fake accounts or fake referer ...

but i think the this porblems will fuck the contentprovider more then the payside owner ... (if they have plugin content )


------------------
"Shock your systemadministration! Read manual-pages!"
awechen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:00 PM   #21
Osholio
Confirmed User
 
Join Date: Sep 2001
Location: UK
Posts: 99
Quote:
Originally posted by erotictrance:
This was mentioned on Netpond yesterday ...

Some people said they tested it, and it worked pretty well ...

As I said, if you're relying on anything that comes from the user's browser (like the referrer header) for authentication then you're going to be fucked like Gary's pets. Users tend to be sneakly buggers and will try all kinds of fun things to by-pass security, and now this tool has been written even the most clueless of plebs, erm, valued customers will try to screw you over.

In short, you won't be able to use the http-referer header as anything more as a line of text that the browser may send. Using it to protect your members areas will no longer work.

To be honest, anyone who used it that way will have been screwed over multiple times by now anyway, they'll just get screwed more often now

------------------
ClickCash - Better than 1:99 and $50 for signing up
Lightspeed Cash - Converts like crazy
Osholio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:04 PM   #22
shunga
Confirmed User
 
Join Date: Apr 2001
Location: Loveland
Posts: 994
Quote:
Originally posted by Kimmykim:
Unfortunately I agree.
Now's the point you tell us your techs are working on something..?
shunga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:48 PM   #23
erotictrance
Confirmed User
 
Join Date: Nov 2001
Location: Southern California
Posts: 328
I totally agree Osholio ...

Since someone said they were testing ... I was just pointing out that the Netponders had also tested it and said it worked ...

Will the ripoffs ever end??? ... LOL

Keeping on top of all this security stuff is enough to drive me insane ... LOL ... but I'm always grateful for the information ...

P.S. Gotta love those "customers" who are always trying to rip us to no end ... LOL
erotictrance is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 12:49 PM   #24
rollin
Confirmed User
 
Join Date: Oct 2001
Posts: 436
i can confirm it works
tried it on one of my members areas, to a content providers plugin we use...and it worked
rollin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 01:13 PM   #25
erotictrance
Confirmed User
 
Join Date: Nov 2001
Location: Southern California
Posts: 328
BTW ...

Is htaccess the only thing that content providers have to protect the stuff they're selling to other sites? I thought they had password protection, among other things ...

Just curious ...

[This message has been edited by erotictrance (edited 11-01-2001).]
erotictrance is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 01:26 PM   #26
danevans
Confirmed User
 
Join Date: Jun 2001
Location: Europe
Posts: 1,295
I heared that Gary is setting up some Bouncer(tm) teams at ThugCash. Beta testing should be in progress..
danevans is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 01:45 PM   #27
rollin
Confirmed User
 
Join Date: Oct 2001
Posts: 436
nope, they just .htaccess
no password protection

btw KimmyKim,
Congrads. You are over 1000 post's!!
rollin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 01:48 PM   #28
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by rollin:
nope, they just .htaccess
no password protection

btw KimmyKim,
Congrads. You are over 1000 post's!!
Do I win something?
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 01:51 PM   #29
Gary
Confirmed User
 
Join Date: Aug 2001
Location: Kimmykims couch
Posts: 6,110
Quote:
Originally posted by Kimmykim:
Do I win something?
I'll give you a back rub when you get home tonight and i finish with your dog.
Gary is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:01 PM   #30
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by Gary:
I'll give you a back rub when you get home tonight and i finish with your dog.
Can't I go before the dog?
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:02 PM   #31
Gary
Confirmed User
 
Join Date: Aug 2001
Location: Kimmykims couch
Posts: 6,110
Quote:
Originally posted by Kimmykim:
Can't I go before the dog?
Hmmmmmm....NO!
Gary is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:03 PM   #32
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by Gary:
Hmmmmmm....NO!
Fine then, you sleep in the lounge chair out back from now on.
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:10 PM   #33
rollin
Confirmed User
 
Join Date: Oct 2001
Posts: 436
gary can sleep with the dog
rollin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:17 PM   #34
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Quote:
Originally posted by rollin:
gary can sleep with the dog
um, no. The dog sleeps with me.
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:18 PM   #35
ElvisManson
Looking California
 
ElvisManson's Avatar
 
Industry Role:
Join Date: Feb 2001
Posts: 5,476
Quote:
Originally posted by Kimmykim:
um, no. The dog sleeps with me.

Now that is a visual.....




------------------
The All NEW www.PythonVideo.com Portal Page
Python
Dollar Machine
Naughty Mail Pay by click
Awesome Content
ElvisManson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 02:19 PM   #36
Kimmykim
bitchslapping zebras!!!!!
 
Industry Role:
Join Date: Jun 2001
Location: In a shack by the beach
Posts: 16,015
Damn, I knew that was too good for some people to pass up
Kimmykim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 04:20 PM   #37
-=HUNGRYMAN=-
Confirmed User
 
Join Date: Jun 2001
Location: Between your mamma's legs
Posts: 4,753
OK KK .... my question is this ...
I have a paysite, with the .htaccess installed as part of the CCBill install.
Will you guys be creating a new means of securing a website, and how soon will it be out ?

------------------

Airforce come and dey flatten your home !!!
The Black Sheep of the Boneprone Family
I like to rub HERTURN on my nipples
-=HUNGRYMAN=- is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 04:57 PM   #38
Phil21
Confirmed User
 
Join Date: May 2001
Location: ICQ: 25285313
Posts: 993
this isn't a ".htaccess" problem, it's "checking for valid users by referrer" problem. CCbill should be okay, I would assume. They use HTTP auth to allow access (coincidently, this ALSO goes in the .htaccess file as well), to member areas. This means the browser must send a valid UID/password *each hit* or the item will not be served up.

I would assume most paysites would not be vulnerable to this, but then again I'm surprised *ANYONE* would be so downright stupid to protect a members area via referrer checking. So I could stand corrected.

-Phil
Phil21 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 05:08 PM   #39
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
Question for ya Phil21.... I have my stuff hard coded into my conf file versus using htaccess. Does that offer me any better resistance than using it in htaccess? (my guess is no, since it's virtually the same code.)
Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 09:14 PM   #40
Phil21
Confirmed User
 
Join Date: May 2001
Location: ICQ: 25285313
Posts: 993
Amp, nope. It's *exactly* the same as having a .htaccess file, it's just the htaccess file is dynamically loaded (and looked for whether or not it exists if AllowOverrides is turned on) and lets users control certain aspects of their apache config. Essentially it's just an extension of your conf file, but loaded for each hit, not all at one time.

Your way is actually better performance-wise, as long as you have AllowOverrides turned off. Apache doesn't have to make the I/O call to see if the file exists (and read it if it does) since it's all "hard coded".

peace,

-Phil
Phil21 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-01-2001, 09:17 PM   #41
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
Thought so.... thanks Phil.
Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-02-2001, 03:57 AM   #42
XP
Confirmed User
 
Industry Role:
Join Date: Mar 2001
Location: Thailand
Posts: 384
I have this mspoofer before from a friend (older versions).

But I don't need mspoofer, I can do it by Internet explorer too )
At Guard, Norton Internet Security allows you modify/block referer, user agent, cookies etc etc.!!

Anyway, its content providers problem. They must resolve that!

------------------
screw you guys, I'm going to home!
XP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.