Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-26-2005, 11:41 AM   #1
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
what is "spoofing" and is this a ccbill security issue?

recently checking some google logs i notice one of my paysites on a hacker webpage devoted to "spoofing" and giving my ccbill login address.

ok, WTF is this, how is it done, and how can these jackoffs be kept out?

knowledgable advice requested.

thanks!
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 11:42 AM   #2
Young
Bland for life
 
Industry Role:
Join Date: Nov 2004
Posts: 10,468
something about faking the referring addy to get past the target site addy. I don't know how its done though.
__________________
★★★
Young is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 11:52 AM   #3
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
well, this is an eye-opener.

i would advise webmasters with popular paysites using ccbill to do a google search with the name of your paysite and the keyword "spoof" or "spoofing" and see what comes back.

digging deeper now.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 11:53 AM   #4
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
example:

alsscan.com spoof

i sense we have a serious issue here.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 11:55 AM   #5
Harmon
( ͡ʘ╭͜ʖ╮͡ʘ)
 
Harmon's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 20,010
Yeah. I think you spoof the referring page in order to gain access to members only pages. Make sure your .htaccess, .htpasswd, etc are all locked up tight. CCBill as a biller *USED* to have tons of security holes... I have no clue about now.
__________________
[email protected]
Harmon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 11:59 AM   #6
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
thanks.

more info requested.

checking other paysites in google now:

blacksonblondes.com and keyword "spoof"

234 entries, many russian

lots of scammers getting a free ride.

now, how can these asswipes be stopped?
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 12:02 PM   #7
Young
Bland for life
 
Industry Role:
Join Date: Nov 2004
Posts: 10,468
thats not really an acurate way of doing it. and i don't think blacksonblondes.com can be spoofed. its only certain sites and certain content stream providers that use referrer ID's.
__________________
★★★
Young is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 12:17 PM   #8
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
well i'm digging for info right now.

big problem for paysite owners, here's a post i see on a "spoofer" message board:
hahahahahahahahahahahahahahahaha
Originally Posted by MadUstasa
Dude, the entire Max Hardcore site, all the movies from Private, Canadian Amateurs, CelebFlix, Deepthroat sites etc etc. 1000's of hardcore membersites!

Just type in what you want and it's there

HOLY SHIT! The entire GGG(German Goo Girls) membersite is available
hahahahahahahahahahahahahahahaha

these kids are breaking into lots of sites. the question is, how can it be stopped?
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 12:20 PM   #9
Harmon
( ͡ʘ╭͜ʖ╮͡ʘ)
 
Harmon's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 20,010
Quote:
Originally Posted by latinasojourn
well i'm digging for info right now.

big problem for paysite owners, here's a post i see on a "spoofer" message board:
hahahahahahahahahahahahahahahaha
Originally Posted by MadUstasa
Dude, the entire Max Hardcore site, all the movies from Private, Canadian Amateurs, CelebFlix, Deepthroat sites etc etc. 1000's of hardcore membersites!

Just type in what you want and it's there

HOLY SHIT! The entire GGG(German Goo Girls) membersite is available
hahahahahahahahahahahahahahahaha

these kids are breaking into lots of sites. the question is, how can it be stopped?
Seriously STFU. It's been going on for YEARS man. It's not like you just discovered that crackers can exploit their way into your members only areas, or brute force passes until they get a hit. This is old news. The only solution is to stay one step ahead of them and tighten up your security. There are a gazillion ways to do it... search Google and do what you need to do
__________________
[email protected]
Harmon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 02:16 PM   #10
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
Quote:
Originally Posted by Harmon
Seriously STFU. It's been going on for YEARS man. It's not like you just discovered that crackers can exploit their way into your members only areas, or brute force passes until they get a hit. This is old news. The only solution is to stay one step ahead of them and tighten up your security. There are a gazillion ways to do it... search Google and do what you need to do

ok, whatever. i already have very good protection on brute force attacks and multiple identical passwords, but this variant of spoofing is a new problem for me, and yes, i do make a living running paysites.

of course this is no big deal if you don't run paysites, and thanks for your knowledgable input

anyway, if any paysite owners are interested in this here's how the kids are getting into your sites:

http://refspoof.mozdev.org/installation.html

and now, i am working on the solution.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 02:21 PM   #11
nastyking
 
Join Date: Nov 2002
Posts: 2,174
latinasofjourn? Do you allow access to your members area from certain Sites (Referrers) without a password?

If no .. then you should have no problem
__________________
nastyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 02:25 PM   #12
Tat2Jr
Confirmed User
 
Tat2Jr's Avatar
 
Join Date: Feb 2001
Location: Sunny California
Posts: 4,882
Wait a second..... this seems to be a business related thread.... what the hell is a business thread doing here on GFY? ;)
__________________
NICHE MONEY >> Ass WorshipPantiesSolo TeenPantyhose
Serving up exclusive fetish sites since 1997!
Tat2Jr is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 02:28 PM   #13
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
Quote:
Originally Posted by nastyking
latinasofjourn? Do you allow access to your members area from certain Sites (Referrers) without a password?

If no .. then you should have no problem

no, but they get in occasionally.

now ccbill generates a little page---"welcome to -----" when a member signs up, and his cc is approved.

still researching, but i believe they are accessing this url then "spoofing" the referreral URL to gain access.

still looking into the mechanics of it.

i believe the fix will involve ccbill. still working on this.

this issue is NOT the same as password hacking or brute force attack.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-26-2005, 02:31 PM   #14
nastyking
 
Join Date: Nov 2002
Posts: 2,174
if it's a CCBill vulnerability there is nothing you can do about it.

What is the URL of the webpage you mentioned in your first post?
__________________
nastyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.