Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-05-2005, 08:22 PM   #1
MikeSmoke
Confirmed User
 
Join Date: Nov 2002
Location: SoCal
Posts: 3,241
Anyone who uses pennywize...

have you noticed anything odd over the last week? I'm getting tons of un/pw combos disabled, including ones that belong to friends who I *know* haven't been trading...and can't see anything unusual on the servers as far as traffic or referrers are concerned...
__________________

icq: 541-739-92
MikeSmoke is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2005, 08:24 PM   #2
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
That is because PW traders know EXACTLY how to beat pennywize. It DOES NOT protect your members area.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2005, 09:27 PM   #3
Gateway69
Confirmed User
 
Gateway69's Avatar
 
Join Date: Jul 2002
Posts: 1,510
proxypass is the way to go.. works like a charme and has safed us sooo much bw
__________________
Gateway - Tech Guru
Dreaming Computers IG
Gateway69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2005, 09:29 PM   #4
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
proxypass is much better than pennywize, strongbox owns them both..

Even PP won't stop pw traders, anything under your set limit will get in, they rotate pw's to stay under those limits and they can still hammer brute force attack.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-05-2005, 10:29 PM   #5
Gateway69
Confirmed User
 
Gateway69's Avatar
 
Join Date: Jul 2002
Posts: 1,510
u can set the limit in PP to what ever u feel comfrotable with.
__________________
Gateway - Tech Guru
Dreaming Computers IG
Gateway69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:13 AM   #6
ninavain
So Fucking Banned
 
Industry Role:
Join Date: Jan 2004
Location: Las Vegas
Posts: 6,268
Quote:
Originally Posted by TheDoc
That is because PW traders know EXACTLY how to beat pennywize. It DOES NOT protect your members area.
pennywize is a joke..dropped them for strongbox..but they have issues too
ninavain is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:19 AM   #7
AdultMegaCash
Confirmed User
 
Join Date: Aug 2004
Posts: 1,017
Yes having the same issue, but we have other custom securities in place.
AdultMegaCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:32 AM   #8
SGS
Confirmed User
 
SGS's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
Quote:
Originally Posted by ninavain
pennywize is a joke..dropped them for strongbox..but they have issues too
What issues does Strongbox have?
__________________
See sig...
SGS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:51 AM   #9
MikeSmoke
Confirmed User
 
Join Date: Nov 2002
Location: SoCal
Posts: 3,241
Quote:
Originally Posted by AdultMegaCash
Yes having the same issue, but we have other custom securities in place.
thanks, glad to hear it's not just me.

(and thanks for the other posts, but i know the various pros and cons of the different systems - my sites are not the usual ones that have "professional" hackers, i only have to worry about amateurs who trade passwords among themselves.)
__________________

icq: 541-739-92
MikeSmoke is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 03:24 AM   #10
venus
Confirmed User
 
venus's Avatar
 
Industry Role:
Join Date: Jan 2003
Location: Phoenix, Az
Posts: 3,112
I have been using password sentry for several years, no problems with it.
__________________
Muscle/Fitness Adult Affiliate Program
Since 1997 www.venuscash.com
venus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 10:30 AM   #11
Gateway69
Confirmed User
 
Gateway69's Avatar
 
Join Date: Jul 2002
Posts: 1,510
dont get me started on password sentry. that thing never worked well for any of our sites.. u should really switch to proxy or strong u will prob see a huge drop in bw usages,
__________________
Gateway - Tech Guru
Dreaming Computers IG
Gateway69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:29 PM   #12
SGS
Confirmed User
 
SGS's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
Quote:
Originally Posted by Gateway69
dont get me started on password sentry. that thing never worked well for any of our sites.. u should really switch to proxy or strong u will prob see a huge drop in bw usages,
The only problem with Strongbox is running it on large load balanced server setups.
__________________
See sig...
SGS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:47 PM   #13
Hunter_ST
Confirmed User
 
Hunter_ST's Avatar
 
Join Date: Feb 2003
Location: Getting messy...
Posts: 763
I love how one person says they've been using "X" forever, and then another person says "x" sucks, you should use "Y".

You'd think there would be some kind of agreement on the best password protection?

Anyone else have any real-world experience with a pw protection system that works?
__________________

Splosh Cash Wet and Messy Fetish Program
I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me.
Hunter_ST is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:53 PM   #14
SGS
Confirmed User
 
SGS's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
Quote:
Originally Posted by Hunter_ST
I love how one person says they've been using "X" forever, and then another person says "x" sucks, you should use "Y".

You'd think there would be some kind of agreement on the best password protection?

Anyone else have any real-world experience with a pw protection system that works?
We have run most of them and are still running several different systems still now for various reasons on different sites but Strongbox is the best available at the moment by miles.
__________________
See sig...
SGS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 12:56 PM   #15
seven
Confirmed User
 
Join Date: Apr 2002
Location: LaLa Land
Posts: 2,697
Quote:
Originally Posted by SGS
What issues does Strongbox have?
same q for you here.. would like to know about the issues you got
__________________
Toy Rev
Rouge Web Design
seven is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 01:11 PM   #16
emmanuelle
Confirmed User
 
emmanuelle's Avatar
 
Join Date: Mar 2003
Location: Oh Canada!
Posts: 3,662
Mike hit me up on icq (64614011) I might be able to help you ;-)
emmanuelle is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 01:32 PM   #17
SGS
Confirmed User
 
SGS's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
Quote:
Originally Posted by seven
same q for you here.. would like to know about the issues you got
Apart from issues with load balanced servers I am not aware of any problems at all.
__________________
See sig...
SGS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 01:56 PM   #18
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
Quote:
Originally Posted by Gateway69
proxypass is the way to go.. works like a charme and has safed us sooo much bw
yes, years ago used pennywize. always had probs.

last couple years on proxypass, no probs.

and antihotlinking.com for movie protection.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-06-2005, 01:57 PM   #19
latinasojourn
Confirmed User
 
Join Date: Oct 2003
Posts: 3,191
and i will say this also.

if you are on ccbill upgrade to their new security.

tedious to do, but bulletproof so far.
latinasojourn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 10:43 PM   #20
PbG
Confirmed User
 
Join Date: May 2003
Posts: 1,025
I often wondered about this ... never been able to get this info from Ray. The only customer we have using it does'nt do enough traffic to hit our radar.

Quote:
Originally Posted by SGS
The only problem with Strongbox is running it on large load balanced server setups.
PbG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 10:51 PM   #21
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
Pennywize is not your problem. If your friends passwords are getting used then this has nothing to do with password protection scripts at all. This has to do with someone obtaining either your password file or database info where user and password are stored. To say it plainly, you've been hacked and now they have all of your passwords.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 10:55 PM   #22
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
i have been using iprotect for years now with not one bit of trouble ever
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 11:05 PM   #23
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally Posted by V_RocKs
Pennywize is not your problem. If your friends passwords are getting used then this has nothing to do with password protection scripts at all. This has to do with someone obtaining either your password file or database info where user and password are stored. To say it plainly, you've been hacked and now they have all of your passwords.
Pennywize doesn't not stop brute force attacks, it doesn't even slow them down. Proxypass is better but it still won't stop attacks. Even strongbox has minor issues with attacks.. If you use htauth, you will get leaks, period, it has NOTHING to do with being hacked or someone getting your pw file, it has EVERYTHING to do with brute force attacks.

BTW.. Proxypass offers form protection now from what I understand, or secret word protection, something like that. That would make it as strong as strongbox..

The strongest solution right now is strongbox, hands down. From what I understand someone has strongbox running on a load balancer.
__________________
~TheDoc - ICQ7765825
It's all disambiguation

Last edited by TheDoc; 08-09-2005 at 11:08 PM..
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 11:15 PM   #24
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
Quote:
Originally Posted by TheDoc
Pennywize doesn't not stop brute force attacks, it doesn't even slow them down. Proxypass is better but it still won't stop attacks. Even strongbox has minor issues with attacks.. If you use htauth, you will get leaks, period, it has NOTHING to do with being hacked or someone getting your pw file, it has EVERYTHING to do with brute force attacks.

BTW.. Proxypass offers form protection now from what I understand, or secret word protection, something like that. That would make it as strong as strongbox..

The strongest solution right now is strongbox, hands down. From what I understand someone has strongbox running on a load balancer.

He stated that his friends own personal accounts were hacked. That means this isn't a cracker bruteforcing, it is a hacker who stole the password file.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2005, 11:25 PM   #25
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally Posted by V_RocKs
He stated that his friends own personal accounts were hacked. That means this isn't a cracker bruteforcing, it is a hacker who stole the password file.

Hehe, yeah, personal accounts can be brute force attacked, without much of problem.. Even more so when you guess a username on pennywize, and it tells you if it's active or not even if the pw is wrong. So then they just need to hammer the username for the pw combo..

Not hard when they have a million word dictionary files.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2005, 02:42 AM   #26
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
Quote:
Originally Posted by TheDoc
Hehe, yeah, personal accounts can be brute force attacked, without much of problem.. Even more so when you guess a username on pennywize, and it tells you if it's active or not even if the pw is wrong. So then they just need to hammer the username for the pw combo..

Not hard when they have a million word dictionary files.
Actually it is very hard and you possibly have never tried it.

#1 If the word isn't in the dictionary it can't be bruteforced since it isn't ever tried (it is not in the list).
#2 With a 3mb connection the best you will be able to do is about 80,000 an hour. If you DID try it that many times an hour, your list of 2000 proxies would begin to be blocked in about 20 minutes or so. At this speed it would take 12.5 hours to try 1,000,000 passwords... and that is per user...

Cracking websites is like stealing cars. If you can spend another 10 minutes to find one without a tracking system, steering wheel locking system or alarm, it is worth it to avoid 4 years in prison. If you can find a website that uses basic authentication and has a large pool of users it is better than a form based login to a site with 200. But if you know how to disable alarms and tracking systems it is like being able to just steal the password file. It is easier than spending 12.5 hours PER USERNAME....

If he had MULTIPLE users with VIP passes, then he was hacked.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.