|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Nov 2002
Location: SoCal
Posts: 3,241
|
Anyone who uses pennywize...
have you noticed anything odd over the last week? I'm getting tons of un/pw combos disabled, including ones that belong to friends who I *know* haven't been trading...and can't see anything unusual on the servers as far as traffic or referrers are concerned...
|
|
|
|
|
|
#2 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
That is because PW traders know EXACTLY how to beat pennywize. It DOES NOT protect your members area.
__________________
It's all disambiguation ![]() |
|
|
|
|
|
#3 |
|
Confirmed User
Join Date: Jul 2002
Posts: 1,510
|
proxypass is the way to go.. works like a charme and has safed us sooo much bw
|
|
|
|
|
|
#4 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
proxypass is much better than pennywize, strongbox owns them both..
Even PP won't stop pw traders, anything under your set limit will get in, they rotate pw's to stay under those limits and they can still hammer brute force attack.
__________________
It's all disambiguation ![]() |
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Jul 2002
Posts: 1,510
|
u can set the limit in PP to what ever u feel comfrotable with.
|
|
|
|
|
|
#6 | |
|
So Fucking Banned
Industry Role:
Join Date: Jan 2004
Location: Las Vegas
Posts: 6,268
|
Quote:
|
|
|
|
|
|
|
#7 |
|
Confirmed User
Join Date: Aug 2004
Posts: 1,017
|
Yes having the same issue, but we have other custom securities in place.
__________________
Do not use Jay AKA Bannerdept.com Click HERE for reasons why! |
|
|
|
|
|
#8 | |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
|
Quote:
__________________
See sig... |
|
|
|
|
|
|
#9 | |
|
Confirmed User
Join Date: Nov 2002
Location: SoCal
Posts: 3,241
|
Quote:
(and thanks for the other posts, but i know the various pros and cons of the different systems - my sites are not the usual ones that have "professional" hackers, i only have to worry about amateurs who trade passwords among themselves.) |
|
|
|
|
|
|
#10 |
|
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Phoenix, Az
Posts: 3,112
|
I have been using password sentry for several years, no problems with it.
|
|
|
|
|
|
#11 |
|
Confirmed User
Join Date: Jul 2002
Posts: 1,510
|
dont get me started on password sentry. that thing never worked well for any of our sites.. u should really switch to proxy or strong u will prob see a huge drop in bw usages,
|
|
|
|
|
|
#12 | |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
|
Quote:
__________________
See sig... |
|
|
|
|
|
|
#13 |
|
Confirmed User
Join Date: Feb 2003
Location: Getting messy...
Posts: 763
|
I love how one person says they've been using "X" forever, and then another person says "x" sucks, you should use "Y".
You'd think there would be some kind of agreement on the best password protection? Anyone else have any real-world experience with a pw protection system that works?
__________________
![]() Splosh Cash Wet and Messy Fetish Program I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me. |
|
|
|
|
|
#14 | |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
|
Quote:
__________________
See sig... |
|
|
|
|
|
|
#15 | |
|
Confirmed User
Join Date: Apr 2002
Location: LaLa Land
Posts: 2,697
|
Quote:
|
|
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Mar 2003
Location: Oh Canada!
Posts: 3,662
|
Mike hit me up on icq (64614011) I might be able to help you ;-)
|
|
|
|
|
|
#17 | |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
|
Quote:
__________________
See sig... |
|
|
|
|
|
|
#18 | |
|
Confirmed User
Join Date: Oct 2003
Posts: 3,191
|
Quote:
last couple years on proxypass, no probs. and antihotlinking.com for movie protection. |
|
|
|
|
|
|
#19 |
|
Confirmed User
Join Date: Oct 2003
Posts: 3,191
|
and i will say this also.
if you are on ccbill upgrade to their new security. tedious to do, but bulletproof so far. |
|
|
|
|
|
#20 | |
|
Confirmed User
Join Date: May 2003
Posts: 1,025
|
I often wondered about this ... never been able to get this info from Ray. The only customer we have using it does'nt do enough traffic to hit our radar.
Quote:
|
|
|
|
|
|
|
#21 |
|
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
|
Pennywize is not your problem. If your friends passwords are getting used then this has nothing to do with password protection scripts at all. This has to do with someone obtaining either your password file or database info where user and password are stored. To say it plainly, you've been hacked and now they have all of your passwords.
|
|
|
|
|
|
#22 |
|
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
i have been using iprotect for years now with not one bit of trouble ever
|
|
|
|
|
|
#23 | |
|
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
BTW.. Proxypass offers form protection now from what I understand, or secret word protection, something like that. That would make it as strong as strongbox.. The strongest solution right now is strongbox, hands down. From what I understand someone has strongbox running on a load balancer.
__________________
It's all disambiguation ![]() |
|
|
|
|
|
|
#24 | |
|
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
|
Quote:
He stated that his friends own personal accounts were hacked. That means this isn't a cracker bruteforcing, it is a hacker who stole the password file. |
|
|
|
|
|
|
#25 | |
|
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
Hehe, yeah, personal accounts can be brute force attacked, without much of problem.. Even more so when you guess a username on pennywize, and it tells you if it's active or not even if the pw is wrong. So then they just need to hammer the username for the pw combo.. Not hard when they have a million word dictionary files.
__________________
It's all disambiguation ![]() |
|
|
|
|
|
|
#26 | |
|
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,428
|
Quote:
#1 If the word isn't in the dictionary it can't be bruteforced since it isn't ever tried (it is not in the list). #2 With a 3mb connection the best you will be able to do is about 80,000 an hour. If you DID try it that many times an hour, your list of 2000 proxies would begin to be blocked in about 20 minutes or so. At this speed it would take 12.5 hours to try 1,000,000 passwords... and that is per user... Cracking websites is like stealing cars. If you can spend another 10 minutes to find one without a tracking system, steering wheel locking system or alarm, it is worth it to avoid 4 years in prison. If you can find a website that uses basic authentication and has a large pool of users it is better than a form based login to a site with 200. But if you know how to disable alarms and tracking systems it is like being able to just steal the password file. It is easier than spending 12.5 hours PER USERNAME.... If he had MULTIPLE users with VIP passes, then he was hacked. |
|
|
|
|