|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
yep comus is handing out too much informationincluding IP's
been pokin around in comus thumbs and found that on a default install the following is world viewable
http://some tgp.com/ct/dat/raws /ct/dat/alog /ct/dat/cstats.dat /ct/dat/dailytotals /ct/dat/history /ct/dat/ip/log /ct/dat/raws /ct/dat/uniques it even gives out the administrators IP to fix ssh into your host drill down to ct folder chmod 622 dat |
|
|
|
|
|
#2 |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
bump for day crew
|
|
|
|
|
|
#3 |
|
...
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
|
oh shit......
__________________
... |
|
|
|
|
|
#4 |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
yep I cant believe this thread went un noticed
wayyyy to much info I just did a test hack and with the information provided above it is possible to take ove the comus site using nothing but the information in /ct/dat/alog which includes the authorized IP as well as the user name and other info |
|
|
|
|
|
#5 | |
|
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
Quote:
|
|
|
|
|
|
|
#6 |
|
www.creationcrew.com
Industry Role:
Join Date: Feb 2005
Location: CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM
Posts: 12,111
|
part of the program.. maybe had significant on it
__________________
![]() ++ Adult and Mainstream Websites Designs | 10 banners for only $50 | html5 Banners ++ email : [email protected] Telegram : https://t.me/creationcrew | HTML5/Responsive Site - Div/CSS - ElevatedX - NATs - Wordpress |
|
|
|
|
|
#8 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2003
Location: icq: 71462500 Skype: Jupzchris
Posts: 27,880
|
hmmmm
sure is kinda strange but only info i could find was the ip addys no login user names? tested it on my comus site
__________________
[email protected] |
|
|
|
|
|
#9 | |
|
Confirmed User
Join Date: May 2001
Posts: 2,944
|
Quote:
Me either. Different setups or is that the smell of BS? |
|
|
|
|
|
|
#10 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,372
|
why is showing the ip address for the domain that important. just nslookup the domain and you will get the ip, nothing special there
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
|
|
|
|
|
#11 |
|
Confirmed User
Join Date: Feb 2005
Location: Haarlem and Amsterdam, capital of the porn world ;-)
Posts: 6,496
|
i have the same shit
but then again.. i only run it on one site atm.. and that one i hardly use
__________________
Need adult hosting? Contact us! WARM Hosting Need an IT solution? or someone to check your site and security? Nossie - IT Professional |
|
|
|
|
|
#12 | |
|
Confirmed User
Join Date: Feb 2005
Location: Haarlem and Amsterdam, capital of the porn world ;-)
Posts: 6,496
|
Quote:
it also shows what you DONT want ppl to know ct/dat/alog shows IP addy of the admin you can then easy try to sniff or hack that box if you suckseed :P then you can sniff the passwords or steal info from him/her/them for epassporte/programs/sponsors/sites you name it
__________________
Need adult hosting? Contact us! WARM Hosting Need an IT solution? or someone to check your site and security? Nossie - IT Professional |
|
|
|
|
|
|
#13 | |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
Quote:
if you used comus you would know that the username is built in ( it dosent ask for one) it authenticates against the IP there is other information there but im not going to tell you how to read the data ( i make script kiddies look stuff up) |
|
|
|
|
|
|
#15 | |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
Quote:
plus more whats funny is why is the folder hidden if viewing the site via FTP?? was this on purpose?? |
|
|
|
|
|
|
#16 | |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
Quote:
http://www.thumbangels.com/ct/dat/alog |
|
|
|
|
|
|
#17 | |
|
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
Quote:
It's a good thing people keep finding flaws but describing and giving clues how the flaw can be detrimental to the server and site owner, on a board where loads of people with time, know-how and desire to screw over their mother, isn't a good thing to do. *Hey, but that's just me* If you've already attempted to advise Comus about it a few times and nothing was done, then I understand why you're putting it out there and making the users aware of how the rest of their stuff can be compromised. |
|
|
|
|
|
|
#18 | |
|
Confirmed User
Join Date: Jul 2002
Location: Montreal
Posts: 833
|
Quote:
__________________
174-38-56
|
|
|
|
|
|
|
#19 | |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
Quote:
just pisses me off when the first thing a person says is oh its BS etc etc I didnt give away anything as far as how to exploit the information and the majority of the people on GFY do not have the know how I doubt half know HTML or PHP or any other web launguage just my ok back to work if someone has contact info for the script writer please contact him/her |
|
|
|
|
|
|
#20 | |
|
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
Quote:
|
|
|
|
|
|
|
#21 |
|
want to get in shape
Join Date: Jan 2003
Location: on the lake
Posts: 12,329
|
I am sure tony will look into this he is a sharp fella and a good businessman.
|
|
|
|
|
|
#22 |
|
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
disclosure bump
__________________
hatisblack at yahoo.com |
|
|
|
|
|
#23 |
|
Registered User
Join Date: Aug 2002
Location: Las Vegas
Posts: 53
|
This post is bullshit.
If you have a problem with Comus.. use our forums or if you have an emergency contact me personally. My phone number is on the front of my website and my forum has personal messaging, my support email is checked every few hours... If you think you can do anything with this information.. OTHER than actually trace a REAL hacker who is trying to get access to your system, then go for it, but expect to be busted. Yes this information is very handy when you need to catch someone. Comus makes extraordinary efforts to stop, trace and track hackers, yes everything is recorded, if you think you can hack Comus and we wont find you then you're an idiot. Just ask some of the guys out there that we've helped to protect. Special thanks to all my friends in Russia, China, Australia, New Zealand, Italy, USA, Germany, Amsterdam, Turkey, Korea, Europe, Asia, North America, South America, the Pacific and Africa for watching our backs. And special thanks to Joe for contacting me personally about this.
__________________
http://comusthumbs - TGP Thumbnailer - The Power and Support you need to grow your TGP site. |
|
|
|
|
|
#24 | |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
Quote:
|
|
|
|
|
|
|
#25 | |
|
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
Quote:
PussyNegro just got owned. Thanks for that SixZeros. Great script too. |
|
|
|
|
|
|
#26 |
|
So Fucking Banned
Join Date: Oct 2005
Location: I convert perverts like catholic church!
Posts: 5,133
|
and for the record I love Comus Thumbs
Jimi eat shit swamp rat |
|
|
|
|
|
#27 | |
|
So Fucking Banned
Join Date: Oct 2003
Location: icq: 121189
Posts: 18,889
|
Quote:
You first, silverback. |
|
|
|
|
|
|
#28 |
|
Biker Gnome
Industry Role:
Join Date: Mar 2004
Location: cell#324
Posts: 23,200
|
I just found this thread, I was offline for the weekend, My role with Comusthumbs hasn't changed, I just need a weekend off every once in a while!
__________________
Carbon is not the problem, it makes up 0.041% of our atmosphere , 95% of that is from Volcanos and decomposing plants and stuff. So people in the US are responsible for 13% of the carbon in the atmosphere which 95% is not from Humans, like cars and trucks and stuff and they want to spend trillions to fix it while Solar Panel plants are powered by coal plants think about that |
|
|
|
|
|
#29 | |
|
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() I dont think the lad meant any harm. I don't agree that allowing this directory to be publicly accessible is better for customers than having it private, might as well hide that directory unless theres some burning need for it to be open right.. regardless of the small chance it would help a hacker gain access to your site or you , no chance is better than a slim chance in my books..
__________________
hatisblack at yahoo.com |
|
|
|
|
|
|
#30 | |
|
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
Quote:
|
|
|
|
|
|
|
#31 | ||
|
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Quote:
Quote:
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
||
|
|
|