|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
pornstarsxtra.com - came across this site mentioned on another board. It appears to be an old school paysite, but it also has pages that show a fake video player window (it's just an image, no attempt at embedding a video) with a link to an executable:
![]() Description of IE SecPlugin IE SecPlugin is an adware application that hijacks search page and monitors internet activities of the user. WHOIS shows the registrant as Netsaits BV with the admin contact Gerco Marsch. clickzs.com has the same details. clickzs.com lives at 64.237.39.70, pornstarsxtra.com lives at 64.237.39.66. 127 IPs from that block are allocated to Netsaits BV, which includes those two IPs. So we have these two domains sharing the same company name, same admin contact, same host, same IP block......... It's not the first time clickzs has been associated with shifty stuff, it wasn't so long ago that they were linking their buttons to Zango. So who links to clickzs? clickzs.com - Inlinks (166,840) www.clicksz.com - Inlinks (95,762) If they ever decided to be more blatant about their installs then there'd be a lot of shit going down. ![]() |
|
|
|
|
|
#2 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,481
|
a lot of people (big sites) use clickzs, this blows
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() My Cam Feeds Script |
|
|
|
|
|
#3 |
|
Make STACK$
Industry Role:
Join Date: Nov 2006
Location: sexy time
Posts: 14,474
|
good heaeds up
__________________
Compound interest. |
|
|
|
|
|
#4 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
I think very few people either understand or choose to understand just how far these codec and spyware installers have gone into the porn business.
I would place a guess today that 30% or more of the joins / money are going to these types of operations, either as direct sales or a traffic buys from PPC sites that use these tools to generate traffic. |
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Here is what just happened when browsing through freedailyporn.com(another site on 64.237.39.66 and same whois)
The following log shows clicking a link to a gallery and being redirected to trojans on the 85.255 ip range posing as spyware removers. The redirect happened instantly and all the other files you see loaded from the initial redirected page. 85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com Code:
GET http://www.freedailyporn.com/ 200 OK ***Click starts here*** GET http://vip.clickzs.com/tgp.php?fdp&thenudeteens.com/ebony/index.html 302 Found to http://85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com GET http://85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com 200 OK GET http://85.255.115.222/site.htm?lng=1&trg=cln&oip=0&trk=xicawxshtfnfffi 200 OK GET http://85.255.115.222/_cntr.htm?trk=xicawxshtfnfffi 200 OK GET http://free-spy-cam.net/index.htm?trk=xicawxshtfnfffi 200 OK GET http://85.255.115.222/cnte-eshdvvw.htm?trk=xicawxshtfnfffi 200 OK GET http://free-spy-cam.net/loading.htm 200 OK GET http://69.50.172.115/sp/fpa/index.html 200 OK GET http://85.255.115.222/cnte-ani_dthcbdg.htm?trk=xicawxshtfnfffi 200 OK GET http://85.255.115.222/cnte-dhncgts.jar?trk=xicawxshtfnfffi 200 OK GET http://85.255.115.222/back.htm 200 OK GET http://85.255.115.222/com/ms/security/SecurityClassLoader.class 404 Not Found GET http://85.255.115.222/riff_last.bin 200 OK |
|
|
|
|
|
#6 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
I believe that the server has been hacked with a modified version of apache... I've seen that before and that's what the host said. Not to me, but someone else.
|
|
|
|
|
|
#7 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
By the way 85.255.112.0 – 85.255.127.255 is INHOSTER and it looks like they're associated with Intercage and the codec installing "group".
|
|
|
|
|
|
#8 |
|
Registered User
Join Date: May 2007
Location: Australia
Posts: 35
|
damn this shit is huge isnt it
nice find rowan
__________________
Graphics Pimp |
|
|
|
|
|
#9 |
|
So Fucking Banned
Join Date: Jul 2006
Posts: 1,087
|
Clickzs
![]() |
|
|
|
|
|
#10 |
|
Back in Black
Industry Role:
Join Date: Mar 2002
Posts: 9,976
|
Using a remotely hosted traffic trading script service is just a flawed idea from the get go.
__________________
Search Engine Optimization Services for Adult Sites |
|
|
|
|
|
#11 |
|
Confirmed User
Join Date: May 2006
Posts: 2,640
|
those big site should be able to afford paid script
|
|
|
|
|
|
#12 |
|
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
Brutal. It's no wonder why I dont use any 3rd party software on my network, just can't trust anyone anymore.
|
|
|
|
|
|
#13 |
|
Registered User
Join Date: Aug 2002
Posts: 11
|
Hello,
it looks like our server has been hacked. We are working on the problem. Thanks Percy |
|
|
|
|
|
#14 |
|
Registered User
Join Date: Aug 2002
Posts: 11
|
This was not our doing, someone hacked our server and placed something on the server causing that fake video player window and it's executable to appear. We are working on the problem and will have it fixed asap.
Thanks again Percy Netsaits/ClickZs |
|
|
|
|
|
#15 | |
|
Too lazy to set a custom title
Industry Role:
Join Date: Jun 2005
Location: 127.0.0.1
Posts: 27,047
|
Quote:
better get this fixed soon....
__________________
Make Money
|
|
|
|
|
|
|
#16 |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
ah it was all an error peeps, nothing to see here.
same with that zango bs you guys pushed right? also a hack or error. seems that clicksz gets more and more shitty, and i for one hope every big site owner will drop this shit on the fly.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
|
|
|
|
#17 |
|
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
|
|
|
|
|
|
#18 |
|
Confirmed User
Industry Role:
Join Date: Apr 2004
Location: The Netherlands
Posts: 4,525
|
Yeah, good thing there are hackers, so we can all blame them LOL
__________________
Download the much improved Free Tube Script adult/mainstream tube solution for FREE! |
|
|
|
|
|
#19 | |
|
Confirmed User
Join Date: Aug 2004
Location: The Netherlands
Posts: 6,589
|
Quote:
![]() |
|
|
|
|
|
|
#20 |
|
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
|
|
|
|
|
|
#21 |
|
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
|
|
|
|
|
|
#22 |
|
Registered User
Join Date: Aug 2002
Posts: 11
|
The executable was placed on our domain pornstarsxtra.com by a hacker. We do not know how they did it but there are just a few sites linking to that content (according to our server logs) and those sites are not ours. Check mommysuncensored dot com (not ours), the top left thumbs are linking to the content on our server (will probably be changed now we have removed the content from our server)
Anyone know the owner of mommysuncensored dot com? Percy Netsaits/ClickZs |
|
|
|
|
|
#23 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
percy, I got news for you... what you found on the domain isn't 10% of the hack. Good luck, the entire box is likely rooted beyond understanding.
|
|
|
|
|
|
#24 |
|
Confirmed User
Join Date: Jul 2006
Location: Canada
Posts: 3,143
|
Not a good way to conduct business, thanks for the heads up !
|
|
|
|
|
|
#25 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
|
|
|
|
|
|
#26 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,481
|
use chkrootkit to find which files have been modified
|
|
|
|
|
|
#27 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Run it daily - because part of the trick is how they get access - the initial breakin occurs via FTP, usually obtained by a compromised webmaster PC. So the webmaster gets their server cleaned up, and the next day, they walk right back in (because even when you change the FTP or telnet passwords, they pick them right up again on your next access).
You need to check and clean not only the server, but any and all PCs that may have FTP or telnet access to the server, including all systems used by your hosting company that might have access. Good fucking luck. |
|
|
|
|
|
#28 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
fuck me....
|
|
|
|
|
|
#29 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
bump....
|
|
|
|
|
|
#30 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
One more bump
|
|
|
|
|
|
#31 | |
|
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Quote:
They took care of those videos right away, but the redirection to the trojans was never addressed. They have had plenty of time to clean up their server, so why is the redirect still happening? Lazy admin, bad host, maybe not a hack? The longer it takes to get fixed the less I believe it is a hack. |
|
|
|
|
|
|
#32 |
|
Blow Me U Geeks
Join Date: Aug 2001
Location: Maximum Security
Posts: 5,108
|
Bump.....
|
|
|
|
|
|
#33 |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
as per my topic, thnk god for hacker, else there wasnt an excuse for this type of bad behaviour.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
|
|
|
|
#34 |
|
Confirmed User
Industry Role:
Join Date: Apr 2004
Location: The Netherlands
Posts: 4,525
|
LOL thats what i said earlier..
__________________
Download the much improved Free Tube Script adult/mainstream tube solution for FREE! |
|
|
|
|
|
#36 |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
|
|
|
|
#37 |
|
Confirmed User
Industry Role:
Join Date: Apr 2004
Location: The Netherlands
Posts: 4,525
|
__________________
Download the much improved Free Tube Script adult/mainstream tube solution for FREE! |
|
|
|
|
|
#38 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
|
|
|
|
|
|
#39 |
|
Confirmed User
Join Date: Apr 2001
Location: Amsterdam
Posts: 724
|
not again, gerco ! wake up !!! jeeez
|
|
|
|
|
|
#40 |
|
So Fucking Banned
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
|
|
|
|
|
|
|
#41 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
Nice... another 100k users infected with the codec trojan, another drop in our sales...
Let me repeat myself.. : I'm pretty sure, from stuff I've seen, that these guys are in the top 3 of affiliates overall with all programs.. You have NO IDEA how much they're stealing |
|
|
|
|
|
#42 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
The amount they are stealing is pretty stunning - and most programs know it and smile and take their traffic anyway.
|
|
|
|
|
|
#43 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
|
|
|
|
|
|
#44 |
|
So Fucking Banned
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
|
|
|
|
|
|
|
#45 |
|
Confirmed User
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
|
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho | |
|
|
|
|
|
#46 |
|
♦ Web Developer ♦
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,472
|
Happy I dont use that ;)
|
|
|
|
|
|
#47 |
|
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Still hacked? This redirect happened today.
htxp://cz8.clickzs.com/tgp.php?bbgx&60&CJ1&hxtp://galleries.babes.tv/mg/08/?nats=MTAwMDQ5OjM6Ng,0,0,0,1107875810&content=suzi ecarina2b htxp://85.255.115.222/ind.htm?e404=1&src=130&surl=cz8.clickzs.com |
|
|
|