GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Is your NATS hacked ? (https://gfy.com/showthread.php?t=794078)

Jet - BANNED FOR LIFE 12-22-2007 04:50 AM

Quote:

Originally Posted by jscott (Post 13550178)
Any input from NATS on this matter? I find this very disturbing, need a little reassurance please John

why do you care, you don't even have an affiliate program

mattyboy 12-22-2007 05:02 AM

Quote:

Originally Posted by Jet (Post 13550243)
why do you care, you don't even have an affiliate program

Perhaps his details have got into the wrong hands if hes joined nats programs :2 cents:

borked 12-22-2007 07:27 AM

Quote:

Originally Posted by SmokeyTheBear (Post 13549328)
i find it odd they would allow an employee one user/pass to get into every nats sponsor.

i find it doubly odd that nobody from nats noticed this account had been compromised before it was posted on gfy.

The TMM login name seems pretty generic and long. AFAIK, there isn't one master access user/pass that accesses all installs.

John said in another thread that it "fully appears to be a compromised password list", so I guess the TMM passwords all got out somehow.

Looks like that's all closed now as he also stated "We have changed our policy so that we no longer maintain ANY passwords to ensure this does not happen via us ever in the future"

borked 12-22-2007 07:40 AM

So, to summarise, since John's last post has gotten buried in a lot of FUD

It looks like a password list has gotten out so NATS owners should contact TMM to see if their customer data has been compromised. OC3 ([email protected]) have also said they can help people with this.

TMM have or are in the process of changing all TMM passwords throughout their client base.

TMM have now taken additional security measures by not storing all passes on their end to prevent this happening again.

TMM are adding additional security measures (1-way encrypted passes) in future NATS releases.

So, if I'm not mistaken, any current NATS owners should now be secured (or over the next day or two) from further compromise via this route.

But, in all, everyone, nomatter what software you use, should take database security very seriously and daily audit any accounts (ssh/mysql/web-based) that have privilege access.

Looks like this issue has come to resolution, so I'm off to enjoy my holidays :thumbsup

s9ann0 12-22-2007 07:42 AM

It wouldn't be the first time it had happenned and it wouldn't be the first time someone got an admin's password and used it on other machines either.

I thought NATS were more security conscious than most though

Paul Markham 12-22-2007 09:11 AM

Quote:

Originally Posted by iMind (Post 13549292)
threats of lawsuit in 10, 9 , 8 , 7 ...

The lawsuit might be coming, but in a different direction.

notoldschool 12-22-2007 09:21 AM

NATS haters unite..lol. TMM is awesome and unliKe most other companies in the industry are on the problems before or as they happen. Its funny you see the shady programs come in here to bash nats when they are the most suspect. Your stats scare the shit out of me....0/10ooo+.

DO NOT TRUST PROGRAMS THAT HAVE CUSTOM BACKENDS. THEY ARE THE ONES TO WATCH FOR.

SmokeyTheBear 12-22-2007 09:27 AM

Quote:

Originally Posted by notoldschool (Post 13550899)
NATS haters unite..lol. TMM is awesome and unliKe most other companies in the industry are on the problems before or as they happen.

thats funny because they were aware of this problem many moons ago and yet instead of fixing the problem they put the blame on their customers. meanwhile MY personal information was stolen.. that doesnt sound like being "on the problem" this issue has been going on for MONTHS.



Quote:

Originally Posted by notoldschool (Post 13550899)
Its funny you see the shady programs come in here to bash nats when they are the most suspect. Your stats scare the shit out of me....0/10ooo+.

you must be the "exception" to the rule , i have never seen any sponsors "bashing" nats , and i think any long term webmaster has noticed non-nats sponsors perform better as a whole.

Quote:

Originally Posted by notoldschool (Post 13550899)


DO NOT TRUST PROGRAMS THAT HAVE CUSTOM BACKENDS. THEY ARE THE ONES TO WATCH FOR.

like nastydollars and bangbros , industry leaders ?

SmokeyTheBear 12-22-2007 09:32 AM

p.s. i should also mention at this point that one of the only sponsors i have heard from that WASN'T hacked was mayors money, and this is because THEY went thru extra security measures above and beyond.

big props to mayors money, your info is secure

SmokeyTheBear 12-22-2007 09:34 AM

Quote:

Originally Posted by borked (Post 13550531)
TMM have now taken additional security measures by not storing all passes on their end to prevent this happening again.

i wonder if one of their security measures will be to listen to their clients and stop blaming their customers for their own security problems.

TheDoc 12-22-2007 09:45 AM

Quote:

Originally Posted by SmokeyTheBear (Post 13550952)
p.s. i should also mention at this point that one of the only sponsors i have heard from that WASN'T hacked was mayors money, and this is because THEY went thru extra security measures above and beyond.

big props to mayors money, your info is secure

http://www.mayorsmoney.com/
http://www.score-group.com/
http://www.evilgneiuscash.com/
http://www.dukedollars.com/

I haven't checked everyone and as I do have updated - corrected them. Thus far, these 4 programs do not have any logins from that IP.

This is a short list of the SEVERAL that use the NATS built in security features that protect your members, webmasters, and admin data.

NATS has the security features already - question is which sponsors are using them?

spacedog 12-22-2007 09:47 AM

Quote:

Originally Posted by mattyboy (Post 13550265)
Perhaps his details have got into the wrong hands if hes joined nats programs :2 cents:

While that certainly is a possibility, there's no indication that this has occured.
It so far just appears to be a harvest of emails

borked 12-22-2007 09:48 AM

Quote:

Originally Posted by TheDoc (Post 13551012)
I haven't checked everyone and as I do have updated - corrected them. Thus far, these 4 programs do not have any logins from that IP.

You need to be checking not for just that IP, but *any* IP on the TMM account that isn't TMM's (67.84.12.95)

TheDoc 12-22-2007 09:50 AM

Mod to above post, wrong URL for score, duh..

http://www.score-cash.com/ (clean program)

TheDoc 12-22-2007 09:51 AM

Quote:

Originally Posted by borked (Post 13551034)
You need to be checking not for just that IP, but *any* IP on the TMM account that isn't TMM's (67.84.12.95)

Aye, I know this.. When the NATS systems are IP locked, nobody but the allowed IP's can access the backend.

SmokeyTheBear 12-22-2007 09:57 AM

Quote:

Originally Posted by spacedog (Post 13551024)
While that certainly is a possibility, there's no indication that this has occured.
It so far just appears to be a harvest of emails

i would find it very unlikely they "only" grabbing emails of members.

the bot is likely used to maintain the list thats why it accesses so often but the affiliate info would likely only be grabbed once making it alot harder to spot amongst the hundreds of email grabs :2 cents:

Gordon G 12-22-2007 10:00 AM

Quote:

Originally Posted by Jet (Post 13550243)
why do you care, you don't even have an affiliate program

Why do you care, you are just a contest whore, amazing you are actually posting in a thread that is not a contest, you silly fuck.

milan 12-22-2007 10:18 AM

Quote:

Originally Posted by SmokeyTheBear (Post 13551080)
i would find it very unlikely they "only" grabbing emails of members.

the bot is likely used to maintain the list thats why it accesses so often but the affiliate info would likely only be grabbed once making it alot harder to spot amongst the hundreds of email grabs :2 cents:


True since they full access they probably collected much more... I just posted what we discovered back in October 2007

https://gfy.com/fucking-around-and-business-discussion/794159-nats-issue.html

D 12-22-2007 10:27 AM

Quote:

Originally Posted by borked (Post 13550081)
No, members passes are cleartext by default. Affiliate passwords are two-way encrypted. What I don't understand is why the need for two-way encryption? To reset an affiliates pass if they forgot it in the backend is nothing, so 1-way encryption would have been far better. John posted in another thread that this is to be included in NATS4. Shame it wasn't sooner IMPO.

Perhaps I'm misremembering, but I coulda sworn that affiliate passwords were displayed... is the encryption something that's changed in the last eighteen months?

And even if passwords are not available, I do, certainly, remember the 'become reseller' option... can affiliates examine their own password via their account's interface, or no? If "no," maybe the case is that I've misremembered, and would appreciate confirmation on that.

Been awhile, and I don't have an updated version of NATs in front of me to play around with.

Ray@TastyDollars 12-22-2007 10:39 AM

Quote:

Originally Posted by TheDoc (Post 13551012)
http://www.mayorsmoney.com/
http://www.score-group.com/
http://www.evilgneiuscash.com/
http://www.dukedollars.com/

I haven't checked everyone and as I do have updated - corrected them. Thus far, these 4 programs do not have any logins from that IP.

This is a short list of the SEVERAL that use the NATS built in security features that protect your members, webmasters, and admin data.

NATS has the security features already - question is which sponsors are using them?

Add TastyDollars to that list.

We had 1 login from that NATS admin account and the date matched on the day they were doing some work for us.

We have also deleted that account just to extra carefull.

Ray

Karupted Charles 12-22-2007 10:42 AM

I wonder if anyone tried to warn people a long time ago that they had serious security issues but was bashed by all the guys John bought drinks for.

fuzebox 12-22-2007 11:08 AM

Quote:

Originally Posted by Brad Mitchell (Post 13549820)
oh jesus christ does NATS really store the affiliate passwords in plain text for an admin access user to view? Tell me that's not true. Please, really. Can anyone confirm?

Brad

Yes, this is true. Both affiliate (including admin users who are stored as affiliates) and members (surfer joins) are stored in plaintext.

borked 12-22-2007 11:13 AM

Quote:

Originally Posted by fuzebox (Post 13551293)
Yes, this is true. Both affiliate (including admin users who are stored as affiliates) and members (surfer joins) are stored in plaintext.

PURE FUD.

Thomas N 12-22-2007 11:33 AM

QuickBuck has not been compromised in any way.

ARS Bryan 12-22-2007 11:35 AM

Quote:

Originally Posted by notoldschool (Post 13550899)
NATS haters unite..lol. TMM is awesome and unliKe most other companies in the industry are on the problems before or as they happen. Its funny you see the shady programs come in here to bash nats when they are the most suspect. Your stats scare the shit out of me....0/10ooo+.

DO NOT TRUST PROGRAMS THAT HAVE CUSTOM BACKENDS. THEY ARE THE ONES TO WATCH FOR.

You're a fucking moron :thumbsup

SmokeyTheBear 12-22-2007 12:22 PM

Quote:

Originally Posted by Ray@TastyDollars (Post 13551213)
Add TastyDollars to that list.

We had 1 login from that NATS admin account and the date matched on the day they were doing some work for us.

We have also deleted that account just to extra carefull.

Ray

:thumbsup:thumbsup

SmokeyTheBear 12-22-2007 12:26 PM

Quote:

Originally Posted by TheDoc (Post 13551053)
Aye, I know this.. When the NATS systems are IP locked, nobody but the allowed IP's can access the backend.

then again , if the head programmer at nats has his password compromised its likely they "could" use nats ip to connect and get the info the same way.

AlienQ - BANNED FOR LIFE 12-22-2007 12:50 PM

Quote:

Originally Posted by Karupted Charles (Post 13551222)
I wonder if anyone tried to warn people a long time ago that they had serious security issues but was bashed by all the guys John bought drinks for.


Raises hand.

WarChild 12-22-2007 12:52 PM

Quote:

Originally Posted by AlienQ (Post 13551639)
Raises hand.

You're just an idiot that nobody takes serious. You didn't warn anybody of anything. You don't have nor have you ever had any insider information about nats or anything else. Again, you're just a broke tool.

notoldschool 12-22-2007 12:55 PM

Quote:

Originally Posted by ARS Bryan (Post 13551364)
You're a fucking moron :thumbsup

You're a fucking dick. Thanks for the compliment.

Rico 12-22-2007 01:38 PM

As mentioned in this thread previously by Uno, our 'version' of nats, has been 'customized' to such extent, we no longer recieve updates from NATS(TMM). This also means we have been taking measures to prevent issues such as this one, via additional security measures that were taken almost 2 years ago.

In a nutshell: Our information is safe.

This is a constant struggle for all of us and we're doing our best to make sure our systems and sites are as safe as they can be, on a continuous basis.

I am sorry to see others have problems, but it is definately not the case for us.

AlienQ - BANNED FOR LIFE 12-22-2007 01:41 PM

Quote:

Originally Posted by WarChild (Post 13551646)
You're just an idiot that nobody takes serious. You didn't warn anybody of anything. You don't have nor have you ever had any insider information about nats or anything else. Again, you're just a broke tool.

Search in the history dumb bitch.
I have long stood against NATS/Porngraph for quite some time.

Nysus 12-22-2007 01:51 PM

Quote:

Originally Posted by rico-panchodog (Post 13551739)
As mentioned in this thread previously by Uno, our 'version' of nats, has been 'customized' to such extent, we no longer recieve updates from NATS(TMM). This also means we have been taking measures to prevent issues such as this one, via additional security measures that were taken almost 2 years ago.

In a nutshell: Our information is safe.

This is a constant struggle for all of us and we're doing our best to make sure our systems and sites are as safe as they can be, on a continuous basis.

I am sorry to see others have problems, but it is definately not the case for us.

So technically you're not really "with NATS" then ...

Quickdraw 12-22-2007 01:52 PM

Quote:

Originally Posted by SwordFish (Post 13551355)
QuickBuck has not been compromised in any way.

maybe so, but they certainly don't fail when it comes to compromising users PC's, or allowing 'rogue' affiliates to steal content from other programs and promote Quickbuck join pages, or using other malware to pop your join pages over other programs join pages.

jcsike 12-22-2007 02:32 PM

smokey, let me ask you this, wouldnt there inherently be another backdoor that nats uses to get into the server to report back to nats what plan level the account is at for billing purposes?

Rico 12-22-2007 02:32 PM

Quote:

Originally Posted by Nysus (Post 13551761)
So technically you're not really "with NATS" then ...

That is correct. But it 'still' is their software, so i prefered to clarify. :)

Trixxxia 12-22-2007 03:04 PM

Quote:

Originally Posted by rico-panchodog (Post 13551892)
That is correct. But it 'still' is their software, so i prefered to clarify. :)

Rico - if you have a moment, could you hit me up please?

Thanks

dial 12-22-2007 03:21 PM

Quote:

Originally Posted by SmokeyTheBear (Post 13550926)


like nastydollars and bangbros , industry leaders ?

more like industry cheaters

aren't these the same guys that only show 1 out of every 100 hits that end up in their system?

yeah, you may have 1:100 ratios, but they are only counting 10% of your traffic, hahaha

dial 12-22-2007 03:24 PM

Quote:

Originally Posted by AlienQ (Post 13551639)
Raises hand.

when I was a drug dealer my sister in law kept telling me for 3 years that I would eventually get busted

sure enough, after drug dealing for 3 years I got busted

does that make her right? lol

DamageX 12-22-2007 03:33 PM

Quote:

Originally Posted by notoldschool (Post 13550899)
NATS haters unite..lol. TMM is awesome and unliKe most other companies in the industry are on the problems before or as they happen. Its funny you see the shady programs come in here to bash nats when they are the most suspect. Your stats scare the shit out of me....0/10ooo+.

DO NOT TRUST PROGRAMS THAT HAVE CUSTOM BACKENDS. THEY ARE THE ONES TO WATCH FOR.

Kind sir, would you be interested in some swampland and a couple of bridges I have for sale?

notoldschool 12-22-2007 03:36 PM

Quote:

Originally Posted by DamageX (Post 13552056)
Kind sir, would you be interested in some swampland and a couple of bridges I have for sale?

Sure at the same time I grab some of that traffic adept traffic.:1orglaugh

DamageX 12-22-2007 03:41 PM

Quote:

Originally Posted by notoldschool (Post 13552064)
Sure at the same time I grab some of that traffic adept traffic.:1orglaugh

Given how gullible you are, you probably wouldn't know what to do with it anyway. :)

notoldschool 12-22-2007 03:50 PM

Quote:

Originally Posted by DamageX (Post 13552074)
Given how gullible you are, you probably wouldn't know what to do with it anyway. :)

and could you please explain the the world what exactly i am gullible about?
If you got some dirty secret about how Ron Paul voted a certain way, did cocaine in college, cheated on two wives, voted for the war, voted for bigger goverment, voted for preemptive invasions of nations that have no chance of hurting us, PLEASE FILL ME IN.

ps. please provide facts with your assumptions.

iMind 12-22-2007 03:56 PM

Quote:

Originally Posted by dial (Post 13552043)
when I was a drug dealer my sister in law kept telling me for 3 years that I would eventually get busted

sure enough, after drug dealing for 3 years I got busted

does that make her right? lol

:1orglaugh yes it does.
You should also stop dippin' into your supply :1orglaugh

Aliens a moron, but even a broken clocks right 2 times a day.

SmokeyTheBear 12-22-2007 03:59 PM

Quote:

Originally Posted by dial (Post 13552035)
more like industry cheaters

aren't these the same guys that only show 1 out of every 100 hits that end up in their system?

yeah, you may have 1:100 ratios, but they are only counting 10% of your traffic, hahaha

no you have the wrong sponsor, nastydollars and bangbros have pretty close stats , your thinking of sponsors like realitycash .

KrisKross 12-22-2007 04:09 PM

Quote:

Originally Posted by dial (Post 13552035)
more like industry cheaters

aren't these the same guys that only show 1 out of every 100 hits that end up in their system?

yeah, you may have 1:100 ratios, but they are only counting 10% of your traffic, hahaha

Math obviously isn't your forte.

dial 12-22-2007 04:42 PM

Quote:

Originally Posted by SmokeyTheBear (Post 13552130)
no you have the wrong sponsor, nastydollars and bangbros have pretty close stats , your thinking of sponsors like realitycash .

at least realitycash says they count "qualified hits" or whatever

bangbros just doesn't count hits...AT ALL

I sent them at least 10,000 hits a while back and saw maybe 100-200 in their admin

i believe there were a few more affiliates that posted on gfy about the same problem....they sent a bunch of hits and maybe saw 10-20% showed up in the admin

the fact is, the adult industry STINKS to high heaven these days, cheaters and scammers have run wild for years now, and that seems to be all that is left

hell, even a few of the largest program owners have been publicly OUTED for scamming or cheating affiliates, and they still get high fives!!!!

dial 12-22-2007 04:43 PM

Quote:

Originally Posted by KrisKross (Post 13552158)
Math obviously isn't your forte.

you got that right, I suck at math, completely

but if you missed the point then intelligence isn't your forte

TheDoc 12-22-2007 04:46 PM

Quote:

Originally Posted by pornopete (Post 13552134)
I thought NATS was supposed to be an inpentrable fortress enabling affiliates to feel confident that the program owners aren't cheating them.

Lets not forget the thread last year that revealed the fact that NATs has a built in feature that allows program owners to approve/disapprove an affiliates sale.

Everything is hackable, every program, every server, every host, at some point, some software, something can have an sql, apache, unix, nats, email from - ect related.. Very common.

NATS has never had a way to approve/disapprove an affiliates sale, ever. Please get your facts straight before posting such slander.

SmokeyTheBear 12-22-2007 04:48 PM

Quote:

Originally Posted by dial (Post 13552278)
at least realitycash says they count "qualified hits" or whatever

so does bangbros
Quote:

Originally Posted by dial (Post 13552278)
bangbros just doesn't count hits...AT ALL

I sent them at least 10,000 hits a while back and saw maybe 100-200 in their admin

i believe there were a few more affiliates that posted on gfy about the same problem....they sent a bunch of hits and maybe saw 10-20% showed up in the admin

i don't disagree there , i have noticed similar things with bangbros but there are lots of other factors such as a qualified hit may be a "unique" ip not a "unique" hit for your ref code

nastydollars counts hits perfect

but hey you are arguing a moot point , i think most webmasters have noticed nats sponsors don't convert as well whatever the stats say. , all my top sponsors use custom backends.

Quote:

Originally Posted by dial (Post 13552278)

the fact is, the adult industry STINKS to high heaven these days, cheaters and scammers have run wild for years now, and that seems to be all that is left

hell, even a few of the largest program owners have been publicly OUTED for scamming or cheating affiliates, and they still get high fives!!!!

can't argue with that for the most part :1orglaugh


All times are GMT -7. The time now is 06:21 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123