![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Virgin by request ;)
Industry Role:
Join Date: Feb 2002
Posts: 1,924
|
patched & safe NATS programs
Here is the list of affiliate sites that I have heard from so far who have confirmed their NATS installations have been "patched", ie, all recommended safety precautions have been taken:
HunkMoney IslandDollars ZBuckZ HapiCash Who else? Please add any other affiliate programs that have confirmed they have addressed this issue, as recommended by TMM. Program owners, if you have already taken actions, please let us know here! cheers, Luke |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
You can add all NATS programs to that list now.
Once TMM found out about this they went in and changed the PW's on programs they had access for. They didn't keep the new info, just fyi. Everyone else would have had IP protection in place or previously had removed/changed the TMM account details. Meaning the data was already secure.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Virgin by request ;)
Industry Role:
Join Date: Feb 2002
Posts: 1,924
|
Thanks TheDoc, I must have missed that in all the threads recently!
cheers, Luke |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
RIP Dodger. BEST.CAT.EVER
Industry Role:
Join Date: Dec 2002
Location: NYC Area
Posts: 18,450
|
Quote:
__________________
-uno icq: 111-914 CrazyBabe.com - porn art MojoHost - For all your hosting needs, present and future. Tell them I sent ya! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
I was avoiding listing all the people that I know did use the Ip protection. Ya miss a few people and the ICQ's of butt hurt people start ![]()
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
wait wait wait , gotta set things straight here.
In my opinion no sponsors are safe until they have had a security audit. The nats admins usernames were stolen, there are hundreds of places the hacker could have injected code that is still UNACTIVATED. regardless of if the admins have been removed, ip's locked down and patched up.. just because you are patched, doesnt mean you are safe. I suggest all sponsors who want to make sure not only for themselves but for their affiliates should clarify if they had a security audit and what was done in the audit. I suggest that any nats sponsor that was compromised using the nats admins passwords should probably send the bill to nats for the security audit or ask nats to supply you one. but this is only my opinion, i have no idea if nats plans on paying for these.
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Smokey, I thought about this more.. I agree, but overall... Not really.
They can't run/upload/execute anything without it being a plugin / script uploaded via FTP first. You can't upload or add anything to the system via the NATS admin. Smarty won't run php, can't do includes, won't do redirects.. NATS locked down several exploitable parts of smarty already. So other than direct join template changes or an iframe exploit in the admin templates (which would take 2 seconds to look and see).. I don't really think they could do much damage this way. Now, they could have deleted members, webmasters, templates, sites, programs, ect.. A small issue needles to say.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
TheDoc is right on this.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Charleston, SC
Posts: 2,468
|
Our IP protection to the admin of NATS was put in place early last week before this news broke, but I agree with TheDoc.. More needs to be done.
__________________
http://www.3dsex.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Nope, Smokey is right on this one.
for those of you that don't know Smarty, the template engine for NATS, all one needs to do is add {debug} to any template and you've given away a *lot* of info. A *FULL* security audit is required by *EVERY* programme that runs NATS. Period.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
![]()
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
it would only take 2 seconds to look and see obvious non-human logins in the nats admin but they missed that for months right .. if you dont look for things they are hard to see .. if they were smart enough to steal the master nats passwd list and build software to remotely retrieve data on a daily basis from numerous sponsors , it doesn't seem a far stretch they would do something as simple as edit a template and drop in a few backdoor scripts incase the admin ever found out the password list was compromised. infact i would think that would be the very very first thing they would do..
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
This tells you about errors and what smarty calls to make. You can not call everything from the debug menu into a nats template. It isn't a security issue of any kind.
MYSQL has nothing to do with this, nor protecting mysql. The IP lock feature is within the Admin area and instantly stopped this attack from happening. Quote:
You can't do anything with the templates, you can't execute, upload, backdoor anything. They are nothing more than text files, executed as text/html. The password list is TMM admin accounts on NATS. Not ALL NATS admin accounts or any other admins, webmasters, ect.. Only the TMM admin accounts were breached.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() could be empty right now (i.e unnoticed) and waiting to scoop
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
What could it do other than run local js on a pc?
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Wait, yeah duh, key stroker.. I can check some programs right fast, most people never touch the admin templates so it really only takes a second to look. And I check the access template since it's the first.
Outside of those, unless you point out a different reason, I don't see that this would do anything.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
well it could redirect joins that would be pretty bad.
if it redirected the joins to a carding page that would be even worse.
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Oh I'm sorry, maybe I was misreading the $config array output from {debug} {$config} Array (168) DB_SERVER => "xxxxxxx" DB_USER => "xxxxxxx" DB_PASSWORD => "xxxxxxx" DB_DB => "xxxxxxx" My bad, this has nothing to do with mysql at all.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
Either way though, nobody is uploading, adding code, creating a backdoor, ect through the NATS admin. However, nasty shit can be done either way.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() ![]() I dont wanna give away too much but fact is the basics got overlooked or this would have been noticed by both nats and the sponsors themselves ages ago ( or was and was ignored ) if someone was smart they likely knew this wouldnt last forever ( admin access ) , place a small js for a fake " nats update your password security alert" in the admin section , so when sponsors learn of this right now like they have they would think oh gee this must be legit" wham bam recompromised
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
I think this subject is....
![]()
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Making $$$$ w/ ClickCash
Industry Role:
Join Date: May 2003
Location: USA
Posts: 18,037
|
getting TheDoc to be carefull on this issue seems to be near impossible. He has been down playing this from day 1 when he was saying he "seems to believe that only emails were stolen". This thread is a perfect example of someone being too quick to give the " all clear" and wanting the issue to be down played and to go away. If smokey wouldn't have convinced him after several posts, people would be reading the doc's inital posts here saying that all NATS programs were now safe. Another assumption he obviously knows nothing about. I'm not bashing on NATS but i agree with SMokey it would be wise to have an audit of yoru server to double check everything, where as the doc would tell it is all fine, nothing to worry about.
__________________
ICQ: 86364801 Email: will [at] innovativeassets [dot] com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
I still DON'T think a program needs to do a check. But to be safe they might as well. With the console issue or 1000 other possible problems, the fact remains the ONLY got email / member data. Don't pull me into your little twisted post games or I will eat you alive and spit your ass back out.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Pounding Googlebot
Industry Role:
Join Date: Aug 2002
Location: Canada
Posts: 34,486
|
__________________
I play with Google. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
Can it be removed and still have the debug console? I went in and checked 5 people, only 2 of us (me included) have the debug on. I don't remember turning my on but I am going to get my host to tell me how to turn it on/off. I would bet though, now that you pointed this out, more changes will be made. That damn console is handy but that could be deadly. Again, pointing out at how bad it could have been - vs what it really was.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | ||||
Making $$$$ w/ ClickCash
Industry Role:
Join Date: May 2003
Location: USA
Posts: 18,037
|
Quote:
TITLE OF THIS THREAD: Quote:
Quote:
Quote:
__________________
ICQ: 86364801 Email: will [at] innovativeassets [dot] com |
||||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Yes, Will76, NATS has been "Patched and is now Safe".. That is 100% correct.
Please take your drama bullshit to another thread and let us adults conduct business.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | ||
Facit Omnia Voluntas
Industry Role:
Join Date: Apr 2003
Location: Offshore
Posts: 2,105
|
Quote:
Quote:
No offense, really - and believe me, I'd like to see this go away as fast as every other webmaster / program owner as well, it's just that you know, better be safe and 100% sure than sorry. It's great that there is work being done and that you're a part of it ![]()
__________________
Facilitation - BizDev - Traffic - Consulting - Marketing Skype: jokerempire | Silent Circle: joker |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Making $$$$ w/ ClickCash
Industry Role:
Join Date: May 2003
Location: USA
Posts: 18,037
|
Quote:
No Drama, and you can continue to reply with insults if you like and try to start a pissing match but I prefer to stick to the topic. Smokey pointed out where people should get their stuff checked. I agree better to be safe and do the right thing. I am just curious why you so quick to tell people that all programs using NATS on their servers are 100% safe. How do you know that? did you check everyone's servers as smokey mentioned?
__________________
ICQ: 86364801 Email: will [at] innovativeassets [dot] com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
No reason to twist this, the answer again is 100% YES! All NATS programs have had all recommenced safety precautions taken. Everything else is how to IMPROVE on it and find more possible holes that could be exploited. And I did agree with Smokey, and I agreed that people should check the installs. But I do not think or agree that they will find any problems due to the fact that a human didn't enter the programs, but rather a bot, which pulled information from reports. So even the debug screen is pointless, but that doesn't mean it isn't something that shouldn't be addressed for future problems. And with you, I didn't say "all clear" as you quoted me saying. So if you want to twist my words I will continue to bash you.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |||
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
Quote:
Quote:
So when people are saying it isn't secure, well.. You are right, but neither is any other affiliage program for that mater, or google, or anyone. So nobody can ever give the 100% all clear vote, we can only state what we know.... That nats is clear of the issue it had and we should all move on and start making more money.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Colorado
Posts: 3,973
|
We took action as soon as we heard about the issue. Add IntenseCash to that list.
![]() Mark
__________________
IntenseCash - If you can't convert us then you might want to look for a new job . BrokeStraightBoys.com converting 1:124 stats counted by Nats |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Oct 2005
Location: StarlightBucks !
Posts: 5,404
|
we are good to go
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Industry Role:
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 5,600
|
MassiveDollars (and all clients of our host) have IP protection. It can be a pain in the butt sometimes but now I'm sure everyone is GLADLY going to grin rather than growl when they need to get an IP authorized.
Despite knowing we are protected, we meticulously went through all IPs that accessed as admins to make sure everyone checked out and matched. All good there. Smokey, borked, quantum-x(in some other threads) and TheDoc - thanks for using your collective brains & experience to foresee any 'possible' issues and giving indications of what to look out for. I personally appreciate it and sleep better at night knowing I've dotted my 'i's' and crossed my 't's - EVEN if we were protected. Like JokerEmpire said - Better safe than sorry. |
![]() |
![]() ![]() ![]() ![]() ![]() |