![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
HOw can a password site post 400 of my passwords?
Fuck knows how this has happened as I have strongbox installed and its working fine. But 400 of my passwords were posted on a password site.
I have noticed Strongbox has been knocking out more members daily in the last month. So how do these thieves get access to the password files? Checked server stats and only me thats been logged on. Thoughts? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Mar 2005
Location: ICQ: 211-417-740
Posts: 5,223
|
What's your site?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
So Fucking Banned
Join Date: Feb 2004
Location: UK
Posts: 195
|
whats the forum url
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Let slip the dogs of war.
Industry Role:
Join Date: Jan 2003
Location: Bermuda
Posts: 17,263
|
Quote:
__________________
. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Sep 2003
Location: East Bay California
Posts: 234
|
If your stats show only you have been logging in, maybe whoever did this got your id and password. Might want to change your pasword.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
MAGIC!1
What's your site, what's the forum, how many members you have, where do you host....
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
But only my IP shows up. If someone else was using my login their IP would be different to mine..
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
Let slip the dogs of war.
Industry Role:
Join Date: Jan 2003
Location: Bermuda
Posts: 17,263
|
Quote:
If you have any scripts running, they may be vulnerable through a variety of measures. Basically, someone could take control of your server by having the script(s) run commands. To you it would appear nobody "logged in" to your server. Your password file may even web accessable. That is, can someone just type in yoursite.com/passwords.txt (or whatever) and retreive the password file? I'm no security expert, especially in regards to web servers, so you'll probably want to get some help from somebody that is. Do you know any good admins that could do a quick once over on your site? You could get some more information by letting us know exactly what you're running script and members protection wise. Maybe someone can point out a vulnerable script from its name.
__________________
. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
My password file is safe from typins. I use strong box for protection. Use CCBill and Epoch for processing.
I have emailed Ray Morris and hopefully he can take a look to see what the problem is and how it happened. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Let slip the dogs of war.
Industry Role:
Join Date: Jan 2003
Location: Bermuda
Posts: 17,263
|
Alright bud just trying to give you some simple advice. Good luck with finding the problem. Hopefully you know people more knowledgable than me.
__________________
. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: Alberta
Posts: 1,864
|
Switch to Phantom Frog and you wouldnt have this problem.
__________________
Coming Soon! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: Alberta
Posts: 1,864
|
www.phantomfrog.com
I dont get money from posting that, lol. But I so use them. With phantom frog even if all your passwords were shared everyone would get blocked so no one that shouldn't have access would get in. And with the automated password recovery the real member can easily get a new password sent to their email instantly so they can log on to your site. This means you wouldn't have to change the password for 400 users, and they wouldn't have to wait more then a few seconds to finish beating off.
__________________
Coming Soon! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
password stealing and server hacking is a lot easier then you think.
the bad guys run a script 24/7 spidering one ip after another getting whatever info it can about operating system, scripts or whatever the server has installed. Once the script has that information it goes through what exploits it knows exists for that operating system or scripts. then the attack happens and takes your passwords or whatever it can. all this usually from an exploited server, so they don't get caught. and the owners of the server don't even know it. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
Just been reading up about Phantom Frog and it does look like it would solve the problem.
Will save on posting out new passwords to members as well. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: Alberta
Posts: 1,864
|
![]() I love waking up in the morning and seeing that a member or 2 recovered their own password at some ungodly hour. Those members are now still happy they could beat off after getting back from the bar and will have that much more reason to rebill ![]()
__________________
Coming Soon! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
The amount of blocked passwords from members and only a few email asking for a new password. Many are too embarressed to ask me and cancel, so again this seems a good idea.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: Alberta
Posts: 1,864
|
Quote:
Just contact Bill, he is a great guy to deal with. And actually has a phone number that he answers which is nice. I dont have your member base, but even with what I have the cost is worth not having to deal with the passwords all the time. Means I can skiing for the weekend and be fine with my blackberry.
__________________
Coming Soon! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
mrwilson 2.0
Industry Role:
Join Date: Jul 2007
Location: ICQ: 465406783
Posts: 5,122
|
Strongbox can be easily bruteforced using a proxy list and wordlist and many of the bruteforce tools available.
instead of usernames you could perhaps use emails? or make the username and password longer with #'s and other characters. Phantomfrog is also recommended... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
working on my tan
Industry Role:
Join Date: Mar 2005
Location: Florida/Kentucky
Posts: 39,151
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Confirmed User
Join Date: Sep 2003
Location: Burlingame CA
Posts: 1,430
|
Quote:
jeffrey, if i signup for this do you have ref code or is there any reward for you?
__________________
_,.:'`- Club JK . com --> 60% payouts RSS, Hosteds, POTD, Your Mother, etc... CCBill |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: Alberta
Posts: 1,864
|
Quote:
![]() but if you let Bill know Jeff from seannalust sent ya he would at least know its me ![]() Melvin got me to use phantomfrog ![]()
__________________
Coming Soon! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
lurker
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
|
phantom frog looks interesting.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Join Date: Jul 2006
Posts: 345
|
is it possible to configure strongbox to automatically reset password and send out new passwords to members?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Confirmed User
Join Date: Aug 2003
Location: Aim - Hydromorphone
Posts: 5,539
|
eeeeeeeeeeeeeeeeeek
__________________
The Sexiest place to Buy & Sell Adult Ads - JuicyAds is where YOUR profits matter!
![]() ---> SPOTS AVAILABLE :|: SIGN UP RIGHT NOW <--- |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Montreal, Quebec
Posts: 29,668
|
That many passwords ....
I would install and run http://www.chkrootkit.org/ Someone has managed to drop a shellscript that gives him access to the root and all folders .... No point in changing password software protection .
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Registered User
Join Date: Dec 2006
Posts: 4
|
![]() Lol, now you're going to hurt Bill's feelings if he reads this board Robbie. I switched to Phantom Frog in September of '06 and I have no intention of going anywhere else for my site security. I tried Pennywize, IPROT, Password Sentry and a few more, but in my humble opinion PhantomFrog kicks everybody's ass. If you're in doubt about how your current security system is performing, have Bill install the Frog Demo for you. You're going to freak when you see how many guys are sneaking in under your nose!
Since I got onboard with Phantom Frog, my password management workload has been cut down to nearly zip! Yeah, there's still a few dim bulbs who will still write you to get a new password, but not many. If you let your members know how to get help when they need it, most will just retrieve their own passwords and be on their way. Sweet! Oh, and Bill is not the "grouchy fucker" he's made out to be. He's a fuckin' sweetheart! One thing I do have to agree with Robbie on is that he really DOES know his shit and support is top notch. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
LOL! Actually I messaged Bill and showed him this thread.
![]() Ironically, the thing he has just built is EXACTLY what I have been looking for over the last couple of months as I have been making deals to maximize the income from the Claudia-Marie.Com website to even greater heights (there never seems to be enough money for my drug and whore habits LOL) I'm having Bill install this new product on my server as we speak. And one of the great things about it is the fact that he is so anal about security that I won't have to worry about anybody stealing from me. Go over to phantomfrog.com and contact Bill if you are a paysite owner. I think you're going to like what he will show you with this new product. Hell, I would post the URL to the new product...but I didn't ask him if it was okay yet. He's still working on putting up some screenshots of the admin so I won't reveal it to everybody yet. But again, if you are a paysite owner...just get over to phantomfrog.com and use his contact info and ask him about it. Tell him you read a post over here by Robbie about some super secret mystery software he is about to release. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Your first and biggest mistake...
Putting all of your paysites on the same server as your free sites. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
bukkakeblogger.com
This wordpress version is full of exploits... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 | |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Quote:
![]() ![]() But I'm hip to what you're trying to say. Especially with all the easy hacks through blogs, forums, etc. I try to make sure my stuff is as safe as possible. Plus I couldn't possibly handle the loads on one server...I'm running about 15 terrabytes of bandwidth a month and I haven't even checked how many megs per second I'm pushing. It's crazy. I'm just glad that bandwidth is cheap these days. Could you imagine those kinda numbers back 10 years ago? I remember when the cheapest bandwidth you could get was a buck fifty a gig. Now I pay 14 cents. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
BTW.. No matter what you use for password management, it still has to conform to the AOL rule. (x) number of IP's over (y) number of minutes. So it won't magically kill passwords when they are shared individually like in a message board via PM's or in a chatroom.
One way to try and do this is to log the region from the IP... Then associate that region to the account. Would stop tons of this. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Oh, okay.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
Confirmed User
Join Date: Mar 2006
Location: Ohio
Posts: 979
|
Pennywise
I had similar probs.....installed pennywize which has seemed to stop password abuse but like everyone has pointed out....I seem to be having alot of passwords blocked, but no emails from members? I heard alot about other scripts....anyone have an opinion on Pennywize?
tia |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 | |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Moo Moo Cow
Join Date: Mar 2004
Location: Washington State
Posts: 14,748
|
anyone telling you to change your password protection script has no clue what they are talking about. Warchild and some others were giving you the correct answers.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
I have a clue. And I think that securing your server is of course step ONE. That should be a given. Then if you want to really stop all password trading and brute force attacks after your server is nailed down...then yes, you would want to change over to the phantom frog software. As far as I know it is the only security software of it's type. Warchild is giving some very solid advise. But shutting the doors on your server isn't gonna help stop people trading passwords, or stop the hundreds that are already out there, or keep you from the hours of headaches and work that goes with dealing with all that customer support. There is a lot more to what this guy is facing than just server security. Though obviously that should be job number one.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 |
Confirmed User
Join Date: Jan 2006
Location: The Valley
Posts: 7,412
|
Using NATS?
__________________
-D. ICQ: 202-96-31 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
That's true. If he's using NATS his passwords are definitely compromised. Another good reason to have a system that blocks them and changes the passwords. And another good reason to listen to Warchild and aico and get the security of the site (including the IP restriction of NATS) up to snuff.
It sucks that there are so many thieves out there and honest hard working people have to watch their backs every second. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Hey D....I like your sites. I'm gonna sign up and promote them. I can definitely use some hot black girl stuff on my tgp's. Love those big asses.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 | |
Confirmed User
Join Date: Jan 2006
Location: The Valley
Posts: 7,412
|
Quote:
![]()
__________________
-D. ICQ: 202-96-31 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 |
Leaner, Meaner, Faster
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
|
Just finished signing up. That's some funny shit on the Shorty Mac site. A rap for every scene description....pure genius! I love it.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 |
Moo Moo Cow
Join Date: Mar 2004
Location: Washington State
Posts: 14,748
|
I say again, Phantom Frog and Strongbox DO NOT protect your .htpasswd file. All of your 400 passwords are on that site because someone got access to your .htpasswd file, while PF and SB will protect your members area from people using those passwords, they will not, and DID NOT, protect your .htpasswd file, someone hacked your server and is still probably doing so.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 |
Confirmed User
Join Date: Aug 2003
Location: Dorset, UK
Posts: 638
|
Agree that the server must have been exploited by a script. I have contacted tech support and asked them to run a diagnostic on it. Changing all my passwords as well as an added precaution. And also dumping wordpress. The less scripts the better.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
I addressed the fact that his server was hacked.
PF is for after this happens... IT DOES HELP! |
![]() |
![]() ![]() ![]() ![]() ![]() |