AVN: NATS/TMM Breached for More Than a Year

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Paul Markham
    Too old to care
    • Jun 2001
    • 52942

    #91
    Originally posted by Chimera1
    Are you really arguing for the sake of it?

    Nats is struggling to survive and may not make it, especially with the backlash developing in spite of their best efforts. Perhaps you can start an argument over that.

    The program owners with an investment are naturally struggling to find justifications in keeping the software and are more inclined towards belief.... Maybe that too is something to argue about.

    They have much to lose and gain in this and their defenses and arguing are expected, though maybe not entirely logical.

    From the affiliate level we don't actually have much to gain or lose except to take notes as to who is alert and who is burying their heads in the sand.

    So why all the argument over tiny points when the main issue is clear and incontrovertible?
    At last someone comes in with common sense. It does not matter if the servers were brought down, to their knees or slowed down. What matters is NATS, as we all know, were well aware of this issue. There had been numerous warnings that email addresses were being compromised. They failed to look at it properly. Even when they had it brought to the their attention in a way they could not ignore they did not fix the problem properly, did not warn other clients and tried to stop the information getting out. A C&D is a legal letter and a threat.

    So the question is why did they take so long to look into it, not fix it and try to keep it quiet?

    Incompetent and don't want people to know. Or. Dishonest?

    There are no other answers.

    Yes I feel for the companies that went the way of NATS. But you made a bad decision and did not keep a good enough control on who you were dealing with. As Chimera says you can keep burying your head in the sand and stick with a company that's incompetent or dishonest.

    Heaven help us if they had put up a site with a few magic join links.



    Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
    PM me for a deal. Skype Paulmarkham70

    Comment

    • Paul Markham
      Too old to care
      • Jun 2001
      • 52942

      #92
      Originally posted by Chimera1
      To be honest I do not know this person. I really don't care to know him.

      I am curious why you are arguing with a person you deem mentally incompetent? That is not logical, nor is it productive.

      Again, I say are you guys arguing for the sake of hearing your jaws work or your fingers type or is there some pathology involved?

      I would certainly hope people could separate news from the bearer. AVN has my vote of confidence in this matter at least in so far as being legally and factually correct in quoting the statements they did.

      I don't feel that arguing with a person you deem unstable is going to change that person's mind or their actions.
      There is personal and there is business. So which is it?
      Another great post. They are arguing with him because he's saying things they don't want to hear and the only attack they have is to attack the messenger. Because the message is best ignored.



      Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
      PM me for a deal. Skype Paulmarkham70

      Comment

      • Paul Markham
        Too old to care
        • Jun 2001
        • 52942

        #93
        Originally posted by MicDoohan
        there is not the slightest shred of evidence to suggest affiliate data was leaked. non.nada.NOTHING but heh don't let that stop you when you are getting 'mad views'

        you are just a frustrated little faggot keith
        All those email addresses getting spammed is not proof?



        Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
        PM me for a deal. Skype Paulmarkham70

        Comment

        • Paul Markham
          Too old to care
          • Jun 2001
          • 52942

          #94
          Originally posted by will76
          See thats the thing that doesn't make sense to me.

          Fact: we know it was a password list that was obtained from TMM some kind of way, either a server hack, someone leaked the info, etc... some kind of way their admin account info for every client was released.

          They say they noticed "this" problem months ago but thought it was isolated and they thought they fixed it.

          Question: If you noticed that a few clients were having someone accessing their servers using your NATS admin account info, why the hell didn't you check all of your client's servers that you have access to.

          Most likely answer: John probably blammed each of the people affected months ago and passed it off as their servers were hacked. I would bet he didn't think the problem was on his end so he didn't bother to take a couple mins to randomly start logging into clients servers to see if NATS admin accounts were accessing those servers 10x a day. He said this much in the first couple threads posted here a couple weeks ago. he siad the most likely answer was that the clients server was hacked.

          If i am wrong please explain to me what I am missing here.
          Another great post.

          If we are to believe TheDoc then hacking is a real problem. Hackers are very devious, persistent and a threat. So why is he supporting someone who clearly does not think they are? Someone who ignores to look at the problem properly?

          Now are TMM bright enough to program something like NATS and so dumb they do not understand that hackers are a problem? I come back to the same question every time, incompetent or dishonest. They have to be one or the other.



          Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
          PM me for a deal. Skype Paulmarkham70

          Comment

          • Paul Markham
            Too old to care
            • Jun 2001
            • 52942

            #95
            Originally posted by ServerGenius
            i've posted raw apache access logs of 6 months ago which showed the issue
            has been on much longer than initially was assumed
            I think the issue of the emails getting spammed was raised a long time ago.



            Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
            PM me for a deal. Skype Paulmarkham70

            Comment

            • ServerGenius
              Confirmed User
              • Feb 2002
              • 9377

              #96
              Originally posted by Paul Markham
              I think the issue of the emails getting spammed was raised a long time ago.
              Yes I know.....but I backed it up with logs.....it was raised something like
              2 years ago if I remember correctly
              | http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |

              Comment

              • Paul Markham
                Too old to care
                • Jun 2001
                • 52942

                #97
                Originally posted by ServerGenius
                Yes I know.....but I backed it up with logs.....it was raised something like
                2 years ago if I remember correctly
                With TheDoc telling us how so many big and secure programs get hacked, how easy the hackers get in and hew common it is. One has to wonder what TMM were doing ignoring it and not even thinking it might be more wide spread than the few who put the proof in front of them.

                Why were they so convinced it was not a wide spread problem?



                Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
                PM me for a deal. Skype Paulmarkham70

                Comment

                • TheDoc
                  Too lazy to set a custom title
                  • Jul 2001
                  • 13827

                  #98
                  Paul and Will76, did both of you end up with the short ends of the stick?

                  Yeah, we know hacks/exploits targeted at NATS have taken place for years. Every host, program owner, and webmaster knows this. It's not some secret that you guys want to find out about.

                  NATS job is NOT to provide security. It’s to provide a program backend, only. YOUR job is to secure it, your hosts and yours, period.

                  So how did those accounts get breached before? That's very simple logic, let me help. When a NATS "Machine" is exploited they got your ass, your pw's, ect.. (Exploits targeted at NATS machines happen daily) Once they have the admin data they can start running the bot that pulls the data.

                  So get it through your heads, NATS thought the attacks were different. Different enough that even Admins at the same host didn’t know it was the same attackers.

                  Why don't you guys go bash the Program Owners who failed basic 101 security? Why not yell at the hosts they host with? NATS job is to provide us the software, not the security.

                  I put my trust into my host, and my own skills not in software that I have ask for support on and can’t modify myself.
                  ~TheDoc - ICQ7765825
                  It's all disambiguation

                  Comment

                  • Doctor Dre
                    Too lazy to set a custom title
                    • Jan 2001
                    • 51692

                    #99
                    Originally posted by BoyAlley
                    Wow, I'm not use to seeing that type of reporting from AVN.
                    John should definitly comment about the investigation and keep everybody that was affected (affiliates and sponsors) updated... At this point, keeping the investigation behind closed doors after having ignored the problem for so long will only make people logically there are some kind secrets they want to keep.
                    Originally posted by rayadp05
                    I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                    Comment

                    • s9ann0
                      Confirmed User
                      • Sep 2001
                      • 4873

                      #100
                      Originally posted by BoyAlley
                      Wow, I'm not use to seeing that type of reporting from AVN.
                      yea are they bringing out their own affil system or something?

                      Comment

                      • TheDoc
                        Too lazy to set a custom title
                        • Jul 2001
                        • 13827

                        #101
                        Originally posted by Doctor Dre
                        John should definitly comment about the investigation and keep everybody that was affected (affiliates and sponsors) updated... At this point, keeping the investigation behind closed doors after having ignored the problem for so long will only make people logically there are some kind secrets they want to keep.
                        NATS/TMM works with the clients and the clients work with the Webmasters. And I don't think after a week NATS had much of an update for us.
                        ~TheDoc - ICQ7765825
                        It's all disambiguation

                        Comment

                        • Doctor Dre
                          Too lazy to set a custom title
                          • Jan 2001
                          • 51692

                          #102
                          Originally posted by Robbie
                          "When everything hit the boards, we went back to check [our server logs] and found the same admin account trying to access our servers every hour," he said Friday. "The IP [address] block was the same one that was blocked over a year ago, so [the person using the account] couldn't get in. It is slowing down the servers a little bit, but they're not actually getting in."

                          That is a quote from the story... So supposedly some big site had their servers brought down to their knees by ONE IP address attempting to log in and fail? Does anybody ever proof read or use common sense with these stories? This is almost as factual as a Bill OReilly story.
                          I *think* they meant that the activity in the nats admin account was slowing down the server.
                          Originally posted by rayadp05
                          I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                          Comment

                          • buzzy
                            Confirmed User
                            • May 2007
                            • 2606

                            #103
                            Originally posted by minusonebit
                            When NATS was sold to the industry, it was pitched as tool to keep the program owners honest by stopping shaving. TMM worked very hard to spin this on the boards and pretty soon affiliates started demanding NATS-based programs. The idea was that John's software, which could not be touched by the programs - would be unshaveable. Thats all good and well and had it actually functioned that way, it would have been a good thing for the industry. But these kind of things never work out this way.

                            Anyone who has taken college level (for that matter, probably high school level as well) courses in government, public service, democracy, world history and the like knows that concentration of power is a dangerous thing. We saw this in Nazi Germany, here in our own country and just about everywhere else throughout the world. The thing is that TMM was saying to affiliates: "Hey, trust US. We have YOUR best interests at heart. We wont let you bring in an independent third party to audit our code to prove this, but we do. You don't wanna get shaved, do you? What? You still don't believe us? You good for nothing board whore, if you publish that, We're, gonna sue you for libel!" and this has worked for a long time for TMM. They have made a good run of scaring their critics into silence and programs into using them. And this concentration of power led to the ultimate in lax, completely incompetent security: a list of passwords sitting on somebody's server.

                            Given the choice between NATS incompetently managing my personal data and the possibility that a dishonest sponsor *may* shave sales, at the end of the day I'll take the possibility of shaved sales. Its a small price to pay. First off, most program owners are honest, most of them are very generous with their affiliates and most of them would not consider - so its not even a really large risk. Second, dishonest people always get caught at their games eventually. iBill's greed eventually caught up to them. John's incompetence and/or crookedness has caught up to him. If you believe the story that PornGraph was actually sold before the trojans went on, then you can see it caught up with the new owners as PG is no more. Finally, program owners who fuck their affiliates through shaving probably fuck their employees, contractors, business partners and talent as well. By proxy, this means they likely already have a bad reputation and everyone knows who to stay away from anyway.
                            I know NATS fucked up big time, but comparing them to nazi germany?

                            Comment

                            • Doctor Dre
                              Too lazy to set a custom title
                              • Jan 2001
                              • 51692

                              #104
                              Originally posted by Robbie
                              S And people who are really in the biz know that. It's always been so. And HELL NO they don't cost no 20 cents a piece! More like 20 cents per THOUSAND.
                              And members area email addresses? Golden? If you think so. Hell, maybe I will sell mine after all. How about that 20 cents each deal? That's a lot cheaper than that dollar quote in that story! Come on man! I'm gonna make you rich! I've got thousands and thousand of members emails! Just think of all the money you'll make!
                              You are totally clueless when it comes to Marketing...
                              Harvested emails are worth nothing.
                              Confirmed porn buyers (credit card + confirmed working email) are worth a TON.
                              Originally posted by rayadp05
                              I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                              Comment

                              • Doctor Dre
                                Too lazy to set a custom title
                                • Jan 2001
                                • 51692

                                #105
                                Originally posted by TheDoc
                                NATS/TMM works with the clients and the clients work with the Webmasters. And I don't think after a week NATS had much of an update for us.
                                Are they investigating the money trail or not ? There was NO statement from what I have read that said anywhere that they will take the proper stepts to report this fraud to the authorities or investigate at all.
                                Originally posted by rayadp05
                                I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                                Comment

                                Working...