Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-29-2002, 11:48 PM   #1
Easy
Registered User
 
Join Date: Feb 2002
Location: Backyard
Posts: 79
password list back online again

http://tmd.df.ru/private.html
Easy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2002, 11:50 PM   #2
Mr.Fiction
Confirmed User
 
Join Date: Feb 2002
Location: Free Speech Land
Posts: 9,484
Thanks.
Mr.Fiction is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:06 AM   #3
Easy
Registered User
 
Join Date: Feb 2002
Location: Backyard
Posts: 79
hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
Easy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:09 AM   #4
echo465
Confirmed User
 
Join Date: Mar 2001
Location: Indiana
Posts: 265
Quote:
Originally posted by Easy
hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
How about this:

When you've detected that an attack is underway, always fail the first login from an IP, even if the password is correct.. a surfer will (hopefully) assume that they mistyped their password, and try again, while a brute forcer will just continue on.

Anyone?
echo465 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:12 AM   #5
pimpdog3
So Fucking Banned
 
Join Date: Aug 2002
Posts: 652
god damn, that list would make a kick ass plugin!!
pimpdog3 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:14 AM   #6
Backov
Confirmed User
 
Join Date: Mar 2001
Location: Cat Detector Van
Posts: 1,600
Quote:
Originally posted by Easy
hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
http://www.proxypass.com

That will kick the shit out of basically all brute force attacks.

Cheers,
Backov
__________________
<embed src="http://banners.spotbrokers.com/button.swf" FlashVars="clickURL=http://banners.spotbrokers.com" quality=high pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" type="application/x-shockwave-flash" width="120" height="60"></embed>
Backov is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:15 AM   #7
Rictor
Old Timer
 
Industry Role:
Join Date: Jan 2001
Location: Indianapolis
Posts: 12,208
Cool. Free porn. Cha ching.
Rictor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:16 AM   #8
echo465
Confirmed User
 
Join Date: Mar 2001
Location: Indiana
Posts: 265
Quote:
Originally posted by Easy
hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...
Another idea -- monitor the webpage for compromized accounts, and then redirect users with that username and password to that 'hey everyone, i'm looking at gay porn!!' page

link to that website that YOU DO NOT WANT TO CLICK ON is http://d-m-s-1-0-0.org/worksucks (without the dashes) (i think, but i'm sure as hell not gonna go check).
echo465 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:17 AM   #9
Mr.Fiction
Confirmed User
 
Join Date: Feb 2002
Location: Free Speech Land
Posts: 9,484
Quote:
Originally posted by pimpdog3
god damn, that list would make a kick ass plugin!!
Mr.Fiction is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:37 AM   #10
kinkyplace
Confirmed User
 
Join Date: Mar 2002
Location: Sweden
Posts: 217
I checked out some of the sites from that list. Gee, I cannot believe people are actually paying for that...!
But maybe that was a collection of all the crappy sites?
kinkyplace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:50 AM   #11
eru
Confirmed User
 
Join Date: Mar 2002
Location: Hawai'i
Posts: 2,612
FREE PORN YES!!!!
__________________
<font color="#FFFFFF" size="2" face="Verdana">This thread will self-destruct in 5 seconds.</font><font color="#FFFFFF" face="Verdana"><br>
<br>
<font size="1">In the meantime, consider hosting with <a href="http://www.choopa.com"><font color="#00FF00">Choopa</font></a>
-- The only provider with 9 x 1000mbps Transit Redundancy</font></font>
eru is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 01:39 AM   #12
BrettJ
ol' timer
 
Industry Role:
Join Date: Jan 2001
Location: Seattle WA
Posts: 4,715
Quote:
Originally posted by kinkyplace
I checked out some of the sites from that list. Gee, I cannot believe people are actually paying for that...!
But maybe that was a collection of all the crappy sites?
Hey Fag - my site was on that =)

well back to jerking off to lots of "FREE" Porn!!

~Brett
BrettJ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 03:42 AM   #13
eru
Confirmed User
 
Join Date: Mar 2002
Location: Hawai'i
Posts: 2,612
lindaoneil.com was on there! Nice! She's one hot mama!
__________________
<font color="#FFFFFF" size="2" face="Verdana">This thread will self-destruct in 5 seconds.</font><font color="#FFFFFF" face="Verdana"><br>
<br>
<font size="1">In the meantime, consider hosting with <a href="http://www.choopa.com"><font color="#00FF00">Choopa</font></a>
-- The only provider with 9 x 1000mbps Transit Redundancy</font></font>
eru is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 03:44 AM   #14
SetTheWorldonFire
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: California
Posts: 7,444
anyone got anymore lotion?
__________________
www.STWOFDesign.com
hit me up on icq 154206276 or Skype: JaimeGizzle
SetTheWorldonFire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 03:55 AM   #15
mastamindz
Confirmed User
 
Join Date: Feb 2002
Location: Canada
Posts: 3,547
Quote:
Originally posted by SetTheWorldonFire
anyone got anymore lotion?
The BBW sites are hot. I must have jerked it 12 times in the last half hour.
mastamindz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 04:07 AM   #16
B40
Confirmed User
 
Join Date: Jul 2001
Posts: 7,020
Quote:
Originally posted by eru
FREE PORN YES!!!!
Time to jerk off!
__________________
B40 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 04:11 AM   #17
sherbert
Confirmed User
 
Join Date: Aug 2002
Location: KAGAWA, Japan
Posts: 470
WOOHOO!
__________________
sdfsdfsdvgf
sherbert is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 04:35 AM   #18
kinkyplace
Confirmed User
 
Join Date: Mar 2002
Location: Sweden
Posts: 217
Quote:
Originally posted by BrettJ


Hey Fag - my site was on that =)

well back to jerking off to lots of "FREE" Porn!!

~Brett
Stop calling me names! I'm a Pervert and not a Fag!

So which of the crappy sites was yours? Is the password still working? I have to check it out...
kinkyplace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 07:11 AM   #19
PxG
Confirmed User
 
Join Date: Feb 2002
Posts: 105
Quote:
Originally posted by Easy
hmm.. maybe here someone has a good idea how to stop bruteforce attacks.

They are using a huge anon proxylist and testing each day 50k combinations within two hours. Blocking the IPs won't work...

Thanks Backov,
As a client of Proxypass, you know that we stop brute force attacks that are run through proxies. But I am sure many people out there haven't heard of our new ProxyPass product.

If anyone has any questions, please feel free to post them and we will do our best to answer them.

On a side note, pr0 posted a concern about non-standard port proxies and my response initially was that ProxyPass did not block them. I asked a programmer and he corrected me: we DO block most non-standard port proxies too. Not only are they extremely rare (only 1 in 8000 according to our counts), but we block most of them anyway. Sorry for the misinformation.
You may also hit us up privately on ICQ: 153529369

Fire away guys,

The ProxyPass Team
__________________
Kill Password Hackers Now!
Kill Hit-Botters Now!
_____________________________
PxG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 10:22 AM   #20
MaxDent
Confirmed User
 
Join Date: Apr 2002
Location: San Francisco
Posts: 851
That list must have just been updated because all the accounts they had for our site weren't suspended yet. Now they are :-)
MaxDent is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 10:30 AM   #21
BVF
Black Vagina Finder
 
BVF's Avatar
 
Join Date: Jan 2002
Location: The Midwest
Posts: 13,975
Quote:
Originally posted by MaxDent
That list must have just been updated because all the accounts they had for our site weren't suspended yet. Now they are :-)
no matter. they'll have a fresh batch of them by tomorrow..fucking russians!
__________________

Black Pussy
Click On Mr Cosby..CCbill, 60/40, 136 FHG's....The Cos Loves Black Ghetto Pussy!!
BVF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 10:30 AM   #22
salsbury
Confirmed User
 
Join Date: Feb 2002
Location: Seattle
Posts: 1,070
i wonder how many of the sites on this list use Epoch or Jettis for billing. no amount of password crack checking would work for them.
__________________
salsbury is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 10:51 AM   #23
JamesK
hi
 
Industry Role:
Join Date: Jun 2002
Posts: 16,731
muhahaha u dix using bruteforce, i got adultbouncer passwords!
__________________
M3Server - NATS Hosting
JamesK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 10:52 AM   #24
JamesK
hi
 
Industry Role:
Join Date: Jun 2002
Posts: 16,731
oh shit u got them too
__________________
M3Server - NATS Hosting
JamesK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 11:37 AM   #25
pink_in_the_middle
Confirmed User
 
pink_in_the_middle's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: O Canada
Posts: 4,503
my sites on that list !!! FUCKERS

LOL it's okay it's all fixed ;)
__________________
pinkysteph AT gmail DOT com

I'm a native english speaker from Canada with a firm ass, excellent grammar and punctuation skills. If you're in need of text for your: blog, paysite galleries, DVD covers, image cropping, content purchasing, content insertion or anything else along these lines, please feel free to give me a shout. And I’m female to boot
pink_in_the_middle is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 11:59 AM   #26
TarPy
Confirmed User
 
TarPy's Avatar
 
Industry Role:
Join Date: Mar 2002
Posts: 758
it's 403 now... LOL, back up, back down
__________________
Not Working
TarPy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:02 PM   #27
gothweb
Confirmed User
 
Join Date: Jun 2002
Location: Back in the USSA
Posts: 8,849
Okay, now... How did they get a new login so fast? I cleared out the three they were using last week, and they already have them down and a new one back up.
__________________

Photos by Ian X.: Distinctive photos of goth babes.
Blood Money:Your traffic, my sites, our money.
MojoHost: Still the best.
gothweb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:04 PM   #28
DrGuile
Confirmed User
 
Join Date: Jan 2002
Posts: 2,025
Quote:
Originally posted by gothweb
Okay, now... How did they get a new login so fast? I cleared out the three they were using last week, and they already have them down and a new one back up.

maybe you should fix the problem this time.

__________________
LiveBucks / Privatefeeds - Giving you money since 1999
Up to 50% Commission!
25% Webmaster Referal
Powered by Gamma

Last edited by DrGuile; 09-30-2002 at 12:10 PM..
DrGuile is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:06 PM   #29
gothweb
Confirmed User
 
Join Date: Jun 2002
Location: Back in the USSA
Posts: 8,849
Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?
__________________

Photos by Ian X.: Distinctive photos of goth babes.
Blood Money:Your traffic, my sites, our money.
MojoHost: Still the best.
gothweb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:10 PM   #30
DrGuile
Confirmed User
 
Join Date: Jan 2002
Posts: 2,025
Quote:
Originally posted by gothweb
Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?
brute force attack most likely...

i.e.: dictionary attacks
__________________
LiveBucks / Privatefeeds - Giving you money since 1999
Up to 50% Commission!
25% Webmaster Referal
Powered by Gamma
DrGuile is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:12 PM   #31
gothweb
Confirmed User
 
Join Date: Jun 2002
Location: Back in the USSA
Posts: 8,849
A brute force attack won't help them get passwords that aren't already there. The logins they have had have not been the result of paying members, or of me manually updating.
__________________

Photos by Ian X.: Distinctive photos of goth babes.
Blood Money:Your traffic, my sites, our money.
MojoHost: Still the best.
gothweb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:16 PM   #32
salsbury
Confirmed User
 
Join Date: Feb 2002
Location: Seattle
Posts: 1,070
if you use Epoch or Jettis they can add passwords to your site themselves. Paypal's script gives me a headache because it is obfuscated - but because it is obfuscated i strongly suspect it's vulnerable as well.
__________________
salsbury is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:22 PM   #33
JFK
FUBAR the ORIGINATOR
 
JFK's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: FUBARLAND
Posts: 67,374
the link you posted is coming up 404 for me !
__________________

FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX
For promo opps contact jfk at fubarwebmasters dot com
JFK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 12:31 PM   #34
Pornwolf
Drunk and Unruly
 
Pornwolf's Avatar
 
Join Date: Jan 2002
Location: Hollywood
Posts: 22,712
Damnit, it's down! I was hoping to see some midget oil wrestling today.
__________________
I've trusted my sites to them for over a decade...

Webair, bitches.
Pornwolf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 03:14 PM   #35
Massivecock
Confirmed User
 
Join Date: Mar 2002
Posts: 800
Where did you get that link?
What I mean is Where did you find it?
--
And can you get me the new one... it seems to have changed file names and is gone?
Massivecock is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2002, 11:59 PM   #36
Easy
Registered User
 
Join Date: Feb 2002
Location: Backyard
Posts: 79
Quote:
Originally posted by gothweb
Hey now, that's not good. The one they had wasn't in the CCBill database... Hacked?
sometimes ccbill fails to remove inactive accounts. So the pwd is still in the password file.. just check your active usernames, download the password file and compare


and that's what the russians answered...

Thanks for your report.

We'd appreciate it if you direct this type of reports to [email protected]
(rather than the webmaster) in the future.
We aren't in a position to determine what legal and what isn't. We
have an Acceptable Use Policy, which is a part of our customer agreement,
and we enforce it whenever we determine or are notified of a violation.

The particular AUP document that we use has been approved by OFISP, a
Russian/CIS ISP forum, and is shared by many Russian ISPs.

Hosting some form of content is not an AUP violation, with the only
exception for "spam support services". "Bypassing server security"
would be it, but only hosting content that enables to do so isn't.

It's only due to the details of agreement with this particular customer
that we can in fact ask and insist that they remove this content simply
because "we don't like it".

--
Alexander Peslyak
DataForce ISP
Easy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-01-2002, 02:08 AM   #37
SeRsH
Confirmed User
 
Join Date: Oct 2001
Posts: 15
I belive the largest daily updated with hundreds of passwords password list is here - http://www.xxxhq.com/vb/ ( you need to register to view )

Also I have see it here - http://www.sublimechat.com/phpBB/vie...hp?forum=7&674 ( the part of sublimedirectory )
SeRsH is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-01-2002, 02:24 AM   #38
kÿ®ëë
Registered User
 
Join Date: Sep 2002
Posts: 41
Quote:
Originally posted by salsbury
if you use Epoch or Jettis they can add passwords to your site themselves. Paypal's script gives me a headache because it is obfuscated - but because it is obfuscated i strongly suspect it's vulnerable as well.
same goes for ibill's mastergate cgi easier than cracking them

that's ALL ibill sites
kÿ®ëë is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.