![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
View Poll Results: do you know how to crack a pass of a paysite | |||
yes |
![]() ![]() ![]() ![]() |
34 | 43.59% |
no |
![]() ![]() ![]() ![]() |
15 | 19.23% |
I wanna learn |
![]() ![]() ![]() ![]() |
14 | 17.95% |
Fuck you asshole. You should be banned... |
![]() ![]() ![]() ![]() |
15 | 19.23% |
Voters: 78. You may not vote on this poll |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Sep 2001
Location: home
Posts: 1,335
|
How many of you know how to crack a password of a paysite?
I was wondering how this password guys can crack so many passes and update them every fucking day. So, I went to one of the password forum's so called security discussion part. I kept reading the posts about password cracking for an hour. I downloaded the software that many of them use. Then, all I needed to have is a proxy list and a wordlist. Oh well, they had threads where they posted wordlists and proxy lists in zip files. After downloading all the zips I had a list of 1500+ working proxies and 30k+ wordlist. I was still not believing that it could be so easy.
Well, I picked one of the most popular sites to crack a pass. It took no more than 5 mins to get access. I thought I was lucky that time and still not believing that this list would help to get access to more sites. Believe it or not right now, I have passes to more than 20 sites ( I almost have %100 success).... I think this is very fucked up. Learning how to use this software and getting a decent word lists does not take more than an hour. Also, the software I used is not much complicated than kazaa. Anybody who knows how to read e-mail can use this program. Also, I noticed that same fucking passes works for many many sites. I always thought those guys that run sites like ultrapasswords are very good hackers. Fuck, any of us can run a password site just by doing a search for an hour and we can get paid by lensman... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Oct 2002
Location: Minneapolis
Posts: 144
|
Nemisis -
Thanks for the info. Now tell us how to PREVENT them from cracking the pw's. Which sites couldn't you crack, and why? Shit, I got busy with other stuff, didn't check my log files, bw was up a little but not a lot, 2 days ago realized I had a thief in there for the past month. Fortunately, I only get about 3-4 a year, but still, how to have zero? It's also possible the subscriber just gave out his un/pw to a trading site . . . ![]() vik |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
2011 GFY Hall of Fame!
Industry Role:
Join Date: Nov 2000
Location: Back in Texas!
Posts: 15,224
|
There's even easier ways than that, but it's unlikely that I will post them here, just not good for business...
![]() Having a site which allows access will likely always be accessible by some "un-savory" types for lack of a better word, but I think you just have to stay on top of it, and make sure that it doesn't get out of hand...
__________________
Looking for Opportunity! ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Sep 2002
Location: The Internet
Posts: 2,681
|
Nevermind
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Join Date: Sep 2001
Location: home
Posts: 1,335
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jul 2002
Location: Crankerville
Posts: 1,003
|
Isn't there third party tools for this?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
CLICK HERE
Industry Role:
Join Date: Jan 2002
Posts: 20,829
|
i just thought of something. when you submit to al4a and they have the picture of the generated number and you have to type that in for verification.... what if someone was to make a password script where you have to type in the generated # along with your user and pass. wouldnt that get rid of the password crackers?
__________________
I host with Vacares |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
See sig. Join Epic Cash.
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
|
are you saying everytime someone logs in, they have to type the randomly generated text in the image?
sure, it'll make your site more secure, but it'll piss off a lot of people and you'd probably end up losing rebills |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: May 2002
Posts: 337
|
Force users to have randomly generated passwords...
ie.. x8572dwesx12312a Longer then 8 letters, that will stop many of these word list program attempts.
__________________
Yo. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
See sig. Join Epic Cash.
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
|
i'd never remember that
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
CLICK HERE
Industry Role:
Join Date: Jan 2002
Posts: 20,829
|
Quote:
__________________
I host with Vacares |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Join Date: Oct 2002
Location: GPS OFFLINE
Posts: 249
|
Quote:
Also most account bruteforcing software isnt able to work with forms so stop using http authentication and switch to a cgi based form authentication.
__________________
![]() Mmmm.......spam! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Feb 2001
Location: atlanta, GA
Posts: 6,432
|
i wish billing companies can force surfers
to use email address as usernames this is will eliminate 90% of the current hacking software |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
See sig. Join Epic Cash.
Join Date: Oct 2002
Location: Montreal, Quebec. ICQ: 214702014
Posts: 22,366
|
if he email address is the username, and he chooses his own password, it'll remain the same on any site he signs up for. get his password and you got access to all his sites.
it'll prevent against word lists tho. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
CLICK HERE
Industry Role:
Join Date: Jan 2002
Posts: 20,829
|
Quote:
__________________
I host with Vacares |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
Quote:
![]() One must probably ask though, is stopping 5 freeloaders a year worth potentially pissing off your customers?
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
CLICK HERE
Industry Role:
Join Date: Jan 2002
Posts: 20,829
|
well you can look at it like this.... if someone cracks 10 of your accounts and you lose 10 customers because they get pissed that their accounts get fucked with. is having this script worth avoiding it? if they have to go through the trouble of typing their using name and password what is typing a few #s from a picture above a text box going to hurt?
__________________
I host with Vacares |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Apr 2002
Posts: 901
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
Quote:
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Confirmed User
Join Date: Oct 2002
Location: European Union
Posts: 1,752
|
Quote:
I.e. www.domain.com/members/fuckyou.jpg ? I use a cgi based form reading the .htpasswd file and redirect to membersarea if auth is OK. But I still need http auth. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Join Date: Oct 2002
Posts: 252
|
Protecting a single picture is easy, I've done it on many paysites. Basically you disable access to *.jpg or *.gif or *.mpg or WHATEVER in your .htaccess file (for Apache, IIS will be different) - you can find info on doing this by reading the Apache docs. Then you write a "frontend" script to interface with the JPEGs. This can be done in any language but I've implemented it in Perl and PHP.
Basically what you do is have it spit out the header with the Content-Type of image/jpeg or image/gif ra ra ra and then read from a file, and spit it out to the browser. Works perfect. This is great if you want to limit user's bandwidth, or prevent multiple IPs from accessing images etc. etc. You can have immense customization. Regarding hacking/cracking, breaking an HTTP auth password is a walk through the park. In fact, breaking most passwords on a paysite is fairly easy. What you need to do (and also make clear in disclaimers etc.) is limit the number of IPs a user can have connected at the same time, for starters. This way, if your password is broken, and the cracker decides to post your password to 5 zillion users on his pathetic XXX Passwords site, users won't get in. You can also consider suspending the account if this happens. The user may be unhappy, yes, but I think it's ultimately a better alternative than having 200GB of bandwidth being used up and paying 20 times what the user pays for that month. You then also prevent the same IP from hammering your site (i.e. brute forcing, even dictionary cracking). All this can be done with simple Perl/PHP scripts (that is, if you're not using htaccess). If you ARE using .htaccess I'm fairly certain there are Apache modules that you can use that do just this. There are many other methods you can use to safeguard password cracking, not solve it however. The main concern with paysites, or in fact ANY sites these days, is the mere fact they are insecure overall. Breaking into paysites is generally EASIER to do by breaking into the whole box. The fact is, most don't have system administrators, and the ones that do are not competent enough to keep up to date with security issues. This imposes much higher danger than a simple breaking of a password to the members' area. All they have to do is hide the amount of bandwidth you're using, backdoor your members' area, hide their files, hide everything and give people free access to the site and there'd be virtually know way of you knowing. Employing a COMPETENT system adminstrator is important in my opinion. But hey, that's just me :P |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Oct 2002
Location: European Union
Posts: 1,752
|
Dragon Curve,
Your solution might work but is not optimal. Disappling access to ex. videofiles will not let a user download a video by rightclicking which is direct linking. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | ||
Confirmed User
Join Date: Sep 2001
Location: home
Posts: 1,335
|
Quote:
Quote:
|
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Join Date: Jan 2002
Location: In the walls of your house.
Posts: 3,985
|
Quote:
__________________
"Every normal man must be tempted, at times, to spit on his hands, hoist the black flag, and begin slitting throats." --H.L. Mencken |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
Quote:
but if you run a paysite, I'm sure we can work out a deal. I'm usually flexible, you can contact me via e-mail: woj at wojfun.com or ICQ:33375924.
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Join Date: Jan 2001
Posts: 3,539
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2002
Location: Corona Del Mar, CA
Posts: 10,520
|
Do us a favor and crack this paysite:
http://www.gbf-archive.com Details here: http://gofuckyourself.com/showthread...threadid=82108 Fuckers. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2002
Location: Corona Del Mar, CA
Posts: 10,520
|
Oh ya, and dont forget to post the U/P here please.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Join Date: Mar 2001
Location: Cat Detector Van
Posts: 1,600
|
Every time people bring this shit up, there's still one or two that aren't educated.
www.proxypass.com Get it, love it. It does everything that pennywize and IProtect do (with less server load) PLUS stops open proxies from accessing your site at all. It protects us very well, and is configurable as hell. I don't own the company, have a stake it, or anything like that, I just like and use the software. Cheers, Backov
__________________
<embed src="http://banners.spotbrokers.com/button.swf" FlashVars="clickURL=http://banners.spotbrokers.com" quality=high pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" type="application/x-shockwave-flash" width="120" height="60"></embed> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Old Timer
Industry Role:
Join Date: Jan 2001
Location: Indianapolis
Posts: 12,208
|
How do I get free porn again?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Feb 2002
Posts: 105
|
Thanks for the nice words Backov! If anyone has more Qs about ProxyPass please hit me up!
ICQ: 153529369 Best regards, PxG |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
with all the free porn on the net , why bother?
unless you want to say "look what I done!" maybe its a fun passtime (time waster) but the script is doing all the work, password cracking skill Zero. if one ip or account is burning big bandwidth then he is stealing from you. dump him |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Industry Role:
Join Date: Feb 2002
Location: California
Posts: 7,444
|
How about a username and password for the username and a password for the password
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |