GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Was Paxum.com Hacked? (https://gfy.com/showthread.php?t=1057165)

evulvmedia 02-10-2012 09:39 PM

Was Paxum.com Hacked?
 
What a strange e-mail!

Quote:

We are glad to inform you that our login security engine has been upgraded to provide enhanced security for all sensitive data.

In order to benefit from the new features, we are kindly asking you to change your password. Enclosed you will find a temporary password that will enable you to login to the site for the first time, at which time you will be prompted to change it. Please select a secure password that is at least 6 characters long, and do not share it with anyone. We also urge you to select a password that is different from any other password you have had with us in the past or may hold with any other secure application.
Normally when a company sends out an e-mail like this it is because they were compromised.

Of course, they usually admit they were compromised, so that any users who also used the same login credentials on other sites could take appropriate action.

Has Paxum been compromised-- in any way?

19teenporn 02-10-2012 09:44 PM

Pathetic thread...

BIGTYMER 02-10-2012 09:46 PM

Could have been.

RuthB 02-10-2012 09:46 PM

No, we are simply upgrading our login security to a better system. Thanks for your concern, but everything is fine. :thumbsup

journalism 02-10-2012 10:10 PM

Until when this update will be done Ruth? this has been 6 - 7 hours now!! Its not normal.

B.Barnato 02-10-2012 10:17 PM

Not that it affects me but would one not give a warning well in advance for a downtime due to a planned upgrade?

Operator 02-10-2012 10:18 PM

Fuck your couch

Best-In-BC 02-10-2012 10:33 PM

Nneexxtt

BIGTYMER 02-10-2012 10:35 PM

Now serving #774

keysync 02-10-2012 10:53 PM

Atleast they're not trying to hide some shit and sending out the email with ZERO links in it was a good idea IMO

Fat Panda 02-10-2012 10:58 PM

sounds dangerous

PSD 02-10-2012 11:04 PM

For a company concerned about security, it seems a bit odd they would send everyone new passwords in the clear.

Coup 02-10-2012 11:19 PM

Quote:

Originally Posted by RuthB (Post 18751736)
everything is fine. :thumbsup

Change your passwords... lol

k0nr4d 02-10-2012 11:21 PM

There's two options here.
1) They got hacked and they were using plaintext passwords, and don't want to look stupid so they aren't admitting to it. The fact they recommend 'not using any passwords used before with them' supports this.
2) They really did change "login engines" (whatever that is supposed to mean...they are just authenticating off a database anyways), changed the passwords to use a different cipher and couldn't port over the current logins because they were already hashed and didn't know the existing one.

It does seem pretty fucking stupid to send over new passwords in plaintext via email. What's even stupider is their 'automatic authentication'. Ever notice how no online bank has this? How paypal does not have this? There's a reason... There should be no automatic login, and they shouldn't even have you entering the entire password to begin with - only a few random letters from it to prevent keyloggers/etc from getting access.

AllAboutCams 02-10-2012 11:26 PM

what a joke sending passwords via email

epitome 02-11-2012 12:06 AM

So my perfectly randomized unique many character password has been replaced by a password that was emailed to me without any type of security? That alarms me.

epitome 02-11-2012 12:08 AM

Imagine if a program has $55k in there and the password was sent to an email address employees have access to. Wowza.

anexsia 02-11-2012 12:15 AM

lol at sending out passwords via email...a company that handles other people's money should NEVER do that

k0nr4d 02-11-2012 12:55 AM

edit: nevermind, i'll just msg ruth about this on icq

helterskelter808 02-11-2012 01:05 AM

Quote:

Originally Posted by anexsia (Post 18751893)
lol at sending out passwords via email...a company that handles other people's money should NEVER do that

No site of any kind should have to do this. Does Paxum actually store passwords in plain text too? Ie, is it possible to get your password by email as a 'reminder'? I doubt it, but then again I wouldn't expect any site to be so colossally inept as to send passwords via email under any circumstances in this day and age.

k0nr4d 02-11-2012 01:06 AM

Quote:

Originally Posted by helterskelter808 (Post 18751933)
No site of any kind should have to do this. Does Paxum actually store passwords in plain text too? Ie, is it possible to get your password by email as a 'reminder'? I doubt it, but then again I wouldn't expect any site to be so colossally inept as to send passwords via email under any circumstances in this day and age.

They store it in an md5 hash, you can see it in the cookie named 'toplabs' that they store when you login:
a:3:{s:4:"user";s:25:"[email protected]";s:4:"pass";s :44:"passwordhashhere";s:2:"no";i:13;}

What they store in the cookie is what appears to be a base64-encoded md5 hash. It appears to be salted.

scouser 02-11-2012 01:19 AM

Quote:

Originally Posted by k0nr4d (Post 18751936)
They store it in an md5 hash, you can see it in the cookie named 'toplabs' that they store when you login:
a:3:{s:4:"user";s:25:"[email protected]";s:4:"pass";s :44:"passwordhashhere";s:2:"no";i:13;}

What they store in the cookie is what appears to be a base64-encoded md5 hash. It appears to be salted.

that really the cookie they set when logging in? :upsidedow
wow

DarkJedi 02-11-2012 02:59 AM

That's what i thought when I got the email.

It also didn't let me use my old password, told me to change to something different.

adultforum 02-11-2012 03:10 AM

Hmmm i feel like paxum was hacked. Anothet one bite the dust

Dirty F 02-11-2012 03:19 AM

http://image.toutlecine.com/photos/a...-ho-ii02-g.jpg

V_RocKs 02-11-2012 03:38 AM

SHA-256: Generates a 44-character string using the SHA-256 algorithm specified by FIPS-180-2.

DWB 02-11-2012 03:45 AM

Quote:

Originally Posted by anexsia (Post 18751893)
lol at sending out passwords via email...a company that handles other people's money should NEVER do that

No problem. You're being paranoid. Put all your money in there and use it like a bank.

vdbucks 02-11-2012 04:11 AM

Quote:

Originally Posted by RuthB (Post 18751736)
No, we are simply upgrading our login security to a better system. Thanks for your concern, but everything is fine. :thumbsup

I'm sorry but anyone with half a brain and who knows anything at all about security knows this is bullshit.

You do not take your system down for 'scheduled maintenance/upgrades' that haven't been previously scheduled. If this were really the case, your clients would have had at least a weeks notice, if not more.

Companies who are simply upgrading their security do NOT manually reset all of their clients' passwords. And they certainly do NOT email them in plain text. Especially considering you are a financial institution so to speak.

So please, just come out with it so people know what to expect when trusting their funds with your company. Your shit was compromised, and your clients have a right to know the truth. Lying about it here only makes people (who know better) distrust you.

DarkJedi 02-11-2012 04:13 AM

Quote:

Originally Posted by vdbucks (Post 18752104)
Lying about it here only makes people (who know better) distrust you.

Agreed. Lying about this stuff just makes it worse.

MPGdevil 02-11-2012 04:30 AM

Unable to confirm new password.

Errors :

"The Username must start with a letter, not contain more than one consecutive . or _ . Please enter a value for this field."

What username? There is only a Email and Authorization key field :upsidedow

suesheboy 02-11-2012 04:30 AM

Quote:

Originally Posted by DarkJedi (Post 18752105)
Agreed. Lying about this stuff just makes it worse.

Illegal too.

If they got hacked and you just got lied to, please sue them and complain to the DOJ.

DamianJ 02-11-2012 04:55 AM

Really can't *believe* they sent out passwords in plain text emails.

WTF?

MKA 02-11-2012 05:23 AM

Errors :
Funds were not transferred. Please try again later

I have enough funds (and i'm sending below the daily limit) in my account however i'm getting this message..

Epass part 2 ?

Dirty F 02-11-2012 05:25 AM

Sending out passwords through mail. Especially a company like this.

Seriously, wtf.

journalism 02-11-2012 05:27 AM

The same thing i cannot transfer funds to my master card

helterskelter808 02-11-2012 05:30 AM

Quote:

Originally Posted by MKA (Post 18752184)
Errors :
Funds were not transferred. Please try again later

I have enough funds (and i'm sending below the daily limit) in my account however i'm getting this message..

Epass part 2 ?

Try not to scare people. I'm sure your funds will soon be in motion.

VladS 02-11-2012 05:42 AM

Why the heck do you carry this on the login page?
  • automatic authentication

L.E. I'll just leave it to that.

12clicks 02-11-2012 05:42 AM

I'm shocked!
Shocked, I tell you!

sixsax 02-11-2012 05:47 AM

http://www.radio-popcorn.com/images/SmileyPopcorn.gif

Drama drama drama! Fucking exciting!

Fletch XXX 02-11-2012 05:51 AM

Hope its worked out more and more clients using paxum to pay me everyday.

Dirty F 02-11-2012 06:18 AM

Quote:

Originally Posted by Fletch XXX (Post 18752266)
Hope its worked out more and more clients using paxum to pay me everyday.

People actually pay you?

Rothstein 02-11-2012 06:27 AM

I've never used Paxum before and glad about this.

Rothstein 02-11-2012 06:37 AM

Doesn't look like redpass allows you to save passwords.

boneless 02-11-2012 06:40 AM

same shit here:
Errors :

Funds were not transferred. Please try again later

k0nr4d 02-11-2012 07:08 AM

Quote:

Originally Posted by V_RocKs (Post 18752066)
SHA-256: Generates a 44-character string using the SHA-256 algorithm specified by FIPS-180-2.

Yes, but that hash that is stored can be base64 decoded without errors (at least in the case of my hash) - leaving me with a 32-char hash. Give it a shot on yours and see:
http://www.opinionatedgeek.com/dotne.../base64decode/

CaptainHowdy 02-11-2012 07:14 AM

http://www.lelanicarver.com/wp-conte.../DontPanic.jpg

nikki99 02-11-2012 07:20 AM

gonna re-change my password again

Fletch XXX 02-11-2012 07:23 AM

Quote:

Originally Posted by Dirty F (Post 18752304)
People actually pay you?

Considering you are the one who has no adult business and ive been in business for over 13 years doing adult, one should ask you the same question?

Look DirtyF I know you cant stand me, but doubting my success is absolutely mind boggling.

in my sig there are links to what i do.... you? Nothing you arent even in adult for the most part youve even said this on gfy..., when you actually run a business in adult, then maybe you could address me, until then,... run along

run along and go pay some kid 5 bucks on fiver to make harry potter videos (thats what you recently bragged about is your new promo method) LOL

leave adult to those of us who are professional.

Dirty F 02-11-2012 07:27 AM

Quote:

Originally Posted by Fletch XXX (Post 18752451)
Considering you are the one who has no adult business

I stopped reading here :1orglaugh

Fletch XXX 02-11-2012 07:31 AM

oh id be willing to bet you read the entire post. LOL :)

you read every other post i make, why stop now.

you quote me every single day trolling, you have a hard on for me always have.

LOL


All times are GMT -7. The time now is 04:48 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123