![]() |
JUST GOT HACKED, paysite owners any ideas?
Hey guys
Just got up to 30 new accounts blocked by pennywize and all with prefixed usernames like p2e_974039 p2e_947721 p2e_924163 p2e_924148 etc etc etc We use Epoch, MPA2, Electracash & CCbill right now. & Pennywize to protect the usernames from abuse. And we just dropped PSWbilling last month. Any ideas if any of these processors are vunerable to hackers doing this with password files? We are looking into our servers being hacked as an option. Burning up the members area with mass bandwidth right now, a huge video archive like wildpass.com just burning it up with hacked accounts. Fun and games :) |
brute force pw extraction script?
|
Quote:
|
Were there any transactions behind those usernames? Check if they're from checking, Electracash is open like a barn door.
|
means one of those scripts is creating the password.
You need to figure out what they are using (hopefully you have apache logs and can see where they are getting added) if you need help icq me |
You may want to look into your ccbill scripts.. DO NOT use common directory names with ccbill. There are huge lists that have all the common directory paths for ccbill and many other processors. Use something unique like %_--29AusmAW-_$ as the directory :)
|
Quote:
matt AT jasonandalex DOT com please :) |
i've heard about some hackers being able to do what they like w/ ccbill, not sure how true it is though
|
Electracash, interesting. Could you send me some more info at
matt a_t wildcash.com Thanks guys. Oh and nope the accounts don't seem to have any processing behind them, just the passwords are being added somehow |
Quote:
|
We've ruled out CCbill as we are only just setting them up and they are not fully active yet.
the pricks added 140 passwords we just removed them, they were spread out threwout the password file, must of been adding them for awhile using a script or something. Then unleashed them today |
Dude if you did get hacked dont mention it here. Alot of talented people here on and just reading that will just try to fuck with you now.
|
if you have any 777 files in your setup follow matt's advice, dont use common directory paths. otherwise hit up your processor and see if they have logged IPs for the usernames you mentioned, if its all from the same IP you can ask them to block it out.
|
Good advice Juicy, thanks for the help guys.
|
| All times are GMT -7. The time now is 10:56 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123