GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Password list (check your sites) (https://gfy.com/showthread.php?t=78838)

Mikel 09-24-2002 07:27 AM

Password list (check your sites)
 
I just found this password site this morning and saw that alot of member's area are accessible, maybe you should all take a look, see if your sites are listed here, the list is huge!!!

http://tmd.df.ru/private.html

Have a good day everyone

bd2gk2 09-24-2002 07:32 AM

Damn, I found my site on that list. Looks like I got few passes to kill. Thanks for the heads up!

XXXPaysiteDesign 09-24-2002 07:34 AM

Thats a big list.. mine isn't on there, yay

blakkfrogg 09-24-2002 07:44 AM

Someone needs to beat that password trader into a coma and post pics as a warning to other traders that, "Yes. It CAN Happen to YOU."

"Assholic Wanna' Jerk Off But Don't Wanna' Pay Cretins" -- That is what I think about password traders.

Easy 09-24-2002 07:50 AM

hmm.. I'm on the list too. And I see that pennywize is working

boldy 09-24-2002 07:51 AM

just fucking iframe that list... he'll be out of business in no time

That list is is 1.4 meg!

Pipecrew 09-24-2002 08:18 AM

ouch, ninaknowsbest took a hard hit

Jizar II 09-24-2002 08:30 AM

:mad: the password kiddies needs to die in hell :ak47:

pipp 09-24-2002 08:32 AM

WOW! thats one bad ass password list

gothweb 09-24-2002 08:43 AM

Three passwords to my main site, one to my newer site. Sheesh. How are they getting these passwords? At least seem to be hacked, since they aren't in the CCBill database.

I also checked some sites of friends of mine. That's a lot of passwords for some sites... Scary.

pr0 09-24-2002 08:46 AM

I found a new homepage :thumbsup

w0000000t

danevans 09-24-2002 08:49 AM

df.com seems to be a russian isp, and that password list is probably on some users personal webspace.. Try contacting DataForce support, to remove the list..

pr0 09-24-2002 08:51 AM

Quote:

Originally posted by danevans
df.com seems to be a russian isp, and that password list is probably on some users personal webspace.. Try contacting DataForce support, to remove the list..
How am i supposed to get free porn without this list? Ohhh..right, tgp's...nevermind, go ahead & kill it.

X37375787 09-24-2002 08:56 AM

damn ...:321GFY

Dugmor 09-24-2002 08:58 AM

Yeah it looks like they got me. So if anyone wants to check out my members area's before I kill the passwords enjoy !

deleteduser 09-24-2002 09:08 AM

didnt we have a list like that some month ago? =)
looks nearly the same :BangBang:

Mutt 09-24-2002 10:04 AM

damn he's back.

that guy back in April had the biggest fucking password list of the best sites i'd ever seen. The fucking thing took like 5 minutes to load it was so big.

Gator 09-24-2002 10:21 AM

Here's another for ya boys...

http://pass.nejcpass.com/

jojojo 09-24-2002 10:53 AM

it is 404'd now

Kimmykim 09-24-2002 10:53 AM

Quote:

Originally posted by gothweb
Three passwords to my main site, one to my newer site. Sheesh. How are they getting these passwords? At least seem to be hacked, since they aren't in the CCBill database.

I also checked some sites of friends of mine. That's a lot of passwords for some sites... Scary.

They arent processor lists, I checked ours and some of them were manually added passes, the rest crossed all processors.

magnatique 09-24-2002 10:58 AM

they might not be processor ones, but these guys knew what they were doing..

we had like 15 passwords in there..

and I checked with epoch, and most of all the logins that were used were logins of Long lasting members... all like 2-5 months, recuring members...

Cogitator 09-24-2002 10:59 AM

Some people just run scripts that run dictionary entries until one of them works. That's a real common way of hacking. What you need to do to prevent this is to limit the velocity of logins from a particular IP address, i.e. no more than 5 login attempts per minute, etc. This way, your regular user can retry his login if he fatfingered something, but the scripts trying to hack you will be slowed down to the point of being impractical.

Mutt 09-24-2002 12:59 PM

99% of these guys are only capable of doing brute force dictionary attacks.

Small number who can actually hack and start adding usernames/passwords.

There really is nothing you can do to completely get rid of the problem. They will hammer away no matter what. Pennywize does a great job of keeping them out of your members area fast. What i don't understand about Pennywize users is that most just leave the freeloaders at a deadend Pennywize page.
You might as well get some use from the traffic, it's no worse than TGP, i actually think it's better. So I don't understand why the Pennywize page doesn't redirect to a banner farm or toplists or just console hell.

salsbury 09-24-2002 01:03 PM

some of them might be using the wide open security holes in Epoch's script, if you use Epoch on your site. (i'm told they've "updated" it, but i have yet to see this on any servers.)


All times are GMT -7. The time now is 11:09 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123