Greenguy's Board


Go Back   Greenguy's Board > Possible Cheaters
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-12-02, 06:01 PM   #1
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
Hacker try to steal money from my account

One prick hacked my account on the sponsor (I'm sure due to the relativily simple password, not because sponsor database has been hacked)

And changed payment info to this (payment by Check):

Company Name: Imantas Liudkevicius
First Name: Imantas
Last Name: Liudkevicius
Address Line 1: Liudo Giros 82-26
City: Vilnius
State/Province: LT
Zip Code: 06315
Country: Luthuania

Check your info, may be you ripped off too.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-02, 06:24 PM   #2
Chop Smith
Eighteen 'til I Die
 
Chop Smith's Avatar
 
Join Date: Apr 2003
Location: Mississippi
Posts: 2,168
Send a message via ICQ to Chop Smith
That sucks.

Was Lithuania a part of the former Soviet Block?
__________________
Chop Smith is offline   Reply With Quote
Old 2005-12-02, 09:12 PM   #3
Halfdeck
You can now put whatever you want in this space :)
 
Halfdeck's Avatar
 
Join Date: Oct 2004
Location: New Haven, CT
Posts: 985
Send a message via ICQ to Halfdeck
Hey Kit,

thanks for the heads up. BTW, I usually type long string of jibberish for passwords, like 8sbw9g2nftDFaDz32.
__________________
Success is going from failure to failure without a loss of enthusiasm.
Halfdeck is offline   Reply With Quote
Old 2005-12-03, 10:16 AM   #4
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
Yes, I changed all paswwords to the unique.
Yes, the Luthuania is the former soviet republic.
BTW, I had a similar problem a month ago, the address has been switched to the Netherlands address.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-03, 10:33 AM   #5
eman
Solipsists of the world unite
 
eman's Avatar
 
Join Date: Oct 2003
Location: xxx axis
Posts: 639
I've not yet had a problem with sponsor accounts but I'm continually surprised at how many email spammers know the names of the people I regularly talk to.
eman is offline   Reply With Quote
Old 2005-12-04, 07:35 AM   #6
Linkster
NO! Im not a female - but being a dragon, I do eat them.
 
Linkster's Avatar
 
Join Date: Mar 2003
Location: Sex Delta
Posts: 5,084
Send a message via ICQ to Linkster
Kit - it would probably be a good idea to post the sponsor as there have been cases in the past where a sponsors database has been hacked - it would let us check without going through 100s of sponsors
__________________
Pussy Chompers
Porn Links
NSCash
Linkster is offline   Reply With Quote
Old 2005-12-04, 01:46 PM   #7
ronnie
Wheither you think you can or you think you can't, Your right.
 
Join Date: Jun 2004
Location: midwest
Posts: 2,274
Send a message via ICQ to ronnie
Quote:
Originally Posted by Linkster
Kit - it would probably be a good idea to post the sponsor as there have been cases in the past where a sponsors database has been hacked - it would let us check without going through 100s of sponsors
Great Idea, I agree..

ronnie
ronnie is offline   Reply With Quote
Old 2005-12-04, 01:52 PM   #8
flyeruk
With $10,000, we'd be millionaires! We could buy all kinds of useful things like ... love!
 
flyeruk's Avatar
 
Join Date: Aug 2003
Location: North East, UK
Posts: 319
That would be great

Took me all day to change my info when I was moving house... lol

Lisa
__________________
Clixxx4porn | Adult XXX | Erection Zone
flyeruk is offline   Reply With Quote
Old 2005-12-04, 07:42 PM   #9
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
I'm sure, there is not a sponsor side problem. The only thing i can tell you, it's a NATS script. But I'm sure, there is not a database hacking. I discussed this problem with Nathan (NATS) and he promised to implement the new strict rules for the payment info changing ASAP. The problem in some new affiliate solutions, they don't send notifications by e-mail about payment info changes. There is a key feature for every program fighting the hackers activity.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-04, 07:48 PM   #10
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
Payment info must be locked after submit, at least partially locked and send verification ot notification to the original e-mail address.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-04, 09:31 PM   #11
Linkster
NO! Im not a female - but being a dragon, I do eat them.
 
Linkster's Avatar
 
Join Date: Mar 2003
Location: Sex Delta
Posts: 5,084
Send a message via ICQ to Linkster
Kit - I know that you want to believe that - but any program can be hacked - and it wouldnt surprise me one bit that Nats has already been hacked many times - it would be helpful to the rest of us to know which sponsor it is so we can check to make sure that it wasnt just you that had their info changed - nothing against any sponsor - just good info
__________________
Pussy Chompers
Porn Links
NSCash
Linkster is offline   Reply With Quote
Old 2005-12-05, 09:24 AM   #12
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
Because two different accounts has been hacked, I'm sure, it's not a sponsor related issue.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-05, 02:32 PM   #13
juggernaut
Registered User
 
juggernaut's Avatar
 
Join Date: Apr 2005
Location: Central Jersey! If I was rich and powerful I would dress as my avatar does.
Posts: 1,448
Send a message via Yahoo to juggernaut
All I can say is pass phrase pass phrase pass phrase. Most of the time I use a simple password for things I really dont care about, but for important things it's one of two. 11 char, #'s and sym's (I have had one that I use for the past 4 years and every program I run on it takes 5 days and it only gets 1/2 the password) the 2nd more secure goody I like to use is a pass phrase like. IE: IwasBorninacroSSfirehuricain@12:10Am
If they can crack a pass phrase they deserve you stuff.
juggernaut is offline   Reply With Quote
Old 2005-12-05, 04:06 PM   #14
DangerDave
Bonged
 
DangerDave's Avatar
 
Join Date: Mar 2003
Location: BrisVegas, AUSTRALIA
Posts: 4,882
Kit, in the words of some great people that went before me - shit or get off the pot!

You have no problem naming the scammer in this thread, or disclosing privileged information in your DMOZ thread, so name the goddamn sponsor, so we can check and get back to work..

DD
__________________
Old Dollars >>>> Now with over 90 Hosted Free Sites <<<<
DangerDave.com.au - Adult Links to Free Porn
DangerDave is offline   Reply With Quote
Old 2005-12-05, 05:52 PM   #15
Chop Smith
Eighteen 'til I Die
 
Chop Smith's Avatar
 
Join Date: Apr 2003
Location: Mississippi
Posts: 2,168
Send a message via ICQ to Chop Smith
gnats - annoying flies
__________________
Chop Smith is offline   Reply With Quote
Old 2005-12-16, 07:23 PM   #16
garry
Internet! Is that thing still around?
 
Join Date: Dec 2005
Posts: 3
Quote:
Originally Posted by kit
One prick hacked my account on the sponsor (I'm sure due to the relativily simple password, not because sponsor database has been hacked)

And changed payment info to this (payment by Check):

Company Name: Imantas Liudkevicius
First Name: Imantas
Last Name: Liudkevicius
Address Line 1: Liudo Giros 82-26
City: Vilnius
State/Province: LT
Zip Code: 06315
Country: Luthuania

Check your info, may be you ripped off too.
I will use my first post here on this great board to say thank you to “Kit” from www.porninspector.com for contacting me and making me aware of this issue. We have now added this to the MPA3 source and
we will automatically upgrade all running mpa3s with this feature when we do our next scheduled upgrade.

Or if any program want this added earlier we are happy to do that up on request!

So again, thanks Kit for bringing up this issue, and if anyone have any other feature requests be sure to let me know. We are here for you !
garry is offline   Reply With Quote
Old 2005-12-16, 07:38 PM   #17
garry
Internet! Is that thing still around?
 
Join Date: Dec 2005
Posts: 3
Oh, forgot to mention, we went a step further too, we also added brute force protection as well. If someone tried to log in to your account using the wrong password 3 times or more the account get closed for 2 hours and you will be notified by email.
__________________
Garry
President And Founder Of
MansionProductions.com
ICQ:11564972
garry is offline   Reply With Quote
Old 2005-12-17, 09:35 PM   #18
Mattinblack
Asleep at the switch? I wasn't asleep, I was drunk
 
Join Date: Nov 2005
Location: London UK in a house share with three 28 yr old girls...perv perv
Posts: 215
Sigh. I have lost count of how many times I have read threads like this on adult and non adult webmaster forums. We live in an age where every company that has a financial payments side to it is capable of being targetted by hackers worldwide, many of the Soviet Mafia hackers have KGB/GRU info war training and a data stick in their back pocket full of hack utilities from the soviet military.

In a previous life I was in charge of all aspects of a large installation and most of the security holes that were exploited had nothing to do with scripts on servers or database security as such. They were mostly Windoze vulnerabilities. The worst problem we had was a guy we simply could not trace for weeks. It turned out that he had taken over a humble PC that was used by the artwork department to process batches of image files.

Of necessity it had its own internet connection and when the system was designed was not connected to our intranet. Some bright spark decided to run an ethernet cable and connect it so that he could backup files onto our main server instead of burning optical discs. The hacker had zombified the PC, run a packet sniffer and a trace utility to map our network and headed straight for accounts.

Luckily we were running our accounts on a legacy HP mainframe and not a PC system, he was obviously all at sea and made some mistakes. If it was a Windoze or unix system we would probably stil be scratching our heads.

The learning outcome of this decision was that I have decided to firewall ANY secure data behind the wierdest and wackiest hardware/software I can find with lots of security logging and audit trails. Hint there are a lot of old but perfectly servicable Dec Minis out there .....If there is only one access pipe and its monitored and logged for any suspicious activity then it can be stopped before too much damage is done. The trouble with using Windoze and unix boxes for this activity is that there are too many unpatched security holes that are well documented and with exploits written for them. Who is to say the machine doing the watching is not itself compromised? If the machine monitoring and controlling the pipe is one which few people know anything about then its much more secure.
__________________
Mattinblack - <a href="http://pornlinks.kwikfire.com">PornLinks</a> - <a href="http://strange-attractor.kwikfire.com">Strange Attractor</a> - <a href="pnav.kwikfire.com">PORNavigator</a> - <a href="http://ukescort.kwikfire.com/">Fem Escorts</a> - <a href="http://kwikfire.com/">Hosting</a>
Mattinblack is offline   Reply With Quote
Old 2005-12-20, 09:22 AM   #19
kit
Do you want the job done right, or do you want it done fast?
 
Join Date: Sep 2003
Posts: 494
Send a message via ICQ to kit
Quote:
Originally Posted by Mattinblack
many of the Soviet Mafia hackers have KGB/GRU info war training and a data stick in their back pocket full of hack utilities from the soviet military.
The pure predujice. After USSR crushing, many people morally degraded especially teenagers in their 10 y.o. They are the real hackers and carders, their average age is 18-25 years now. They're still here because the weak state. But I hope (and really see during last years) how they getting screwed!

There is a big problem with Eastern Europe and Asian countries.
__________________
PornInspector.com
kit is offline   Reply With Quote
Old 2005-12-21, 05:36 AM   #20
Mattinblack
Asleep at the switch? I wasn't asleep, I was drunk
 
Join Date: Nov 2005
Location: London UK in a house share with three 28 yr old girls...perv perv
Posts: 215
Quote:
Originally Posted by kit
The pure predujice.
No prejudice intended Kit. This is from experience and advice from UK law enforcement.

Quote:
Originally Posted by kit
teenagers in their 10 y.o. They are the real hackers and carders, their average age is 18-25 years now.
Yeah they can get into sites that have little or no security. However the attacks on the well secured big-money sites are nearly all organised crime, and those are nearly all Russian Mafia, and they employ nearly all ex KGB/GRU Information Warfare specialists. This is what was patiently explained to me a year ago by the deputy head of Londons Scotland Yard Computer Crime division after a site with state of the art security and storing a few thousand sets of personal financial details was comprehensively trashed.

We had insurance but our concern was 'where was the hole in our security' the worrying thing was all three experts we hired plus the polices own expert concluded there werent any. The even more worrying thing was that the police had at least 2-3 cases like this a month in the UK alone. The IP addresses all traced back to the same server which was on a dial-up line physically located in the Ukraine but was mobile on the trunk network (ie that too had been hacked and whenever you try to trace a number the software reports a different one back).
__________________
Mattinblack - <a href="http://pornlinks.kwikfire.com">PornLinks</a> - <a href="http://strange-attractor.kwikfire.com">Strange Attractor</a> - <a href="pnav.kwikfire.com">PORNavigator</a> - <a href="http://ukescort.kwikfire.com/">Fem Escorts</a> - <a href="http://kwikfire.com/">Hosting</a>
Mattinblack is offline   Reply With Quote
Old 2005-12-21, 06:52 AM   #21
urb
All the way from Room 101
 
urb's Avatar
 
Join Date: Aug 2003
Posts: 3,557
Send a message via ICQ to urb
Quote:
Originally Posted by Mattinblack
This is what was patiently explained to me a year ago by the deputy head of Londons Scotland Yard Computer Crime division ...
Interesting circles you move in, to be sure.
__________________
urb is offline   Reply With Quote
Old 2005-12-22, 04:36 AM   #22
Mattinblack
Asleep at the switch? I wasn't asleep, I was drunk
 
Join Date: Nov 2005
Location: London UK in a house share with three 28 yr old girls...perv perv
Posts: 215
Quote:
Originally Posted by urb
Interesting circles you move in, to be sure.
I used to work for a *big* company in the UK before I went freelance Urb. When you have big and very public problems that make the national press then you do what you gotta do! Hell if I thought it would have helped I would have brought in the SAS and a squadron of Royal Corgis!

Eventually got so stressed out that my doctor said ;
'change jobs or else'
__________________
Mattinblack - <a href="http://pornlinks.kwikfire.com">PornLinks</a> - <a href="http://strange-attractor.kwikfire.com">Strange Attractor</a> - <a href="pnav.kwikfire.com">PORNavigator</a> - <a href="http://ukescort.kwikfire.com/">Fem Escorts</a> - <a href="http://kwikfire.com/">Hosting</a>
Mattinblack is offline   Reply With Quote
Old 2005-12-21, 10:16 AM   #23
Papa
Kids are great, Appu. You can teach them to hate the things you hate and they practically raise themselves now-a-days, you know, with the internet and all
 
Join Date: Nov 2005
Posts: 190
Quote:
Originally Posted by kit
The pure predujice. After USSR crushing, many people morally degraded especially teenagers in their 10 y.o. They are the real hackers and carders, their average age is 18-25 years now. They're still here because the weak state. But I hope (and really see during last years) how they getting screwed!

There is a big problem with Eastern Europe and Asian countries.
I'm afraid to say that they won't dispear. Imagine the "skills" of a 25year old guy if he started in this shit 10 years ago
Wow, i'm sure he could hack anything !
Papa is offline   Reply With Quote
Old 2005-12-30, 06:31 PM   #24
DJilla
You can now put whatever you want in this space :)
 
DJilla's Avatar
 
Join Date: Sep 2005
Posts: 525
Send a message via ICQ to DJilla
Quote:
Originally Posted by Mattinblack
It turned out that he had taken over a humble PC that was used by the artwork department to process batches of image files.

Of necessity it had its own internet connection and when the system was designed was not connected to our intranet. Some bright spark decided to run an ethernet cable and connect it so that he could backup files onto our main server instead of burning optical discs.
I gotta say, that everything you've posted here is so completely correct and "classic" that I was almost doubting you didn't just lift this from a book.... up until you mentioned using a PDP as a front end which is really quite a clever, cheap and innovative idea. OK... I believe you! (not that I think you care). What I don't get is why you'd leave the leading edge field of security for this stuff? Stress...?!!!>><??! Agggh... buck it up soldier!
DJilla is offline   Reply With Quote
Old 2006-01-01, 09:13 AM   #25
Mattinblack
Asleep at the switch? I wasn't asleep, I was drunk
 
Join Date: Nov 2005
Location: London UK in a house share with three 28 yr old girls...perv perv
Posts: 215
Was hardly on the leading edge of security Urb- just managing the companies web business. Also happento be a bit of a techie.

As for why... my doctor told me if I did not fin a less stressful career then my life expectancy would be measured in months rather than years. Adult is not all that I do - I enjoy the variety of work!

Matt
__________________
Mattinblack - <a href="http://pornlinks.kwikfire.com">PornLinks</a> - <a href="http://strange-attractor.kwikfire.com">Strange Attractor</a> - <a href="pnav.kwikfire.com">PORNavigator</a> - <a href="http://ukescort.kwikfire.com/">Fem Escorts</a> - <a href="http://kwikfire.com/">Hosting</a>
Mattinblack is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 07:15 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc