![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
No comment
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jul 2011
Posts: 552
|
erm, hello fristopher
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
so how you got that members url link? there are some numbers i havent seen anywhere else in the video ... you are something like magician?
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
i didn't see in your screencast how you got the path in /members to the WMV file.
and the purpose of copying the URL of the jpeg?
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
So Fucking Banned
Industry Role:
Join Date: Sep 2010
Posts: 3,405
|
Shouldn't you be telling the site, rather than promoting it here?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,601
|
Quote:
There is the studio name and the video id which is needed. But how he got the url structure to the members area remains a question ![]()
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
It's over there...
Industry Role:
Join Date: Nov 2004
Location: Portugal
Posts: 4,212
|
Quote:
or anything like that since u can directly access the movies and download them :P
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
So Fucking Banned
Industry Role:
Join Date: Sep 2010
Posts: 3,405
|
Quote:
In 'hacker' circles, when a security hole is discovered, it's good practice to inform the site or software vendor with the hole before announcing it publicly. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
Quote:
![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
Why would you make a screencast like that?
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
one of the easiest sites to get in imho, downloading some tanner mayes movie right now. and yes i used an username and password, was easy to guess em...
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
i don't get it - the /members directory is password protected but when you link to a file directly within that directory you can play or download it without getting a password prompt box.
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Dec 2006
Posts: 1,497
|
this shit does work, just tried it.. they should look into their server protection I guess
__________________
¤´¨) ¸.•´¸.•*´¨) ¸.•*¨) (¸.•´ (¸.•`¤ICQ:491 496 482 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Confirmed User
Industry Role:
Join Date: Jul 2005
Location: icq#: 639544261
Posts: 1,965
|
Quote:
Porn. Where the amateur coder is king.
__________________
I'm out. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Too lazy to set a custom title
Industry Role:
Join Date: Mar 2004
Posts: 16,116
|
Looks to be patched here. Keep getting a login popup.
__________________
Your Paysite Partner Strength In Numbers! StickyDollars | RadicalCash | KennysPennies | HomegrownCash |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Unregistered Abuser
Industry Role:
Join Date: Feb 2006
Posts: 25,447
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Apr 2011
Location: En la reverendisima concha de tu madre!
Posts: 3,034
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
|
LOL I can't belie this shit...
![]() If they hired me to make a CMS for them or have consulted me on security issues - this would NEVER be possible. ![]() If you are SELLING something - you need to PROTECT IT!!! There are only 2 ways to do it right: 1. put .htaccess password on members folder (+brute force protection) 2. putting your content outside public_html/www folder and reaching it using php (or whatever you use) http://www.awmzone.com/services
__________________
Make a bank with Chaturbate - the best selling webcam program ![]() ![]() ![]() Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!! PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email: ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Vegas
Posts: 3,243
|
Guys, come on.. this is really easy stuff.. almost all elevated x site you can do this.. with
I just checked.. and it works on pornstar and like 10 other sites.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2002
Posts: 34,431
|
then that's a major fail on elevated-x's part.
__________________
I moved my sites to Vacares Hosting. I've saved money, my hair is thicker, lost some weight too! Thanks Sly!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Registered User
Industry Role:
Join Date: Aug 2011
Posts: 27
|
Quote:
Anyone know any good tools to protect content? -max |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: Nov 2009
Location: Heaven
Posts: 4,306
|
wooohoo....more free porn.,
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: Vegas
Posts: 3,243
|
well it is not all elevated x sites.. but a lot of them use the members content to link to the tour..
I found out about this because one of my sites ( not even open yet.. ) was getting hammered.. but it was just one video.. my site http://notnormaltoys.com/tour/1/?nat...cuMC4wLjAuMC4w from my server logs ( most popular files in order) /tour/1/category.php /tour/1/ /_assets/data/options/font/bebasneue-webfont.woff /content/upload/(**********)/(***).wmv /content/upload/(**********)/(******).wmv well the last 3 are protected by the members area.. unless you know the direct link.. you can download the content.. I have tested this on like 20 different elevated x sites.. and if you know some basic information you can get pretty much anything.. Some sites are harder than others.. ---- |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Confirmed User
Industry Role:
Join Date: Nov 2002
Location: Southern California
Posts: 1,306
|
Quote:
I know it wasn't your intention but you inferred that Elevated X is somehow flawed and allows free downloading of content (the title of this thread). As a long time customer you know this is not the case. For the record - Elevated X DOES NOT power pornstar.com You may be surprised to learn that Elevated X DID have obfuscation in the early days. It was later removed because there wasn't as much benefit to overcome some of the problems it created such as on the fly, random naming and cache invalidation that wreaked havoc on high traffic sites. -------------------------------------------------------------------------------------- Some content protection facts for sites without obfuscation: -------------------------------------------------------------------------------------- 1) Content that resides behind htaccess or another protection method can't be linked to unless you're already logged into the site. In this case, nobody is getting free porn, the person accessing it is already a paying customer. 2) A user needs to know the folder name of the update and the filename of the content itself in order to get to it. This means they already need to be on a page of the site to get the content. They're not going to magically guess where the content is and get it all for free. 3) Nearly all Elevated X customers (and any smart pay site owner) uses site protection scripts along with their CMS and billing/auth process. 4) Unless you've symlinked your content folder or done something to remove authentication/protection from your site there's no way for tour surfer or any non-member to get to your content. 5) The only area this poses any concern whatsoever for an Elevated X customer might be inside a trial area where someone has a membership and could start looking at source code and hitting 1 link at a time. We've yet to see this be a cause of concern. Keep in mind all of us are professionals and are web savvy. Yes, a very select few will do it but the average guy who buys a membership isn't going to start viewing source code and copying a path fragment and then manually type in a video filename and view or download them 1 by 1. A video collector type of guy might but the typical consumer won't go to the trouble. 6) The real problem is as much about how people name their video files e.g. 1, 2, 3 for every update and not appending any prefix or suffix to them. Makes it too easy for people to just add 1, 2, 3 to the end of a URL and watch video after video. -------------------------------------------------------------------------------------- NOTE TO ELEVATED X CMS CUSTOMERS: -------------------------------------------------------------------------------------- In 5 years of running Elevated X, less than 10 customers have ever mentioned this being an issue or said they wanted obfuscation. This leads me to believe it's not really posing much of a problem to most people. If it is, by all means, submit a support ticket and suggest it and if enough people really need this we'll look to add it to the software and make it happen. AJ
__________________
Owner, Elevated X - The 4 Time Award Winning Adult CMS Software Company Used by More Than 2000 Adult Sites. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Industry Role:
Join Date: Nov 2002
Location: Southern California
Posts: 1,306
|
Just an update -
As a result of this thread we've just posted a knowledge base help file for Elevated X customers who are using a free or limited trial area and want to make it impossible for anyone to get to your non-trial content. Trial members can no longer get to the non-trial content if they try to download it by hitting the URL directly. ![]() AJ
__________________
Owner, Elevated X - The 4 Time Award Winning Adult CMS Software Company Used by More Than 2000 Adult Sites. |
![]() |
![]() ![]() ![]() ![]() ![]() |