Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 03-12-2012, 09:17 AM   #1
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Porn site breached in hack attack

Quote:
Hackers claim to have stolen the details of more than 73,000 subscribers to porn site Digital Playground.

The data includes user names, email addresses and passwords. Also taken were the numbers, expiry dates and security codes for 40,000 credit cards.

The attack is the second successful breach of a site run by website management company Manwin.

A previously unknown hacker group called The Consortium said it was behind the attack.
'Tempting target'

While Manwin investigates, the Digital Playground site has been left online but is not accepting new members and its members area has been taken offline.

The Consortium posted some of the data it stole on the web and said security on the site was full of holes that "made it too enticing to resist" stealing the data.

"This company has security, that if we didn't know it was a real business, we would have thought to be a joke - a joke that we found much more amusing than they will," wrote The Consortium in a log posted on the web.

Visible in the log were admin login names and passwords as well as a selection of the email addresses and user names of some members. Internal emails, details of the four servers underpinning the site and software licence keys were also posted.

The Consortium claims some of the credit card data was stored in plain text form. The group claims to be connected to the Anonymous and Lulzsec hacker groups.

Porn producer Digital Playground is based in California but its website is managed and run by Canadian firm Manwin. The London office of the company declined to comment on the attack.

In a statement provided to porn industry news site AVN, Manwin said it took over management of the site on 1 March and said the breach may have occurred before it took charge.

Manwin management was overseeing the investigation and Digital Playground subscribers had been contacted to let them know what had happened.

In late February, details of more than 6,000 users of YouPorn's discussion forums, known as YP Chat, were stolen. YP Chat is also administered by Manwin. Lax security at a third-party provider was blamed for the breach.
http://www.bbc.co.uk/news/technology-17339508
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:18 AM   #2
Roald
SecretFriends.com
 
Roald's Avatar
 
Industry Role:
Join Date: May 2001
Location: IMC Headquarters
Posts: 27,882
wow again!!!
__________________


WE ARE BUYING PAY SITES! CONTACT ME



ClubSweethearts | ManUpFilms | SinfulXXX | HOT * AdultPrime * HOT


Paying webmasters since 1996! Contact: r.riepen @ sansylgroup.com | telegram: roaldr
Roald is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:25 AM   #3
Wilsy
Confirmed User
 
Industry Role:
Join Date: Oct 2009
Location: UK
Posts: 1,865
Quote:
Originally Posted by Roald View Post
wow again!!!

Twice in one month sucks
__________________
Affiliate Manager
Wilsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:26 AM   #4
OverdueNudes
Confirmed User
 
OverdueNudes's Avatar
 
Industry Role:
Join Date: Nov 2008
Posts: 606
Some people just don't learn the first time!!
__________________
Great Whitelabel Dating
OverdueNudes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:27 AM   #5
jigg
Confirmed User
 
Join Date: Feb 2002
Posts: 2,527
"The Consortium claims some of the credit card data was stored in plain text form"

really? in 2012?

Idiots
jigg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:31 AM   #6
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
https://gfy.com/showthread.php?t=1060217

Time warp ....
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:33 AM   #7
porno jew
Too lazy to set a custom title
 
Industry Role:
Join Date: Nov 2006
Posts: 10,166
think someone hacked the internet timeline instead.
porno jew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:35 AM   #8
scouser
marketer.
 
Industry Role:
Join Date: Aug 2006
Location: bcn
Posts: 2,280
wasnt this a few days ago? or is this a new one?
scouser is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:38 AM   #9
directfiesta
Too lazy to set a custom title
 
directfiesta's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,589
Quote:
Originally Posted by jigg View Post
"The Consortium claims some of the credit card data was stored in plain text form"

really? in 2012?

Idiots
That contrevenes the bank merchant account terms
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT !

But I can't figure out how he can breathe or type , at the same time ....
directfiesta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:40 AM   #10
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Great Scott!

DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:40 AM   #11
Fat Panda
Porn is Dead. Move along.
 
Fat Panda's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 13,295
Please report all crimes to the FBI or http://www.ic3.gov/default.aspx
Fat Panda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:44 AM   #12
lucas131
¯\_(ツ)_/¯
 
Industry Role:
Join Date: Aug 2004
Posts: 11,475
Quote:
Originally Posted by SAC View Post
Please report all crimes to the FBI or http://www.ic3.gov/default.aspx
nice site, is it yours? wanna trade hardlinks?
lucas131 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 09:52 AM   #13
Rothstein
So Fucking Banned
 
Industry Role:
Join Date: Jan 2012
Location: Frostburg, MD
Posts: 682
more like manlose
Rothstein is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 10:05 AM   #14
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Quote:
Originally Posted by jigg View Post
"The Consortium claims some of the credit card data was stored in plain text form"

really? in 2012?

Idiots
A free tip for them and anyone with a similar system where the web server needs access to the same database that holds billing information:

Use federated tables. Tables with sensitive data like card numbers are on an intranet machine, behind the firewall. Card numbers etc. can be encrypted with Twofish or AES. That intranet server then federates the user table from the web server, so the public web server only has access to the data it needs.

Which tables go on the protected intranet machine and which on the public web server? The web server should hold only the tables it needs to do it's job. Any data that doesn't HAVE to be on the web server isn't placed there.

Similarly for internal email - run your internal IMAP from the intranet, preferably with each essential service on a VM which has one way access control so it can make only outgoing connections if at all possible, and only to those internet servers it needs to access.

The theme here is clear separation between public data (web pages) and secured data. The same concept makes transparent tours less secure, despite their convenience.

Last edited by raymor; 03-12-2012 at 10:12 AM..
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2012, 10:05 AM   #15
bean-aid
So Fucking Banned
 
Industry Role:
Join Date: Jun 2011
Location: the land of woke sleuths
Posts: 16,493
Whenever this happened everyone should be aware that storing credit cards in plain text is a *huge* violation of every credit card company.

It is stored in an encrypted vault usually by your gateway to your biller.

Last edited by bean-aid; 03-12-2012 at 10:07 AM..
bean-aid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.