Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-04-2009, 09:45 AM   #1
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
:stop Comus Thumbs Backdoor/Trojan: Don't be reading this now, then post next week crying.

Just imagine losing ALL Google SE Traffic and ALL Firefox Surfer traffic on ALL of your sites OVERNIGHT!! potentially for days, weeks even months.. (it could happen to you).

There are a few threads circulating around about Comus Thumbs being vulnerable (again) to a backdoor/trojan issue:

I got hit... (FYI.. I have multiple servers, but out of the 250+ sites on the server i had my only copy of Comus on, only about 35-40 or so other sites got infected before I was able to catch it... )

BUT it jumped to over 18 different master accounts on that server.. because of that, it made it extremely frustrating and time consuming to remove...

Anywhoo..
This thread has some info on how to remove the backdoors/trojans:
Secure/Delete your Comus Installation, ALL HTML/PHP Files on Server infected (credit to hjnet)

My approach was slightly different, I used these two commands to search:
a) grep -R "6966202873" * > list_of_backdoor_files
b) grep -R "59} else if" * > list_of_infected_files

my second scan for infected files (b) is different than what was in the thread I mentioned because with the help of my host we found that the code mutated spontaneously and the code you were using did not always catch them...

I think that because many of my toplists that were infected were set to re-rank every 10 minutes so the mutation was more noticeable.

This is not just about the hassle of finding/ removing the backdorrs/trojans and losing traffic until you figure it out... The sucky part about all of this is Google (safebrowsing.clients.google.com) flagged a bunch of my sites before I could remove the trojans, thereby killing the traffic on at least 8-10 or so of them. (not only killed SE traffic by saying my site will harm your computer in the search engine results pages, but also Firefox users get a big red warning screen, so the toplists are pretty much dead as far as surfers using firefox, except for IE surfer traffic).

Now I have to go request that the flagging be removed.. I wonder how long that will friggin take??????????? (This is where my first line comes in about losing that traffic for days/weeks/months).

Never going back to Comus... that was not a fun ordeal.. took several days to narrow it down and then 2 days to remove (1 of which was figuring it out)... between the lost work time and lost traffic this was kind of expensive.

Anyone who has Comus thumbs really should not gamble with keeping the script with the "Wait and See" attitude.. (especially if you have your own servers with multiple sites on them)...

This could potentially put some people completely out of business..

Even though it hurt me, I got lucky... I only had one copy of Comus on one server, but if i would have had it on all of my servers, and had been on vacation giving it time to spread to all of my sites (nearly 1000 sites) that would have killed me.

Don't be reading this today and then posting here next week crying...

Last edited by Naughty-Pages; 10-04-2009 at 09:49 AM..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 09:51 AM   #2
Twig
Confirmed User
 
Twig's Avatar
 
Join Date: Nov 2005
Location: ICQ - 703894
Posts: 1,949
fuck your avatar is sexy
__________________
Twig is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 09:54 AM   #3
hjnet
Confirmed User
 
Join Date: May 2002
Location: European Union
Posts: 3,815
Good to mention this again, the Google Warning gets removed rather quickly, took ~24h for MOST of my sites, unfortunately for one of my sites it took almost 2 weeks.....
hjnet is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 10:10 AM   #4
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by hjnet View Post
Good to mention this again, the Google Warning gets removed rather quickly, took ~24h for MOST of my sites, unfortunately for one of my sites it took almost 2 weeks.....
~24h? that's not too bad.. I've got quite a few blocked, I hope I don't get any of those with a 2 week block...

Quote:
Originally Posted by Twig View Post
fuck your avatar is sexy
Thanks man.. I can shoot some content of her if ya need some ;) (problem is lately her availability has been kinda sucky)..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 10:34 AM   #5
BlueDude
Confirmed User
 
Join Date: Apr 2008
Posts: 271
comus already lost a great deal of webmasters.
BlueDude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:02 AM   #6
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
from what i know, tony is working on it, he found where they possibly came in and is removing the files/dependencies.

forum is currently offline as they hit that one as well.

Im trying to get him to work as fast as possible on it, but it a hell of a job. also involves thinning comus out to the pure basics of the script namely a thumb rotator, nothing more and nothing less.

He also had to move the license admin cause of the hacks, and that is one hell of a beast to move around.

google is fast in removing the sites from blocked to unblocked, takes less then 12 hours if done properly.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:05 AM   #7
Marcus Aurelius
No Refunds Issued.
 
Marcus Aurelius's Avatar
 
Industry Role:
Join Date: Apr 2003
Posts: 14,809
Bump for the cause. good luck to all affected webmasters.
Marcus Aurelius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:13 AM   #8
cykoe6
Confirmed User
 
cykoe6's Avatar
 
Industry Role:
Join Date: Apr 2005
Location: Vegas
Posts: 4,499
Delete your Comus installs right away or you will be totally fucked. I caught them a few hours after they hit me and was able to straighten it out pretty quickly but it can really fuck your shit up bad.
__________________
бабки, шлюхи, сила
cykoe6 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:42 AM   #9
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by boneless View Post
google is fast in removing the sites from blocked to unblocked, takes less then 12 hours if done properly.
Final count on what was blocked was only 13 sites out of the batch of infected sites. Just finished submitting the requests.. 12 hours (or even the 24 mentioned before) would be sweet.

even if it is 12 to 24 hours, I'm sure if any webmasters who have toplist accounts visit the toplists, they'll probably pull their links, even though the infections were removed, due to the warning in firefox..

I guess I can't complain too much, it could have been far worse had I not caught it when I did, or if I had Comus on all of my servers.
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:12 PM   #10
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
I don't know how you people got infected? Was it your computer and then when accessing the server via FTP it spread there too? I myself, never had problems with comus thumbs and I believe that's because I keep my server very clean and maintained properly. Among all the security mechanisms I've implemented there I have mod_security on apache, and few password protected directories where comus resides.

I also have clamAV for scanning and removing infected files. So far, only one account on the server got infected, and that's my friend's account who had his computer infected. But all my sites are totally ok.

That's why I am wondering how the hell did you get hit by this shit? What security hole is exploited on comus, from where?
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:24 PM   #11
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by beta-tester View Post
I don't know how you people got infected? Was it your computer and then when accessing the server via FTP it spread there too? I myself, never had problems with comus thumbs and I believe that's because I keep my server very clean and maintained properly. Among all the security mechanisms I've implemented there I have mod_security on apache, and few password protected directories where comus resides.

I also have clamAV for scanning and removing infected files. So far, only one account on the server got infected, and that's my friend's account who had his computer infected. But all my sites are totally ok.

That's why I am wondering how the hell did you get hit by this shit? What security hole is exploited on comus, from where?
It is not an infected PC issue (scanned all my systems twice with 2 different AV scanners and also spybot.. I'm not a noob, owned a computer shop for 7 years, sold it and then did computer networking and security for multiple government offices before switching to doing adult shit full time).

It is not an FTP issue (checked all FTP logs, nothing other than my IP and everything was exactly what I had uploaded/downloaded).

I ran ClamAV when I first noticed the problem, it picked up shit.. it found nothing even though the server was infected.

"Somewhere" in Comus is a vulnerability which allows backdoor files to be created, then those backdoors create the trojans across the server.

If you have not been hit, it is simply because your script has not yet been targetted. It could be an hour from now, a week from now, a year from now, or never. Just because it is vulnerable, does not mean you WILL get infected.. it just means it's possible.. but if I were a betting man, I would say it will probably happen sooner or later to you.

Comus thumbs site has been messed up for some time, and then this issue occured.. with no mention from them about what's up, with the exception of boneless commenting in a few threads that they are trying to deal with it.

Last edited by Naughty-Pages; 10-04-2009 at 12:26 PM..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:30 PM   #12
Dennis69
Confirmed User
 
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
Fucking peice of shit Comus... I got hit as well... thousands of galleries etc! Fuck the free/skim traffic traders for this guy! Pisses me is I use love Epower.. bought it years ago but guess who bought that from Epower... anything that has to do with Comus creators is coming off my servers!!!!
__________________
HaHaHa

Last edited by Dennis69; 10-04-2009 at 12:31 PM..
Dennis69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:37 PM   #13
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by Dennis69 View Post
Fucking peice of shit Comus... I got hit as well... thousands of galleries etc! Fuck the free/skim traffic traders for this guy! Pisses me is I use love Epower.. bought it years ago but guess who bought that from Epower... anything that has to do with Comus creators is coming off my servers!!!!
so whats the issue then with epower? maybe think before ya post mate... epowerstill works like it allways has...
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:49 PM   #14
Dennis69
Confirmed User
 
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
Quote:
Originally Posted by boneless View Post
so whats the issue then with epower? maybe think before ya post mate... epowerstill works like it allways has...
Epower was awesome but when Comus bought it they changed some stuff around... and right now anything that Comus touches I don't trust! I've got nothing against the ORIGINAL Epower script
__________________
HaHaHa
Dennis69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 12:52 PM   #15
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by Dennis69 View Post
Epower was awesome but when Comus bought it they changed some stuff around... and right now anything that Comus touches I don't trust! I've got nothing against the ORIGINAL Epower script
so what changed? the fact that epower now runs from an ept dir? has an auto upgrade function? easier licensing system? or something else i missed as being the tech support for epower?
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:00 PM   #16
Dennis69
Confirmed User
 
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
Quote:
Originally Posted by boneless View Post
so what changed? the fact that epower now runs from an ept dir? has an auto upgrade function? easier licensing system? or something else i missed as being the tech support for epower?
Cool... wish I would of found you after Comus bought the script and I did there upgrade and I never did it to work right for me anymore!
__________________
HaHaHa
Dennis69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:06 PM   #17
18teens
Confirmed User
 
Industry Role:
Join Date: Dec 2002
Posts: 1,605
I'm just glad I heeded the warnings about Comus a few weeks ago and got rid of it.
18teens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:12 PM   #18
Spudman
Confirmed User
 
Spudman's Avatar
 
Join Date: Aug 2002
Location: UK
Posts: 3,198
I really don't see why tony is bothering to work on comus, its name has been dragged through the mud so badly now no one is going to be stupid enough to touch it again.
__________________
Take it Easy !!!
Spudman is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:14 PM   #19
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
Quote:
Originally Posted by Naughty-Pages View Post

"Somewhere" in Comus is a vulnerability which allows backdoor files to be created, then those backdoors create the trojans across the server.

If you have not been hit, it is simply because your script has not yet been targetted. It could be an hour from now, a week from now, a year from now, or never. Just because it is vulnerable, does not mean you WILL get infected.. it just means it's possible.. but if I were a betting man, I would say it will probably happen sooner or later to you.

Comus thumbs site has been messed up for some time, and then this issue occured.. with no mention from them about what's up, with the exception of boneless commenting in a few threads that they are trying to deal with it.
Hmm.. do you have mod_security installed on your apache? Also, do you know which comus files are directly hit with this infection? Meaning, which files you first noticed that had malicious code in?

I am not playing with this, but i want to make sure comus is really vulnerable.
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:37 PM   #20
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by beta-tester View Post
Hmm.. do you have mod_security installed on your apache? Also, do you know which comus files are directly hit with this infection? Meaning, which files you first noticed that had malicious code in?

I am not playing with this, but i want to make sure comus is really vulnerable.
from what i gathered, menu.php in the admin dir gets attacked. Since i run 100s of installations it would be mad work to get them all switched in a short time span, so i worked around it:

- Delete menu.php from the admin dir
- htpasswd protected the admin dir

i noticed lots of peeps not affected they all had their admin dir htpasswd protected.

regards,

Ed
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:39 PM   #21
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by Dennis69 View Post
Cool... wish I would of found you after Comus bought the script and I did there upgrade and I never did it to work right for me anymore!
perhaps you made a mistake when you upgraded, can happen to anyone, but saying you need to ditch epower cause comus ahs a problem right now is just plain stupid.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 01:44 PM   #22
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
Quote:
Originally Posted by boneless View Post
from what i gathered, menu.php in the admin dir gets attacked. Since i run 100s of installations it would be mad work to get them all switched in a short time span, so i worked around it:

- Delete menu.php from the admin dir
- htpasswd protected the admin dir

i noticed lots of peeps not affected they all had their admin dir htpasswd protected.

regards,

Ed
I've had my admin dir protected for 2 years now. I realized from looking at audit logs (mod_security) that a lot of admin files get hit by bots, trying to execute sql injection. Then I protected it with htaccess, and those problems gone. Menu.php might be on the hit because it contains iframe of comus' website, and attacker can, by exploiting something on comus' site, affect the comus installation.
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 02:20 PM   #23
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by beta-tester View Post
Hmm.. do you have mod_security installed on your apache? Also, do you know which comus files are directly hit with this infection? Meaning, which files you first noticed that had malicious code in?

I am not playing with this, but i want to make sure comus is really vulnerable.


mod_security is set by default on all of our servers..

And as far as which file was hit first, i cannot tell you.. I was traveling out of state the week that it happened and my time online was limited.. Because of my limited time, to begin with I was frantically removing everything I could (which they just came back).

Had I not been traveling I would have taken the time to notice time stamps, etc (although those can also be faked).

I did not narrow it down to Comus until a few days ago when I was searching for a solution and noticed a common issue that others using Comus were having the same exact issue and that most of the backdoors were in Comus (although they had spread to dozens of other sites, those other sites only had about 1-3 backdoor files).

And the deciding factor (aside from what everyone else is saying) was that I was not able to begin to remove the backdoors and trojans permanently until i deleted Comus.

You can take boneless/Ed's advice to try to secure it if you want, I just know that the risks for me far outweigh the benefits.. Maybe I would feel differently if I had 100 sites running Comus and had to worry about the labor involved to convert them over to some other script.. but I only had one Comus script that I had just setup like 3 months ago.. so it is far easier for me to just ditch it.

If this isn't all you do, you might not be as scared as I am.. I've been doing this since the late 90's and full time as my sole source of income since 2002, so I simply cannot gamble with things like this.. Just don't need the risk...
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 02:22 PM   #24
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by beta-tester View Post
Menu.php might be on the hit because it contains iframe of comus' website, and attacker can, by exploiting something on comus' site, affect the comus installation.
well.. i dunno.. but i do know that this time comus's site had issues right before all of this went down..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 05:11 PM   #25
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by boneless View Post
from what i gathered, menu.php in the admin dir gets attacked. Since i run 100s of installations it would be mad work to get them all switched in a short time span, so i worked around it:

- Delete menu.php from the admin dir
- htpasswd protected the admin dir

i noticed lots of peeps not affected they all had their admin dir htpasswd protected.

regards,

Ed
Ed, not being an ass, but why is he not informing people or posting something on his website.. If he wanted to protect his rep, some personal damage control would be helpful... as well as making public on his site some measures people can take to remove infections and/or prevent them until he can fix shit.

Last edited by Naughty-Pages; 10-04-2009 at 05:16 PM..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 05:49 PM   #26
pornpf69
Too lazy to set a custom title
 
pornpf69's Avatar
 
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
I just hope they can solve this issue as fast as possible because they will get ruined if they don't...
pornpf69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 08:16 PM   #27
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by pornpf69 View Post
I just hope they can solve this issue as fast as possible because they will get ruined if they don't...
they probably already are ruined.. mainly because they have not focused on any PR issues.. and when i say PR, i am not talking about google page rank but instead public relatons...

no public notifications to help people solve the problem, nor no warnings on their site or elsewhere....

makes them seem not too focused on customer service, so in the end their lack of response could be a death sentence..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 08:40 PM   #28
katharos
So Fucking Banned
 
Join Date: Nov 2005
Posts: 1,515
all firefox surfer traffic ... then i am done reading ...
katharos is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 08:52 PM   #29
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by pornpf69 View Post
I just hope they can solve this issue as fast as possible because they will get ruined if they don't...
Tony is atm working on it and prolly tonight an interim fix will be presented, problem we are facing is that the attack was also aimed at the comus box, and specificly the license admin, ftp server, sendmail and a few other thingys.

Tony is working around the clock on it, he just doesnt like to get mixed in all the drama atm surrounding the issue.

I have been sending him messages with all the board threads and he is aware off all the issues peeps had.

For now he just tries to focus on the dev of the script and mainly figuring how they got in, we looked at the menu.php code and theres according ot us 0 that can be exploited.

In the first beta that is going out tonight menu.php is removed. Plus there will be some minor tweaks on it.

Just a FYI the menu.php file is tied into a lot of different files on comus so taking it out is a daunting task.

Hope to have some news shortly for you guys.

regards,

Ed
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 08:55 PM   #30
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
also theres gonna be a lot of moving around of folders and files in the script. this is all for added security.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 08:57 PM   #31
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by katharos View Post
all firefox surfer traffic ... then i am done reading ...
google SE results should have been the bigger scare..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:13 PM   #32
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
Quote:
Originally Posted by boneless View Post
also theres gonna be a lot of moving around of folders and files in the script. this is all for added security.
I just hope he won't miss something in the process and hence make the bigger problem.
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2009, 11:47 PM   #33
Nurgle
Confirmed User
 
Nurgle's Avatar
 
Join Date: Feb 2001
Location: Land of OZ
Posts: 2,337
unbelievable that this script still has so many fucking holes in it and that Tony never bothered to properly lock down this script after so many attacks over the years

anyone who uses comus still needs their head checked
__________________
I am not a megalomaniac.. I just rule the world
Need Quality Hardlinks? We have several packages and custom deals available.
*High Quality Hard Links For Sale*
ICQ: 394016570
Nurgle is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 01:18 AM   #34
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
well, what do you suggest Nurgle? Just switching over to something else? I've been tweaking my site for years to properly tune it. Also, sudden change of the links structure would have evident affect to SE rankings.

But, I think ST does better job in maintaining the productivity than CT, though.
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 05:34 AM   #35
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by Nurgle View Post
unbelievable that this script still has so many fucking holes in it and that Tony never bothered to properly lock down this script after so many attacks over the years

anyone who uses comus still needs their head checked
so i need to get my head checked out, noted it down so i can make an appointment with my doctor later today...

tony pushed the first beta upgrade out last night when i was sleeping so my post is a bit late (i tend to sleep at odd hours)

Beta will kill menu.php from the ct folder.

it will copy htaccess htpasswd from your ept install (if present) to the ct admin dir and the templates folder to make em more secure.

these are only temp fixes atm.

easiest way to make ya secure, is to remove menu.php for now and htpasswd the admin dir.

Tony is resting atm after coding for over 18hours and will be going further into the code once he gets up again.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 05:35 AM   #36
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by beta-tester View Post
But, I think ST does better job in maintaining the productivity than CT, though.
i tend to disagree, i switched an entire box over to smart thumbs and prod on smaller sites is simply horrifying. To me its like st was designed for bigger sites, small sites tend to have a hard time getting their prod right.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 06:04 AM   #37
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by Naughty-Pages View Post
Final count on what was blocked was only 13 sites out of the batch of infected sites. Just finished submitting the requests.. 12 hours (or even the 24 mentioned before) would be sweet.

even if it is 12 to 24 hours, I'm sure if any webmasters who have toplist accounts visit the toplists, they'll probably pull their links, even though the infections were removed, due to the warning in firefox..
Woke up this morning and all of the sites that were blocked are now unblocked.. ;)

thank god..
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 06:14 AM   #38
tranza
ICQ: 197-556-237
 
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
Quote:
Originally Posted by Naughty-Pages View Post
~24h? that's not too bad.. I've got quite a few blocked, I hope I don't get any of those with a 2 week block...

Thanks man.. I can shoot some content of her if ya need some ;) (problem is lately her availability has been kinda sucky)..
__________________
I'm just a newbie.
tranza is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2009, 01:17 PM   #39
beta-tester
Rock 'n Roll Baby!
 
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
Quote:
Originally Posted by boneless View Post
i tend to disagree, i switched an entire box over to smart thumbs and prod on smaller sites is simply horrifying. To me its like st was designed for bigger sites, small sites tend to have a hard time getting their prod right.
what kind of prod booster do you use on your sites? I tried wide variety of prod boosters, but categories populated with less than 100 galleries tend to get their thumbs on the site more often, because of spin... i guess i'll have to move all my gals into one big category and set its spin to around 99% and see how it goes.
__________________

Sig for sale. Affordable prices. Contact me and get a great deal ;)

My contact:
ICQ: 944-320-46
e-mail: manca {AT} HotFreeSex4All.com
beta-tester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.