Prosper202 Security Hole, DL new version

Status
Not open for further replies.


I was thinking about removing half the domain. Any objections? Either that or I can just call the people. At least the ones I can find.

Oh yeah, and regarding the info I posted above, I just triple checked, and it's dead on.
Yeah i think half the domain with *s so people who own it know it's theres.
 
Oh I wouldn't worry too much about the guys behind it anymore..

Aside for having all of their affiliate accounts nuked today, and pissing off a shitload of affiliates, we also have all of their info both personal and business, IP's, domains, photos, phone numbers, paypal info, etc. -- Also had Wes and Steven from P202 speak to the FBI about it, and they've got all of his info and the evidence we raped from their server. Apparently while he was smart enough to figure out how to hack into people's P202 accounts and take screen shots of the data, he wasn't smart enough to cover his tracks by any means.

Everything will be posted later tonight by SlightlyShadySEO.

Haha - this is going to be good.

68416045.wGDPMlLK.popcorn.gif
 
Yeah i think half the domain with *s so people who own it know it's theres.
I missed a lot in my screenshotting frenzy. I tried to get a pretty broad array of stuff as proof for when the guy's server went offline, so I missed the bigger lists. The mofo was ajax, so not exactly easy to scrape.
For the few I do have, I'll put the first letter of the first name of the owner if I could find it(so I don't have to reveal as much of the domain), and the censored domain.
Adsup* (R)
PPc-*-* (G)
trk2*** (No first name found)
directb* (A)
---I got tired of tracking people down here---
adtr*
dsbh*
6fig*
dig-*
ljum*
lnktosi*
loki*
adstr*
dsmt*
redirecting*
dought*
monea*
super*.info (whoever this is, contact me. I've got the subid he came in as, so maybe we can find the IP of this guy's partner)
track*stat
dig-
b4**.com
ljum*

Ok. Holy fuck. Turns out a LOT more guys were broken into. They just didn't add the part of the software that makes it obvious until later or something. That's probably half the list, and about 50% of the servers they found they didn't break into.
 
Some people were alerted last night and so some of the IPs visting the server in the last 24-Hours might be WF members.
 
So do i.

Funny how I've had issues lately with some douche copying my landing pages and showing up in the same advertising spots.
 
I looked in my apache logs for prosper202. Found both ips in there at about the same time. March 29th, 2009 about 7:30pm Central time. Funny thing is that I dont see the login attempts in the actual prosper application. Can anyone provide any insight into this? Did the comprimised boxes give them SQL access to remove their login attempts?
 
hey shady, newb question, sry. If i dont see any bad login attempts on my admin on p202, does that mean nothing has happened? Or is there another way to get in that I cant monitor? Thanks for all the info man, really appreciate it.
 
@Bryn, jpet10 - you'll just see them in your apache logs. A quick way to check is to do a:
grep 74.86.121 /var/log/httpd/*
from your server.

@testonej - Just from looking really quickly through the changed code, he was able to get access to the entire prosper202 database. I don't think (THINK*) that it was possible for them to get shell access unless your p202/database password was the same as your root password.
 
hey shady, newb question, sry. If i dont see any bad login attempts on my admin on p202, does that mean nothing has happened? Or is there another way to get in that I cant monitor? Thanks for all the info man, really appreciate it.
If you're not on the list, honestly I don't know. My role in this was mostly tracking. Not the IPs the logins came from.
Right now it looks like he's got IPs within the 72.9.147.149 - 72.9.147.156 block(multiple).
 
For those of you looking for another level of secuirty, some have been talking about blocking access to your login page to just your ip address. Here is some code I just tested. Add this to your apache httpd config for your prosper202 directory. Just replace XX.XX.XX.XX with your ip address. (make sure it is your internet ip and not your private ip).

<Files "202-login.php">
Order deny,allow
deny from all
allow from XX.XX.XX.XX
</Files>

Although this seems to work fine me, I am totally open to other comments/ideas to protect things.
 
Status
Not open for further replies.