Prosper202 Security Hole, DL new version

Status
Not open for further replies.


I don't think failed login attempts will show in your P202 install. You'll need to look through the raw logs.

He targeted basically every P202 install pushing traffic on Facebook as a priority then others. With the number of installs compromised ASSUME he broke into your account. Upgrade your install and consider blocking every IP aside from yours from logging in.

Aside from that not much you can do. His accounts are being knocked off the networks and assuming he didn't drop some sort of remote exploit onto the servers when he entered, shouldn't be too many ramifications from all of this.
 
Affiliate URLs and IDs
Credit.com - Affiliate p39017
Azoogle(link is) x.azjmp.com/1hwpb
Clickbank - wwwsr
Copeac - 3063 (and 138)?
Linkshare - Onc6Cv5nnDw
More coming.
--edit---
CJ.com - 1509877
webventures.directtrack.com - CD91
click2go.org 852
 
Last edited:
So what's the long term solution?

Stick with open source p202 tracking code and risk all your data in the future?

Sure this exploit was solved, quickly and efficiently, but are there others that haven't been caught yet?

What's the best way to cover up any footprints that are being left?
 
Moar affiliate IDs.
Primary Ads - 10044
Incentaclick - 12241
CPA Empire/Affiliate.com Link http://login.tracking101.com/ez/ceaenkpaqlqx/ (secure version)
Hydra - 23493
EAdvertising - 401437
Yep! Revenue - 483
SocialTrack.net - 47041
sq2trk.com - 48230
Market Leverage - CD8530
MediaWhiz - 18145
Tatto Media - 852
----Old ones---
Credit.com - Affiliate p39017
Azoogle(link is) x.azjmp.com/1hwpb
Clickbank - wwwsr
Copeac - 3063 (and 138)?
Linkshare - Onc6Cv5nnDw
CJ.com - 1509877
webventures.directtrack.com - CD91
click2go.org - 852

If anyone is friendly with people at these companies(especially the less common ones), how about dropping em a line?
 
So what's the long term solution?

Stick with open source p202 tracking code and risk all your data in the future?

Sure this exploit was solved, quickly and efficiently, but are there others that haven't been caught yet?

What's the best way to cover up any footprints that are being left?
Microsoft has been saying the same thing for decades.
Servers exposed to the internet with expensive data get hacked. Few exceptions.
 
So what's the long term solution?

Stick with open source p202 tracking code and risk all your data in the future?

Sure this exploit was solved, quickly and efficiently, but are there others that haven't been caught yet?

What's the best way to cover up any footprints that are being left?

Well the real answer is although not perfect, learn a thing or three about server administration. Password protect the login directory if it resides in a separate directory. Make it so only your IP can access certain directories. That kind of stuff.

If you think some commercial product is any safer, I'd say your probably wrong. There's always new exploits to be developed, and it doesn't even mean that a commercial product is any more secure.
 
dumb question but how do you restricting your login to your IP only login if you're at a different IP?

Pull that ip, and then change the script to only then allow this one? Perhaps I'm in the minority who access from both laptops while traveling and iphone constantly?

Am I not thinking about this correctly or is simply restricting and then editing this to allow whatever new IP you need the way to go? (which then obviously rules out any iphone logging in).
 
I missed a lot in my screenshotting frenzy. I tried to get a pretty broad array of stuff as proof for when the guy's server went offline, so I missed the bigger lists. The mofo was ajax, so not exactly easy to scrape.
For the few I do have, I'll put the first letter of the first name of the owner if I could find it(so I don't have to reveal as much of the domain), and the censored domain.
Adsup* (R)
PPc-*-* (G)
trk2*** (No first name found)
directb* (A)
---I got tired of tracking people down here---
adtr*
dsbh*
6fig*
dig-*
ljum*
lnktosi*
loki*
adstr*
dsmt*
redirecting*
dought*
monea*
super*.info (whoever this is, contact me. I've got the subid he came in as, so maybe we can find the IP of this guy's partner)
track*stat
dig-
b4**.com
ljum*

Ok. Holy fuck. Turns out a LOT more guys were broken into. They just didn't add the part of the software that makes it obvious until later or something. That's probably half the list, and about 50% of the servers they found they didn't break into.


Wow 2 of those in there are mine

could you AIM me? Yours isn't listed. willraim
 
Here are the sites he has listed in one of his network accounts, in case this helps. The name & email match what have been posted before.
Code:
http://www.satellite.info
http://iloancalculator.com 
http://wwwsitereviews.com 
http://www.wheelsworld.com 
http://www.motorcycleforum.com 
http://www.matrixmania.com 
http://www.linkroll.com 
http://www.imageark.net
http://www.d2forum.com 
http://www.creditpro.org 
http://www.creditprovide.com 
http://www.carloans.net 
http://www.33rpm.com
 
I had him nuked here: A4D, Hydra, MediaWhiz, and Azoogle. (showed proof first to back up the claim)

I'm sure Copeac, CX, Yep!, MarketLeverage, Eads, Tatto and CPAE will nuke him if asked and shown proof to back up the claims.
 
Status
Not open for further replies.