Prosper202 Security Hole, DL new version

Status
Not open for further replies.
Thanks guys for info.

Other than updating the prosper code, Is there anything else we should do? Like:
Should we change DB Username and Password?
Should we change prosper Password?
Did he run any suspicious software on our servers?

Thanks,
Adi
 


Fucker pwned me too. I've upgraded and locked down the login page. Would it be prudent to wipe everything up to the doc root where p202 was installed, or even the whole server?
 
slightyshady hit me up on aim asap thanks!
I'm hittin the sack shortly(I fly out to FL tomorrow, bright and way too early) but I'll try and get ahold of ya tomorrow :)
I'm on that list too. Fun fun.
Yeah you were one of the guys I actually tried to call.

Which reminds me. If I specified the first letter in the parentheses(in the big list of hacked ones) that means there were actual screenshots of the p202 installation(keywords, referrers, etc)

And to everyone who sent PMs, I'm getting back as fast as I can. Most left are gonna have to be tomorrow though.

Edit: And a few more affiliate IDs
Convert2Media - CD3327
Motive Interactive - cpa.php?50107.3678&_asid=4269984 (no idea how to parse the affid out of that link)
Role Model Networks - CD8530
SharkAdnetwork.com - CD14 (err a little freakishly low of a number there)
 
someone attempted access on my login but failed on the march 15th from this ip
203.160.1.71

I have the same thing, with a username: C1AL1S which is totally unrelated to MY login name. That was on march 19th, but I had another on March 13th from an IP 212.116.219.91 but with a similar username: C1al1s

Anyone know anything about that?
 
weird you say that Buddy, this is from my p202:

March 19 @ 6:24pm Cialis 125.165.42.197 Failed
 
I have the same thing, with a username: C1AL1S which is totally unrelated to MY login name. That was on march 19th, but I had another on March 13th from an IP 212.116.219.91 but with a similar username: C1al1s

Anyone know anything about that?


Same here
 
Mar 20, 09 at 10:40am - viarga 203.160.1.71

Mar 20, 09 at 10:38am - Cialis 196.29.205.44

Mar 15, 09 at 5:26pm - v1agra 195.244.128.16

No traces that I can easily see before 3/15.
 
Mar 20, 09 at 12:35pm V1AGRA 85.12.47.185
Mar 29, 09 at 2:26pm Viagra 219.93.178.162
Mar 29, 09 at 2:28pm c1al1s 222.240.254.108
Mar 30, 09 at 8:11am c1alis 74.86.121.3
Mar 30, 09 at 8:14am c1al1s 72.9.147.149
Mar 30, 09 at 8:15am c1al1s 70.86.6.18
Mar 30, 09 at 8:36am c1al1s 74.86.121.20
Mar 30, 09 at 1:30pm V1ARGA 74.86.121.3
 
Yes, I have the same login attempts too.

So if you see these c1al1s and V1ARGA login attempts does that mean you have been hacked?

If so, are we sure it is only P202 data they gain access too or should we be worried about the whole box?
 
Seems this guy has been pretty busy during March. Earliest report from an affiliate of getting hit is around March 15th.

After looking through what seems to be just TONS of domains and different hosts (the guy has like 4-5 domains at most per host), he's been taking screen shots of people's affiliate stats from P202, the ones he's been able to breach at least, and just copying them with identical ads, identical LP's, using the same keywords and traffic sources, and using the same network for the offer too.

So as weird as all of this gets, he's just a copycat. I bet he had a few laughs over people here getting pissed about outting LP's, psh, fuck that, what about outting ENTIRE affiliate campaigns!

I'm busy all of tomorrow and Thursday so maybe other people can pore over this and help out.
 
Kiss my ass motherfucker :nopenope:


Mar 16, 09 at 6:49am viarga 189.56.150.110 :: ARIN / RIPE Failed
Mar 16, 09 at 6:49am viarga 203.160.1.71 :: ARIN / RIPE Failed
Mar 15, 09 at 2:23pm viagra 203.160.1.71 :: ARIN / RIPE Failed
Mar 15, 09 at 2:23pm cial1s 203.160.1.71 :: ARIN / RIPE Failed
 
He actually has 4 of my prosper domains in his list

Im willing to take further action if someone can send me more solid information. I have full logs of him hacking my servers and snooping data. Im not sure if thats enough though.

I doubt he has much money but would be worth it gain or not
 
I have the same crap...

Mar 23, 09 at 11:07pm V1arga 189.16.157.58 :: ARIN / RIPE Failed
Mar 22, 09 at 10:36am viarga 67.69.254.244 :: ARIN / RIPE Failed
Mar 22, 09 at 10:36am c1alis 203.160.1.71 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm cialis 202.86.220.34 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm V1agra 85.12.47.185 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm V1arga 64.66.192.61 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm C1al1s 202.86.220.34 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm C1AL1S 203.160.1.71 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm cial1s 222.124.8.66 :: ARIN / RIPE Failed
Mar 19, 09 at 3:44pm v1agra 125.165.42.192 :: ARIN / RIPE Failed
Mar 19, 09 at 3:43pm V1ARGA 203.160.1.71 :: ARIN / RIPE Failed
Mar 13, 09 at 4:52pm C1AL1S 121.22.29.185 :: ARIN / RIPE Failed
 
I have the server ip/domain name that he used to run these exploits as I'm sure a few others have as well. Looking forward to seeing this asshat get what's due.
 
my friggin domain is on that list. W/E, glad it's over now. Thanks SSS + jon for helping us all out. I'm going to pw protect my login page tonight....

good that wes + steven reacted so fast though. Anyone knows how much the dude ended up making with all these copycats?
 
Status
Not open for further replies.