Prosper202 Security Hole, DL new version

Status
Not open for further replies.
Having in-house tracking doesn't necessarily make you more secure. Obscurity isn't security. Microsoft is a good example.

For those interested in the exploit, here's the diff output, basically all the changes between 1.2 and 1.2.1. Don't apply this patch to your 1.2 install though, install 1.2.1 from scratch.

Private Paste - Pastie
 


Mar 06, 09 at 9:57am 66.232.97.32 :: ARIN / RIPE Failed
Mar 06, 09 at 3:26am Elsie 61.14.163.75 :: ARIN / RIPE Failed
Mar 05, 09 at 8:25pm 190.22.248.5 :: ARIN / RIPE Failed
Mar 14, 09 at 7:33am C1AL1S 203.160.1.71 :: ARIN / RIPE Failed
Mar 15, 09 at 6:15pm viagra 203.160.1.71 :: ARIN / RIPE Failed
Mar 19, 09 at 6:42pm c1alis 81.177.3.7 :: ARIN / RIPE Failed

How do I know if my account was compromised?
 
Having in-house tracking doesn't necessarily make you more secure. Obscurity isn't security. Microsoft is a good example.

For those interested in the exploit, here's the diff output, basically all the changes between 1.2 and 1.2.1. Don't apply this patch to your 1.2 install though, install 1.2.1 from scratch.

Private Paste - Pastie

Sorry if I'm missing something but you're saying NOT to apply the patch and install from scratch? Is this only for those interested in the exploit or in general?

I just patched and moved/rename my 202-login.php to a pw protected subdir, going to do block ips later.. thanks for all the work you put in Wes, SSS & Jon.. damn sweet!
 
Really appreciate all the work you did Shady, Jon and others. I noticed failed login attempts in my 202 installation but never paid much attention to it since I know shit about servers and stuff.

Here are some failed attempts from my logs:

Mar 17, 09 at 5:31am cuong 123.17.199.154 :: ARIN / RIPE Failed
Mar 17, 09 at 5:31am cuong 123.17.199.154 :: ARIN / RIPE Failed
Mar 17, 09 at 5:30am cuong 123.17.199.154 :: ARIN / RIPE Failed
Mar 17, 09 at 5:30am cuong 123.17.199.154 :: ARIN / RIPE Failed
 
yeah here is my shit can someone with the prosper install list please contact me or is sss the only one who has the list?

Mar 19, 09 at 6:25pm viagra 67.69.254.244 :: ARIN / RIPE Failed
Mar 15, 09 at 4:52pm VIARGA 212.116.219.92 :: ARIN / RIPE Failed
Mar 13, 09 at 8:02pm v1agra 212.116.219.52 :: ARIN / RIPE Failed
Mar 13, 09 at 7:13pm VIAGRA 121.22.29.185 :: ARIN / RIPE Failed
 
Most of the networks contacted about it have nuked the guy and swore to not accept him back. A few of them even saw this thread and killed him off before I could get in touch with them. So thanks to those networks for not putting up with a fraudster like this. As someone said before, we'll check back and see who hasn't nuked him yet but I don't think anyone except for maybe CJ, Clickbank or Linkshare is going to keep him on board much longer.
 
yeah here is my shit can someone with the prosper install list please contact me or is sss the only one who has the list?

Mar 19, 09 at 6:25pm viagra 67.69.254.244 :: ARIN / RIPE Failed
Mar 15, 09 at 4:52pm VIARGA 212.116.219.92 :: ARIN / RIPE Failed
Mar 13, 09 at 8:02pm v1agra 212.116.219.52 :: ARIN / RIPE Failed
Mar 13, 09 at 7:13pm VIAGRA 121.22.29.185 :: ARIN / RIPE Failed

SSS is the only one with the lists that is voluntarily helping out WickedFire members who got breached through their P202, individually. So give him some time to get to you, just shoot him a PM about it and be patient. He said earlier he wasn't going to be able to get back to anyone until sometime tonight.
 
SSS is the only one with the lists that is voluntarily helping out WickedFire members who got breached through their P202, individually. So give him some time to get to you, just shoot him a PM about it and be patient. He said earlier he wasn't going to be able to get back to anyone until sometime tonight.

I love this place

Thanks for looking out guys, seriously :)
 
Most of the networks contacted about it have nuked the guy and swore to not accept him back. A few of them even saw this thread and killed him off before I could get in touch with them. So thanks to those networks for not putting up with a fraudster like this. As someone said before, we'll check back and see who hasn't nuked him yet but I don't think anyone except for maybe CJ, Clickbank or Linkshare is going to keep him on board much longer.


talk about a good day for the networks- nuke the guy, hold the unpaid commissions, profit.
 
The networks that did the right thing deserve to keep the profits, and the networks that don't deserve to be outed and blackballed by everyone on WF.

oh I agree- however my comment stands- at the volume we estimate w/ him it's a nice present for the networks for sure - would be cool to kick a little to the 202 donation fund like Ruck.
 
Just saw this. If there is anything we can do to help out on our end let me know and I'll get on it. What was this guy thinking?

And yes. We've denied him before. Pretty sure the info dug up is accurate.
 
SSS is the only one with the lists that is voluntarily helping out WickedFire members who got breached through their P202, individually. So give him some time to get to you, just shoot him a PM about it and be patient. He said earlier he wasn't going to be able to get back to anyone until sometime tonight.


thanks man
 
So perhaps copy 202-login.php to some obscure name and bookmark it for your own login.

Then modify 202-login.php to simply email you any username/pass attempts, that way you'll know straight away if any asshole tries to login.
 
Status
Not open for further replies.