[OUR PARTNERS: GoldRater | HYIPMailer | Autosurfs.net ]our advertising disclaimer | Disclaimer - Must be read before using forum or clicking any links
750% After 1 Day
Stabilitycapital.com
TheHYIPForum.com
ALL NEW! HYIP, Autosurf, Cycler, MLM Forum! Check it out today and earn money!
YOUR AD HERE!
For only $17/day, $99/week or $379/month on the most Popular HYIP related site online!
Put your banner or text ad in the rotation above!ONLY $17/day, $99/week, or $379/month!


Your Ad Here!
Your Ad Here

above banners and links are advertisements only. We do not endorse or vouch for any advertisers.Put Your 728X90 Banner Here NOW!

Go Back   Talkgold HYIP, Investment & Money Forum > Caution : Risky High Yield Investing Programs > HYIP - AutoSurf Program Admin Talk
User Name
Password
Reply
 
Thread Tools Display Modes
  #1  
Old 05-12-2006, 08:54 AM
neversay's Avatar
neversay neversay is online now
"Talkgold's Best" Club
Join Date: Nov 2005
Posts: 2,051
Send a message via Yahoo to neversay
Default How hacker hack your GC script? just found another clue today

One of my client got hacked. After 2 hours investigation I found and SQL injection to his site.. thats why many GC sites been hacked..

I can even start hacking other hyip right now
Its very simple keyloging implantation into admin computer.. and every username password will be known to him..

I was in the big fight with Hacker.. fortunately I was in phpmyadmin of my client's web site. Fast enough to delete his new password.

The secreat can not be revealed in the open. All of my paid customer can PM for security updates. Any AS,HYIP script can be open to this kind of attack, decode or encrypted code doesn't help. Just a pure SQL injection.
__________________
PHP programmer find me here
Reply With Quote
-- Sponsored Links --
  #2  
Old 05-12-2006, 09:20 AM
snøfrisk snøfrisk is offline
Investor
Join Date: Oct 2005
Posts: 339
Default Re: How hacker hack your GC script? just found another clue today

Sendt you a mail NS
__________________
Forum
Reply With Quote
  #3  
Old 05-12-2006, 11:51 AM
MoneyTraders_John MoneyTraders_John is offline
Amateur Investor
Join Date: May 2006
Posts: 42
Default Re: How hacker hack your GC script? just found another clue today

lol. you know this just now ? You need only 3 little programs (I got them home, I'm testing a new hyip script against this tool). I even got a video tutorial for hacking a webpage with password and username login protected.
Are you a hyip owner? I'm surprised you know this only now. SQL injection is an old story. Every server can be hacked with this tool.
They show you in a dos command prompt all the tables they got in the MYSQL server. and you can easily add or delete other keys in MYSQL.

The 3 little programs that I got, are NOT FOR SELL !!! They are home made tools from a very old friend. And he doesn't want to be guilty for hacking other website with his tool.


Regards, john
Reply With Quote
  #4  
Old 05-13-2006, 05:01 AM
neversay's Avatar
neversay neversay is online now
"Talkgold's Best" Club
Join Date: Nov 2005
Posts: 2,051
Send a message via Yahoo to neversay
Default Re: How hacker hack your GC script? just found another clue today

LOL indeed... I know its SQL injection but did not realized that the current GC script and AS script is not protected.

Well what I just found was another way to inject the info... this hacker is real good and fast , he change admin pass in less than 5 seconds
__________________
PHP programmer find me here
Reply With Quote
  #5  
Old 05-13-2006, 05:20 AM
kennethtan's Avatar
kennethtan kennethtan is offline
"Talkgold's Best" Club
Join Date: Jun 2005
Posts: 2,168
Default Re: How hacker hack your GC script? just found another clue today

Quote:
SQL injection is a hacking technique which attempts to pass SQL commands through a web application for execution by a backend database. This is one of the most common application layer attacks currently being used on the Internet. The technologies vulnerable to this attack are dynamic script languages like ASP, ASP.NET, PHP, JSP, CGI, and so on.

To be able to perform SQL Injection hacking, all an attacker needs is a web browser and some guess work to find important table and field names. This is why SQL Injection attacks are so popular.
Try google and there are tons of informations.
Note that hacker can decode gc source code in order to have a full understanding regarding the table, string etc. Then he/she can start "the project" and hyip or autosurf admins will suffer.

As a conclusion, popular or famous script always have problem because those scripts become hacker main target.
__________________
Best Regards,
Kenneth Tan
HOUSE OF PROFIT GREENPAPER Administrator - Private Investment Club
Owner of JobListed.com | BatikBeauty.com | Craftangan.com
Reply With Quote
  #6  
Old 05-13-2006, 06:26 AM
chris_j's Avatar
chris_j chris_j is online now
Senior Investor
Join Date: Oct 2005
Location: US
Posts: 538
Send a message via ICQ to chris_j Send a message via AIM to chris_j Send a message via MSN to chris_j Send a message via Yahoo to chris_j
Default Re: How hacker hack your GC script? just found another clue today

Quote:
Originally Posted by neversay
this hacker is real good and fast , he change admin pass in less than 5 seconds
Make sure that your don't have the folder "/public_html/vti_pvt/" in your account. If you see this folder, make sure that it doesn't have any hacker's files. This folder is used for FrontPage Extensions & it's the easiest target to upload hacker's files due to wide-spread Frontpage vulnarability. The best thing to do is to DELETE all the folders that start with "_vti" in your "/public_html/" & always use FTP for your uploads (instead of using Frontpage Extensions). Enabling Frontpage Extensions are a BIG security hole for a server.
__________________
Chris J.
Zydus Networks [Operating successfully since Sep-2005]
$4.99 = Peace of Mind from HACKERS. Read more...
Pay with: Liberty Reserve, AlertPay
More than 3000 satisfied customers can't go wrong!!!
Reply With Quote
  #7  
Old 05-13-2006, 08:44 AM
neversay's Avatar
neversay neversay is online now
"Talkgold's Best" Club
Join Date: Nov 2005
Posts: 2,051
Send a message via Yahoo to neversay
Default Re: How hacker hack your GC script? just found another clue today

Thanks chris: That is another big holes apart from hyip site that do not have .htaccess in tmpl_c folder
__________________
PHP programmer find me here
Reply With Quote
  #8  
Old 05-13-2006, 09:57 AM
ehostbiz ehostbiz is offline
Amateur Investor
Join Date: Dec 2005
Posts: 31
Default Re: How hacker hack your GC script? just found another clue today

Hey NS I have pm'ed you.... and thanks for the info chris...
Reply With Quote
  #9  
Old 05-13-2006, 10:35 AM
Alexey's Avatar
Alexey Alexey is offline
Amateur Investor
Join Date: Mar 2006
Posts: 115
Default Re: How hacker hack your GC script? just found another clue today

just add a tiny function everytime you read input.. search trim slashes or injection on php.net
Reply With Quote
  #10  
Old 05-13-2006, 07:19 PM
tarek's Avatar
tarek tarek is offline
Folder Moderator
Join Date: Aug 2005
Location: Virtual Reality
Posts: 1,301
Default Re: How hacker hack your GC script? just found another clue today

i think it is better to stay away from GC Script .

Don't you ?
__________________
Forex Accounts management.
Start from Only $5000 for limited time.
1-10% monthly returns.
Tarek Forex Services
CTA, IB For Fxsol ( Open Real Forex Accont )
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


TALKGOLD
SIDEBAR ADS

ADVERTISE HERE. Must read: Advertising Terms & Disclaimer
PUT YOUR 120X120 AD HERE FOR ONLY $310/WEEK!
Click Here for details.
Your ad here! Cost of Ad - $300
Cost of Ad - $290
Your ad here! Cost of Ad - $285
Your ad here! Cost of Ad - $230
Your ad here! Cost of Ad - $210
Your ad here! Cost of Ad - $190
Your ad here! Cost of Ad - $150
Your ad here! Cost of Ad - $140
Your ad here! Cost of Ad - $130
BlockDOS.net
The absolute best DDOS Protection at the most affordable prices. Endorsed by Talkgold.com
Cost of Ad - $110
Your ad here! Cost of Ad - $75
Your ad here! Cost of Ad - $75
YOUR AD HERE

PUT YOUR NON-ROTATING AD HERE NOW!
ONLY $75/Week


click here
click here
YOUR AD HERE!
YOUR AD HERE!
WWW.NVHSERVER.COM

Excellent HYIP Hosting + Autosurf Hosting! Accept Almost E-currency Payment Processors! 24/7 Super Support!

Only $39/week or $135/month - Advertise Now!
888% AFTER 8 HOURS

[Fully Instant Withdrawals]
8% Referral Bonus
WWW.PROFITSHORE.COM
Only $39/week or $135/month - Advertise Now!
Check our Advertising Rates!

All times are GMT. The time now is 03:05 AM.

Add to Google

Protected by BlockDOS.net - DDOS Protection
Powered by: vBulletin - Copyright ©2000 - 2005, Jelsoft Enterprises Ltd.