Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - £25 Reward
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

£25 Reward

 Post Reply Post Reply Page  123 4>
Author
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Topic: £25 Reward
    Posted: 03 July 2005 at 11:05am
Dear everyone on WWF,

Recently my website was broken into, and I would like to discover the method of entry as soon as possible.

On C4SMS.com I have set up an account with the username 'BreakTest'.  I invite anyone to try (without disrupting service) to enter that account.

I will pay via Paypal, £25 (nearly $50) if you manage to tell me the details of the entry stored in the address book for that user when logged into the account.

To claim the reward you must also tell me step by step how you achieved the entry.

Thanks to anyone that trys.

Tom
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 03 July 2005 at 6:17pm
I take it you've eliminated brute force and it is a glitch?
Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Posted: 03 July 2005 at 7:33pm
As an interim step, you should add some limitations on the number of messages/cc's that can be sent within some time period.

Lead me not into temptation... I know the short cut, follow me.
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 04 July 2005 at 5:08am
I'm giving it a go, but I entered an incorrect password too many times (I was trying a SQL Injection) and now it says

Account locked! Too many invalid login attempts. A re-activation email has been sent.

Ouch
Back to Top
huwnet View Drop Down
Senior Member
Senior Member


Joined: 30 May 2003
Location: England
Status: Offline
Points: 1375
Post Options Post Options   Thanks (0) Thanks(0)   Quote huwnet Quote  Post ReplyReply Direct Link To This Post Posted: 04 July 2005 at 10:48am
@Mart: I think that might have been me using brute force Embarrassed


Edited by huwnet - 04 July 2005 at 10:48am
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 04 July 2005 at 10:54am
Set up more accounts if you want.
 
I can eliminate brute force, my password is 6 characters alphanumeric and non dictionary.  It also takes 1 second per request to login via FTP etc etc so I don't think it's pheasable.
 
I saw a guest on my site (I track guests) and he had 11,000 page views in a day, so hes suspect.  However, his IP address was the same IP as my server?  What's going on there?
 
I want to put a limit on messages per day, but how?  If I put it on accounts, he can set new accounts up.  He also is probably spoofing his IP address so I can't do it on that.
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 04 July 2005 at 3:30pm
The guest with 11,000 hits and the same ip as your server is probably some software your hosting company uses or something.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 04 July 2005 at 7:48pm
I'm lost...  What software would need to do that? 
Back to Top
 Post Reply Post Reply Page  123 4>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.