Was hacked. Lost over $1,000. You could be effected also!

Discussion in 'Directories' started by aaron_nimocks, Jun 2, 2007.

  1. onlinedude

    onlinedude Peon

    Messages:
    1,193
    Likes Received:
    322
    Best Answers:
    0
    Trophy Points:
    0
    #21
    That really is a new low! Sorry to hear about it.

    If you were using phpld, there's a table PLD_PAYMENT which shows details for all the payments you receive. It doesn't look like it contains urls, but you should be able to re-construct from this the name and email address for all the submissions you received. Maybe use this info to email people affected.
     
    onlinedude, Jun 2, 2007 IP
  2. aaron_nimocks

    aaron_nimocks Im kind of a big deal Staff

    Messages:
    5,563
    Likes Received:
    627
    Best Answers:
    0
    Trophy Points:
    420
    #22
    Ya Im using esyndicat for that directory. Really no idea how they got in or what they did but its fixed now.

    Also with that script theres no way to pull up old data of what was submitted after I delted it.
     
    aaron_nimocks, Jun 2, 2007 IP
  3. smub

    smub Notable Member

    Messages:
    3,443
    Likes Received:
    375
    Best Answers:
    0
    Trophy Points:
    230
    #23
    demn man that sucks ...

    i need to check mine now
     
    smub, Jun 2, 2007 IP
  4. malcolm1

    malcolm1 Prominent Member

    Messages:
    7,148
    Likes Received:
    758
    Best Answers:
    0
    Trophy Points:
    310
    #24
    I would notify Paypal immediatly and have that account shut down ASAP..
    ( As im sure you have already done)...then as onlinedude said contact all interested parties and offer them thier link as im sure that they dont want to get burnt and this will only build your reputation as a decent directory owner whom cares about his customers.
    Yes that does suck and this should be a reminder to all to make those passwords harder or in effect take better precautions so this sort of thing doesnt keep happening to others.... Getting with your host may also be a good idea for them to do somthing about these sort of things...

    thx
    malcolm
     
    malcolm1, Jun 2, 2007 IP
  5. aaron_nimocks

    aaron_nimocks Im kind of a big deal Staff

    Messages:
    5,563
    Likes Received:
    627
    Best Answers:
    0
    Trophy Points:
    420
    #25
    Can do all that but theres no way to contact the people who submitted. If anyone did. All links that were submitted without payment were deleted. Usually get 10 of those a day normally so didnt think much of it.

    Now that I think of it the contact form on the site works and no one every contacted me about it. Maybe whatever they did broke the payment processing and no one ever bought a link. Only reason I say that is no one has contacted me yet.
     
    aaron_nimocks, Jun 2, 2007 IP
  6. MeetHere

    MeetHere Prominent Member

    Messages:
    15,399
    Likes Received:
    994
    Best Answers:
    0
    Trophy Points:
    330
    #26
    @malcolm - he dont have submitters contact email - He deleted all of them in a go..

    Thats very sad.. We will try hard to support you in every respect.
    Can you remember any of the url you deleted :(
     
    MeetHere, Jun 2, 2007 IP
  7. aaron_nimocks

    aaron_nimocks Im kind of a big deal Staff

    Messages:
    5,563
    Likes Received:
    627
    Best Answers:
    0
    Trophy Points:
    420
    #27
    No I dont remember any. It was 10 a day for 3 weeks.

    But I am starting to think maybe no one every paid because the script was broke. I would have definetly got an email from my contact form by now
     
    aaron_nimocks, Jun 2, 2007 IP
  8. MeetHere

    MeetHere Prominent Member

    Messages:
    15,399
    Likes Received:
    994
    Best Answers:
    0
    Trophy Points:
    330
    #28
    As blogmaster told that Saad was going to submit to your directory (or submitted) - Better to ask him to which paypal account he paid for a listing on your site..
     
    MeetHere, Jun 2, 2007 IP
  9. malcolm1

    malcolm1 Prominent Member

    Messages:
    7,148
    Likes Received:
    758
    Best Answers:
    0
    Trophy Points:
    310
    #29
    I agree that if i submitted and i paid and dont see my link i will make the effort of contacting you so obviosly the money never went threw...OR the contact page was changed or is broke is/are really the only options that i see available.

    Again my sites are all phpld so im only used to how that works and not syndicat so i dont know if its the same set up...

    thx
    malcolm
     
    malcolm1, Jun 2, 2007 IP
  10. mywebsearches

    mywebsearches Peon

    Messages:
    764
    Likes Received:
    116
    Best Answers:
    0
    Trophy Points:
    0
    #30
    Hummmm,

    There must be something to know who did it. It is impossible not to leave a something behind.

    Your story is unique, I have heard others but yours is the best.

    I wish you good luck!
     
    mywebsearches, Jun 2, 2007 IP
  11. Laceygirl

    Laceygirl Notable Member

    Messages:
    4,617
    Likes Received:
    188
    Best Answers:
    1
    Trophy Points:
    250
    #31
    Someone hacked a site of mine and I mentioned it in a topic that he was in at digital point.

    I was nearly banned for harassing him.

    I wouldn't bother. If you got his Paypal ID, then you can get lots of info from him. Just go after him.
     
    Laceygirl, Jun 2, 2007 IP
  12. Steve Myers

    Steve Myers Active Member

    Messages:
    724
    Likes Received:
    49
    Best Answers:
    0
    Trophy Points:
    90
    #32
    aaron, sorry to hear this situation, I really hope everything goes back to normal, I couldn't imagine how much stress that may have caused.

    Take it easy and let us know how everything is going.
     
    Steve Myers, Jun 2, 2007 IP
  13. SFOD_D223

    SFOD_D223 Peon

    Messages:
    4,512
    Likes Received:
    174
    Best Answers:
    0
    Trophy Points:
    0
    #33
    I was wondering is there any way for a scammer to bypass the payment process. How do they get past the files that bring up the paypal submission page?
     
    SFOD_D223, Jun 2, 2007 IP
  14. dargre

    dargre Peon

    Messages:
    1,007
    Likes Received:
    161
    Best Answers:
    0
    Trophy Points:
    0
    #34
    Horrible story, even hard to imagine.
    Did you investigate on someone who could have access to your network?
    Telling the truth I could do the same with about 500+ directories.
    And not because people trust me while installing mods.
    But then what? Escape where? All for $1K?
    Whoever the thief is - he's very stupid thief.
     
    dargre, Jun 2, 2007 IP
  15. aaron_nimocks

    aaron_nimocks Im kind of a big deal Staff

    Messages:
    5,563
    Likes Received:
    627
    Best Answers:
    0
    Trophy Points:
    420
    #35
    Well the 1k if that was actually the number I could care less about. Im not even mad over that part.

    Only thing I really cared about is all the submissions that people did and where that money went and that they got nothing in return.
     
    aaron_nimocks, Jun 2, 2007 IP
  16. Gnet

    Gnet Peon

    Messages:
    5,340
    Likes Received:
    529
    Best Answers:
    0
    Trophy Points:
    0
    #36
    Woa aaron...sorry to hear that!
    Can ya post the email id of this scammer? this thread will get picked up in serps soon so post it on the first post too.
     
    Gnet, Jun 2, 2007 IP
  17. sweetfunny

    sweetfunny Banned

    Messages:
    5,743
    Likes Received:
    467
    Best Answers:
    0
    Trophy Points:
    0
    #37
    If you had no idea how they got in, how did you fix it?

    I take it by fixed you mean the site's working again but the vulnerability still exists. Don't suppose you have any server logs after this long?
     
    sweetfunny, Jun 2, 2007 IP
  18. livingearth

    livingearth Well-Known Member

    Messages:
    1,469
    Likes Received:
    83
    Best Answers:
    0
    Trophy Points:
    140
    #38
    With all the interest I'm sure you will get it sorted out. This is good reason for the rest of us to double check our security. Pls let us know if you ever figure out just what the vulnerability was...
     
    livingearth, Jun 2, 2007 IP
  19. aaron_nimocks

    aaron_nimocks Im kind of a big deal Staff

    Messages:
    5,563
    Likes Received:
    627
    Best Answers:
    0
    Trophy Points:
    420
    #39
    Well contacted Paypal and that account was already under investigation so anyone that bought something through my website are getting refunded. Thats all they could tell me because its really not my business since they frauded my buyers and not me.

    Anyways I can say the email address now to be aware of.



    But dont think they will be around for much longer at all.
     
    aaron_nimocks, Jun 2, 2007 IP
  20. malcolm1

    malcolm1 Prominent Member

    Messages:
    7,148
    Likes Received:
    758
    Best Answers:
    0
    Trophy Points:
    310
    #40
    well im sure they will get another email and then try again with someone elses site till they get caught then it becomes a federal crime if they are US citizens or sometimes it dont matter like the Enron scam as they grabbed those brits and dragged them to USA soil for prosecution...

    Glad to see its been handled though...

    thx
    malcolm
     
    malcolm1, Jun 2, 2007 IP