Violation

Discussion in 'Co-op Advertising Network' started by HostGeekZ, Apr 9, 2005.

  1. #1
    Hello,

    We belive a user of your service has gained unauthorized access to one of our servers. The details of this user taken from the ad_network_ads_189.txt file shows

    1113101663|216.9.35.51|us82jsdd|400|900|4

    Can you please investigate this users account, we will provide further information on which site the ads are running on(they are still there), we belive this user has gained things from your network because its running on one of our larger websites.

    Also, I want to signup with my own website, but it says my site url is in use, but its not me occupying that can you show me what email is using it or remove them, I can provide information that it is MY website.

    -Scott
     
    HostGeekZ, Apr 9, 2005 IP
  2. Arnie

    Arnie Well-Known Member

    Messages:
    4,004
    Likes Received:
    116
    Best Answers:
    0
    Trophy Points:
    105
    #2
    Did someone take action in your case? I believe what your're saying.
    I had troubles ones before when I joined coop. When I tried to delete the textfile it was still on the server. Needed to contact my hosting company to remove it and a day later installed a new one.
    Still I'm using coop now, even there are recently strange movements with the weight which seems not normal.
     
    Arnie, Apr 9, 2005 IP
  3. E Doc Tong

    E Doc Tong Peon

    Messages:
    111
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Bit of friendly advice for anyone using the co-op.
    Move that text-file out of the public_html (www) folder.
    I suggest making a new folder at the same level as public_html
    and placing it in there.

    At the very least rename the text file to something weird.

    (obviously you also need to change the PHP code to reflect your changes :p)
     
    E Doc Tong, Apr 10, 2005 IP
  4. minstrel

    minstrel Illustrious Member

    Messages:
    15,082
    Likes Received:
    1,243
    Best Answers:
    0
    Trophy Points:
    480
    #4
    whois on 216.9.35.51

    Blacklist Status: Clear
    Whois History: 16 records stored
    Record Type: IP Address
    IP Location: United States - California - San Diego - Digital Point Solutions
    Reverse IP: No websites hosted using this IP address
    Reverse DNS: blink.digitalpoint.com


    --------------------------------------------------------------------------------
    NetHere Inc. NETHERE-3 (NET-216-9-32-0-1)
    216.9.32.0 - 216.9.47.255
    Digital Point Solutions NTHR-DIGITAL-POINT (NET-216-9-35-48-1)
    216.9.35.48 - 216.9.35.63
     
    minstrel, Apr 10, 2005 IP
  5. minstrel

    minstrel Illustrious Member

    Messages:
    15,082
    Likes Received:
    1,243
    Best Answers:
    0
    Trophy Points:
    480
    #5
    Why do you feel a need to do this?
     
    minstrel, Apr 10, 2005 IP
  6. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Must be due to the fact is you 777 it everybody can write to it right? So if a spammer finds all Co-op sites and figures out the location and name of the txt file he can write his links into it... Am I correct here or am I talking nonsense?
     
    T0PS3O, Apr 10, 2005 IP
  7. E Doc Tong

    E Doc Tong Peon

    Messages:
    111
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #7
    That was my thinking.

    However, I believe it depends how your server is set up to run PHP... (?)
    I seem to have it working just fine now with permissions set to 660

    The advise I've read on this forum would suggest that you need to set it to 666
    Which seems to me like anyone could write to it - either by writing their ads to it, writing some nasty text-links in there, or just plain writing TONS of garbage to your filesystem. Dunno - might well be talking sh!te

    I moved mine out of the public_html directory when I read that it needed to be set to 666 (before I had taken the time to have a good look at the code). I see no real reason to make it world-writable, tried 660 and it seems to be working just fine.
     
    E Doc Tong, Apr 10, 2005 IP
  8. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #8
    The minimal permissions would just need to be that the user the web server is running as can write to the .txt file. Truthfully, though, I'm not sure how effective it would be for a hacker to write their links to the .txt file, since the PHP file flushes those ads in a rotating fashion... so they would have to come back every day to re-add them. Also, of course make sure permissions to the PHP file are not writable by anyone except you.
     
    digitalpoint, Apr 10, 2005 IP
  9. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #9
    What is the site URL?
     
    digitalpoint, Apr 10, 2005 IP
  10. HostGeekZ

    HostGeekZ Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I have sent it to you.
     
    HostGeekZ, Apr 14, 2005 IP