Home TheRandomizer Forum Index Log in Register FAQ Search
TheRandomizer Forum Index » Bug Reports » Hacker bypassing Payment Gateway Goto page Previous  1, 2
Post new topic  Reply to topic View previous topic :: View next topic 
PostPosted: Fri Sep 30, 2005 4:22 am Reply with quote
Traffic Matrix
Newbie
Joined: 23 Oct 2004
Posts: 8




Hello therandomizer.net, this guy has signed up again over night. Using the IP above, he used the same IP yesterday until I deleted him and he tried again using 202.3.217.125.

How about a ban IP address for now, to block him?
PostPosted: Fri Sep 30, 2005 5:09 am Reply with quote
fewrandomizers
Visitor
Joined: 08 Sep 2005
Posts: 16
Location: USA




There isn't any way to ban IP address from the randomizer script.

However, I believe you can from your hosting account (cPanel or etc).
PostPosted: Fri Sep 30, 2005 6:55 am Reply with quote
Traffic Matrix
Newbie
Joined: 23 Oct 2004
Posts: 8




Unfortunately it is not possible with my control panel, however it is possible to add something like this to the PHP script. It is the responsibility of therandomizer.net to ensure that the script is safe.

It is not safe.

It is about credibility, there is a security hole in the script that needs to be sorted ASAP. I hace heard nothing from Manish on the subject.
PostPosted: Fri Sep 30, 2005 5:49 pm Reply with quote
fewrandomizers
Visitor
Joined: 08 Sep 2005
Posts: 16
Location: USA




Quote:
Unfortunately it is not possible with my control panel, however it is possible to add something like this to the PHP script. It is the responsibility of therandomizer.net to ensure that the script is safe.

It is not safe.

It is about credibility, there is a security hole in the script that needs to be sorted ASAP. I hace heard nothing from Manish on the subject.


Yes true- should do something about blocking/unblocking IP address in therandomizer's admin section.

Manish- He is currently unavailable because of the moving of the host or whatever... which he unable to access to the internet or this website. I saw a message about 'Manish Unavailable' somewhere on this forum about it.
Actually it's pretty easy...
PostPosted: Fri Sep 30, 2005 7:38 pm Reply with quote
Chris
Site Admin
Joined: 05 Feb 2005
Posts: 304




I attempted this when I first got my script, and it's actually very easy to bypass the payments all together, although no hacking is actually taking place, the user is simply tricking the script into thinking a payment is made and therefore taken to the next step with no problem until he is finally taken to the final account signup stage. The script itself is encrypted, the payment part is encrypted using a low-level encryption easily bypassed if you know how to do it which I am not going to tell anyone how to do it, but I don't think there is anyway to protect the signup process unless an API is used to verify payment before the account will be setup. All you have to do is set it to manual verify in the admin area and the accounts won't be active until the admin of the system verifies payments across the board.
Turn this hacker into the FBI
PostPosted: Sat Oct 01, 2005 3:53 am Reply with quote
koopa1961
Visitor
Joined: 10 Sep 2005
Posts: 32
Location: Walla Walla, WA




I have just turned the hacker Maestro into the FBI. I suggest everyone else that has had a problem with this person file a complaint with the FBI at the following link:

http://www.ic3.gov/

He hacked in again tonight. But thanks to mchris10587 he could not do anything. Thanks for the info. I set my site for manual verify.

Thats send a message to all the hackers not to mess with us!
I have one too!
PostPosted: Fri Mar 10, 2006 7:24 pm Reply with quote
richsar
Newbie
Joined: 10 Mar 2006
Posts: 1
Location: Australia




Dear Randomizer Pro Owner's,

My Name Is Richard Monssen...

I own Instant Cash Randomiser only new....but i have discovered that i have a cheater too...this is what lead me here to get some answer's on how to ban their IP Address or something...

His Detail's are:

Username : Shobhit
Firstname : Shobhit
Lastname : Prabhakar
Address : Vikas nagar
City : Lucknow
State/Region : UP
Country : India
Email address : irfriend@gmail.com
Gateway used:PayPal

I have read the other post's.....and am not like our chance's of the Administrator's being able to do anything for us!

But I will keep my finger's crossed...

Kind Regard's

Richard Monssen
Hi Richard
PostPosted: Fri Mar 10, 2006 10:16 pm Reply with quote
Chris
Site Admin
Joined: 05 Feb 2005
Posts: 304




What you can do is ban his IP across the network from within CPanel, that's your best bet. Also try and find out who his ISP is and report him for hacking.

Chris
PostPosted: Sun Nov 05, 2006 4:12 pm Reply with quote
traffexoneclix
Newbie
Joined: 09 Jun 2006
Posts: 3




I bleieve this may have happened just recently to our site. We had the script show a person sign up via eGold, yet there is no record of this in my eGold account.
IP Address: 203.190.250.104

I put on the Block IP from my server, and enabled Approve accounts manually to try and see if this happens again.

Any other thoughts! Or has this IP address shown up in other sites?

Jeff Rogers
http://www.traffexoneclix.com
http://www.myblog.market2myspace.com
 Hacker bypassing Payment Gateway 
 TheRandomizer Forum Index » Bug Reports
All times are GMT  
Page 2 of 2  
Goto page Previous  1, 2
  
  
 Post new topic  Reply to topic  


Powered by phpBB© 2001-2006 phpBB Group |Randomizer Script | Web Hosting | phpBB Skin by Vjacheslav Trushkin