Adblock breaks this site

Be careful when using GPBets.com

Discussion in 'Report A Scammer Archive' started by Dial, Aug 1, 2014.

Thread Status:
Not open for further replies.
  1. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    This is not just an issue if they get hacked, this is a basic security problem that can be exploited extremely easily.

    I first told him about this a week ago.

    These are only 2 small things that I have tested. If they neglect these basic issues, then who knows what else they have that isn't done properly. THESE ARE PHP/SQL BASICS TO FIX THIS.

    I warned him that the users would be made aware, so here it is.

    [​IMG]

    He passes usernames and passwords as a $_GET through the address bar, making it available for anyone to see whether it's through Zopim (Zopim tells the live chat agents what URL the user is at), your history, or someone looking over your shoulder. THIS IS CODING 101. YOU DO NOT LET THIS HAPPEN.

    [​IMG]

    This is an indication that he may not encrypt the passwords, so I tested it.

    [​IMG]

    Sure enough, they're not even encrypted. If they were, he wouldn't be able to list it on another page. This means that he and his developer, as well as hackers, can see your password at any time. This is not a huge problem in itself, the problem comes from the fact that most internet users use the same password among many sites. If you used the same password on GPBets.com as anywhere else, then change it.

    His developer is either a complete moron for not fixing these, or he's interested in your passwords.

    [​IMG]

    He was trying to silence me at first, but -Ryan wasn't having any of that bullshit.

    [​IMG]

    This is not trashing, this is all backed up with proof. I will only remove it if you fix your god damn security problems and stop acting like this is nothing.

    I will continue to post this on every site you advertise on if it doesn't get fixed, because at least I care about the security of your users, even if you don't.

    If anyone ends up hacked on Sythe/Skype and has used this site, Astrola and his developer should be questioned first. They have EVERYONES PASSWORDS and are not fixing it.
     
  2. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    Reason for this being in RaSc is because this guy has either hired a complete moron, or is trying to harvest user data that puts Sythe users at serious risk.

    He should be banned until he can prove that his code is clean.
     
  3. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    Bump for exposure.
     
  4. Ardy

    Ardy dOnT bE sIlLy Im StIlL gOnNa SeNd It
    $200 USD Donor New Retired Global Moderator

    Joined:
    Jul 9, 2007
    Posts:
    5,828
    Referrals:
    1
    Sythe Gold:
    122
    Discord Unique ID:
    178668500468891648
    Discord Username:
    Ardy#1492
    Be careful when using GPBets.com

    Just so you're aware staff are looking into this, just so you know we've seen it. :)
     
  5. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    Okay thanks Drento.
     
  6. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    Any updates? :)
     
  7. Ardy

    Ardy dOnT bE sIlLy Im StIlL gOnNa SeNd It
    $200 USD Donor New Retired Global Moderator

    Joined:
    Jul 9, 2007
    Posts:
    5,828
    Referrals:
    1
    Sythe Gold:
    122
    Discord Unique ID:
    178668500468891648
    Discord Username:
    Ardy#1492
    Be careful when using GPBets.com

    Astrola will be banned until he fixes the security problems as determined by a staff discussion.
     
< HighRiser21 is a scammer! | Tontern is scammer >
Thread Status:
Not open for further replies.


 
 
Adblock breaks this site