Be careful when using GPBets.com

Discussion in 'Spam Forum' started by Dial, Aug 1, 2014.

Be careful when using GPBets.com
  1. Unread #1 - Aug 1, 2014 at 10:52 AM
  2. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Be careful when using GPBets.com

    This is not just an issue if they get hacked, this is a basic security problem that can be exploited extremely easily.

    I first told him about this a week ago.

    These are only 2 small things that I have tested. If they neglect these basic issues, then who knows what else they have that isn't done properly. THESE ARE PHP/SQL BASICS TO FIX THIS.

    I warned him that the users would be made aware, so here it is.

    [​IMG]

    He passes usernames and passwords as a $_GET through the address bar, making it available for anyone to see whether it's through Zopim (Zopim tells the live chat agents what URL the user is at), your history, or someone looking over your shoulder. THIS IS CODING 101. YOU DO NOT LET THIS HAPPEN.

    [​IMG]

    This is an indication that he may not encrypt the passwords, so I tested it.

    [​IMG]

    Sure enough, they're not even encrypted. If they were, he wouldn't be able to list it on another page. This means that he and his developer, as well as hackers, can see your password at any time. This is not a huge problem in itself, the problem comes from the fact that most internet users use the same password among many sites. If you used the same password on GPBets.com as anywhere else, then change it.

    His developer is either a complete moron for not fixing these, or he's interested in your passwords.

    [​IMG]

    He was trying to silence me at first, but -Ryan wasn't having any of that bullshit.

    [​IMG]

    This is not trashing, this is all backed up with proof. I will only remove it if you fix your god damn security problems and stop acting like this is nothing.

    I will continue to post this on every site you advertise on if it doesn't get fixed, because at least I care about the security of your users, even if you don't.

    If anyone ends up hacked on Sythe/Skype and has used this site, Astrola and his developer should be questioned first. They have EVERYONES PASSWORDS and are not fixing it.
     
  3. Unread #2 - Aug 1, 2014 at 11:36 AM
  4. LoLSmurfin
    Joined:
    May 21, 2013
    Posts:
    2,295
    Referrals:
    1
    Sythe Gold:
    0

    LoLSmurfin Gonna need AT LEAST three more dads.
    Banned

    Be careful when using GPBets.com

    It's pretty funny how he's crying defamation..
     
  5. Unread #3 - Aug 1, 2014 at 11:40 AM
  6. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Be careful when using GPBets.com

    When someone notices your plan to steal passwords, it's best to not admit it and try to get their accusations deleted. ;)
     
  7. Unread #4 - Aug 1, 2014 at 1:12 PM
  8. Shin
    Joined:
    Mar 10, 2007
    Posts:
    14,172
    Referrals:
    23
    Sythe Gold:
    197
    Discord Unique ID:
    777373911821713408
    Pool Shark (4) Village Drunk <3 n4n0 (29) Battleship Champion

    Shin Join the Sythe.org Discord
    Retired Administrator Legendary Mudkips $100 USD Donor

    Be careful when using GPBets.com

    #exposed
     
  9. Unread #5 - Aug 1, 2014 at 1:27 PM
  10. FireZ
    Joined:
    Dec 3, 2009
    Posts:
    27,899
    Referrals:
    20
    Sythe Gold:
    2,410
    Detective Top Striker Sythe Awards 2013 Winner Sythe's 10th Anniversary Heidy Not sure if srs or just newfag...

    FireZ BRZ Club Member (2014)
    Retired Administrator Highly Respected

    Be careful when using GPBets.com

    All threads = locked
     
  11. Unread #6 - Aug 1, 2014 at 2:22 PM
  12. Matt
    Joined:
    Nov 28, 2012
    Posts:
    6,149
    Referrals:
    6
    Sythe Gold:
    58
    SOTMx5 In Memory of Jon

    Matt Don't be afraid to fail... Be afraid not to try.
    Retired Sectional Moderator Ninja Graphics Artist Competition Winner THERSG0D Donor

    Be careful when using GPBets.com

    Oh god... 0.0 im happy of the password I used lol. I always use different passwords on forums and new websites. This should be fixed ASAP tho... Its certainly not a good thing..
     
  13. Unread #7 - Aug 1, 2014 at 2:28 PM
  14. owl9142
    Joined:
    Apr 12, 2013
    Posts:
    71
    Referrals:
    0
    Sythe Gold:
    0
    Christmas 2014 Yellow rat

    owl9142 Member

    Be careful when using GPBets.com

    Glad i used different passwords.Hope he gets this fixed
     
  15. Unread #8 - Aug 1, 2014 at 2:34 PM
  16. ilovegold69
    Joined:
    Aug 28, 2011
    Posts:
    1,195
    Referrals:
    0
    Sythe Gold:
    77
    Doge I'm LAAAAAAAME

    ilovegold69 Guru

    Be careful when using GPBets.com

    astrola has made a series of betting sites in which he has people donate money all just to cancel the site a few weeks later.
     
  17. Unread #9 - Aug 1, 2014 at 2:51 PM
  18. Snowbear
    Joined:
    Nov 25, 2013
    Posts:
    1,751
    Referrals:
    0
    Sythe Gold:
    655
    Discord Unique ID:
    291474870003433483
    Discord Username:
    Snowbear#4660

    Snowbear Guru

    Be careful when using GPBets.com

    I'm impressed Dia, good work.

    I personally never even used GPBets, Astrola and his minions spam my skype 3+ times daily asking me to play or join some giveaway or something.
     
  19. Unread #10 - Aug 1, 2014 at 2:53 PM
  20. Delta Squad
    Joined:
    May 19, 2011
    Posts:
    8,945
    Referrals:
    6
    Sythe Gold:
    2,827
    Discord Unique ID:
    1141474466820538398
    Discord Username:
    deltasquadsythe
    Live Streamer Two Factor Authentication User

    Delta Squad Don't mind me, just getting my postcount up.
    Village Drunk C++ Programmer $200 USD Donor New

    Be careful when using GPBets.com

    what if dial works for da fbeyes and is spying on betting sites to go and shut dem down?
     
  21. Unread #11 - Aug 1, 2014 at 3:29 PM
  22. Wonderland
    Joined:
    Oct 28, 2012
    Posts:
    10,442
    Referrals:
    0
    Sythe Gold:
    1,154

    Wonderland spokesman

    Be careful when using GPBets.com

    Good looking out
     
  23. Unread #12 - Aug 1, 2014 at 4:13 PM
  24. Laurie
    Joined:
    Nov 26, 2007
    Posts:
    7,630
    Referrals:
    0
    Sythe Gold:
    1,197
    M
    Two Factor Authentication User SytheSteamer

    Laurie
    Retired Sectional Moderator Pirate $50 USD Donor

    Be careful when using GPBets.com

    Fucking faggot
     
  25. Unread #13 - Aug 1, 2014 at 4:23 PM
  26. Alex_J_Leon
    Joined:
    Jan 3, 2006
    Posts:
    1,692
    Referrals:
    0
    Sythe Gold:
    969
    Yellow rat Bitch! Heidy Why can't I hold all of these feels? Lumpy Space Princess 420 yolo swag blaze it fuck the popo legalize it anyone got some chips Le Monkey Doge UWotM8? Not sure if srs or just newfag...
    Spyro Wubba Lubba Dub Dub Wait, do you not have an Archer rank? Smashing Rupee I'm LAAAAAAAME Penguin Green eggs and spam Pizza Muncher MushyMuncher

    Alex_J_Leon Guru
    Mudkips

    Be careful when using GPBets.com

    No one overlooks password security that much. Simple password hashing is one thing, but plaintext as well as keeping it in the address bar is horrible. No one can be that ignorant.

    I feel like they'd still plaintext passwords even when they fix the issue, or do a simple MD5 or SHA1 or something really easy to crack.
     
  27. Unread #14 - Aug 1, 2014 at 4:43 PM
  28. nodnarbusn
    Joined:
    Mar 12, 2012
    Posts:
    3,248
    Referrals:
    1
    Sythe Gold:
    214
    Sythe's 10th Anniversary Two Factor Authentication User Village Drunk Not sure if srs or just newfag... UWotM8?

    nodnarbusn Grand Master

    Be careful when using GPBets.com

    Any proof? Sounds like scamming.
     
  29. Unread #15 - Aug 1, 2014 at 4:56 PM
  30. FireZ
    Joined:
    Dec 3, 2009
    Posts:
    27,899
    Referrals:
    20
    Sythe Gold:
    2,410
    Detective Top Striker Sythe Awards 2013 Winner Sythe's 10th Anniversary Heidy Not sure if srs or just newfag...

    FireZ BRZ Club Member (2014)
    Retired Administrator Highly Respected

    Be careful when using GPBets.com

    I am thinking the same thing
     
  31. Unread #16 - Aug 1, 2014 at 5:03 PM
  32. Aesiir
    Joined:
    May 4, 2011
    Posts:
    1,180
    Referrals:
    0
    Sythe Gold:
    76

    Aesiir The Infamous Spam Forum Queen.

    Be careful when using GPBets.com

    Sounds like he has a bad history too. Not like he's helping the community, just abusing it.
     
  33. Unread #17 - Aug 1, 2014 at 5:10 PM
  34. Chillzer
    Joined:
    Apr 20, 2012
    Posts:
    5,191
    Referrals:
    68
    Sythe Gold:
    3,385
    Vouch Thread:
    Click Here
    Discord Unique ID:
    350006911409586176
    Discord Username:
    Frank#2644
    Two Factor Authentication User Easter 2016 In Memory of Jon Paper Trading Competition Participant Sythe's 10th Anniversary Bitch! Homosex (2) Heidy Halloween 2013
    Potamus (2) Easter 2015 (2)

    Chillzer Buying/Selling 07 gold cheapest rates guaranteed!
    Chillzer Donor

    Be careful when using GPBets.com

    well he did get banned already in the past for "getting hacked" and he fucked over everyone on his site by closing it down after taking a bunch of buy ins/amounts off of people buying chips or maybe something similar, thats what I remember at least, cbf to gravedig
     
  35. Unread #18 - Aug 1, 2014 at 5:22 PM
  36. XX_PLANKER_xx
    Joined:
    Feb 24, 2007
    Posts:
    2,476
    Referrals:
    0
    Sythe Gold:
    14
    Two Factor Authentication User Not sure if srs or just newfag... Wubba Lubba Dub Dub MushyMuncher Wait, do you not have an Archer rank? Halloween 2014

    XX_PLANKER_xx Grand Master
    $5 USD Donor New

    Be careful when using GPBets.com

    brb haxing every1
     
  37. Unread #19 - Aug 1, 2014 at 5:25 PM
  38. nodnarbusn
    Joined:
    Mar 12, 2012
    Posts:
    3,248
    Referrals:
    1
    Sythe Gold:
    214
    Sythe's 10th Anniversary Two Factor Authentication User Village Drunk Not sure if srs or just newfag... UWotM8?

    nodnarbusn Grand Master

    Be careful when using GPBets.com

    Nono dont take my glod

    Also FireZ, you know what to do.
     
  39. Unread #20 - Aug 1, 2014 at 5:32 PM
  40. XX_PLANKER_xx
    Joined:
    Feb 24, 2007
    Posts:
    2,476
    Referrals:
    0
    Sythe Gold:
    14
    Two Factor Authentication User Not sure if srs or just newfag... Wubba Lubba Dub Dub MushyMuncher Wait, do you not have an Archer rank? Halloween 2014

    XX_PLANKER_xx Grand Master
    $5 USD Donor New

    Be careful when using GPBets.com

    I hope he reads my password. I half expected something like this to happen.
     
< dear boatswain, | Nerfed >

Users viewing this thread
1 guest


 
 
Adblock breaks this site