Adblock breaks this site

Be careful when using GPBets.com

Discussion in 'Spam Forum' started by Dial, Aug 1, 2014.

  1. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    This is not just an issue if they get hacked, this is a basic security problem that can be exploited extremely easily.

    I first told him about this a week ago.

    These are only 2 small things that I have tested. If they neglect these basic issues, then who knows what else they have that isn't done properly. THESE ARE PHP/SQL BASICS TO FIX THIS.

    I warned him that the users would be made aware, so here it is.

    [​IMG]

    He passes usernames and passwords as a $_GET through the address bar, making it available for anyone to see whether it's through Zopim (Zopim tells the live chat agents what URL the user is at), your history, or someone looking over your shoulder. THIS IS CODING 101. YOU DO NOT LET THIS HAPPEN.

    [​IMG]

    This is an indication that he may not encrypt the passwords, so I tested it.

    [​IMG]

    Sure enough, they're not even encrypted. If they were, he wouldn't be able to list it on another page. This means that he and his developer, as well as hackers, can see your password at any time. This is not a huge problem in itself, the problem comes from the fact that most internet users use the same password among many sites. If you used the same password on GPBets.com as anywhere else, then change it.

    His developer is either a complete moron for not fixing these, or he's interested in your passwords.

    [​IMG]

    He was trying to silence me at first, but -Ryan wasn't having any of that bullshit.

    [​IMG]

    This is not trashing, this is all backed up with proof. I will only remove it if you fix your god damn security problems and stop acting like this is nothing.

    I will continue to post this on every site you advertise on if it doesn't get fixed, because at least I care about the security of your users, even if you don't.

    If anyone ends up hacked on Sythe/Skype and has used this site, Astrola and his developer should be questioned first. They have EVERYONES PASSWORDS and are not fixing it.
     
  2. LoLSmurfin

    LoLSmurfin Gonna need AT LEAST three more dads.
    Banned

    Joined:
    May 21, 2013
    Posts:
    2,295
    Referrals:
    1
    Sythe Gold:
    0
    Be careful when using GPBets.com

    It's pretty funny how he's crying defamation..
     
  3. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Be careful when using GPBets.com

    When someone notices your plan to steal passwords, it's best to not admit it and try to get their accusations deleted. ;)
     
  4. Shin

    Shin Join the Sythe.org Discord
    Retired Administrator Legendary Mudkips $100 USD Donor

    Joined:
    Mar 10, 2007
    Posts:
    14,172
    Referrals:
    23
    Sythe Gold:
    197
    Discord Unique ID:
    777373911821713408
    Pool Shark (4) Village Drunk <3 n4n0 (29) Sythe's 20th Anniversary Battleship Champion
    Be careful when using GPBets.com

    #exposed
     
  5. FireZ

    FireZ BRZ Club Member (2014)
    Retired Administrator Highly Respected

    Joined:
    Dec 3, 2009
    Posts:
    27,899
    Referrals:
    20
    Sythe Gold:
    2,410
    Detective Top Striker Sythe Awards 2013 Winner Sythe's 10th Anniversary Heidy Not sure if srs or just newfag...
    Be careful when using GPBets.com

    All threads = locked
     
  6. Matt

    Matt Don't be afraid to fail... Be afraid not to try.
    Retired Sectional Moderator Ninja Graphics Artist Competition Winner THERSG0D Donor

    Joined:
    Nov 28, 2012
    Posts:
    6,149
    Referrals:
    6
    Sythe Gold:
    58
    SOTMx5 In Memory of Jon
    Be careful when using GPBets.com

    Oh god... 0.0 im happy of the password I used lol. I always use different passwords on forums and new websites. This should be fixed ASAP tho... Its certainly not a good thing..
     
  7. owl9142

    owl9142 Member

    Joined:
    Apr 12, 2013
    Posts:
    71
    Referrals:
    0
    Sythe Gold:
    0
    Christmas 2014 Yellow rat
    Be careful when using GPBets.com

    Glad i used different passwords.Hope he gets this fixed
     
  8. ilovegold69

    ilovegold69 Guru

    Joined:
    Aug 28, 2011
    Posts:
    1,195
    Referrals:
    0
    Sythe Gold:
    77
    Doge I'm LAAAAAAAME
    Be careful when using GPBets.com

    astrola has made a series of betting sites in which he has people donate money all just to cancel the site a few weeks later.
     
  9. Snowbear

    Snowbear Guru

    Joined:
    Nov 25, 2013
    Posts:
    1,751
    Referrals:
    0
    Sythe Gold:
    655
    Discord Unique ID:
    291474870003433483
    Discord Username:
    Snowbear#4660
    Be careful when using GPBets.com

    I'm impressed Dia, good work.

    I personally never even used GPBets, Astrola and his minions spam my skype 3+ times daily asking me to play or join some giveaway or something.
     
  10. Delta Squad

    Delta Squad Don't mind me, just getting my postcount up.
    Village Drunk C++ Programmer $200 USD Donor New

    Joined:
    May 19, 2011
    Posts:
    8,950
    Referrals:
    6
    Sythe Gold:
    2,832
    Discord Unique ID:
    1141474466820538398
    Discord Username:
    deltasquadsythe
    Live Streamer Two Factor Authentication User
    Be careful when using GPBets.com

    what if dial works for da fbeyes and is spying on betting sites to go and shut dem down?
     
  11. Wonderland

    Wonderland spokesman

    Joined:
    Oct 28, 2012
    Posts:
    10,442
    Referrals:
    0
    Sythe Gold:
    1,154
    Be careful when using GPBets.com

    Good looking out
     
  12. Laurie

    Laurie
    Retired Sectional Moderator Pirate $50 USD Donor

    Joined:
    Nov 26, 2007
    Posts:
    7,630
    Referrals:
    0
    Sythe Gold:
    1,197
    M
    Two Factor Authentication User SytheSteamer
    Be careful when using GPBets.com

    Fucking faggot
     
  13. Alex_J_Leon

    Alex_J_Leon Guru
    Mudkips

    Joined:
    Jan 3, 2006
    Posts:
    1,692
    Referrals:
    0
    Sythe Gold:
    969
    Yellow rat Bitch! Heidy Why can't I hold all of these feels? Lumpy Space Princess 420 yolo swag blaze it fuck the popo legalize it anyone got some chips Le Monkey Doge UWotM8? Not sure if srs or just newfag...
    Spyro Wubba Lubba Dub Dub Wait, do you not have an Archer rank? Smashing Rupee I'm LAAAAAAAME Penguin Green eggs and spam Pizza Muncher MushyMuncher
    Be careful when using GPBets.com

    No one overlooks password security that much. Simple password hashing is one thing, but plaintext as well as keeping it in the address bar is horrible. No one can be that ignorant.

    I feel like they'd still plaintext passwords even when they fix the issue, or do a simple MD5 or SHA1 or something really easy to crack.
     
  14. nodnarbusn

    nodnarbusn Grand Master

    Joined:
    Mar 12, 2012
    Posts:
    3,248
    Referrals:
    1
    Sythe Gold:
    214
    Sythe's 10th Anniversary Two Factor Authentication User Village Drunk Not sure if srs or just newfag... UWotM8?
    Be careful when using GPBets.com

    Any proof? Sounds like scamming.
     
  15. FireZ

    FireZ BRZ Club Member (2014)
    Retired Administrator Highly Respected

    Joined:
    Dec 3, 2009
    Posts:
    27,899
    Referrals:
    20
    Sythe Gold:
    2,410
    Detective Top Striker Sythe Awards 2013 Winner Sythe's 10th Anniversary Heidy Not sure if srs or just newfag...
    Be careful when using GPBets.com

    I am thinking the same thing
     
  16. Aesiir

    Aesiir The Infamous Spam Forum Queen.

    Joined:
    May 4, 2011
    Posts:
    1,180
    Referrals:
    0
    Sythe Gold:
    76
    Be careful when using GPBets.com

    Sounds like he has a bad history too. Not like he's helping the community, just abusing it.
     
  17. Chillzer

    Chillzer Buying/Selling 07 gold cheapest rates guaranteed!
    Chillzer Donor

    Joined:
    Apr 20, 2012
    Posts:
    5,191
    Referrals:
    68
    Sythe Gold:
    3,385
    Vouch Thread:
    Click Here
    Discord Unique ID:
    350006911409586176
    Discord Username:
    Frank#2644
    Two Factor Authentication User Easter 2016 In Memory of Jon Paper Trading Competition Participant Sythe's 10th Anniversary Bitch! Homosex (2) Heidy Halloween 2013
    Potamus (2) Easter 2015 (2)
    Be careful when using GPBets.com

    well he did get banned already in the past for "getting hacked" and he fucked over everyone on his site by closing it down after taking a bunch of buy ins/amounts off of people buying chips or maybe something similar, thats what I remember at least, cbf to gravedig
     
  18. XX_PLANKER_xx

    XX_PLANKER_xx Grand Master
    $5 USD Donor New

    Joined:
    Feb 24, 2007
    Posts:
    2,476
    Referrals:
    0
    Sythe Gold:
    14
    Two Factor Authentication User Not sure if srs or just newfag... Wubba Lubba Dub Dub MushyMuncher Wait, do you not have an Archer rank? Halloween 2014
    Be careful when using GPBets.com

    brb haxing every1
     
  19. nodnarbusn

    nodnarbusn Grand Master

    Joined:
    Mar 12, 2012
    Posts:
    3,248
    Referrals:
    1
    Sythe Gold:
    214
    Sythe's 10th Anniversary Two Factor Authentication User Village Drunk Not sure if srs or just newfag... UWotM8?
    Be careful when using GPBets.com

    Nono dont take my glod

    Also FireZ, you know what to do.
     
  20. XX_PLANKER_xx

    XX_PLANKER_xx Grand Master
    $5 USD Donor New

    Joined:
    Feb 24, 2007
    Posts:
    2,476
    Referrals:
    0
    Sythe Gold:
    14
    Two Factor Authentication User Not sure if srs or just newfag... Wubba Lubba Dub Dub MushyMuncher Wait, do you not have an Archer rank? Halloween 2014
    Be careful when using GPBets.com

    I hope he reads my password. I half expected something like this to happen.
     
< dear boatswain, | Nerfed >


 
 
Adblock breaks this site