Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2007-12-23, 03:48 AM   #1
SheepGuy
It's the end of the world as we know it, and I feel fine
 
SheepGuy's Avatar
 
Join Date: Jul 2006
Location: Canada
Posts: 2,527
NATS hacker?

Just got this email, can't remember ever making a sale with these guys, but thought I'd pass it on. I don't visit a lot of boards so I hadn't heard of it

Hi Dan,

Dave from SterlingCash.com here - you may have already heard about the situation regarding a compromise of data from sponsors who use NATS. If not, it's all over the webmaster boards so if you want a very long read, I'm sure you know where to go.

At this point it isn't clear if our data has been compromised or not, but we are going to assume it has and react accordingly.

As far as we see it, the worst case scenario is that our affiliate and member databases have been accessed by a hacker using a NATS admin account which is reserved for use by the NATS tech team. We disabled this account as soon as this issue was brought to our attention, and we have changed passwords on our other admin accounts.

The affiliate data we hold is the information you may have entered when you signed up with us: your name, address, email address, and your ePassporte account name (but NOT your ePass account password). The password for your Sterlingcash.com account is not available via the NATS admin interface, but it is encrypted on our server. It is therefore unlikely (but not impossible) that your Sterlingcash.com password has been decrypted, so we suggest that you change your password as soon as possible. It would also be wise to change the passwords you may have on any other online accounts if you are using the same username / password combination. Please note that we use an email validation system for any affiliate account changes - we ask that anyone who has received any unexpected account change verification emails contact us immediately.

We will be working closely with the NATS techs on this issue and will be in touch again if there are any new developments or useful information we can pass on to you. Don't hesitate to contact me if you have any questions.

Please accept my apologies for any inconvenience caused, and enjoy the holidays!

Regards,
__________________
If the Environment was a bank, they would have saved it by now.
SheepGuy is offline   Reply With Quote
Old 2007-12-23, 05:45 AM   #2
T Pat
You can now put whatever you want in this space :)
 
T Pat's Avatar
 
Join Date: Aug 2003
Location: Paridise
Posts: 3,244
Send a message via ICQ to T Pat
I got one last night from another sponsor:
RagingBucks Affiliate:

Due to the recent NATS exploit that has been brought to our attention, we would like to advise all of our affiliates to change the password they use for our affiliate program. If you use the same password for any other sites, such as epassporte, please change your password on all of those sites as well.

This is a wide spread problem that affected many sponsors that use NATS. If you are an affiliate of any other sponsors that use NATS we would advise you to change the password you use for those sites as well. We are working with NATS to make sure a problem of this nature does not happen again in the future. Your privacy is of the most importances to us and we wanted to bring this matter to your attention.

If you would like to read more about what has happened and NATS' public statement go to:

http://www.gfy.com/showthread.php?t=793881
http://www.gfy.com/showthread.php?t=794219

If you have any questions please feel free to contact me.
__________________
How To Keep An Asshole In Suspense

I'll Tell You Later
T Pat is offline   Reply With Quote
Old 2007-12-23, 06:06 AM   #3
DangerDave
Bonged
 
DangerDave's Avatar
 
Join Date: Mar 2003
Location: BrisVegas, AUSTRALIA
Posts: 4,882
Fucking Nats!
__________________
Old Dollars >>>> Now with over 90 Hosted Free Sites <<<<
DangerDave.com.au - Adult Links to Free Porn
DangerDave is offline   Reply With Quote
Old 2007-12-23, 08:20 AM   #4
tigermom
You can now put whatever you want in this space :)
 
tigermom's Avatar
 
Join Date: Dec 2005
Posts: 893
Send a message via ICQ to tigermom
Thanks for the heads up! Does that mean all nats sponsors have been compromised?
__________________
XLEF
tigermom is offline   Reply With Quote
Old 2007-12-23, 08:27 AM   #5
Bobc01
Banned
 
Join Date: Apr 2007
Location: Hell
Posts: 817
Fuck sake, nothing is ever safe.

Thanks for the info.
Bobc01 is offline   Reply With Quote
Old 2007-12-23, 10:35 AM   #6
Toby
Lonewolf Internet Sales
 
Toby's Avatar
 
Join Date: Mar 2005
Location: Houston
Posts: 4,826
Send a message via ICQ to Toby
Quote:
Originally Posted by tigermom View Post
Thanks for the heads up! Does that mean all nats sponsors have been compromised?
I doubt that ALL nats sponsors have been compromised, but any that had not already disabled the admin password that TMM used for updating and maintaining nats installs is/was vulnerable.

It appears that TMM's internal database of these admin logins was compromised. The fact that this information was even web accessible is appalling. A serious fuck-up by TMM, compounded by the fact that they knew there was some kind of 'hacker' problem many months ago and failed to inform ALL of their clients.

I spent a fair amount of time yesterday checking my account info for all sponsors I've signed up with that use nats. Not exactly how I'd planned to spend several hours yesterday.

"Fucking Nats!" is right. I think CCBill's new cascading solution may have a few additional clients after this fiasco.
Toby is offline   Reply With Quote
Old 2007-12-23, 10:55 AM   #7
JustRobert
Bow Ties Are Cool
 
JustRobert's Avatar
 
Join Date: Jun 2006
Location: California
Posts: 9,386
I received one from Island Dollars as well.
I already hate NATS and this is just adding to it. I probably now need to go thru all fucking accounts and change passwords just to be safe. Hours of fucking joy joy. This may be the time I need to look at the poor converting NATS (nearly all) sponsors and remove them even if they owe me money.
__________________
Submit Your Galleries To The Porn Luv Network!
JustRobert is offline   Reply With Quote
Old 2007-12-23, 11:20 AM   #8
Toby
Lonewolf Internet Sales
 
Toby's Avatar
 
Join Date: Mar 2005
Location: Houston
Posts: 4,826
Send a message via ICQ to Toby
Quote:
Originally Posted by JustRobert View Post
...I probably now need to go thru all fucking accounts and change passwords just to be safe...
and a couple more things just to add a little extra cheer to your pre-holiday Sunday...

Changing your pass is a waste of time until the individual programs have taken the necessary steps to lock down their NATS admin. Being a long holiday weekend, I'm guessing that it will take some programs until the middle of the week to get this done. The ones that you've not heard from regarding this issue are the ones to be concerned about.

If you use the same user/pass combos elsewhere, you'd best be changing all those passes too.

Have a nice holiday
Toby is offline   Reply With Quote
Old 2007-12-23, 11:22 AM   #9
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
One of the thing that I do in case something like this happens is use a different user ID and password on each program.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2007-12-23, 12:28 PM   #10
JustRobert
Bow Ties Are Cool
 
JustRobert's Avatar
 
Join Date: Jun 2006
Location: California
Posts: 9,386
Toby, did not think about the ones I have not heard from yet. Thanks for mentioning that. Either way, probably should check them all out and then will have to go back later when they lock their system down. Yep, a little extra cheer.

Thankfully I do not use the same user/pass combos.
__________________
Submit Your Galleries To The Porn Luv Network!
JustRobert is offline   Reply With Quote
Old 2007-12-23, 12:57 PM   #11
koolkat
Remember to rebel against the authorities, kids!
 
koolkat's Avatar
 
Join Date: Aug 2003
Location: SC
Posts: 401
Quote:
Originally Posted by Toby View Post
The ones that you've not heard from regarding this issue are the ones to be concerned about.
And I haven't got a notice from a single fucking one! Just wonderful!
__________________
Harry Beaver's Lodge
koolkat is offline   Reply With Quote
Old 2007-12-23, 01:04 PM   #12
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
i just got an email from jaymancsh about that nats issue.
stuveltje is offline   Reply With Quote
Old 2007-12-23, 01:40 PM   #13
Toby
Lonewolf Internet Sales
 
Toby's Avatar
 
Join Date: Mar 2005
Location: Houston
Posts: 4,826
Send a message via ICQ to Toby
Quote:
Originally Posted by stuveltje View Post
i just got an email from jaymancsh about that nats issue.
Yup, and kudos to them for already having their shit locked down months ago.
Toby is offline   Reply With Quote
Old 2007-12-23, 01:54 PM   #14
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by Toby View Post
Yup, and kudos to them for already having their shit locked down months ago.
yep thats what their email said, because of their email i checked the gg board about the nats thing, because i didnt heard shit about it before and most of my sponsors are nats users........i hate those issuesmore clusterfucks in my world now.
stuveltje is offline   Reply With Quote
Old 2007-12-23, 04:38 PM   #15
T Pat
You can now put whatever you want in this space :)
 
T Pat's Avatar
 
Join Date: Aug 2003
Location: Paridise
Posts: 3,244
Send a message via ICQ to T Pat
Dear Webmasters,

It has just come to our attention that the NATS user admin login (software provider) that is stored may have been compromised.

Your personal data is important to us and as a precaution, we suggest you change your fetishassets password.

If you have any questions, or need any help doing this. Please email me at: mick@fetishassets.com and I will be happy to help.

Kind regards,

Mick Derbyshire.
www.FetishAssets.com
__________________
How To Keep An Asshole In Suspense

I'll Tell You Later
T Pat is offline   Reply With Quote
Old 2007-12-23, 04:54 PM   #16
JackDaniel's
I like work, it fascinates me, I can sit and look at it for hours...
 
JackDaniel's's Avatar
 
Join Date: Dec 2006
Posts: 3,217
Send a message via ICQ to JackDaniel's
Damn I hate this .... most of my sponsors use nats too
__________________
Submit Your Sites : Get Porn Links
JackDaniel's is offline   Reply With Quote
Old 2007-12-23, 06:50 PM   #17
bluebrit
Along for the ride and loving it.
 
Join Date: Aug 2005
Location: Canada
Posts: 1,873
I need to check my stats for nats sponsors now. I don't think i ever did any good with them and now may be the time to call it quits. As for user names and pw's i have to go check them all out because i haven't had a single email about this.
bluebrit is offline   Reply With Quote
Old 2007-12-24, 02:12 AM   #18
SheepGuy
It's the end of the world as we know it, and I feel fine
 
SheepGuy's Avatar
 
Join Date: Jul 2006
Location: Canada
Posts: 2,527
I'm one of those dumbasses who used variations of the same user/password combo so I switched all of my non-NATS passwords today, as well as those few NATS sites that I actually see checks from. I never liked their pain-in-the-ass interfaces anyways, and since they basically suck as far as earners go, I won't bother with them for any new ventures.
__________________
If the Environment was a bank, they would have saved it by now.
SheepGuy is offline   Reply With Quote
Old 2007-12-24, 02:43 AM   #19
Porn Junkie
I've always wondered if there was a god. And now I know there is -- and it's me
 
Porn Junkie's Avatar
 
Join Date: Apr 2007
Location: Canada Eh!
Posts: 325
Send a message via ICQ to Porn Junkie
i'll second the notice from jaymancash, thank god i don't use many others.

killing my entire night checking sponsors
__________________
EzAngels EzLinks - Submit here
Porn Junkie is offline   Reply With Quote
Old 2007-12-24, 02:48 AM   #20
tigermom
You can now put whatever you want in this space :)
 
tigermom's Avatar
 
Join Date: Dec 2005
Posts: 893
Send a message via ICQ to tigermom
What exactly is it that they can retrieve about me? There's nothing I give out to a nats sponsor that's too secret, I think. It's not fun, for sure, and a breach of my privacy, but I'm not sure how it can hurt me exactly.

I never use the same login/password for anything, so they can't access my epass or paypal accounts or my servers or anything.
__________________
XLEF
tigermom is offline   Reply With Quote
Old 2007-12-24, 07:11 AM   #21
T Pat
You can now put whatever you want in this space :)
 
T Pat's Avatar
 
Join Date: Aug 2003
Location: Paridise
Posts: 3,244
Send a message via ICQ to T Pat
Dear Patrick,

As I am sure you are all aware by now either from monitoring webmaster communities or from multiple sponsor program e-mails there is a potential security breach issue involving all programs who use NATS software to manage their affiliate programs. We are not going to BS you and tell you that we are not affected by any of what is going on because the simple truth of the matter is that at this time we are unsure as to the effect this "breach" has had on our system.

We can tell you that we do monitor our affiliate program very closely and have not noticed anything out of the ordinary at this point; however, it is not improbable that an issue could have occurred and has not been revealed to us at this point. We are working around the clock with NATS and our server company to review activity through our admin access and will notify you of any changes that come to light.

We do, however, highly recommend that all affiliates take this opportunity to log in and change their login password to safeguard the security of your account. We recommend affiliates do this on a regular basis anyway but this situation gives us all a reminder to stay on top of password changes.

As for our responsibility please be assured that we are working through the holidays to keeps tabs on this situation, we have already put IP blocks up and limited access to our admin area and continue to take all other safeguard measures recommended to maintain security of our affiliates and our program.

Sincerely,
Vegas & Angel

MadMoolah.Com
ICQ: 243-499-827
__________________
How To Keep An Asshole In Suspense

I'll Tell You Later
T Pat is offline   Reply With Quote
Old 2007-12-24, 10:40 AM   #22
JustRobert
Bow Ties Are Cool
 
JustRobert's Avatar
 
Join Date: Jun 2006
Location: California
Posts: 9,386
Quote:
Originally Posted by tigermom View Post
What exactly is it that they can retrieve about me? There's nothing I give out to a nats sponsor that's too secret, I think.
I thought the same as I was going thru my sponsors last night. I came across a couple that show your social security number (US webmasters) on the same page as your address, name and epassporte info (if you use them). That is enough info to make someones life miserable in the wrong hands. Sorry, but I do not remember which ones.
__________________
Submit Your Galleries To The Porn Luv Network!
JustRobert is offline   Reply With Quote
Old 2007-12-24, 11:17 AM   #23
T Pat
You can now put whatever you want in this space :)
 
T Pat's Avatar
 
Join Date: Aug 2003
Location: Paridise
Posts: 3,244
Send a message via ICQ to T Pat
I can only change three or four passwords before I feel like breaking something and go on to something else, at this rate it will be New Years by the time I'm done.
Fucking NATS is right
__________________
How To Keep An Asshole In Suspense

I'll Tell You Later
T Pat is offline   Reply With Quote
Old 2007-12-24, 11:27 AM   #24
Useless
Certified Nice Person
 
Useless's Avatar
 
Join Date: Oct 2003
Location: Dirty Undies, NY
Posts: 11,268
Send a message via ICQ to Useless
Quote:
Originally Posted by T Pat View Post
I can only change three or four passwords before I feel like breaking something and go on to something else, at this rate it will be New Years by the time I'm done.
Fucking NATS is right
I did two this morning, so I've had my fill. I wish they could globally change everyones' password instead of having us login and do it ourselves. I'll never see a cent from most of those programs, so I'm not overly concerned if some devious fucker logs in and changes my payout info. |shocking|
__________________
Click here to purchase a bridge I'm selling.
Useless is offline   Reply With Quote
Old 2007-12-24, 11:33 AM   #25
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
i think i just drop all nats sponsors, i dont like to change things and with all the info i have readed about nats now and before i think its no good to use them.
stuveltje is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:44 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc