Page 2 of 2 FirstFirst 12
Results 21 to 36 of 36
  1. #21
    casinoportal's Avatar
    casinoportal is offline Private Member
    Join Date
    June 2002
    Location
    UK
    Posts
    1,172
    Blog Entries
    1
    Thanks
    68
    Thanked 159 Times in 103 Posts

    Default

    SSL is one of the easiest things you can do to increase security, I just don't understand why the GPWA still havn't added it.
    "Many of life's failures are people who did not realize how close they were to success when they gave up"

  2. The Following 3 Users Say Thank You to casinoportal For This Useful Post:

    -Shay- (28 October 2019), DanHorvat (28 October 2019), Former Member 14 (4 November 2019)

  3. #22
    Pokerface's Avatar
    Pokerface is online now Public Member
    Join Date
    August 2016
    Posts
    3,155
    Blog Entries
    1
    Thanks
    686
    Thanked 1,004 Times in 743 Posts

    Default

    Great to see GPWA is back up. Really missed having this great resource.
    nousviz.com

    What's Nous?

    StatsDrone now offers Freemium plan to connect up to 30 programs - FREE!.

  4. The Following User Says Thank You to Pokerface For This Useful Post:

    drifter8 (28 October 2019)

  5. #23
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,932
    Thanks
    4,528
    Thanked 9,288 Times in 5,975 Posts

    Default

    SSL does not stop over 90% of attacks or hacks.

    Rick
    Universal4

  6. #24
    DanHorvat's Avatar
    DanHorvat is offline Private Member
    Join Date
    November 2008
    Location
    Actual location may vary.
    Posts
    1,994
    Blog Entries
    3
    Thanks
    1,417
    Thanked 1,319 Times in 783 Posts

    Default

    Quote Originally Posted by universal4 View Post
    SSL does not stop over 90% of attacks or hacks.
    Do get the SSL to protect the important users.

    I kind of tried to phrase that so you know what I mean without having to explain the problem and the solution explicitly. You know what SSL is used against.

    Ironically, this was an encrypted message sent over a non-encrypted connection.
    Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.

  7. The Following User Says Thank You to DanHorvat For This Useful Post:

    -Shay- (29 October 2019)

  8. #25
    Join Date
    November 2005
    Posts
    4,507
    Blog Entries
    1
    Thanks
    1,920
    Thanked 2,216 Times in 1,278 Posts

    Default

    Quote Originally Posted by universal4 View Post
    SSL does not stop over 90% of attacks or hacks.
    Semantics...

    However, fact remains without SSL everything transmitted to and from the server to this forum etc., etc., in sent unsecured via "plain text".

  9. The Following User Says Thank You to Former Member 14 For This Useful Post:

    -Shay- (29 October 2019)

  10. #26
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,349
    Blog Entries
    1
    Thanks
    7,100
    Thanked 4,341 Times in 2,834 Posts

    Default

    Joining everyone about the SSL talk, it is important, there are many services that can help such as - https://letsencrypt.org/

  11. #27
    Malikbhai is offline Private Member
    Join Date
    September 2017
    Posts
    786
    Thanks
    204
    Thanked 378 Times in 247 Posts

    Default

    Passwords are hashed, so any local exploit can result in getting emails and usernames.

    Hacks where big money or an impact - say anonymous hacking the Pentagon - is made is usaully a result of social engineering. People-to-people contact, and getting into the network through acting as clients, fake employees etc. There's ton of ways.

    SSL doesn't protect crap. If a slightly above-average hacking network wants to target you - you're a done deal. But you got to be worth their money and time.

  12. The Following User Says Thank You to Malikbhai For This Useful Post:

    universal4 (29 October 2019)

  13. #28
    MichaelCorfman's Avatar
    MichaelCorfman is offline GPWA Executive Director
    Join Date
    June 2004
    Location
    Newton, MA
    Posts
    4,701
    Thanks
    1,089
    Thanked 6,364 Times in 2,040 Posts

    Default

    I edited my original post with the following additional information:

    Quote Originally Posted by MichaelCorfman View Post
    We reported the attack to the FBI and are providing information about the attack to the division of the FBI responsible for investigating and responding to this type of criminal activity.

    We do not believe the attack targeted the GPWA, or that any potential vulnerabilities in the GPWA website were exploited in the attack. Rather, we believe the impact on the GPWA website was collateral damage.

    We implemented many security measures within the GPWA website years ago. For example, access to the the forum administrative interface is restricted to those connected to our internal network, either physically or through VPN. And we have active monitors that look for any instances of elevated forum privileges on a continuous basis and report them for action immediately. There are also many other security measures in place, although, for obvious reasons, I don't want to provide extensive documentation regarding our security measures in a publicly available post.
    Separately, the issue of the use, or rather the current lack of use SSL on the GPWA website has been raised in this post. We did begin a project some time ago to convert to SSL, and I expect that project to be concluded soon. I will be reporting progress on that project in a separate thread. However, we firmly believe the fact that SSL is not currently used on the GPWA website was not exploited in the attack.

    Michael
    GPWA Executive Director, Casino City CEO, Friend to the Village Idiot
    Resources for Affiliates: iGamingDirectory.com, iGamingAffiliatePrograms.com, GamingMeets.com

  14. #29
    Join Date
    November 2005
    Posts
    4,507
    Blog Entries
    1
    Thanks
    1,920
    Thanked 2,216 Times in 1,278 Posts

    Default

    Quote Originally Posted by Malikbhai View Post
    Passwords are hashed, so any local exploit can result in getting emails and usernames.
    For those who aren't savvy to what all this means. The following person explains this far better than I could
    https://security.stackexchange.com/u.../thomas-pornin

    This is his post to a question about passwords and data sent over non SSL.
    https://security.stackexchange.com/q...ssl-connection

    When data is exchanged over the Internet, it hops from router to router, starting with the source (your desktop computer) and ending with the destination (the authentication server to which you are sending the password). All the routers, by definition, "see" the data. Moreover, all machines which are directly plugged with the link between any two routers can also see the data.

    In practice, for low-level attackers, password sniffing mostly occurs through three mechanisms:

    1. Close to the user (you). E.g. you are using your laptop and connecting through a WiFi access point; other machines connected to the same access point see all your traffic. Note that "taking steps" to prevent such local attackers can be quite difficult (for instance, forget it is WiFi is involved).
    2. Close to the server. Typically, servers are mass-hosted in some shared facilities, and indelicate server owners may spy on their neighbours. Whether this is possible or even easy depends a lot on the competence of the network administrators at the hosting site.
    3. Through active redirection. When you want to connect to a server, you actually type a name, and then the DNS finds the IP address which corresponds to that name. Your machine will send the packets to that IP address. However, the DNS, as a whole, is poorly protected, and can be altered by malicious individual. A bad guy may then transparently redirect your packets to his own machines; he may even inspect the data but still forward it to their true destination, which makes him a Man-in-the-Middle. At that point, the attacker sees all the data, including the password and whatever the password protects, and can hijack the connection at any time.

    All three kinds of sniffing can be put into practice, and are actually applied, by students with a few hundreds of dollars of budget and a lack of morality. More advanced criminals can employ other active methods, e.g. trying to disturb dynamic routing mechanisms. Or simply bribe employees at network facilities (in particular Internet Service Providers).
    SSL (now known as "TLS") fixes things in several ways:

    • It encrypts all the data with a key that only the two end points (your machine and the server) know, effectively keeping out passive eavesdroppers.
    • It uses the server's certificate, so that the client can gain some confidence that it is indeed talking to the intended genuine server, not an attacker-controlled fake. This is the point of the padlock picture and the scary warnings in Web browsers.
    • SSL ensures continuous integrity, meaning that an active attacker cannot simply put himself in MitM position, forward data bytes back and forth, and then hijack the connection after the authentication has taken place. The protection granted by SSL is both for confidentiality (data is unreadable by outsiders) and integrity (data cannot be altered by outsiders), and this encompasses the complete connection, not just the initial steps.

    With SSL active and no certificate validation issue, you can send your password with reasonable guarantee that only the intended server will see it. How the server verifies the password is irrelevant here. Moreover, and again thanks to SSL, the server can assume that the initial authentication is valid for all subsequent traffic over the same connection, because SSL guarantees that it will be talking to the same client all along.
    Last edited by Former Member 14; 30 October 2019 at 7:32 pm. Reason: edit

  15. The Following 2 Users Say Thank You to Former Member 14 For This Useful Post:

    -Shay- (31 October 2019), DaftDog (31 October 2019)

  16. #30
    Tonny is offline Private Member
    Join Date
    March 2011
    Location
    UK
    Posts
    130
    Thanks
    41
    Thanked 61 Times in 42 Posts

  17. #31
    AmyWilson's Avatar
    AmyWilson is offline Public Member
    Join Date
    July 2019
    Location
    Auckland, New Zealand
    Posts
    21
    Thanks
    17
    Thanked 5 Times in 5 Posts

    Default

    Quote Originally Posted by Azureus View Post
    What about HTTPS (certificate)? The website doesn't load through https for me now, only http. I know it may seem like a detail but exactly things like this can increase security.

    Malikbhai don't judge like this... it is just retarded to put an equal sign between hacker and Russian. Could be from anywhere, China, Arab countries, Europe, even USA. There was even a theory with good evidence that biggest ransomware/Wannacry was done by North Korea. Could even be specifically targeted attack by someone from the industry, when you allow free speech about companies, you will have enemies.

    Anyways, glad to see the forum online again. What about SSL?
    Totally agree with Azureus regarding SSL. Moreover, it is wrong and unethical to judge so superficially like Malikbhai, hackers can be from any country in the world.

  18. The Following User Says Thank You to AmyWilson For This Useful Post:

    drifter8 (5 November 2019)

  19. #32
    -Shay- is offline Public Member
    Join Date
    November 2012
    Posts
    3,061
    Thanks
    12,175
    Thanked 3,133 Times in 1,685 Posts

    Default

    I suspect that this site and the servers are not out of the woods yet. Long load times and blocked access to home page...

  20. #33
    MichaelCorfman's Avatar
    MichaelCorfman is offline GPWA Executive Director
    Join Date
    June 2004
    Location
    Newton, MA
    Posts
    4,701
    Thanks
    1,089
    Thanked 6,364 Times in 2,040 Posts

    Default

    Quote Originally Posted by -Shay- View Post
    I suspect that this site and the servers are not out of the woods yet. Long load times and blocked access to home page...
    There were two separate issues we dealt with over the weekend.

    We switched the ad server used to serve advertisements on the GPWA website, changing from the OpenX to the Revive ad server platform. This has been planned for a while, and is one of the steps involved in our plans to migrate the GPWA website to use https. We had some hiccups during the transition where some materials needed to render ads were not available, and the result was sometimes significant delays in rendering pages on the site. Since then we have consistently made sure that all advertisements are served within iframes, so that any disruption in our advertising servers can never again have an adverse effect on rendering other parts of pages.

    On another front, a file was corrupted very early this past Saturday morning. Out of an abundance of caution we shut down all external access to the site until we fully assessed the situation, corrected the file corruption, and determined it was safe to bring the site back up.

    In terms of the question about whether we are out of the woods yet, the answer is no. We have a lot of projects underway to improve security and improve our disaster recovery capabilities. Those projects will take a while to complete.

    Michael
    GPWA Executive Director, Casino City CEO, Friend to the Village Idiot
    Resources for Affiliates: iGamingDirectory.com, iGamingAffiliatePrograms.com, GamingMeets.com

  21. The Following 3 Users Say Thank You to MichaelCorfman For This Useful Post:

    allaboutthebets (12 November 2019), Cash Bonus (11 November 2019), GPWA Maria (11 November 2019)

  22. #34
    Malikbhai is offline Private Member
    Join Date
    September 2017
    Posts
    786
    Thanks
    204
    Thanked 378 Times in 247 Posts

    Default

    Michael. I could be wrong. Correct me, if I am. But, it seems as if you do a lot of coding in-house.

    This is despite the fact that the market is full of solutions. There is a software available for every type of task out there. I'm not sure of the scale you operate in, but it's quite unnecessary to code most of your own stuff, when cheaper and more secure options are roaming the streets.

    This is say, in reference to CasinoCity.

  23. #35
    ddm
    ddm is offline Former Member
    Join Date
    July 2006
    Posts
    1,118
    Thanks
    418
    Thanked 470 Times in 287 Posts

    Default

    Quote Originally Posted by -Shay- View Post
    I suspect that this site and the servers are not out of the woods yet. Long load times and blocked access to home page...
    and nobody mentioned changing passwords after the breach. Weird.

  24. The Following User Says Thank You to ddm For This Useful Post:

    -Shay- (12 November 2019)

  25. #36
    Tomas_4578's Avatar
    Tomas_4578 is offline Public Member
    Join Date
    July 2019
    Location
    Czech Republic
    Posts
    40
    Thanks
    6
    Thanked 5 Times in 5 Posts

    Default

    oh... I'm happy to see you guys here! I was worried about you, caisu I can't access and I don't know why. so, congrats to all that one of the best forum is live!

Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •