Bitcoin Forum
May 08, 2024, 04:56:13 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 [2]
21  Economy / Digital goods / Re: Faucet Rotator PHP Script - fRotator V0.1 on: July 27, 2016, 11:18:54 AM
fRotator is a faucet rotator that I have developed and will have lot of future updates as I keep improving it everyday.
Features of fRotator includes:
- Nice interface made with bootstrap.
- Easy control panel to manage faucets & ads.
- Supports FaucetBox, Direct faucets.
- Categorize faucets.
- Rotator [next, prev].
- Saves users address so they can copy it anytime easily.
- Optimized for search engines.

I will be selling hosted versions for a cheap price, the hosted versions will have updates regulatory and automatically and I will be fixing issues on them for free.

fRotator v0.1 - 0.05 BTC includes:
xyz domains -  free when buying rotator.
Hosting - free when buying rotator.
.com domains is 10 USD paid in BTC.

Source code available for 0.1 BTC

All clients hosted or ones with source on their own host gets free updates for life, price might go higher when new features are added so the sooner you get the script the more you save in the future.

Screenshots & Demo:






Hi,
Im interested in this rotator script if there are no bugs and have easy customized admin panael with ads space.

please check your privte inbox, i sent you a message

thank you
22  Economy / Micro Earnings / Re: Please Help My Faucet Was Hacked And 4337500 Satoshi Stolen on: July 27, 2016, 10:18:29 AM
...

U can use faucet box script only but with some measures ,
Change password for admin panel
Change faucet box password
Enable 2FA authentication on faucet login
Set limit for withdraw within 30 minutes
Block TOR browsing
Block VPN
Block IP address in .htacess file (search for avoid bot articles on forum)

...


Additional to that is, DO NOT put too much funds on your faucet. Too much amount of funds on faucet can also attract stealers.
IMO, it is better to refill your funds daily with very small amounts than fill your faucet with big amount in one shot.

Thank you alfaboy23, I have learn a lot of lessons which will help me as I make progress. I am trying to install antibot link now
23  Economy / Micro Earnings / Re: Please Help My Faucet Was Hacked And 4337500 Satoshi Stolen on: July 27, 2016, 10:12:03 AM
I think you have used same passwords for all accounts , some one who knows ur password as accessed ur faucet box and withdrawn your balance or used ur API key and withdrawn all ..

U can use faucet box script only but with some measures ,
Change password for admin panel
Change faucet box password
Enable 2FA authentication on faucet login
Set limit for withdraw within 30 minutes
Block TOR browsing
Block VPN
Block IP address in .htacess file (search for avoid bot articles on forum)

You can contact any time for any suggestions.



The guy from fiverr who first install the script had my database password. the scond guy from guru and freelancer also had my passwords, I don't use same password for all logins, the problem is that, I gave him all passwords related to my domain to enable him do the job, then I forgot to change database password, I left fttp access open. So it is easy for anyone who has faucetscript database info to access admin panel. Though my faucetbox account itself is secured, no one can access it because I didn't share the password and Im using a unic ogin info. But I didn't control payout limit from faucetbox account section. So I have learnt alot after these attacks and Im still learning. The big problem is that you can find anyone trust worthy in this niche to help, everyone with evil and negative interest even when you are paying.


Right now I want to install the ntibot link script,
24  Economy / Micro Earnings / Re: Please Help My Faucet Was Hacked And 4337500 Satoshi Stolen on: July 27, 2016, 10:02:51 AM
What script did you use? did you use the faucet script from faucetbox. or you down the script from share by someone?

The first time, it was the fiverr guy who installed the script, so I do't know the version of faucetbox script he used, the second time, the guy in guru and freelancer did, same thing, but the third one, I did it myself using the most current faucetbox script. Yet I got attacked.
25  Economy / Micro Earnings / Please Help My Faucet Was Hacked And 4337500 Satoshi Stolen on: July 19, 2016, 03:39:06 PM
I need the help of kind individuals and generous faucet owners who have build security around their faucet to help me out with any available and working security measure that could be implemented to secure faucets from hack and bot activities.

On 1st of July 2016, it was just like a dream to me when I checked my balance and it was reading 456 satoshi whereas the night before i went to bed it was 4 337 968 satoshi: https://postimg.org/image/f99gg063r

Though I wish to continue, but I really worried at the moment. There is something I tried to understand in this whole issue. 2 weeks before this very hack, I experienced such attempt, 5, 600 000 satoshi disapeared from my balance, but immediately I reported the issue to faucet box not up to 5 minutes the balance was returned, and faucetbox did not return a mail to this effect till today.

When the second one happened, I was already sleeping but once I noticed it and mailed them, the same scenario happened agained. After 3 minutes of sending the mail to faucetbox, when I checked my faucet site, I discovered the balance was returned again. Then I logged into faucetbox account area, to confirm the balance, unfortunately it didn't reflect. I returned back to my faucet site, the balance returned to 456. I was on a confused state. Another mail to faucetbox returned a reply:

"Hello,

We cancel this payout and returned coins to you.

Kind regards
Marcin"

I returned another mail with explanation of what I noticed and informed him that the balance is back to 456 satoshi.

This was his reply againn on the second of July 2016

"Hello,

We're really sorry, but there's nothing we can do now. The 0.04340155 BTC which was claimed by 18aewAbuAoHwQ3icyng6ykYj1NfUH6bQnJ was payout before you send us a message.

It looks like someone have access to your faucet's admin panel or know your api key. Why don't you have ACL enabled? Have you set up Send Limits? If you're using our Faucet Script you can also disable admin panel i config.php.

Kind regards
Marcin"



He gave me some security tips and I tried all, but I am not comfortable with the response because my hosting company told me they saw some vulnerability in funcaptcha.php.


Hi there,  After thorough analyzing the logs, our technicians didn't find any vulnerability or any suspicious activity on server from the given dates. But instead, vulnerability was found on the codes (in file /libs/funcaptcha.php => function => getIP( )).  Please consider to check this from your end.
Best regards  Michael


public function getIP() { if (isset($_SERVER["HTTP_X_FORWARDED_FOR"])) { return $_SERVER["HTTP_X_FORWARDED_FOR"]; } else if (isset($_SERVER["REMOTE_ADDR"])) { return $_SERVER["REMOTE_ADDR"]; } else if (isset($_SERVER["HTTP_CLIENT_IP"])) { return $_SERVER["HTTP_CLIENT_IP"]; }

Greetings,  Thank you for contacting email support services.  HTTP_X_FORWARDED_FOR should never be used as a means to validate the user’s IP and if the coder outputs this data then there would be a problem of attacker being able to fake their IP but the "safe" data becomes a XSS injection point.  So filtration of all user supplied data including User-agent etc is needed. PHP code with just $_SERVER[‘HTTP_X_FORWARDED_FOR’] shouldn't be blindly trusted.  You may try to do a Google search for "XSS injection point" for more information about this vulnerability.  Please do not hesitate to contact us again via our chat or email support services as we are more than willing to assist you with any concern you may have regarding your account with us.
Best regards


I'm not a coder, I don't know much of this. This info was forwarded to faucetbox but uptil date they have not returned a mail with any detail.

This gives me so much worries, as I don't know what to hold on or even trust. I think of switching to another script.

I will appreciate if there are kind hearted faucet owners here that could help me with any security advice, general advice about switching to another script that is more secure if any, or just anything that could help me move on with this.

Thank you
26  Economy / Micro Earnings / Re: 0.6 btc was stolen from my faucet by hacker on: July 19, 2016, 02:47:57 PM
so how the hacker can stolen your bitcoin faucet?

I am also facing the same issues, I lost  more than 0.045btc last month on the spot to a hacking activity on my faucet and faucetbox is not helpful in returning enough mail to help me out, they only gave me some security tips to implement but not enough details how to do this even after i mailed several times. The worst is that, you don't even know who to trust online when it comes to faucet security. I met a guy on fiverr who installed faucetbox script for the first time on my site: https://bitcoinlordz.com . I asked him to add antibot script, but he told me the then faucetbox script couldn't handle the antibot script, I asked him of all other security options and he discouraged me. He said my faucet was good the way it is.

He even told me to increase payment to 500 satoshi every 360 minutes. These were strategies he had designed in place to steal from my coin since he knew my API, database password and admin. We both disagreed on several occasions because he was trying to use fiverr service to screw money out of me. But I felt he was behind several both attacks on my sites at the early stage. After changing all my domain and database password, I discovered that the bot activities reduced. This made me hire another dude trying to improve security, but this guy from guru.com and freelancer.com was behind the hacking and stealing of my over 0.045 btc.

To make sure I was in control of all security measures, I had to clean all the files and database and reinstall the new version of faucetbox script. But at this juncture, I don't know what to do. My hosting company provided some security tips I have implemented too which is helpful in a way. But I don't know if I need to switch to another faucet script or if there is anyone who could be so kind and really generous enough to help me with security tips on a private message. Is cloudflare a good security option?
Thank you
27  Economy / Micro Earnings / Re: 2nd captcha for faucets ? on: June 14, 2016, 04:47:34 PM
Hello everyone, I like this topic so much, in fact ran into this discussion as i was searching for threads about 2nd captcha for faucets. This should be a very good alternative to reduce if not eliminate bots. To many it might not be a good idea, but if you have been a victim, you soon realise the need for it. As I type this, my faucet has been under attach for more than 5 days now. The worst is that I can't add ads codes to my faucets due to bots taking over my faucet. To use 2 captchas means increasing visitors earnings, if boths can be kept off our sites, why not 2nd captcha.
I also need help with this issue, my coin is deceasing without earnings from adverts even after implementing some security measures. I want to connect wit the good guys here.
28  Economy / Services / Re: ◄◄ Th0ur's Web/Graphic Development - Frontend Designer ►► on: May 25, 2016, 11:05:17 PM
Get a fully custom - responsive - mobile friendly website at $10
Cheapest!


I need this service very urgently, how do we connect one on one to finalize this?

Thank you
29  Economy / Services / Re: ◄◄ Th0ur's Web/Graphic Development - Frontend Designer ►► on: May 25, 2016, 10:53:58 PM
Hello,

Since you said this is afordable can you tell me how  much it will cost to install faucetbox script with a little web design job?
Pages: « 1 [2]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!