DialerNET
03-26-2002, 05:24 AM
Tim gave me permission to post this on the main forum.<br /><br />It was brought to my attention recently by one of my dialer webmasters "Rage", that his trade script was hacked by another webmaster using the same dialers. "Rage" supplied us with the account name of the offending dialer, and it appeared to be a webmaster that Ztik was using to test the performance of the new dialers before going live with them.<br />"Rage" then supplied me with entries from his apache logfile that showed an unknown IP address accessing his trade script setup and admin functions.<br /><br />This section of his log is supplied below. I've edited out his domain, and the name of the script files for security reasons.<br /><br /></font><blockquote><font size="1" face="Verdana, Arial">code:</font><hr /><pre style="font-size:x-small; font-family: fixed;">65.31.229.170 - - [25/Mar/2002:09:22:09 -0800] "GET /*******.*** HTTP/1.1" 200 1078 "http://www.google.com/search?q=*******.***+trade+traffic&hl=en&start=70& sa=N" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:22:15 -0800] "GET /*******.*** HTTP/1.1" 200 1098 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:24:22 -0800] "POST /*******.*** HTTP/1.1" 200 552 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:24:59 -0800] "GET /*******.*** HTTP/1.1" 200 1078 "http://www.google.com/search?q=*******.***+trade+traffic&hl=en&start=70& sa=N" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:07 -0800] "GET /*******.*** HTTP/1.1" 200 1098 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:26 -0800] "POST /*******.*** HTTP/1.1" 200 236 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:31 -0800] "GET /*******.*** HTTP/1.1" 200 673 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:37 -0800] "POST /*******.*** HTTP/1.1" 200 2269 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:41 -0800] "POST /*******.*** HTTP/1.1" 200 1118 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:49 -0800] "POST /*******.*** HTTP/1.1" 200 625 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:52 -0800] "POST /*******.*** HTTP/1.1" 200 2266 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [25/Mar/2002:09:25:57 -0800] "POST /*******.*** HTTP/1.1" 200 1045 "http://www.xxxxxxxx.net/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"</pre><hr /></blockquote><font size="2" face="Verdana, Arial">The offending IP is of course, 65.31.229.170<br /><br />While continuing to investigate, my own partner in my TGP side of things, reported that his TGP trade script had also been hacked.<br />I also had him supply the offending section out of his logfile. This is below, also with the domain and script files edited out;<br /><br /></font><blockquote><font size="1" face="Verdana, Arial">code:</font><hr /><pre style="font-size:x-small; font-family: fixed;">65.31.229.170 - - [24/Mar/2002:19:31:05 -0600] "GET /*******.*** HTTP/1.1" 200 5230 www.xxxxxxxx.com "http://www.google.com/search?q=*******.***+trade+traffic&hl=en&start=10& sa=N" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:31:14 -0600] "GET /*******.*** HTTP/1.1" 200 5103 www.xxxxxxxx.com "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:31:29 -0600] "POST /*******.*** HTTP/1.1" 200 1167 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:31:38 -0600] "POST /*******.*** HTTP/1.1" 200 1167 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:32:43 -0600] "POST /*******.*** HTTP/1.1" 200 1205 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:32:46 -0600] "GET /*******.*** HTTP/1.1" 200 5103 www.xxxxxxxx.com "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:32:52 -0600] "POST /*******.*** HTTP/1.1" 200 1167 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:34:58 -0600] "POST /*******.*** HTTP/1.1" 200 1158 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br /><br />65.31.229.170 - - [24/Mar/2002:19:35:47 -0600] "POST /*******.*** HTTP/1.1" 200 1158 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"<br />65.31.229.170 - - [24/Mar/2002:19:35:49 -0600] "POST /*******.*** HTTP/1.1" 200 1171 www.xxxxxxxx.com "http://www.xxxxxxxx.com/*******.***" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; T312461)"</pre><hr /></blockquote><font size="2" face="Verdana, Arial">As you can see, the same IP appears accessing his files.<br />65.31.229.170<br /><br />In both cases, the scripts were modified to redirect to the following URL<br />ultrateenporn.com<br /><br />At this point, "Rage" contacted me again to tell me that he had done a search on AWI for the offending URL, and it turned up the following thread.<br /><a href="http://bbs.adultwebmasterinfo.com/ubb/ultimatebb.php?ubb=get_topic;f=1;t=012151" target="_blank">http://bbs.adultwebmasterinfo.com/ubb/ultimatebb.php?ubb=get_topic;f=1;t=012151</a><br /><br />Near the bottom of the thread, Ztik posts the following message - check his email address:<br /><br /> </font><blockquote><font size="1" face="Verdana, Arial">quote:</font><hr /><font size="2" face="Verdana, Arial"><br />I would also like details on expected traffic + pricing if you have any spots left.<br />will@ultrateenporn.com<br /><br />--------------------<br />ZtikDialers<br /></font><hr /></blockquote><font size="2" face="Verdana, Arial">As we had already narrowed down the dialer account to being under Ztik, this started ringing some alarm bells.<br />So we contacted Tim at AWI, and had him send us Ztik's IP address as recorded on this forum.<br />You guessed it<br />65.31.229.170<br /><br />As a final check, I did two whois checks.<br />This is the info on the URL that traffic was being sent to:<br /><br /></font><blockquote><font size="1" face="Verdana, Arial">code:</font><hr /><pre style="font-size:x-small; font-family: fixed;"> Domain Name: ULTRATEENPORN.COM<br /><br /> Created on..............: Sun, Nov 18, 2001<br /> Expires on..............: Mon, Nov 18, 2002<br /> Record last updated on..: Mon, Mar 25, 2002<br /><br /> Administrative Contact:<br /> Ztik Inc<br /> William Range<br /> 112 SanteFe Tr.<br /> Lincoln, NE 68621<br /> US<br /> Phone: 1231231231<br /> Email: will@ztik.com<br /><br /> Technical Contact, Zone Contact:<br /> Register.Com<br /> Domain Registrar<br /> 575 8th Avenue - 11th Floor<br /> New York, NY 10018<br /> US<br /> Phone: 902-749-2701<br /> Fax..: 902-749-5429<br /> Email: domain-registrar@register.com</pre><hr /></blockquote><font size="2" face="Verdana, Arial">And this is the whois on the domain ztikdialers.com<br /><br /></font><blockquote><font size="1" face="Verdana, Arial">code:</font><hr /><pre style="font-size:x-small; font-family: fixed;"> Domain Name: ZTIKDIALERS.COM<br /><br /> Created on..............: Sun, Sep 23, 2001<br /> Expires on..............: Mon, Sep 23, 2002<br /> Record last updated on..: Sun, Mar 03, 2002<br /><br /> Administrative Contact:<br /> Ztik Media<br /> Ztik Media<br /> 112 SanteFe Tr.<br /> Lincoln, NE 68506<br /> US<br /> Phone: 4024751327<br /> Email: emps@afr0.zzn.com<br /><br /> Technical Contact:<br /> Ztik Media<br /> Ztik Media<br /> 112 SanteFe Tr.<br /> Lincoln, NE 68506<br /> US<br /> Phone: 4024751327<br /> Email: emps@afr0.zzn.com</pre><hr /></blockquote><font size="2" face="Verdana, Arial">I am also awaiting replies from several other webmasters who's domains appear to have been hacked, and hopefully will be able to supply several other logfiles exposing this IP too.<br /><br />I'll let you all decide how you want to use and process this info.<br />Suffice to say, his account has been deactivated, and I would suggest whoever else is supplying ztickdialers with his reseller accounts, does the same.<br /><br />Jason.