FurrTrax - Furry Networking!!!!!




FurrTrax Furry Group
FurrTrax Twitter Feed

Get the FurrTrax App
for Android Today


Add Comment
Article: Furnation.com Security Failures
Posted By: DarkXander
Date: 05-27-2016 00:45 AM
Views: 3448
I tried to speak with SYSTEM over at furnation tonight, but instead of letting me talk with him about what he needs to fix, he banned me, deleted my posts, and then proceeded to announce on his homepage that he will sue me if """I""" continue to attack him. He seems to be very paranoid about me.... And i have absolutely had it with his readiness to make threats, but unwillingness to listen when someone finds something they need to fix, to the point of banning to shush someone.

Then he denies that i ever tried to report this to him before, when i have screenshots showing him doing the same exact thing on July 3rd 2015, it even shows the posts he tried to hide after the site unfortunatly got minorly defaced:
https://cdn.furrtrax.com/other/

We even offered them free web hosting when their site went down completely and their host refused to allow them to run it anymore, see this:
https://www.flayrah.com/6331/offer-help-furnation-furrtrax

This is a copy of an E-Mail sent to furnations two admin email accounts, 5 minutes ago...


In the hope that you read this accounts emails, i will provide your list of Issues, since you have banned me yet again, since you seem completely convinced im the blood idiot attacking you, which i am not.

1. Get the mailserver off your server box, most important issue, the mailserver reveals your ip instantly to anyone who knows how to look. I run my mailserver on a totally independent box on a totally different subnet and ip range, check the headers of this email if you dont believe me.

Setup a mailserver away from the main server, or get a hosted mail solution, or something for your outgoing notifications, thats what i did, thats how FA does it, and i believe even sofurry.

2. Your server is right on the internet, no firewall device or appliance of any kind between it and the internet, GET ONE, or virtualize it in HyperV and setup a PFSENSE, or some other firewall VM and force all traffic to route through that.

3. You have no ip restrictions on your Remote Desktop port, you know, 3389, fix it, or disable it and use a client vpn or some other method of remote that doesnt leave a port open, hell logmein is more secure....

4. This is the old issue that i believe plagued you in the past, no protection or limit on stage 3 hung syn connections, but it wouldnt exist if you had any decent firewall, even a cheap used sonicwall would solve this, ebay one, or ask OVH what options they have available, GET SOMETHING SOON!

I have sent items 1 and 4 to you several times before, i dont recall if i noted 2, and 3 previously, but fix them regardless.

And quit making up stories about me being the one that hacked you, or that im some evil person that has a vendetta or something, im a 24 time certified Cyber Security and Network Engineer, Your just lucky whatever moron does have a vendetta apparently isnt too bright on this stuff.

I should never see this stuff again, if i can, the hackers that are after you can too!
Windows Server 2012 R2 x64
IIS 8.5 with HTTPAPI
***.***.**7.208

And quit making threats about legal action, and worry more about the legal action you might find yourself in if all your users private information got leaked due to your security issues like FAs possibly was just a few days ago.


This article will stay up untill they acknowledge that they plan to fix these issues!

Comments:
Celeste : Please don't make more drama between social sites. I honestly enjoy looking at both websites and both of you are saying different things making the other look bad. Focus on making your place the best it can be rather than trying to deface others.
DarkXander: ive explained this before zuul, i am not a graphics guy, im an engineer, i make extraordinary things function and operate, but i am not the one who can put a nice photoshop finish on it. I am looking for a new graphics person, thus far ive had slim luck.
Zuulass: Why do you try and help other sites so much? Could use that time to make this site look nice for furries looking for another furry site. Competition and all

Donate to FurrTrax

Who's Online?
Google Bot
wolfstarthesixth
Server

Guests: 48



Advertise with us!
Template Designed by: FurrTrax Admin
© Copyright 2024 FurrTrax®, All Rights Reserved.
0.058159112930298