Author

Topic: BPIP problems (Read 653 times)

Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
July 09, 2018, 04:06:43 PM
#38
Geez, sorry LoyceV, I completely missed this post.
No problem, you found it now Tongue
In the mean time, I've updated my Merit data collection, and update a full Merit history for all users on Fridays. Here's yours. The graph (still raw without description) shows 5 days per column (starting the second the first Merit was transfered), and shows up to 100 Merit in height. If a column is higher, the top gets darker.
For a full list of users, see usernames (note that starting merit is still inaccurate).

Quote
Yes, the site will have full real time merit history for all users, available as a download or viewable/searchable.
Real time full histories would beat mine, so once it works, I think I can stop updating. Although I like my graphs, it quickly shows likely Merit abuse.

Quote
The new site and new domain will be launching by the end of this month.
Can you share the domain name yet?

I will as soon as I find a new home for the server.  Using AWS (on demand resources) for a data intensive site is not a good idea...$$$  :/

Once things get up, we can talk about your graphs and my data.  Smiley
legendary
Activity: 3290
Merit: 16489
Thick-Skinned Gang Leader and Golden Feather 2021
July 09, 2018, 03:52:55 AM
#37
Geez, sorry LoyceV, I completely missed this post.
No problem, you found it now Tongue
In the mean time, I've updated my Merit data collection, and update a full Merit history for all users on Fridays. Here's yours. The graph (still raw without description) shows 5 days per column (starting the second the first Merit was transfered), and shows up to 100 Merit in height. If a column is higher, the top gets darker.
For a full list of users, see usernames (note that starting merit is still inaccurate).

Quote
Yes, the site will have full real time merit history for all users, available as a download or viewable/searchable.
Real time full histories would beat mine, so once it works, I think I can stop updating. Although I like my graphs, it quickly shows likely Merit abuse.

Quote
The new site and new domain will be launching by the end of this month.
Can you share the domain name yet?
legendary
Activity: 2240
Merit: 3150
₿uy / $ell ..oeleo ;(
July 09, 2018, 03:09:40 AM
#36
The new site and new domain will be launching by the end of this month.
This is a great news, I'll remove the link of the old site from my sig and I will wait until the new site is up and running .

Quote
@iasenko - merit issues are fixed.  Smiley
Happy to hear that, I would like to test it again Smiley

Edited:
Is there a place we can check whether some is/was banned /modlog database/?
I used to check it on the BPIP before.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
July 08, 2018, 07:04:19 PM
#35
Vod, would you be interested in keeping full records of all Merit transactions per user? See your history as an example.
Your site looks like the perfect place to keep them.

Geez, sorry LoyceV, I completely missed this post.

Yes, the site will have full real time merit history for all users, available as a download or viewable/searchable.

I am posting here today to announce that the old BPIP website now has old, unreliable data.

The new site and new domain will be launching by the end of this month.


@iasenko - merit issues are fixed.  Smiley
legendary
Activity: 3290
Merit: 16489
Thick-Skinned Gang Leader and Golden Feather 2021
June 11, 2018, 09:26:35 AM
#34
Vod, would you be interested in keeping full records of all Merit transactions per user? See your history as an example.
Your site looks like the perfect place to keep them.
hero member
Activity: 2576
Merit: 883
Freebitco.in Support https://bit.ly/2I9BVS2
June 11, 2018, 03:10:19 AM
#33
Makes sense now that you say it's not working at the moment.

It looks to be back up and running again now.
hero member
Activity: 882
Merit: 976
June 08, 2018, 04:38:42 AM
#32
The update user now feature is already there:



I used it quite a bit as the Coinhive donation method seemed like a good way to help Vod fund the site. It does seem to have stopped working for the moment though.

Ah, then that's the issue I faced, because after I clicked it and went through the coinhive process, it took me to my page that still had the message "We plan to check it again 7/3/2018 10:23:22 AM" on it. That is what confused me. Makes sense now that you say it's not working at the moment.
hero member
Activity: 2576
Merit: 883
Freebitco.in Support https://bit.ly/2I9BVS2
June 08, 2018, 04:33:16 AM
#31
The update user now feature is already there:



I used it quite a bit as the Coinhive donation method seemed like a good way to help Vod fund the site. It does seem to have stopped working for the moment though.
hero member
Activity: 882
Merit: 976
June 08, 2018, 04:24:52 AM
#30
Hey Vod, is there any way to update a profile on BPIP on-the-fly instead of having to wait for the next scheduled check? Possibly by donating or solving some captchas, or perhaps extending the coinhive mining process (so that it's an opt-in by the user)?
newbie
Activity: 51
Merit: 0
June 03, 2018, 10:00:53 AM
#29
it's been a long time
hero member
Activity: 2576
Merit: 883
Freebitco.in Support https://bit.ly/2I9BVS2
May 26, 2018, 03:45:41 AM
#28
Congratulations on getting the complete database back at last. I don't know how long it has been there but I just noticed the "Update this profile now" link which is pretty useful. I just think it might be a good idea to but a warning there that it is going to redirect to coinhive to do the PoW. I've got no problem with it and I think it's a great way to fund a site, but I know some people will think differently.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 16, 2018, 01:25:16 PM
#27
No, my crawler does nothing but load the page - does not follow or index any links.

I have noticed there are some old profiles that still have an avatar from an external source, and they time out when I try to connect.  Examples:
https://bitcointalksearch.org/user/offtomalta555-3758
https://bitcointalksearch.org/user/lalmri-5153

I feel this is somehow related to that issue.  


Why is your crawler even downloading images? all I would expect it to do is just grab the HTML.

Hmmm, good point.  I run the default webBrowser control in C#, which loads everything into a little browser window.  I'll see if there is a way to have it only download the code and not load anything else...

Edit:  I run the parser on a VM where I don't need to browse, so I just had to disable the loading of images from IE.  Thanks!
newbie
Activity: 19
Merit: 26
April 16, 2018, 12:33:45 PM
#26
No, my crawler does nothing but load the page - does not follow or index any links.

I have noticed there are some old profiles that still have an avatar from an external source, and they time out when I try to connect.  Examples:
https://bitcointalksearch.org/user/offtomalta555-3758
https://bitcointalksearch.org/user/lalmri-5153

I feel this is somehow related to that issue. 


Why is your crawler even downloading images? all I would expect it to do is just grab the HTML.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 16, 2018, 09:51:17 AM
#25
I'm stuck right now... my parser is suddenly getting this popup.  Is it legit?

That url is in the signature of https://bitcointalksearch.org/user/sir-chris333-9428

Would your crawler try and follow that link for any reason?


No, my crawler does nothing but load the page - does not follow or index any links.

I have noticed there are some old profiles that still have an avatar from an external source, and they time out when I try to connect.  Examples:
https://bitcointalksearch.org/user/offtomalta555-3758
https://bitcointalksearch.org/user/lalmri-5153

I feel this is somehow related to that issue. 
legendary
Activity: 2240
Merit: 3150
₿uy / $ell ..oeleo ;(
April 16, 2018, 08:16:21 AM
#24
So somewhere in your calculation there is something wrong.  How do you calculate the initial sMerit? .

I don't count initial sMerit.  That's why it says "has at least".  I simply take the amount of sMetrit you have received, divide it by two, then subtract the amount you have sent.  You can have no less than that.  I get my data right from the merit log.  I'd like to discuss this with you in more detail.

OK, let me know what you need, I'll help with what I can Smiley

That would be great!  I need at least a couple weeks as I have made some major chances that will not allow me to restore data from a backup.  Sad

OK, let me know when everything is up and running and I'll add your link to my sig. and share it on Twitter:)
hero member
Activity: 2576
Merit: 883
Freebitco.in Support https://bit.ly/2I9BVS2
April 16, 2018, 06:17:11 AM
#23
I'm stuck right now... my parser is suddenly getting this popup.  Is it legit?

That url is in the signature of https://bitcointalksearch.org/user/sir-chris333-9428

Would your crawler try and follow that link for any reason?
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 16, 2018, 05:36:11 AM
#22
So somewhere in your calculation there is something wrong.  How do you calculate the initial sMerit? .

I don't count initial sMerit.  That's why it says "has at least".  I simply take the amount of sMetrit you have received, divide it by two, then subtract the amount you have sent.  You can have no less than that.  I get my data right from the merit log.  I'd like to discuss this with you in more detail.


I would like to help you advertise your project with a link in my signature if you agree. I will also share it on my twitter just to spread the word Smiley

That would be great!  I need at least a couple weeks as I have made some major chances that will not allow me to restore data from a backup.  Sad

I'm stuck right now... my parser is suddenly getting this popup.  Is it legit?


legendary
Activity: 2240
Merit: 3150
₿uy / $ell ..oeleo ;(
April 16, 2018, 04:10:08 AM
#21
@Vod
I have investigated the case, as I said in the previous topic you have locked.
Here is what I found checking the merit database dump file you posted. Quick check in Excel :



My profile ID is > 1291828

I got 142 merit and I have given 51 (the database dump is from 12.04.18)
I have initial 10 merit ( I was a Member when the merit system came).

Now I have the following according to my merit stats in the forum:
Quote
You have received a total of 154 merit. This is what determines your forum rank. You typically cannot lose this merit. You have 21 sendable merit (sMerit) which you can send to other people.

So somewhere in your calculation there is something wrong.  How do you calculate the initial sMerit? .
I was Member when the merit came and apparently I had 1* initial sMerit but now I'm Full Member and if you calculate my initial sMerit based on my current rank (Full member), the calculations will be wrong. Maybe there is the problem.

Lets check my initial sMerit to be sure>
The formula is My total Merit - Initial merit divided by 2 to get the sMerit I got. Then I take out the given sMerit til now and compare the result with my current sMerit.

(154-10)/2=72

We take out the 52 smerit I have sent til now.

72-52=20 so this does not equal to what I have now (21), so my initial sMerit was 1.


*I don't remember how much smerit I had that time, but it seems that  I had only 1 based on the calculations.
We need a table with the the initial sMerit for the different ranks.


I would like to help you advertise your project with a link in my signature if you agree. I will also share it on my twitter just to spread the word Smiley
hero member
Activity: 882
Merit: 976
April 15, 2018, 06:42:28 PM
#20
I could throw down a couple bucks for this project. Just tell me which address to send it to, and how much will help you get the ball rollin'!

I think that the "Donation Address for Prayer Messages" (1CDyx8AUTiYXS1ThcBU3vy4SJWQq6pdFMH) is still valid.
@Vod : Can you please confirm my thoughts about this Address? 0.005BTC is ready to be send for one year of renting. Cool  

That address is valid, but I created a new address just for BPIP donations.  I'll also create a page when I list the donators.
13tdtWCiaaxY1Zo1C6aDpWUowU6eD4RtqH

Looks like all the hacker did was boost interest in the project!  Smiley

https://blockchain.info/tx/225849ea7b5afb9e3d089d68dc23b02dd755f7325ce40678be6000ffaaa96414

Here’s a tad bit more support for a great cause. Keep it up, and whoever the hacker was, make sure to thank them lol. I believe there is always good, even where there is bad. Good luck moving forward!
legendary
Activity: 3038
Merit: 1104
This is what I do. I drink and I know things.
April 15, 2018, 06:22:05 PM
#19
I'm more than sure that you will use the BTC in a proper way for the benefit of the project. Wink

Until you put the project in the right track (self-sustaining), expenses will burden your pocket. I'm glad that i helped you (and the project) this time.
If you need though any further help with this (at any point), just let me know. It will be a pleasure to assist again. Cool

Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 15, 2018, 12:32:45 PM
#18

The project thanks you!   I've added that link to my signature.  Smiley

What I will use the coin for:
1) Design
2) Domain Name

It's my goal to have this project pay for itself through advertising and donations, but for now, I am paying for most everything necessary.

legendary
Activity: 3038
Merit: 1104
This is what I do. I drink and I know things.
April 15, 2018, 12:07:56 PM
#17
I could throw down a couple bucks for this project. Just tell me which address to send it to, and how much will help you get the ball rollin'!

I think that the "Donation Address for Prayer Messages" (1CDyx8AUTiYXS1ThcBU3vy4SJWQq6pdFMH) is still valid.
@Vod : Can you please confirm my thoughts about this Address? 0.005BTC is ready to be send for one year of renting. Cool 

That address is valid, but I created a new address just for BPIP donations.  I'll also create a page when I list the donators.
13tdtWCiaaxY1Zo1C6aDpWUowU6eD4RtqH
Ok, sounds good. Smiley
https://live.blockcypher.com/btc/tx/2ebf6c88b0c6ac3715c44cb766e69ea4ead9cc1368764dc5c52dab04aaeed501/

Looks like all the hacker did was boost interest in the project!  Smiley

Indeed he make a great impact!  Grin
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 15, 2018, 11:36:47 AM
#16
I could throw down a couple bucks for this project. Just tell me which address to send it to, and how much will help you get the ball rollin'!

I think that the "Donation Address for Prayer Messages" (1CDyx8AUTiYXS1ThcBU3vy4SJWQq6pdFMH) is still valid.
@Vod : Can you please confirm my thoughts about this Address? 0.005BTC is ready to be send for one year of renting. Cool 

That address is valid, but I created a new address just for BPIP donations.  I'll also create a page when I list the donators.
13tdtWCiaaxY1Zo1C6aDpWUowU6eD4RtqH

Looks like all the hacker did was boost interest in the project!  Smiley
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 15, 2018, 11:35:02 AM
#15
Any idea how they gained access?

Yes, I was lazy when I wrote the code for my search page.  I allowed SQL injection.  
Thx to TryNinja for confirming it too.

My host said they have a backup, so I should be restored by Monday.  Smiley



legendary
Activity: 2758
Merit: 6830
April 15, 2018, 10:10:12 AM
#14
Hey Vod,

Looks like I found out what vulnerability the hacker used to access your db. I just tested it and managed to change every user's name to TryNinjaIs1337 (sorry about that).

I will PM you with more info.
legendary
Activity: 3038
Merit: 1104
This is what I do. I drink and I know things.
April 15, 2018, 08:26:17 AM
#13
I could throw down a couple bucks for this project. Just tell me which address to send it to, and how much will help you get the ball rollin'!

I think that the "Donation Address for Prayer Messages" (1CDyx8AUTiYXS1ThcBU3vy4SJWQq6pdFMH) is still valid.
@Vod : Can you please confirm my thoughts about this Address? 0.005BTC is ready to be send for one year of renting. Cool 
hero member
Activity: 882
Merit: 976
April 15, 2018, 06:42:45 AM
#12
How long will it take to run initially to rebuild the database to the point where your aws instance can take over?
If it's only about 12-240 hours I can run it on my normal computer, if not, I'll purchase a vps from somewhere.

For the amount of time it would take me to reprogram the tool, I would want you to run it all the time. Smiley
It would take both of us 11-12 days.

Look into Amazon - they offer a free VPS with many OS for free - you just pay for usage over the free amount.
With my parsing tool running 24/7 it cost me about $3 last month.



I could throw down a couple bucks for this project. Just tell me which address to send it to, and how much will help you get the ball rollin'!
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
April 15, 2018, 06:41:16 AM
#11
How long will it take to run initially to rebuild the database to the point where your aws instance can take over?
If it's only about 12-240 hours I can run it on my normal computer, if not, I'll purchase a vps from somewhere.

For the amount of time it would take me to reprogram the tool, I would want you to run it all the time. Smiley
It would take both of us 11-12 days.

Look into Amazon - they offer a free VPS with many OS for free - you just pay for usage over the free amount.
With my parsing tool running 24/7 it cost me about $3 last month.



OK, I got a code from theymos to bypass the captcha for an alt.

I'll take a look into that Amazon one, is it ec2 you were using and is there a way to track your usage as you go, so I don't get extensive bills at the end of the 12 days?
staff
Activity: 3304
Merit: 4115
April 15, 2018, 06:14:42 AM
#10
That sucks. Used this for checking accounts that I reported. I guess the only saving grace is not that much damage has been done and it came relatively early in the development otherwise it would of taken more than 22 days. Plus, I don't think you'll be overlooking backups anymore.

Any idea how they gained access?
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 14, 2018, 11:02:20 PM
#9
How long will it take to run initially to rebuild the database to the point where your aws instance can take over?
If it's only about 12-240 hours I can run it on my normal computer, if not, I'll purchase a vps from somewhere.

For the amount of time it would take me to reprogram the tool, I would want you to run it all the time. Smiley
It would take both of us 11-12 days.

Look into Amazon - they offer a free VPS with many OS for free - you just pay for usage over the free amount.
With my parsing tool running 24/7 it cost me about $3 last month.

copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
April 14, 2018, 05:37:38 PM
#8
Is there anyway other users can help? perhaps trusted forum mebers could scrape portions of the data on your behalf using their IP's.

They would need to clear it with Theymos first and get a special code to bypass the captcha.

Can I be of any help here Vod? Is it just a bot that can be run to gather the data for you - if I get a code from Theymos and use an account to gather the information (with your self-made code that scrapes the data).

Sure, I can make changes to my parser to allow multi-user.  Just PM me the user name and password once Theymos approves you.

Currently I have it running on an Amazon Windows instance.  Costs me around $2/month.

How long will it take to run initially to rebuild the database to the point where your aws instance can take over?
If it's only about 12-240 hours I can run it on my normal computer, if not, I'll purchase a vps from somewhere.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 14, 2018, 04:00:03 PM
#7
Is there anyway other users can help? perhaps trusted forum mebers could scrape portions of the data on your behalf using their IP's.

They would need to clear it with Theymos first and get a special code to bypass the captcha.

Can I be of any help here Vod? Is it just a bot that can be run to gather the data for you - if I get a code from Theymos and use an account to gather the information (with your self-made code that scrapes the data).

Sure, I can make changes to my parser to allow multi-user.  Just PM me the user name and password once Theymos approves you.

Currently I have it running on an Amazon Windows instance.  Costs me around $2/month.
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
April 14, 2018, 03:29:02 PM
#6
Is there anyway other users can help? perhaps trusted forum mebers could scrape portions of the data on your behalf using their IP's.

They would need to clear it with Theymos first and get a special code to bypass the captcha.

Can I be of any help here Vod? Is it just a bot that can be run to gather the data for you - if I get a code from Theymos and use an account to gather the information (with your self-made code that scrapes the data).
hero member
Activity: 2338
Merit: 757
April 14, 2018, 01:33:20 PM
#5
It doesn't take so much time to backup a website and its sql database. For the same case last year, the task was not that hard. I found this article (french) so helpful.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 14, 2018, 01:26:46 PM
#4
You sure its some bozo,and not someone who *hates* you? Undecided

Aren't they the same thing?   Grin

Aww man that sucks it'll take 22 days to get it back up.

Yep - that's the time it takes to scan 2,000,000 records at one record per 1.5 seconds.

Is there anyway other users can help? perhaps trusted forum mebers could scrape portions of the data on your behalf using their IP's.

They would need to clear it with Theymos first and get a special code to bypass the captcha.
legendary
Activity: 2383
Merit: 1551
dogs are cute.
April 14, 2018, 01:23:30 PM
#3
Some bozo has decided to attack my "unofficially announced" website - BPIP.  :/
You sure its some bozo,and not someone who *hates* you? Undecided Because you know,you're Vod,people hate you for who you arei.e. fight scammers.
Hope your site comes up real soon. Good luck,
newbie
Activity: 19
Merit: 26
April 14, 2018, 01:12:46 PM
#2
Aww man that sucks it'll take 22 days to get it back up. Is there anyway other users can help? perhaps trusted forum mebers could scrape portions of the data on your behalf using their IP's. Or maybe the hosting company has a backup of the database?
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
April 14, 2018, 01:06:43 PM
#1
Some bozo has decided to attack my "unofficially announced" website - BPIP.  :/

Because the site was a hobby I did not prioritize backups.

I lost all current profile information in my MSSQL database.  Sad   

I'm using this as an opportunity - since I started this as a hobby the database is a mess.  Great time to organize and make things better.  Smiley

Sorry to everyone that used the site - but it will be down/incomplete for at least 22 days.  :/








Jump to: