Author

Topic: Closed (Read 311 times)

hero member
Activity: 1540
Merit: 508
December 06, 2017, 10:49:01 AM
#9
I have many ideas with this script if it hasn't got hacked. Undecided Undecided Undecided LOL hope someone can help me fix it now.
full member
Activity: 409
Merit: 103
December 06, 2017, 10:44:55 AM
#8
I have added .htaccess restriction to config.php, faucethub.php and function.php. allowed only server ip access.

then made new database user/pw/name.
regenerated api and changed it all. now only faucet has access to those files.


I hope this will restict and prevent stealing those access codes/api and sending info to thos files.

That's good, but if you see any problem then Change your faucet script

my problem is that every faucet script ive used got botted eventualy. I think ive used 4 diffrent ones by now.

I like how it all works now and just want it more secure. I do get less claims in already now.

Now i like to find out if i close port 3306 for MySQL database will be even better. but just havent figured that out yet.
member
Activity: 336
Merit: 11
December 06, 2017, 10:36:22 AM
#7
I have added .htaccess restriction to config.php, faucethub.php and function.php. allowed only server ip access.

then made new database user/pw/name.
regenerated api and changed it all. now only faucet has access to those files.


I hope this will restict and prevent stealing those access codes/api and sending info to thos files.

That's good, but if you see any problem then Change your faucet script
full member
Activity: 409
Merit: 103
December 06, 2017, 10:08:05 AM
#6
I have added .htaccess restriction to config.php, faucethub.php and function.php. allowed only server ip access.

then made new database user/pw/name.
regenerated api and changed it all. now only faucet has access to those files.


I hope this will restict and prevent stealing those access codes/api and sending info to thos files.
newbie
Activity: 56
Merit: 0
December 06, 2017, 09:47:04 AM
#5
thanks for the warning. Site is no longer secure.
member
Activity: 336
Merit: 11
December 06, 2017, 09:28:46 AM
#4
how do they steal api key?

do they read or download config file?




I just guess, because i can't find their address in my database. It could be local attack or  Huh Huh Huh

I think there is some problem in script because one more user asked me that he also facing same issue.. His faucet is draining continuously
hero member
Activity: 1540
Merit: 508
December 06, 2017, 09:01:54 AM
#3
how do they steal api key?

do they read or download config file?




I just guess, because i can't find their address in my database. It could be local attack or  Huh Huh Huh
full member
Activity: 409
Merit: 103
December 06, 2017, 08:48:23 AM
#2
how do they steal api key?

do they read or download config file?



hero member
Activity: 1540
Merit: 508
December 06, 2017, 01:38:42 AM
#1
Closed
Jump to: