Web Hosting Talk







View Full Version : The Unoffical Q & A Thread By A User


csparks
04-08-2009, 11:31 PM
Okay, I hope I am not over stepping any boundaries here, but I suggested, and am now started a questions and answers thread for the incidents surrounding the hacks.

This is what I would think would work best for this thread for question format:

Post your question once, if its been asked, dont ask again
Please be detailed with your question.
Post only questions, no comments around the questions, but addons to the questions would be ok

For the answers:

Only iNet officials should answer
Answers should be complete, and not simply one line answers like 'sorry'
If at current time the answer is unknown or cannot be discussed, pleases state that, and why, and then come back with a answer to the question, as soon as possible.


I am doing this only to help resolve some of my own thoughts and questions, and I am hoping to help the community, because I really do love this place!

MODS: I hope you do not remove this thread, and take it seriously, I also hope you decide to change the the title to something you feel more appropriate.

csparks
04-08-2009, 11:42 PM
I will start off my answering the nagging question:

While iNet obviously knows what they are doing in many ways...

Why would iNet choose to log credit card information unencrypted? Also what was the point of logging the CVV number? As a programmer myself, I cannot see the point of logging cc information unencrypted. Two way encryption is plentiful in php, and therefor no need to store the information in plain text format. Anybody with a lick of common sense would know not to do this.

Also, was this a pre-made application that logged it this way, or was it a custom made application?

FastServ
04-09-2009, 09:22 AM
I would like to know if my CC was compromised. Having not been contacted at all by Inet, Could someone who has access to the db PM me?

RayWomack
04-09-2009, 09:34 AM
I would like to know if my CC was compromised. Having not been contacted at all by Inet, Could someone who has access to the db PM me?

..... if anyone wishes to PM me ONLY THE NAME THAT APPEARS ON THE CARD I will tell you if it shows up on the list.

Coolraul
04-09-2009, 09:47 AM
..... if anyone wishes to PM me ONLY THE NAME THAT APPEARS ON THE CARD I will tell you if it shows up on the list.

I know that you know this Ray but I think it bears asking.

Can you just confirm yes/no and not provide anything else back including source of the file, any other data except maybe the last 4 digits so they can recall which card it was?

I would hate for someone to give you my name and get some information back.

RayWomack
04-09-2009, 09:56 AM
I know that you know this Ray but I think it bears asking.

Can you just confirm yes/no.....

Yup, Andre, all you will get out of me is a one word reply.

SoftWareRevue
04-09-2009, 10:49 AM
I would like to know if my CC was compromised. Having not been contacted at all by Inet, Could someone who has access to the db PM me?If anyone is concerned, please contact support at inetinteractive.com so someone can clarify for you.