Pages: 1

Another one hacked - MegaInvest.biz

(Click here to view the original thread with full colors/images)


Posted by: admin

Quote:
Dear Members of MegaInvest.biz,

First I want to say that I am no here to make you believe what happened.
It is your own choice. Believe if you want to!! I will just tell you the sad facts:
We generally use Golds4u.com to make payments, but as we were told by a friend,
who is also a HYIP admin that got his program account hacked and was using the same autopayment site,
we changed our e-gold account password immeditely.
From this moment on we used our E-gold account password only once....on the Golds4u.com to make the daily payments.
After a few hours a received an e-mail from E-gold that my account password was changed by
some Belarusian IP address. I tried to log into my account....but no effect, the password was changed
Now after my experience and this from my friend admin who used the same site, and after readung an article
in the TheBestHYIP forum. I am 101% sure that Golds4u.com and from this the damn TheBestHYIP.com admin, named TAHERI
are HACKERS AND SCAMMERS.
I use Norton Antivirus 2003 with latest updates, BulletProofSoft Spyware remover latest version,
I have set cookies to high-security setting, and I have disabled Active-X.
I can say that I am pretty sure that nobody has stealed my account password from my computer.

Read the artice by another HYIP admin , that got his account hacked (this is not my friend admin, this is another victim of this scammer). This article can dissapear soon, because it is in the own forum of ThebestHYIP scammer.
http://www.thebesthyip.com/foru m/viewtopic.php?t=4725

I will say it one more time: believe it if you want!
MegaInvest.biz Administrator




Posted by: awty

I can think of few things that would be more important than picking an 'autopay' provider who is trustworthy. Giving direct access to accounts used for program payouts should, in my opinion, be given only to THOROUGHLY trusted associates.
Just my opinion.
(Another program that ?possibly? did not do the research to get the best possible tools for the job?)
I maintain that a good solid program with a carefully considered business plan should have considered possibilities like this BEFORE beginning operations.
Just about anybody can put together a program, but it takes due consideration and planning to do it right, including looking at all possible contingencies, and periodically re-evaluating the situation, as things can (and do) change.
Just my opinion,
Jeff



Posted by: memorex

This must be the simplest form of reasoning, that any admin can pass along to their members as there reason for loss of funds. :^o

No question of their ability or capability to administrate their programs , nor seemingly accountability . [-X

Just because they! say they have changed their Account Passphrase and still! they were hacked. :-s

This is just closing the stable door after the horse has bolted. =;

When any system has a flaw, which is either detected in advance, by notification, whether by hearsay, or, whatever. 8-[

It is beyond me why they still use the same security system and this I mean on both sides of the coin. ](*,)

If a program or site is suspect to attack then you must put more secure measures in place. #-o

It would take an extra five minutes a day to change your Account Passphrase after using it everytime. :-k

Sure it is a pain !! but hey! the members would be pleased to know the admins are looking after their money securely at least. =D>

But of course by doing this it would take out the factor of the runner's excuses to disappear with their ill gotten gains. [-X

Or dare I say it stay and take more from the unsuspecting punter's Now where have I seen this before .

So why dont the admins do this every time they use their accounts pay system. [-o<

Surely this would then alleviate a lot of their problems regarding the security of their accounts. [-o<

And possibly thwart a hackers attempt to gain access to their member's funds which should be one of their main priorities. =D>

Now, I am sure their will be many admins come back at me for this but I personally dont care.

I am in this arena to make money for myself and if I want to give it away.

I will choose a charity not some unsavoury characters that cant even manage a booze up in a Brewery.

regards
memorex



Posted by: awty

Yes, indeed. Even if using an autopay system that is 'trusted', as SOON as payments are done, it would seem to be simply good practice to change the account password. Just good business!
If there's even the remotest chance that ANYONE besides the 'paymaster' might have access to the password, that's a risk that should be, and can be EASILY, removed.
ESPECIALLY when it's OTHER people's money at stake!
Jeff



Posted by: jaboles

Quote:
Originally Posted by awty
Yes, indeed. Even if using an autopay system that is 'trusted', as SOON as payments are done, it would seem to be simply good practice to change the account password. Just good business!
If there's even the remotest chance that ANYONE besides the 'paymaster' might have access to the password, that's a risk that should be, and can be EASILY, removed.
ESPECIALLY when it's OTHER people's money at stake!
Jeff


Very true. When using *any* automation software, it's always best to change your passphrase frequently, and use a separate account. You should run the separate account "on empty" and only transfer money to it when you're about to use the automation software.

Why? Even if you trust the programmer of the software, you can't trust someone who manages to break into the server and, in one way or another, cause users' passphrases to be compromised.




eXTReMe Tracker