Featured New Release
Box cover for If It Feels Good 6
If It Feels Good 6
Studio: Deeper
Release date: 7/31/2026


all new releases
All Forums > Shopping Info > Shopping Info Forum Page 22 > XRentDVD-email re: ADT crash
AuthorPost
AztecGold11
Member


514 Posts
8/05
Posted - Feb 25 2006 : 9:06AM
I received this email yesterday.

Due to a security breach at an affiliate website, which you are also a member, we have taken the precautionary step of changing your password and removing all saved credit cards you had on file with XRentDVD. Please take a moment to change your password as soon as possible. DO NOT set your password to something you have previously used.

They also assigned me a password. How do they know where I'm a member?

Jacco All-Star Supporter
All-Star Member

"liable to deprave and corrupt"
2673 Posts
5/04
Posted - Feb 25 2006 : 9:24AM
Maybe it's not about ADT. Or maybe it is and you have been using ADT kickbacks or discount codes.

Jacco

AztecGold11
Member

514 Posts
8/05
Posted - Feb 25 2006 : 9:29AM
I've never bought anything from that site, except maybe some streaming minutes about 6 months ago-can't remember.
Bill All-Star Supporter
All-Star Member

5334 Posts
6/00
Posted - Feb 25 2006 : 9:34AM
Go login to their site and check. Under "My Account" they have order history that goes back at least 4 years. It could go further back, but my first order with them was in April '02. So that's all that I can vouch for.
Drew Black
broken crankshaft

8011 Posts
9/99
Posted - Feb 25 2006 : 10:24AM
I told them.

I received a phone call from Xrent late yesterday afternoon. They detected what appeared to be a dictionary-based attack originating from the UK trying to get into user accounts at their site. They shut the attack down but felt this event was too coincidental for comfort. I agreed.

Xrent has traffic records for all of the traffic we send their way. They can tell if a customer clicks through from ADT and places an order or shops at their site. It takes time to mine through this data though and it's not 100% accurate. (Some customers woudl be overlooked if they don't shop through our links on ADT.) Xrent and ADT wanted to be 100% sure though that none of their customers used email addresses and passwords that matched ADT user profiles.

I quickly generated a list of all forum user email addresses that were in place at the time of our security breach and sent them the a portion of these email addresses. So if your email address was 'drew@adultdvdtalk.com' Xrent received 'drew@a'. This list enabled them to quickly match up ADT forum accounts with customer accounts on their end that might have been used in such an attack.

This was the absolute fastest way to ensure that no Xrent customers that are also ADT users were at risk. I think there was only 45 minutes from the time they detected the attack until the new password notification emails went out.

 
Drew Black
broken crankshaft

8011 Posts
9/99
Posted - Feb 25 2006 : 10:34AM
Xrent doesn't do streaming minutes so it wasn't them you're thinking of.
AztecGold11
Member

514 Posts
8/05
Posted - Feb 25 2006 : 10:47AM
Glad to know it's not a scam email.
I get fake emails from "ebay & paypal" all the time-I forward them to spoof ebay/paypal and they investigate them.
I wonder if the hacker will try to get into the other adult DVD sites.
Drew Black
broken crankshaft

8011 Posts
9/99
Posted - Feb 25 2006 : 11:26AM
I can't speak for Xrent but from what I know of the situation they couldn't tell that the attacker was using the data they gained from ADT. The coincidence of of over a 1000 account access attempts from a few IP addresses in the UK is what threw up the red flag. It could be unrelated, this kind of stuff happens all the time at retailer's websites.

I do know that at least one ADT user had the same email address and password used at both Xrent and the ADT forum and their account was not accessed in this attack. (I know this because the person confirmed it via email to me.)

fatalbert
Member

Diagonally parked in a parallel universe
576 Posts
5/03
Posted - Feb 25 2006 : 2:27PM
I, too, got the e-mail warning from Xrent. There was no hyperlink embedded, so it wasn't like any spoof-mail I've gotten.

I logged on to their site via my own bookmark, using the temporary new password the e-mail had supplied, and everything looks kosher to me.

astroknight All-Star Supporter
Questionable Moderator

Tastes so good...
4187 Posts
11/99
Posted - Feb 25 2006 : 2:43PM
Although the attack sucks, it's great to see how on top of things XRent was and I think it's great that they did this to try protecting their customers.

"Vegetarianism for me is about saying ‘yes’ to things - even meat." - Coupling

Von Hugenstein
Member

63 Posts
2/06
Posted - Feb 25 2006 : 6:57PM
I got this email too and I appreciate the fact that Drew and Xrent were proactive. Makes me doubly happy to have joined up.

Edited by - Von Hugenstein on 2/25/2006 6:57:52 PM

axlsfury
Senior Member

1110 Posts
7/04
Posted - Feb 26 2006 : 4:50PM
Thanks Drew, greatly appreciated!



Jump To: