Welcome to World of IPTV

With

+23k members
+11k threads
+106k posts

we are the most popular IPTV community on the web. 

IMPORTANT NOTE:
WE HAVE RECENTLY NOTICED THAT TOO MANY DOUBLE FAKE ACCOUNTS ARE CREATED IN THE PAST.
TO PREVENT THIS ISSUE THE DECISION WAS MADE THAT IN THE FUTURE A ANNUALLY FEE 20 EURO WILL BE RAISED FOR NEW MEMBERSHIPS.

Join now to the World of IPTV

Forum Rules

Before you start, check out the forum rules first

Account upgrade

Upgrade your account to get access to full features

Advertising

Would you like to place your advertisement with us ?

Resources Manager

Hundreds of IPTV scripts and apps are available for download

Fatal Exploits found on Xtream UI

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
Hello, Guys

Some Moroccan Guys have found some fatal Exploits on Xtream UI All verssions they can Restream all the streams from you Using valid usernam & Password Can overload the server Overload the LB ..... they have destroyed 40 IPTV Servers and Now they are playing with me i don't know how the hell they put on all streams even if all my streams are on demand
 

makeitso

Extended Member
Ext. Member
Joined
Sep 22, 2019
Messages
450
Reaction score
978
Points
104
Location
Dublin
In would be more inclined to say some one leaked a line on the web
 

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
In would be more inclined to say some one leaked a line on the web

Sir this customer bought a Line after 10 Min i begin receiving more than 5000 connections for Same IP in Hetzner so its a Dedicated server connections not HOme IP and max_connections is set to 1 when i contacted the guy he told me im from morocco
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
Here is the client LOG
IDUSERNAMESTREAMREASONUSER AGENTIPDATE
20171GR: MONTREAL GREEK TVAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20170DE: RTL PASSION (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20169IT: RAI PREMIUMAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20168DE: DISNEY JR (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20167IT: FOCUSAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20166DE: ARD ALPHA (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20165GR: NOVA CINEMA ACTION HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20164IT: TOPCRIMEAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20163PT: TV RECORD HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20162PT: FOX LIFE HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01

all of you ban this IP !!!!
 

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
Hello, Guys

Some Moroccan Guys have found some fatal Exploits on Xtream UI All verssions they can Restream all the streams from you Using valid usernam & Password Can overload the server Overload the LB ..... they have destroyed 40 IPTV Servers and Now they are playing with me i don't know how the hell they put on all streams even if all my streams are on demand
Ban the account being used. Set the no user agent denial.
Here is the client LOG
IDUSERNAMESTREAMREASONUSER AGENTIPDATE
20171GR: MONTREAL GREEK TVAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20170DE: RTL PASSION (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20169IT: RAI PREMIUMAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20168DE: DISNEY JR (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20167IT: FOCUSAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20166DE: ARD ALPHA (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20165GR: NOVA CINEMA ACTION HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20164IT: TOPCRIMEAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20163PT: TV RECORD HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20162PT: FOX LIFE HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01

all of you ban this IP !!!!
Start running user agents. Also you can set it to disallow 2nd connection from same IP.
 

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
Here is the client LOG
IDUSERNAMESTREAMREASONUSER AGENTIPDATE
20171GR: MONTREAL GREEK TVAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20170DE: RTL PASSION (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20169IT: RAI PREMIUMAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20168DE: DISNEY JR (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20167IT: FOCUSAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20166DE: ARD ALPHA (VIP)AUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20165GR: NOVA CINEMA ACTION HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20164IT: TOPCRIMEAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20163PT: TV RECORD HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01
20162PT: FOX LIFE HDAUTH_FAILEDXtream-Codes IPTV Panel Pro95.217.34.1302020-03-15 01:17:01

all of you ban this IP !!!!
Also after like 8 connections from a single connection account nothing will play on 22b ea. Tested that myself. Even one over creates a disruption in service. Upgrade to 22b ea if you already have not. Also a hard coded DNS in an App with a Hard Coded user-agent solves a lot of problems. Plenty of ways to prevent this.
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
Also after like 8 connections from a single connection account nothing will play on 22b ea. Tested that myself. Even one over creates a disruption in service. Upgrade to 22b ea if you already have not. Also a hard coded DNS in an App with a Hard Coded user-agent solves a lot of problems. Plenty of ways to prevent this.
Yes im using Darkmedia Hardcoded and im still R21 im afraid of Upgrading and losing my data as i have more than 500 Customers sing my iptv service
 

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
Ban the account being used. Set the no user agent denial.

Start running user agents. Also you can set it to disallow 2nd connection from same IP.

How can i Set the no User agent denial ? and for people with who IM exchange how im i suposed to do ?
 

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
Yes im using Darkmedia Hardcoded and im still R21 im afraid of Upgrading and losing my data as i have more than 500 Customers sing my iptv service
If you fixed the Geo previously with the recoding you can find on here you won't have any issues. This is all open source so definitely has some bugs but you will be ok. 22b ea is decent.
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
How can i Set the no User agent denial ? and for people with who IM exchange how im i suposed to do ?
It is in settings. Also ban the default one that person used. Banned user agents. It comes on every panel. The Xtreme Codes on.
 

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
If you fixed the Geo previously with the recoding you can find on here you won't have any issues. This is all open source so definitely has some bugs but you will be ok. 22b ea is decent.

Can you please send me command on how to fix Geo please when i start service i still have geo error please if its possible and sorry for disturbing you
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

score22in

Extended Member
Ext. Member
Joined
Jan 31, 2020
Messages
40
Reaction score
81
Points
29
Location
N/A
Dude, use Cloudflare or another similar service.
How can you prevent such things using cloudflare ? its IPTV bro one customer bought a line a added this line to his xtream codes and streamed all my streams at once and xtream UI allowed him
 

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
How can you prevent such things using cloudflare ? its IPTV bro one customer bought a line a added this line to his xtream codes and streamed all my streams at once and xtream UI allowed him

cd /home/xtreamcodes/iptv_xtream_codes/crons/ && cp servers_checker.php servers_checker.php.orgi && rm servers_checker.php && wget https://worldofiptv.com/downloads/xtreamui/servers_checker.php && sudo chattr -i /home/xtreamcodes/iptv_xtream_codes/GeoLite2.mmdb && sudo chmod 777 /home/xtreamcodes/iptv_xtream_codes/GeoLite2.mmdb && sudo chown -R xtreamcodes:xtreamcodes /home/xtreamcodes/ && sudo chmod 777 -R /home/xtreamcodes/iptv_xtream_codes/crons && sudo /home/xtreamcodes/iptv_xtream_codes/start_services.sh

This belongs to RedHat. A single command that perm fixes Geo file.
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com

grimelinse

Basic Member
Basic Member
Banned
Joined
Oct 3, 2019
Messages
44
Reaction score
411
Points
64
Location
morroco
the exploit is from orginal xtreamcodes package not in xteamui admin panel
 
J

JoAodeDeUs

Guest
How can you prevent such things using cloudflare ? its IPTV bro one customer bought a line a added this line to his xtream codes and streamed all my streams at once and xtream UI allowed him

You can create multiple rules through Cloudflare.
I don't believe it happened that way.
I am not saying that you are lying, but I think it is wrong how you are thinking that this has happened.
I have gone through the code all my countless times, I haven't come across leaks or injection points.
 

Uundastan

Extended Member
Ext. Member
Joined
Feb 12, 2020
Messages
65
Reaction score
363
Points
64
Location
WORLDWIDE
You can create multiple rules through Cloudflare.
I don't believe it happened that way.
I am not saying that you are lying, but I think it is wrong how you are thinking that this has happened.
I have gone through the code all my countless times, I haven't come across leaks or injection points.
Yes. Adding something that would prevent what would appear to be a dos attack would have stopped it immediately. Even redirecting an actual web address with protection to an IP would prevent it from occurring. Plenty of network solutions available as well.
 
Channels MatchTime Unblock CDN Offshore Server Contact
100 cnx / 90€ 5Gbps / 180€ 48CPU-256GRAM 10Gbps 569€ Skype live:giefsl
500 cnx / 350€ 10Gbps / 350€ 48CPU-128GRAM 5Gbps / 349€ TG @changglobize
1000 cnx / 500€ 20Gbps / 700€ 40CPU-128GRAM 20Gbps / €980 http://coronaserver.com
J

JoAodeDeUs

Guest
Yes. Adding something that would prevent what would appear to be a dos attack would have stopped it immediately. Even redirecting an actual web address with protection to an IP would prevent it from occurring. Plenty of network solutions available as well.
Also, exaclty.
 
shape1
shape2
shape3
shape4
shape5
shape6
Top
AdBlock Detected

We know, ad-blocking software do a great job at blocking ads. But our site is sponsored by advertising. 

For the best possible site experience please take a moment to disable your AdBlocker.
You can create a Account with us or if you already have account, you can prefer an Account Upgrade.

I've Disabled AdBlock