Funscript.org post-mortem

Funscript.org post-mortem
Funscript.org which was a service that advertised on Eroscripts is considered a security hazard and we advise you to delete your account and stop using the service. This thread below will serve as a history of the events that took place.

Funscript.org was successful in committing fraud against the forum and disputed the advertising services and paypal sided with them despite the evidence that we did deliver the service.


The last message from funscript.org:

Re: A word regarding the Funscript.org notice (annotated by me)

I understand you’re angry about the PayPal outcome, but I’d genuinely rather resolve this properly than keep trading blows, so I want to lay out where things actually stand.

On the security concern, I think it’s important to separate what happened from how it was presented. What was shown as a “breach” was someone loading the shell of the admin panel through their browser’s developer console. That returns the front-end only: the layout, buttons and labels. No actual data was ever exposed. Every real figure on that panel is served through authenticated, server-side API requests that require proper authorisation; without it, the server returns nothing. (The data was pollable and included real names, and emails. There was no authentication or authorization. You sent the admin username in the headers and it spat out personally identifiable information)

The screenshot being circulated actually demonstrates this. Every statistic on it was scribbled over to make things look worse, but the “Scriptos” balance in the top-right was missed, and it’s showing blank/error precisely because the API refused to return a value to an unauthorised session. In a genuinely authenticated session that field populates normally. They saw the wallpaper, not the house. (It was demonstrated to me that the tokens were irrelevant. They weren’t even needed for the bypass to work.)

For context on how this escalated: the original issue was users uploading scripts they weren’t the creators of. I addressed that immediately, but it snowballed from there. (This was the first issue which was promptly resolved and I was willing to forgive, the gross negligence on security and continued use of AI-only written code from someone who very evidently knew nothing about web dev or security is what rose out of this. The forum now has a very intentional AI code clause in future and current agreements)

Here’s my difficulty. The site-wide notice you published and the “Security Notice” link that still live on your platform, has caused real and ongoing damage: it has driven users to delete accounts, undermined trust in funscript.org, and effectively neutralised the advertising I paid for (This doesn’t make what he did not fraud, the service was delivered and paid for) , since steering people away from the platform makes those impressions worthless.

Because of that, a defamation claim has been raised against your company (I have not been served) for the damage to my business. I’m not telling you that to threaten you, I’m telling you because I’d genuinely prefer not to pursue it. I’m willing to resolve the matter in full if you’ll put things right:

  1. Post a site-wide notice for 5 days confirming that funscript.org is safe and that the earlier warning was based on incomplete/incorrect information.
    (I’m not interested in lying to my community)
  2. Remove the “Security Notice” link from your platform.
    (I will remove the notice when a report from a verified and reputable security audit comes out clean)

Do those two things and I’ll consider the matter closed and drop the claim and won’t process anymore PayPal disputes (This is blackmail). I think that’s a fair way to draw a line under this for both of us.

Happy to talk it through if you’d prefer.

Ed

10 Likes

For context, using the Script Editor is a premium feature and Scripto Credits are used for AI generation features (AI companions and voice cloning).

1 Like

Correct, soon we will be allowing scriptos for subscriptions and further down the line scripto’s will hold a monetary value.

I’m curious to see how the Scripto Credit market will change by then. As it currently stands with the cost of Premium and Scripto Credits with the current bounties, one would need to script more than 25 minutes of requested video per month to go net neutral for access to the Script Editor.

I only launched the script request feature a few days ago and it has a lot of activity. I can see 1 video has had 550 scriptos bid so I think it will be worthwhile for scripters.
As for premium membership, it is only ÂŁ4.99 (50 Scriptos) a month which I believe to be a fair asking price. With the public library we have already had over 1000 videos added to our server which is over 2TB storage and then bandwidth usage on top, this all costs money. This feature is less than 2 months old and I can see it will ramp up quickly. So you have to understand that membership fees are essential for the platform to survive and evolve. I think ÂŁ4.99 is very reasonable - some people spend more than that on a cup of coffee.

After the Funscripted.com situation are you able to verify that users aren’t stealing and reuploading scripts?

Unfortunately I can’t control how other platforms protect their scripts. I can only focus on how we handle script management. But I will definitely take a look.

1 Like

I can’t see the whole library without paying, but here’s what I can see without paying




It looks like your library also consists of stolen free scripts. The first script is mine, and I also edited the video for it. The second and third are also popular scripts from Eroscripts.

8 Likes

@VladTheImplier Could you also draw attention to this topic?

3 Likes

@revxxx can you answer for this?
It will need to be soon as it does affect the forum in more than just your reputation. We advertise your service. For the duration of this I’m taking that ad offline.

4 Likes

A lot of videos/scripts that have been added were openly available on faptap and other sources. With this in mind, I intentionally added a transfer ownership to setting on my admin account so I can transfer scripts to other accounts if needed..

We also have a dmca takedown area: Copyright & DMCA Policy - Funscript.org but this is more for video content.

When scripts are readily available to download for free from other sources, it is next to impossible to determine ownership.

With that said, if people are certain that their scripts have been used, please email me at: support@funscript.org and I will happily go through each one on a case by case basis.

My script is uploaded to faptap for free and by me personally. Here you can earn money from it.

5 Likes

This is not a satisfactory answer.
Firstly, I just signed up for the service, the “public library” which includes “community shared scripts” is behind a paywall.
Secondly you can see above @qweer has pointed out an instance of their scripts being stolen and sold.

Lastly you uploaded this script below, and I know you didn’t make it. You are personally culpable.
Your next answer better be pretty good because this doesn’t look good.

https://discuss.eroscripts.com/t/blake-blossom-nurse-edges-to-ultimate-reward-primal-s-fantasy-pov/7727
https://discuss.eroscripts.com/t/rs-blake-blossom-nurse-edges-to-ultimate-reward/5354

8 Likes

and if there is a library with more free scripts from this forum and requires money to view them that is another issue. Script authors did not not authorize for their free scripts to be reuploaded and especially not to be put under a pay wall.

7 Likes

You’re right, and I appreciate you being straight with me.

On the paywall. The premium subscription is there to cover video hosting and streaming costs, not to sell scripts. But I get the concern.

On the imports. When I first launched the public library, I added a number of videos and scripts myself from FapTap to get things off the ground and to test to make sure the system was working. They were freely available for download at the time and honestly I didn’t think much of it. That was a mistake on my part.

On the script I uploaded. You’re right, I didn’t make it. No excuse for that, I’m happy to remove it.

What I’d like to do about it:

  1. Any script a creator wants removed will be removed straight away, no questions asked. Tag me here or email support@funscript.org.
  2. If creators would rather keep their content on the platform, I’m happy to set them up with a free premium membership and transfer full ownership of their videos and scripts to their account where they can add any of their personal links for monetisation. That way they have control over their own work and actually benefit from the platform.
  3. The script @qweer flagged, I have opened a dialog with him and were resolving this as we speak.

My apologies to anyone who has been affected. Please know that my intention was to create a platform to make scripted videos and creating scripts easy.

This statement is MORE than ridiculous! How are creators supposed to tell if you’ve uploaded their scripts without permission without shoving money down your throat? You can’t possibly be serious! I’m sorry, but the number of AI-generated websites (it’s quite obvious that your website is AI-generated) that specifically steal scripts to line their own pockets seems to be reaching a new high once again.
Obviously, you don’t even understand why this is a problem! At least @Telemacy had the decency to take his website offline until the matter is resolved. Too bad that doesn’t seem to be your style.
Unfortunately, I have to agree with @Shownshadow here: A ban is probably the only correct course of action.
A request to remove your entire website has just been submitted to Namecheap.

7 Likes

Script authors shouldn’t have to go through your platform to see if their scripts were reuploaded without permission anything that you can’t verify was authorized to be reuploaded should be removed from your platform which I’d imagine would be the majority of scripts on your platform. It shouldn’t be an opt out it should be an opt in. You should be able to easily say how many scripts are from this forum and how many script authors authorized it to be reuploaded.

You still also have a paywall with such content you can say it’s to cover hosting fees but I’m sure you are still making money via ads and or through other means so the problem still persists free scripts are being paywalled and reuploaded without permission for revenue

7 Likes

To add to Vlad pointing out that you’ve uploaded others’ scripts yourself to your RevX account:

A lot of the scripts submitted by the “ScriptShare” account are clear reuploads of content by EroScripts users, in some cases the scripts are collaborations between forum users and the videos are original edits from here shared via file sharing services.

ScriptShare is your account as shown in the Public Library walkthrough video.
An example of reuploaded content is @softserve’s script for Flim13’s Mitsuki Karaoke Blowjob video, with the video and script extended by @Baxtyr.


https://discuss.eroscripts.com/t/flim13-record-of-blowjob-in-karaoke-room/38329/37

Given the amount of scripts you’ve reuploaded, you might be seeing a surge in takedown requests. Which raises the issue of takedown notices being hindered by the library being paywalled.

How are funscript authors supposed to obtain the site URL to their reuploaded content when the Public Library is inaccessible without a subscription?
And that’s assuming they are able to access enough of it to even find out that their content is hosted there in the first place.

8 Likes

Ah, would this be a valid URL format to submit when issuing a takedown notice for that example video?
https://funscript.org/pages/player.php?video_id=92

2 Likes

Ah yes. Nothing instills trust in me than seeing that Vibe Code Violet website design. Scummy to put community scripts behind a paywall and without the creator’s permission.

Even if you claim that the premium sub wasn’t for the scripts, you know full well that the scripts would be the main draw for any potential customer.

6 Likes