Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: cuddlefish on June 17, 2011, 12:01:41 AM



Title: BitcoinBoom.org STEALING WITCOINS
Post by: cuddlefish on June 17, 2011, 12:01:41 AM
http://bitcoin.witcoin.com/p/1811/
They are using a XSRF exploit to forcibly upvote their post... giving themselves 0.01 (20 cents!!!) with each click of a link.

DO NOT CLICK THE LINK IN THAT POST.


Title: Re: BitcoinBoom.org STEALING WITCOINS
Post by: bcearl on June 17, 2011, 04:08:57 AM
Can't any forum administrator replace donation addresses by his own ones?


Title: Re: BitcoinBoom.org STEALING WITCOINS
Post by: fabianhjr on June 17, 2011, 04:12:35 AM
Yes we can, no we won't. Honestly, we are helping you help us help us all, yeah. :)


Title: Re: BitcoinBoom.org STEALING WITCOINS
Post by: bcearl on June 17, 2011, 04:18:42 AM
Yes we can, no we won't. Honestly, we are helping you help us help us all, yeah. :)

I didn't intend to suspect anyone, but it's always good to think about possible vulnerabilities and discuss them openly.


Title: Re: BitcoinBoom.org STEALING WITCOINS
Post by: fabianhjr on June 17, 2011, 11:39:35 AM
Don't worry about it. :P

Quite frankly this is just a temporary issue, one that is easily avoidable with the NoScript addon. So I can follow the heperlink and nothing will happen. Give it a try.