Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: tacotime on April 20, 2013, 04:53:17 PM



Title: LTCMine hacking, change your passwords now (Pool ops, check the suspect list)
Post by: tacotime on April 20, 2013, 04:53:17 PM
List of LTCmine accounts compromised:
https://bitcointalk.org/index.php?topic=92522.msg1892862#msg1892862

This occurred after Balthazar banned a known botnet operator from his pool

It appears the attacker got the users/passwords from another pool by SQL injection, possibly coinotron:
pool-x.eu
litecoinpool.org
Burnside's pool (ltc.kattare.com)
give-me-ltc.com
NuKingsMiningCo

https://bitcointalk.org/index.php?topic=92522.msg1893276#msg1893276

Users are urged to change their passwords for all pools and lock their deposit addresses where they can.

edit:
List of attacker addresses
Litecoin
LZ799S7zBUwuj68MqSXqHudgGEgBvB2sKD (http://explorer.litecoin.net/address/LZ799S7zBUwuj68MqSXqHudgGEgBvB2sKD)

Bitcoin
1Mh9uHViV9MhBiW3tACQj5PB4JRx7tcJQx (https://blockchain.info/address/1Mh9uHViV9MhBiW3tACQj5PB4JRx7tcJQx)
1FxvLMD4nigvDi6ynaJpfsMxpWKcbtJeQL (https://blockchain.info/address/1FxvLMD4nigvDi6ynaJpfsMxpWKcbtJeQL)
1DxmLunbUVbkoXe7LTs1TM5Lftrz7ujccP (https://blockchain.info/address/1DxmLunbUVbkoXe7LTs1TM5Lftrz7ujccP)
1JS6iyDne5DvwxwzCFyHZkUMYvpsCtL3uG (https://blockchain.info/address/1JS6iyDne5DvwxwzCFyHZkUMYvpsCtL3uG)


Title: Re: LTCMine/Coinotron hacking, change your passwords now
Post by: coinotron on April 20, 2013, 08:44:49 PM

I checked out today's payouts. There were no payouts to attacker addresses.
I didn't find any suspicious withdrawals or significant brute force attacks in last few days.


If those passwords were get from another pool, it certainly wasn't Coinotron.


Title: Re: LTCMine/Coinotron hacking, change your passwords now
Post by: tacotime on April 20, 2013, 08:46:13 PM
Okay, thanks for the information.


Title: Re: LTCMine hacking, change your passwords now
Post by: milly6 on April 20, 2013, 08:50:36 PM
thanks for the info. +1 for info gathering


Title: Re: LTCMine hacking, change your passwords now (Pool ops, check the suspect list)
Post by: mr_random on April 20, 2013, 08:57:46 PM
+2 thanks for the info


Title: Re: LTCMine hacking, change your passwords now (Pool ops, check the suspect list)
Post by: coinotron on April 20, 2013, 09:05:50 PM
Just in case I disabled payouts for all users with account names from LTCMine list of hacked accounts:


a-bolt,imsaguy,MinerG,drjunk,pushyk,nikola,csandr,mutano,aili,Nabi,dextro,Tenechek,metal,skoomskoom,46d938,witcher,Goga43,

Enzo,Alekse777,Acidd,Sinner3232,scorpy,yanes,alexx,drozd,boroda,NTWII,a102030b,ttls,yuren,xefirot,mladen811,228,alexchel,zullus000,

stasson4ik,norman14,fujifotoguy,vatten,Happyendl,bogdan0410,dpushkarev,mining,forgaill,riv2013,NigikGmen,thor,rain,blindas,ekvelibriym,

dimadsp,superbrain,simcity44,calabass

EDIT
Only two of those accounts have some withdrawals today.


Title: Re: LTCMine hacking, change your passwords now (Pool ops, check the suspect list)
Post by: g2x3k on August 28, 2013, 01:56:25 AM
still floating some around i think but thats to be expected had one user getting his account compromised