Bitcoin Forum

Other => Meta => Topic started by: erk on March 17, 2017, 02:14:04 AM



Title: Spectrocoin hacker
Post by: erk on March 17, 2017, 02:14:04 AM
I think there is a security hole in the forum.

When I logged in this morning, my Avatar had been changed to A Spectrcoin logo, and my signature had some of their promotional material.

When I checked show posts, someone has been posting from my account since March 12th.

I deleted the avatar and signature and changed my password. However I don't think the password was the issue.

When I looked at some of the posts that had come from my account I noticed a whole lot of posts in the thread from other users that also seemed to have the same Spectrocoin logo etc.

I think the forum itself has been hacked.



Title: Re: Spectrocoin hacker
Post by: nydiacaskey01 on March 17, 2017, 02:17:38 AM
I think there is a security hole in the forum.

When I logged in this morning, my Avatar had been changed to A Spectrcoin logo, and my signature had some of their promotional material.

When I checked show posts, someone has been posting from my account since March 12th.

I deleted the avatar and signature and changed my password. However I don't think the password was the issue.

When I looked at some of the posts that had come from my account I noticed a whole lot of posts in the thread from other users that also seemed to have the same Spectrocoin logo etc.

I think the forum itself has been hacked.


If the password were changed, how are you able to log in and make a post? You mean they change back to original password so that you will never notice? Sec logs only recorded password change with your account is just yesterday, other than that up to February 15 there's no changes made on your account.


Title: Re: Spectrocoin hacker
Post by: erk on March 17, 2017, 02:57:38 AM
I think there is a security hole in the forum.

When I logged in this morning, my Avatar had been changed to A Spectrcoin logo, and my signature had some of their promotional material.

When I checked show posts, someone has been posting from my account since March 12th.

I deleted the avatar and signature and changed my password. However I don't think the password was the issue.

When I looked at some of the posts that had come from my account I noticed a whole lot of posts in the thread from other users that also seemed to have the same Spectrocoin logo etc.

I think the forum itself has been hacked.


If the password were changed, how are you able to log in and make a post? You mean they change back to original password so that you will never notice? Sec logs only recorded password change with your account is just yesterday, other than that up to February 15 there's no changes made on your account.

I didn't word that very well. What I meant was I changed the password earlier today to try and stop the hacker, but I don't think the hack was by using my previous password, because many other people seem to be showing the same hacked avatar.

I think it might be a forum bug/exploit hence starting this thread to try and warn people. I have notified the moderators already.





Title: Re: Spectrocoin hacker
Post by: Cast12 on March 17, 2017, 03:09:15 AM
This could still be related to the bitcointalk hack back in 2015. Some of the accounts could be dormant accounts that weren't on in awhile so they couldn't change their password.


Title: Re: Spectrocoin hacker
Post by: BitcoinEXpress on March 17, 2017, 03:16:27 AM
@OP


Pro tip:

Change your password to "Incorrect" so when you forget it, just enter anything and the site will tell you

"Your password is Incorrect"


Geez, the forum hasn't been hacked.

Like it or not, your PW was the issue.

Just be glad you got your account back.


~BCX~



Title: Re: Spectrocoin hacker
Post by: erk on March 17, 2017, 03:18:27 AM
This could still be related to the bitcointalk hack back in 2015. Some of the accounts could be dormant accounts that weren't on in awhile so they couldn't change their password.

I see, I don't think I have changed my password for a couple of years, so what you say makes sense.

Perhaps the other users whose avatars were changed might also have old passwords?
In which case a hacker is on the forums today using the passwords gathered from the 2015 hack you mentioned.




Title: Re: Spectrocoin hacker
Post by: Lutpin on March 17, 2017, 03:20:22 AM
Don't blame spectrocoin for whoever got your account enrolling it in their signature campaign.

I would like to be a part of this campaign.

Username : erk
Number of posts: 2590
Rank : Sr. Member
Bitcoin Address : 1EtUPGLEqsx7rEM4oc8i5AsyV8EHkvaMgN

Thanks in advance



Perhaps the other users whose avatars were changed might also have old passwords?
In which case a hacker is on the forums today using the passwords gathered from the 2015 hack you mentioned.
The hashes of all passwords leaked, which is why everyone was adviced to update their password.


Title: Re: Spectrocoin hacker
Post by: erk on March 17, 2017, 03:52:34 AM
I am in the process of deleting all the bogus posts from my account.
It was mainly some sort of scam to get people to put money into a bitcoin account supposedly on coinbase for some sort of signature promotion.




Title: Re: Spectrocoin hacker
Post by: goomezd on March 17, 2017, 10:57:27 AM
May be your accound had  remain signed in somewhere else than your browser Or someone knows your password. You can simply change your email and password if this is the issue.


Title: Re: Spectrocoin hacker
Post by: achow101 on March 17, 2017, 02:22:02 PM
I see, I don't think I have changed my password for a couple of years, so what you say makes sense.
Then you must have also had a fairly weak password too. Anyways, that your account was compromised has nothing to do with spectrocoin.

Perhaps the other users whose avatars were changed might also have old passwords?
It was mainly some sort of scam to get people to put money into a bitcoin account supposedly on coinbase for some sort of signature promotion.
No. Your account being compromised has nothing to do with spectrocoin, and what spectrocoin is doing is not scamming. Spectrocoin is operating a signature and avatar campaign where they pay people to wear their avatar and their signature and make posts. Whoever got control of your account decided to enroll the account in spectrocoin's campaign and then make posts so that they could make money.