Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: grue on June 19, 2011, 08:24:32 PM



Title: What mtgox number are you? (from DB leak)
Post by: grue on June 19, 2011, 08:24:32 PM
from accounts.csv (you know which one) ;)
Quote
4856,gruez,free.133ch@gmail.com,$1$ZyEFTEke$cWSfcMkc7pjPmHLzMt7dv0

ps. this idea was stolen off of someone else.


Title: Re: What mtgox number are you?
Post by: borgfish on June 19, 2011, 08:30:15 PM
you just want to bragg with your low number ;)


Title: Re: What mtgox number are you?
Post by: grue on June 19, 2011, 08:31:54 PM
you just want to bragg with your low number ;)
you sound a bit jelly :P


Title: Re: What mtgox number are you?
Post by: speeder on June 19, 2011, 08:32:42 PM
Let's do something usefull, post your number (even if not really precise, just 4xxx for example is mine accounts) and your date of joining (or what you can remember of it) mine is mid april.


Soon if enough people post, someone can make a calculation of how much mtgox (and thus bitcoin) userbase is growing :D


Title: Re: What mtgox number are you? (from DB leak)
Post by: dev^ on June 19, 2011, 08:38:04 PM
28500 +/- 100
... about max 3 weeks ago


Title: Re: What mtgox number are you? (from DB leak)
Post by: imperi on June 19, 2011, 08:38:16 PM
I'm 22983.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Maged on June 19, 2011, 08:40:47 PM
Umm.. You guys know that we've known our account numbers all along, right? You had to include it on all deposits to MtGox.


Title: Re: What mtgox number are you?
Post by: qwk on June 19, 2011, 08:45:00 PM
Let's do something usefull, post your number (even if not really precise, just 4xxx for example is mine accounts) and your date of joining (or what you can remember of it) mine is mid april.


Soon if enough people post, someone can make a calculation of how much mtgox (and thus bitcoin) userbase is growing :D

You could also lookup the user list of this forum

http://forum.bitcoin.org/index.php?action=mlist (http://forum.bitcoin.org/index.php?action=mlist)

compare the usernames and "date registered" in the list with the usernames in the .csv

and you'll get a good estimate on percentage of users here trading on mt gox and probably also a good approximation of their date of joining mt gox, which will most likely be around the same time they created their accounts here.



Title: Re: What mtgox number are you? (from DB leak)
Post by: nixpins on June 19, 2011, 08:45:22 PM
1169, who's got lower than that?

(The answer is, "1168 people have a lower account number than that.")


Title: Re: What mtgox number are you? (from DB leak)
Post by: w0mbat on June 19, 2011, 08:47:06 PM
...


Title: Re: What mtgox number are you? (from DB leak)
Post by: giszmo on June 19, 2011, 09:01:33 PM
the list is definitely interesting to read ...

Umm.. You guys know that we've known our account numbers all along, right? You had to include it on all deposits to MtGox.

well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.

also i never really cared but now seeing i'm a first-25%-early-adopter while i thought i had been late to the train is quite impressive.

also i would be interested in other stats like mail adresses that indicate certain origins, quota of male vs. female names, list of actual passwords ...

23879,w0mbat,max.schmalzl@gmail.com,$1$9RgPb3r2$jrR/rSYL6l3nmLb76pKy/.
if you use the same nick here and there, you got little to loose by posting whole lines :(
i realized that my password was the password that i got assigned the first day in university 14 years ago. finally a good reason to finally bury it :)
stupid me thought it is not a problem as i never had money on mtGox but i also restarted using that pw for my mail account half a year ago.

actually i like it how bitcoin teaches us to not only theoretically know how to deal with security :)


Title: Re: What mtgox number are you? (from DB leak)
Post by: AngelusWebDesign on June 19, 2011, 09:08:12 PM
HUH?

So the truth is that the ENTIRE MtGox database was compromised and made public -- and although the passwords are stored in hashed form, someone could use hash-cracking to crack the passwords?

Matthew


Title: Re: What mtgox number are you? (from DB leak)
Post by: EricJ2190 on June 19, 2011, 09:23:59 PM
If we are bragging about low numbers here, check mine. ;)


Title: Re: What mtgox number are you? (from DB leak)
Post by: BombaUcigasa on June 19, 2011, 09:41:45 PM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?


Title: Re: What mtgox number are you? (from DB leak)
Post by: Man From The Future on June 19, 2011, 09:48:46 PM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?

Is that message implying that PHP is insecure, or am I misreading it?

PS: College-level? I was 13 and I released a perfectly secure Club Penguin Private Server, with multi-pass SHA256... :P

PPS: Don't do the above unless you like angry Disney lawyers


Title: Re: What mtgox number are you? (from DB leak)
Post by: BombaUcigasa on June 19, 2011, 09:54:11 PM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?

Is that message implying that PHP is insecure, or am I misreading it?

PS: College-level? I was 13 and I released a perfectly secure Club Penguin Private Server, with multi-pass SHA256... :P

PPS: Don't do the above unless you like angry Disney lawyers
I'm saying  (current) college-level PHP coding is unsecure. It's a curse of the software industry, that nobody adds security unless it's been proven to be required. Usually the proof of requirement is pretty damaging. I suppose the quality level of mtgox coding is on par with their ability on html/css/graphic output.

Does nobody consider that some (PHP/Web) CMS projects have millions of lines of code and years of user testing on millions of installations and still identify and fix security holes? And people never use those (in this community), instead they cowboy-code their own low complexity implementations?


Title: Re: What mtgox number are you? (from DB leak)
Post by: dutt on June 19, 2011, 09:54:52 PM
In the top 2000. Never had any coins/cash in it tho. Thank God.


Title: Re: What mtgox number are you? (from DB leak)
Post by: gst on June 19, 2011, 10:25:26 PM
1169, who's got lower than that?

801


Title: Re: What mtgox number are you? (from DB leak)
Post by: breandan81 on June 19, 2011, 10:27:47 PM
761


Title: Re: What mtgox number are you? (from DB leak)
Post by: Man From The Future on June 19, 2011, 10:30:59 PM
Y'know, those < 3100 are all easily crackable? :(


Title: Re: What mtgox number are you? (from DB leak)
Post by: breandan81 on June 19, 2011, 10:43:19 PM
Didn't have anything in there, I keep my coins in an airgapped wallet unless they need to be somewhere else for a reason.


Title: Re: What mtgox number are you? (from DB leak)
Post by: joepie91 on June 19, 2011, 10:45:18 PM
2503.


Title: Re: What mtgox number are you? (from DB leak)
Post by: giszmo on June 19, 2011, 11:06:28 PM
If we are bragging about low numbers here, check mine. ;)
#7 @ MtGox but only 24 posts here??? Or did you just change your name for a prank?


Title: Re: What mtgox number are you? (from DB leak)
Post by: teamdren on June 19, 2011, 11:33:53 PM
Is this in order of when you registered?  I'm ~14k mtgox.  I feel like emailing some of these motherfuckers and making new friends.  Who's with me?


Title: Re: What mtgox number are you? (from DB leak)
Post by: RandyMarsh on June 19, 2011, 11:39:56 PM
Y'know, those < 3100 are all easily crackable? :(

I was able to find 640 passwords belonging to users 1 through 3036... and i know absolutely nothing about Cryptography (Which also means they could be wrong) just by feeding them into some gammy online hash cracker yokie


Title: Re: What mtgox number are you? (from DB leak)
Post by: gst on June 19, 2011, 11:49:57 PM
Y'know, those < 3100 are all easily crackable? :(

Shouldn't be a problem if you use different passwords for each website.


Title: Re: What mtgox number are you? (from DB leak)
Post by: skull88 on June 19, 2011, 11:53:12 PM
If we are bragging about low numbers here, check mine. ;)
#7 @ MtGox but only 24 posts here??? Or did you just change your name for a prank?
There are people here registered far behind me with a much larger postcount, doesn't mean a thing just that some people don't post much in here.

I'm number 118, thought I would be higher in number on the list (at least 4 digits), no clue however when I exactly registered at Mt Gox.
A year ago I guess.

Y'know, those < 3100 are all easily crackable? :(
Have fun with my pass, I only use it on MtGox which will be changed when it's back online


Title: Re: What mtgox number are you? (from DB leak)
Post by: MintCondition on June 20, 2011, 12:14:04 AM
actually i like it how bitcoin teaches us to not only theoretically know how to deal with security :)

Too soon man, too soon.. :o   ;)  

Actually I hope the modest balance I kept there will come out of all this unscathed. That'll be the moment I will transfer it out of Mt Gox, and after that they will never see a bitpenny from me ever again.

[Captain hindsight]But then again, the whole Mt Gox experience has always had a cheap feel to it for me. Combine that with the quick rise in daily transaction value and something was bound to go wrong. We should've never put so much trust in them![/captain hindsight]


Title: Re: What mtgox number are you? (from DB leak)
Post by: Isepick on June 20, 2011, 12:26:28 AM
Not my number, but I am sure a few people would be interested in this one...

http://i167.photobucket.com/albums/u160/Isepick/satoshi.jpg


Title: Re: What mtgox number are you? (from DB leak)
Post by: skull88 on June 20, 2011, 12:32:00 AM
Not my number, but I am sure a few people would be interested in this one...

http://i167.photobucket.com/albums/u160/Isepick/satoshi.jpg
yes, a new small trail to find our epic god, we've got his mail address  :D

...if that is the real Satoshi, I would think he would be a much earlier user of mtgox.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Mahkul on June 20, 2011, 12:35:43 AM
Y'know, those < 3100 are all easily crackable? :(

I was able to find 640 passwords belonging to users 1 through 3036... and i know absolutely nothing about Cryptography (Which also means they could be wrong) just by feeding them into some gammy online hash cracker yokie

329,Mahkul,p.makulski@gmail.com,$1$e1u03TlV$wGLXQ8ynWjXib5E4qj0fm.

Did you manage to crack my password? I thought it was pretty good. You can post it here, I never use the same password for more than one site anyway.


Title: Re: What mtgox number are you? (from DB leak)
Post by: srb123 on June 20, 2011, 12:37:15 AM
Woohoo, 78.

I remember it like yesterday, I bought in with Paypal, it doubled in a couple of days, sold half and withdrew using paypal and have sat on the rest and waited ever since. Back when bitcoin was fun, now it is just stressful.


Title: Re: What mtgox number are you? (from DB leak)
Post by: EricJ2190 on June 20, 2011, 12:45:10 AM
If we are bragging about low numbers here, check mine. ;)
#7 @ MtGox but only 24 posts here??? Or did you just change your name for a prank?

Nope, I am me. I have just not been very active here.


Title: Re: What mtgox number are you? (from DB leak)
Post by: saqwe on June 20, 2011, 12:47:35 AM
haha
i am jed, #1
and play thefarwilds all the time
 ;D




Title: Re: What mtgox number are you? (from DB leak)
Post by: BeeCee1 on June 20, 2011, 12:48:22 AM
I'd like to know when people with the highest numbers registered, that would help determine when the file was retrieved.  I only signed up a couple of days ago and there are almost a thousand accounts after mine.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Hach-Que on June 20, 2011, 12:59:07 AM
332-bit KeePass passwords.  Damn near unbreakable and easily replaceable too.  I'd recommend it to pretty much anyone affected by this (it's also good for generating super-strong passwords for the TrueCrypt partition that your wallet.dat should be sitting on).


Title: Re: What mtgox number are you? (from DB leak)
Post by: d.james on June 20, 2011, 01:09:00 AM
NUMBER is in no relation to the signed up date, I signed up for a second account yesterday afternoon to split my risk, (or did I just double my risk???), And my new account number is in the 30ks... unless 30k more ppl signed up yesterday then I don't think they're related at all.



Title: Re: What mtgox number are you? (from DB leak)
Post by: BeeCee1 on June 20, 2011, 01:33:06 AM
NUMBER is in no relation to the signed up date, I signed up for a second account yesterday afternoon to split my risk, (or did I just double my risk???), And my new account number is in the 30ks... unless 30k more ppl signed up yesterday then I don't think they're related at all.

That's a good bit of information, thanks for sharing it. 

Now we know that this list was posted less than 24 hours after it was retrieved, and, either the account compromises from 3 days ago were unrelated, or this file was retrieved on multiple occasions.


Title: Re: What mtgox number are you? (from DB leak)
Post by: AtlasONo on June 20, 2011, 02:15:20 AM
These are your merchant Id#'s btw


Title: Re: What mtgox number are you? (from DB leak)
Post by: Quantumplation on June 20, 2011, 03:01:55 AM
from accounts.csv (you know which one) ;)
Quote
4856,gruez,free.133ch@gmail.com,$1$ZyEFTEke$cWSfcMkc7pjPmHLzMt7dv0

ps. this idea was stolen off of someone else.

Actually, aren't you

Quote

56   grue   grue@joshua.in   9d7c5870687bd54118663f5422ea2b9c


?


Title: Re: What mtgox number are you? (from DB leak)
Post by: grue on June 20, 2011, 03:02:30 AM
from accounts.csv (you know which one) ;)
Quote
4856,gruez,free.133ch@gmail.com,$1$ZyEFTEke$cWSfcMkc7pjPmHLzMt7dv0

ps. this idea was stolen off of someone else.

Actually, aren't you

Quote

56   grue   grue@joshua.in   9d7c5870687bd54118663f5422ea2b9c


?
that was someone else.


Title: Re: What mtgox number are you? (from DB leak)
Post by: imperi on June 20, 2011, 03:02:47 AM
from accounts.csv (you know which one) ;)
Quote
4856,gruez,free.133ch@gmail.com,$1$ZyEFTEke$cWSfcMkc7pjPmHLzMt7dv0

ps. this idea was stolen off of someone else.

Actually, aren't you

Quote

56   grue   grue@joshua.in   9d7c5870687bd54118663f5422ea2b9c


?

I think he knows what his own email is?


Title: Re: What mtgox number are you? (from DB leak)
Post by: Astro on June 20, 2011, 03:26:32 AM
I'm under 2000 but above 1000.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Quantumplation on June 20, 2011, 06:12:15 AM
Wait, that means... There are MULTIPLE grues around these parts?  I get the feeling I'm about to be eaten...


Title: Re: What mtgox number are you? (from DB leak)
Post by: The Script on June 20, 2011, 07:13:54 AM
Hey anyone want to do me a favor and look "The Script" up on the list? I'm on my iPad at home, 3G Internet and I can't download the csv file but I'm curious what number I am at. I'm guessing less than 3000


Title: Re: What mtgox number are you? (from DB leak)
Post by: BtcNmcMiner on June 20, 2011, 07:22:08 AM
I'm

51319   roebuck85   roebuck85@gmail.com   $1$Qc8worl4$dhGEsjtdKyEX9VS0C8Xko0


I signed up June 14th


Title: Re: What mtgox number are you? (from DB leak)
Post by: franzl on June 20, 2011, 08:35:05 AM
I'm 100  :)

I think I've registered on 2010-07-29, that's when I first sent coins to mtgox.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Timo Y on June 20, 2011, 09:00:46 AM
Y'know, those < 3100 are all easily crackable? :(

looks like somebody already cracked mine.

(Mine is < 400)

When I tried to log into my gmail account that was registered on mtgox I got this message from gmail: "suspicious activity reported. please change your password".

Good thing I had a unique password just for mtgox!  ;D



Title: Re: What mtgox number are you? (from DB leak)
Post by: scribe on June 20, 2011, 09:41:25 AM
I'm #604 (same username as here), but not logged in for months so my password is in the old hash form - I'm assuming it's been cracked, but would love to have confirmation. Anyone that's run Jack on the file able to PM or e-mail me or something if they have?

Paranoia mode on.


Title: Re: What mtgox number are you? (from DB leak)
Post by: Inedible on June 20, 2011, 10:15:58 AM
To make the game more interesting, if you could also post the last IP address that accessed the account, your email address (bonus points if you can provide that password too), account name your old password (as that's now useless) and your full physical address, age, date of birth and your mother's maiden name, we can make a nice graph out of that. What do you say chaps?





(For those without a sense of humour or sense that is common: DO NOT TAKE THIS POST SERIOUSLY!)


Title: Re: What mtgox number are you? (from DB leak)
Post by: killer2021 on June 20, 2011, 10:22:07 AM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?

Is that message implying that PHP is insecure, or am I misreading it?

PS: College-level? I was 13 and I released a perfectly secure Club Penguin Private Server, with multi-pass SHA256... :P

PPS: Don't do the above unless you like angry Disney lawyers
I'm saying  (current) college-level PHP coding is unsecure. It's a curse of the software industry, that nobody adds security unless it's been proven to be required. Usually the proof of requirement is pretty damaging. I suppose the quality level of mtgox coding is on par with their ability on html/css/graphic output.

Does nobody consider that some (PHP/Web) CMS projects have millions of lines of code and years of user testing on millions of installations and still identify and fix security holes? And people never use those (in this community), instead they cowboy-code their own low complexity implementations?

True but there is a cost to everything. Not everyone can afford to hire 15 php master coders with 20+ years experience and PHDs in computer science, ya know!


Title: Re: What mtgox number are you? (from DB leak)
Post by: killer2021 on June 20, 2011, 10:27:18 AM
Y'know, those < 3100 are all easily crackable? :(

I was able to find 640 passwords belonging to users 1 through 3036... and i know absolutely nothing about Cryptography (Which also means they could be wrong) just by feeding them into some gammy online hash cracker yokie

329,Mahkul,p.makulski@gmail.com,$1$e1u03TlV$wGLXQ8ynWjXib5E4qj0fm.

Did you manage to crack my password? I thought it was pretty good. You can post it here, I never use the same password for more than one site anyway.

Its 123456789.

Pretty good, eh?


Title: Re: What mtgox number are you? (from DB leak)
Post by: joepie91 on June 21, 2011, 02:41:13 AM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?

Is that message implying that PHP is insecure, or am I misreading it?

PS: College-level? I was 13 and I released a perfectly secure Club Penguin Private Server, with multi-pass SHA256... :P

PPS: Don't do the above unless you like angry Disney lawyers
I'm saying  (current) college-level PHP coding is unsecure. It's a curse of the software industry, that nobody adds security unless it's been proven to be required. Usually the proof of requirement is pretty damaging. I suppose the quality level of mtgox coding is on par with their ability on html/css/graphic output.

Does nobody consider that some (PHP/Web) CMS projects have millions of lines of code and years of user testing on millions of installations and still identify and fix security holes? And people never use those (in this community), instead they cowboy-code their own low complexity implementations?

True but there is a cost to everything. Not everyone can afford to hire 15 php master coders with 20+ years experience and PHDs in computer science, ya know!
You don't realize how many fees Mt. Gox has been raking in?


Title: Re: What mtgox number are you? (from DB leak)
Post by: allinvain on June 21, 2011, 09:57:01 PM
400,000 BTC can buy a boat load of coders...


Title: Re: What mtgox number are you? (from DB leak)
Post by: speeder on June 21, 2011, 10:36:59 PM
well ... i know companies that don't give sequential numbers starting at 1 just to hide real numbers.
You mean companies that care about their customers and don't use amateur college-level PHP coding full of security holes?

Is that message implying that PHP is insecure, or am I misreading it?

PS: College-level? I was 13 and I released a perfectly secure Club Penguin Private Server, with multi-pass SHA256... :P

PPS: Don't do the above unless you like angry Disney lawyers
I'm saying  (current) college-level PHP coding is unsecure. It's a curse of the software industry, that nobody adds security unless it's been proven to be required. Usually the proof of requirement is pretty damaging. I suppose the quality level of mtgox coding is on par with their ability on html/css/graphic output.

Does nobody consider that some (PHP/Web) CMS projects have millions of lines of code and years of user testing on millions of installations and still identify and fix security holes? And people never use those (in this community), instead they cowboy-code their own low complexity implementations?

True but there is a cost to everything. Not everyone can afford to hire 15 php master coders with 20+ years experience and PHDs in computer science, ya know!
You don't realize how many fees Mt. Gox has been raking in?

You don't realize WHEN the fees were raked in?

MtGox went from nothing to everything in 2 months, MagicalTux more than once mentioned desperately trying to hire workers and not working so well. It is not much of a money issue, but also time issue.


Title: Re: What mtgox number are you? (from DB leak)
Post by: goodlord666 on June 23, 2011, 09:55:43 PM
To make the game more interesting, if you could also post the last IP address that accessed the account, your email address (bonus points if you can provide that password too), account name your old password (as that's now useless) and your full physical address, age, date of birth and your mother's maiden name, we can make a nice graph out of that. What do you say chaps?

THAT's the spirit!   :D


Title: Re: What mtgox number are you? (from DB leak)
Post by: grue on June 23, 2011, 10:05:17 PM
To make the game more interesting, if you could also post the last IP address that accessed the account, your email address (bonus points if you can provide that password too), account name your old password (as that's now useless) and your full physical address, age, date of birth and your mother's maiden name, we can make a nice graph out of that. What do you say chaps?
last ip: 127.0.0.1
email: in original post
email pass: same as mtgox pass