Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: ploum on June 27, 2011, 08:34:14 PM



Title: Someone tried to retrieve my mtgox password
Post by: ploum on June 27, 2011, 08:34:14 PM
I received a mail from MtGox saying that I tried to reset my password.

This was not me (this is obvious, the request is coming from a Windows PC  ;D )

But the strangest thing is that if you try to reply to the mail (as they told you to do if you haven't requested the reset), the mail is sent to :
Mt.Gox@w001.mo.us.xta.net

Do you smell that?

http://img.over-blog.com/500x375/0/25/91/81//peche192-silure-aout-07-004.jpg


Title: Re: Someone tried to retrieve my mtgox password
Post by: nosfera2 on June 27, 2011, 08:37:36 PM
No way! They hacked Mt Gox again and changed the domain name!


Title: Re: Someone tried to retrieve my mtgox password
Post by: Dirt Rider on June 27, 2011, 08:38:31 PM
I received the same email.  Looks like some form of phishing attempt.


Title: Re: Someone tried to retrieve my mtgox password
Post by: Dirt Rider on June 27, 2011, 08:39:40 PM
No way! They hacked Mt Gox again and changed the domain name!

No.  Anyone can send you an email and set the reply-to address to be anything they want.


Title: Re: Someone tried to retrieve my mtgox password
Post by: Vince Torres on June 27, 2011, 08:40:54 PM
I think this is a conspiracy. We need some answers.


Title: Re: Someone tried to retrieve my mtgox password
Post by: ploum on June 27, 2011, 08:41:31 PM
With the list of users and their email address having been made public, I'm astonished we are not receiving more of those  ::)


Title: Re: Someone tried to retrieve my mtgox password
Post by: Dirt Rider on June 27, 2011, 08:47:34 PM
I think this is a conspiracy. We need some answers.

Oh give me a break.  Have you never received spam and/or phishing emails?


Title: Re: Someone tried to retrieve my mtgox password
Post by: EricJ2190 on June 27, 2011, 08:47:34 PM
All of Mt. Gox's mail originates from the server w001.mo.us.xta.net. Just check the headers on your account recovery emails. The fact that is shows up in the From address of the password reset email is probably just a mistake on their part.


Title: Re: Someone tried to retrieve my mtgox password
Post by: twobitcoins on June 27, 2011, 08:48:05 PM
I received such an email.  I determined it was most likely from Mt. Gox because I had recently changed my email address on Mt. Gox to a new, unique one and the email came to that address.  The strange From field is disconcerting, but I think it is a misconfiguration rather than an attack in this case.


Title: Re: Someone tried to retrieve my mtgox password
Post by: LightRider on June 27, 2011, 08:48:19 PM
I have received a similar message, although I had not made such a request. The IP address the request originated from is a tor server in Germany. Someone is definitely trying to break back into the accounts.


Title: Re: Someone tried to retrieve my mtgox password
Post by: Dirt Rider on June 27, 2011, 08:51:27 PM
All of Mt. Gox's mail originates from the server w001.mo.us.xta.net. Just check the headers on your account recovery emails. The fact that is shows up in the From address of the password reset email is probably just a mistake on their part.

So confirm that the address is real by looking at the header of the suspect email?

Sure, I suppose it's possible that MtGox just goofed on the reply-to, which of course means that someone requested password recovery for my account and also ploum's (and it wasn't us).


Title: Re: Someone tried to retrieve my mtgox password
Post by: nosfera2 on June 27, 2011, 08:51:53 PM
No way! They hacked Mt Gox again and changed the domain name!

No.  Anyone can send you an email and set the reply-to address to be anything they want.

Whooshitywhoo!  ;)


Title: Re: Someone tried to retrieve my mtgox password
Post by: Dirt Rider on June 27, 2011, 08:55:44 PM
I have received a similar message, although I had not made such a request. The IP address the request originated from is a tor server in Germany. Someone is definitely trying to break back into the accounts.

Ok so someone is for some reason triggering password recovery requests.  I am not sure what they have to gain from that, unless they think they can somehow intercept the outbound email messages from MtGox, that's a scary thought.


Title: Re: Someone tried to retrieve my mtgox password
Post by: Seraphim401 on June 27, 2011, 09:18:41 PM
I got the same e-mail,be careful guys.
 


Title: Re: Someone tried to retrieve my mtgox password
Post by: dacoinminster on June 28, 2011, 12:04:57 AM
I got it too. I'm relieved that lots of people got this - I thought maybe someone had hacked my email and they were trying to reset my password because they knew they had access to my email.

Of course, I don't have enough BTC to be worth stealing, so they would be disappointed even if it worked :)


Title: Re: Someone tried to retrieve my mtgox password
Post by: Vinnie on June 28, 2011, 12:16:29 AM
I got it, too.


Title: Re: Someone tried to retrieve my mtgox password
Post by: kwukduck on June 28, 2011, 12:54:18 AM
too, as have 2 of my friends.


Title: Re: Someone tried to retrieve my mtgox password
Post by: Rogue Star on June 28, 2011, 01:36:35 AM
at first i thought it was someone trying to reset my password because the IP was off. then I thought it was a phishing attempt when i saw the reply to address was weird after responding. i don't know what to think now, but i'm still leaning toward phishing :-/

in any case i forward it to mtgox which triggered the support site to create a ticket, hopefully i'll hear back from them.


Title: Re: Someone tried to retrieve my mtgox password
Post by: dacoinminster on June 28, 2011, 03:25:34 PM
They replied to my support ticket as follows:

Ticket #****: Re: [Mt.Gox] Password recovery

Your request (#****) has been deemed solved.

To review, comment and reopen the request, follow the link below:
http://support.mtgox.com/tickets/****


Jiraiya, Jun-28 18:33 (JST):

Hello,

We have identified an issue with our password reset system that caused many users to receive unsolicited password reset emails. It is likely this was the cause of you receiving this email.

We would, however, like to remind you that having the same password for multiple online accounts is not secure.

Thanks,
Regards,
Jiraiya

MtGox.com Team


Title: Re: Someone tried to retrieve my mtgox password
Post by: Mousepotato on June 28, 2011, 05:26:10 PM
No.  Anyone can send you an email and set the reply-to address to be anything they want.
I'm pretty sure he was being sarcastic :)


Title: Re: Someone tried to retrieve my mtgox password
Post by: bitcon on June 28, 2011, 05:32:53 PM
if you use(d) the same password for mt. gox and your email account, then they might be able to send a password reminder to your email and check your email and get your password that way or even lock you out of your own account.  never use the same password twice.


Title: Re: Someone tried to retrieve my mtgox password
Post by: LightRider on June 28, 2011, 08:13:11 PM
Quote
This is an automatically generated Delivery Status Notification

THIS IS A WARNING MESSAGE ONLY.

YOU DO NOT NEED TO RESEND YOUR MESSAGE.

Delivery to the following recipient has been delayed:

    Mt.Gox@w001.mo.us.xta.net

Message will be retried for 2 more day(s)

Technical details of temporary failure:
The recipient server did not accept our requests to connect. Learn more at http://mail.google.com/support/bin/answer.py?answer=7720
[w001.mo.us.xta.net (1): Connection refused]

Just got this.