Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: BitJohn on June 25, 2013, 07:31:36 PM



Title: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 07:31:36 PM
We are currently having an issue with our service provider and our public IP space. All servers are functioning fine, all accounts are secure and all fund are safe. As soon as our providers fix the issue we will be back online. Thank you.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: eule on June 25, 2013, 07:34:48 PM
It's interesting that vircurex and bter are down at the same time.  ???


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: DiamondCardz on June 25, 2013, 07:35:23 PM
Thanks for the update, John.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 07:36:40 PM
It's interesting that vircurex and bter are down at the same time.  ???

We have no official word from provider on why the IP space is down. Though it seems obvious that it may be an attack at this point we cannot rule out coincidence.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: fendlestick on June 25, 2013, 07:38:14 PM
Thanks for the updates, bloody computers they really no good for anything.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: broken_pixel on June 25, 2013, 07:45:53 PM
DDos!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Isotactic on June 25, 2013, 07:47:41 PM
Thanks for the update. Any ETA on when it might be back up?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 07:49:38 PM
DDos!

prolly that same chinese ip address as the pwc attack


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 07:51:29 PM
Thanks for the update. Any ETA on when it might be back up?

Our provider has hard reset the servers and is acknowledging that there is odd network activity at this time. Again much like many coins its pure speculation at this point :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 08:11:53 PM
Provider is saying that there really isn't a bandwidth problem and that it may be a hardware issue. Still being worked at this time.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: stevenlam on June 25, 2013, 08:12:56 PM
Can you estimate the time cryptsy will be back again ?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 08:15:01 PM
Can you estimate the time cryptsy will be back again ?
We have been escalated up the support ladder by the provider........ *insert favorite Muzak here*


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: baritus on June 25, 2013, 08:29:15 PM
Can you estimate the time cryptsy will be back again ?
We have been escalated up the support ladder by the provider........ *insert favorite Muzak here*

Crackling so bad, terrible.. I hate that on hold music. :P


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: jdebunt on June 25, 2013, 08:30:02 PM
thanks for the updates :) hope it gets fixed soon :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kneim on June 25, 2013, 08:32:47 PM
I can load the webpage, but vircurex and bter are down yet. I will wait with login until John approves.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: igysa on June 25, 2013, 08:34:29 PM
all three YAC exchanges at the same time before YAC N changes to 10 .. coincidence ?! ;)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: zulufields on June 25, 2013, 08:47:58 PM
Big thanks to the guys at cryptsy for all their hard work and it is great to hear funds are safe. Try to see this as a good test of cryptsy's systems and when you are back running it will show what a professional site you guys run.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: trenal on June 25, 2013, 08:57:09 PM
Can haz nullroute?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 09:00:58 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: daggerismo on June 25, 2013, 09:11:16 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)



thanks BitJohn for the official info


just keeping  calm and be patience :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nviere on June 25, 2013, 09:11:48 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)

Good job :) Thanks for the update!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 09:11:52 PM
hmmmm... i'll stop the attack if you pay me 100 BTC!!! :P


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: amytheplanarshift on June 25, 2013, 09:16:15 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: brambi on June 25, 2013, 09:16:30 PM
hmmmm... i'll stop the attack if you pay me 100 BTC!!! :P


I'll do it for 50 :D


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: LosingAlpha on June 25, 2013, 09:26:38 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?
Yeah I wouldn't log in until this question gets answered.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 09:27:44 PM
Expect another hour of downtime attack seems to be subsiding we are using the downtime to enable additional protections to prevent this in the future. Sorry for the delay. Some folks just want to see the world burn.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 09:32:26 PM
Expect another hour of downtime attack seems to be subsiding we are using the downtime to enable additional protections to prevent this in the future. Sorry for the delay. Some folks just want to see the world burn.

have you tried the ddos protect implementation in your htaccess file? i think apache comes with a template and tutorial that shows you how to do it.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: ohiwastedmylif on June 25, 2013, 09:33:15 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?
Yeah I wouldn't log in until this question gets answered.

Yes I just got the same thing. I cannot find anything on 4rx.

That sounds like a smart way to trick users into putting their data through another source.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 09:35:09 PM
I will announce when the site is fully operational. Again your funds and accounts are fine just a nice DDOS attack. We are implementing additional features with this downtime to deter this attack in the future.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 09:35:32 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?
Yeah I wouldn't log in until this question gets answered.

Yes I just got the same thing. I cannot find anything on 4rx.

That sounds like a smart way to trick users into putting their data through another source.

its some kind of pharmaceutical phishing website


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: amytheplanarshift on June 25, 2013, 09:37:23 PM
its some kind of pharmaceutical phishing website

Good thing I didn't go on to the site then...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 25, 2013, 09:40:59 PM
Expect another hour of downtime attack seems to be subsiding we are using the downtime to enable additional protections to prevent this in the future. Sorry for the delay. Some folks just want to see the world burn.

have you tried the ddos protect implementation in your htaccess file? i think apache comes with a template and tutorial that shows you how to do it.
That will work vs script kiddies, not vs botnets.
Waiting for you to come back on :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: broken_pixel on June 25, 2013, 09:43:16 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 25, 2013, 09:47:04 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 09:51:40 PM
Expect another hour of downtime attack seems to be subsiding we are using the downtime to enable additional protections to prevent this in the future. Sorry for the delay. Some folks just want to see the world burn.

have you tried the ddos protect implementation in your htaccess file? i think apache comes with a template and tutorial that shows you how to do it.
That will work vs script kiddies, not vs botnets.
Waiting for you to come back on :)

actually that does work versus botnets. if you recall trollzilla, my ddos protect stopped a flood of 1100+ chinese ips at my website. however they still chewed up 430 gb bandwidth in an hour attempting to flood the server. it worked and my account was cancelled.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: cobrabyte on June 25, 2013, 09:52:25 PM
I can confirm invalid SSL certificate. I'm getting SSL cert for *.professionalperformanceonline.nl -- definitely not going to log in.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 09:56:27 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved

Yes please wait until we confirm that our servers are back online.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: mr_random on June 25, 2013, 09:58:57 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved

Yes please wait until we confirm that our servers are back online.

Can you tell us who your service provider is?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 25, 2013, 10:01:22 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved


UPDATE EDIT: now www.cryptsy.com resolves to IP 199.83.128.157, also Incapsula, North Carolina

Seems like Incapsula.com offers some DDoS protection and general web security and cryptsy.com just put them in front of their site? So at least not a MITM attack but possibly just some Incapsula fuckup

Please confirm BitJohn


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 10:08:53 PM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved


UPDATE: now www.cryptsy.com also resolves to IP 199.83.132.157 Incapsula, Delaware

Seems like Incapsula.com offers some DDoS protection and general web security and cryptsy.com just put them in front of their site? So at least not a MITM attack but possibly just some Incapsula fuckup

Please confirm BitJohn

still wading through details Ill have vern give the whole write up once the madness is over for now just wait for an official we are up before logging in


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: XRcode on June 25, 2013, 10:11:25 PM
Hmmmmmmmmmm....

http://s21.postimg.org/rld9vgoyf/ooops.png


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: amytheplanarshift on June 25, 2013, 10:13:29 PM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: smitemesmith on June 25, 2013, 10:15:13 PM
Thank you for the update


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: DigitalDoom on June 25, 2013, 10:20:47 PM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.

Really? Do you really find that interesting?

Personally, it's not something I find at all interesting.

LOL...JK


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: peonminer on June 25, 2013, 10:23:46 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)
For those of us with auto payout from pools sending directly to cryptsy deposit addresses, will those funds still transfer safely or at all? Should we stop the auto transfers until the site is back up?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 25, 2013, 10:24:35 PM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 25, 2013, 10:25:02 PM

Now that's weird

Code:
www.luggagepros.com resolves to 66.40.35.112 Peer 1 Dedicated Hosting, Georgia

Seemingly unrelated to Incapsula..

but this:

I can confirm invalid SSL certificate. I'm getting SSL cert for *.professionalperformanceonline.nl -- definitely not going to log in.

resolves to 149.126.74.128, again Incapsula

Hopefully just some Incapsula issue


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 25, 2013, 10:25:38 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)
For those of us with auto payout from pools sending directly to cryptsy deposit addresses, will those funds still transfer safely or at all? Should we stop the auto transfers until the site is back up?

i cant speak for the cryptsy team, but i would atleast as a precautionary metric.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 25, 2013, 10:38:50 PM
I'm not logging in yet, but at least now I see data ...

https://166.78.0.180/markets/view/43

~nhminer


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kevindeangelis on June 25, 2013, 10:42:06 PM
Thanks for keeping everyone posted on the status of things!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 25, 2013, 10:44:59 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)
For those of us with auto payout from pools sending directly to cryptsy deposit addresses, will those funds still transfer safely or at all? Should we stop the auto transfers until the site is back up?
You're sending it to their wallet not their website.. jeesh


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: saber on June 25, 2013, 10:45:34 PM
Thanks for the update John!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: donjonson on June 25, 2013, 10:47:35 PM
Bad for letting the attack to happen.

Good for the constant communication and update, this is what's needed when this type of things happen.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: ohiwastedmylif on June 25, 2013, 10:49:28 PM
waiting for bigsausagepizza.com to be the new re-route


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: snowcrashed on June 25, 2013, 10:50:49 PM
I'm not logging in yet, but at least now I see data ...

https://166.78.0.180/markets/view/43

~nhminer

I would highly advise against anyone using that link to attempt to login.  Especially since the SSL is not functioning.

Bad for letting the attack to happen.

Good for the constant communication and update, this is what's needed when this type of things happen.

I wouldn't necessarily blame the website operators for "letting" the attack happen, after all they are not the service provider.  I would assume they picked a provider who has some form of DDoS protection.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 10:52:03 PM
Yes our provider has DDOS protection however nothing is DDOS proof. We are implementing even more protections with this downtime and will be up VERY soon.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 25, 2013, 10:54:26 PM
I'm not logging in yet, but at least now I see data ...

https://166.78.0.180/markets/view/43

~nhminer

I would highly advise against anyone using that link to attempt to login.  Especially since the SSL is not functioning.


Agreed -- not for logging in, just to get data -- SSL certificate on this site will identify itself as cryptsy.com, which is correct -- the SSL match will fail b/c the link uses the IP address

~nh


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: LosingAlpha on June 25, 2013, 10:56:39 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)
For those of us with auto payout from pools sending directly to cryptsy deposit addresses, will those funds still transfer safely or at all? Should we stop the auto transfers until the site is back up?
You're sending it to their wallet not their website.. jeesh
Well, yeah from the weird SSL certs it kinda looks like the domain has been hijacked - possibly not, but without an official steer we're certainly in 'do not log in under any circumstances' territory.

If it *is* the case that the domain that got boosted but the real server hasn't been compromised (which if it has, is probably the case - there are far more elegant ways of doing this if you get control of the server) then your wallets are safe -  unless you log in, in which case the attacker would just scoop up your login details, use them to log into the real site, and drain your funds.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: peonminer on June 25, 2013, 11:07:40 PM
Provider is now officially calling it a DDOS again all funds are fine exchange is actually running just fine internally of course noone can get to it which is obviously an issue :)
For those of us with auto payout from pools sending directly to cryptsy deposit addresses, will those funds still transfer safely or at all? Should we stop the auto transfers until the site is back up?
You're sending it to their wallet not their website.. jeesh
Didn't know if they had l33t online wallets or not. Good they didn't!!!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: frobley on June 25, 2013, 11:20:28 PM
A record is: qrq4x.x.incapdns.net -> [ 149.126.77.157  ]
http://www.intodns.com/cryptsy.com


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: broken_pixel on June 25, 2013, 11:20:42 PM
I logged in a few min ago to get my frank addy lol! Typed anyone home in the chat, lulz!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: ohiwastedmylif on June 25, 2013, 11:33:38 PM
I logged in a few min ago to get my frank addy lol! Typed anyone home in the chat, lulz!

Hope you had 0 money in the account and had different passwords for other exchanges and used an account specific email and are now going to change all of that when the site is back to normal....


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 25, 2013, 11:38:47 PM
I logged in a few min ago to get my frank addy lol! Typed anyone home in the chat, lulz!

Hope you had 0 money in the account and had different passwords for other exchanges and used an account specific email and are now going to change all of that when the site is back to normal....
I agree on this one.
Else prepare to get hacked everywhere..


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: snowcrashed on June 25, 2013, 11:47:50 PM
Hmm well I can access the site as per normal now, but ssl still isn't active and there's a little "Protected & Accelerated by Incapsula" pop-out on the side.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: LosingAlpha on June 25, 2013, 11:49:47 PM
I logged in a few min ago to get my frank addy lol! Typed anyone home in the chat, lulz!
You lose at Internet.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 25, 2013, 11:53:55 PM
Site is up waiting for SSL generation with new security service.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: erpbridge on June 25, 2013, 11:55:25 PM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.

From BigVern on Cryptsy's Chatbox:

BigVern: @erpbridge: whoever made those screenshots prob has a virus then

....so I suggest you guys go get your virus scanners fixed.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 25, 2013, 11:58:48 PM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.

From BigVern on Cryptsy's Chatbox:

BigVern: @erpbridge: whoever made those screenshots prob has a virus then

....so I suggest you guys go get your virus scanners fixed.
Wrong that's coming from chroome and I had that a while ago too, now it's gone, and in my case it was a different url.. but heey i have a virus said the smart guy..
Tried again now it's another even more different url, but that's just my viruses..  ::)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: LosingAlpha on June 26, 2013, 12:04:16 AM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.

From BigVern on Cryptsy's Chatbox:

BigVern: @erpbridge: whoever made those screenshots prob has a virus then

....so I suggest you guys go get your virus scanners fixed.
Definitely not a virus, happened here on a stock iPad, a stock android device, and a clean win7 build.

Absolutely, categorically *not* a virus.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 12:04:59 AM

Mine is still pointing to secure.4rx.com over here. Interesting that you are getting something different.

From BigVern on Cryptsy's Chatbox:

BigVern: @erpbridge: whoever made those screenshots prob has a virus then

....so I suggest you guys go get your virus scanners fixed.

What does he say about the invalid certificate warnings regarding other domains, namely:

Code:
professionalperformanceonline.nl
secure.4rx.com

which several users here reported and which resolve to IPs associated with Incapsula.com, the DDoS mitigation service crytpsy are now apparently using as well?

If he thinks a virus is the most probable explanation then cryptsy needs a new security team. This should be fully resolved in cooperation with Incapsula, immediately, and a full attack mitigation statement and impact report be published here and on the site if there is any interested in maintaining a base level of user trust. The site doesn't even offer two-factor authentication and now a potential MITM is about to be swept under the "must be a virus" rug?

And nobody should login before any of that is resolved


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kevindeangelis on June 26, 2013, 12:05:57 AM
not a virus, just looks like an invalid cert config


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 26, 2013, 12:07:06 AM
From BigVern on Cryptsy's Chatbox:

BigVern: @erpbridge: whoever made those screenshots prob has a virus then

....so I suggest you guys go get your virus scanners fixed.

No, this is just a warning from chrome that your DNS record is still hosed.  It will take a while until the dns poisoning goes away


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bigvern on June 26, 2013, 12:08:17 AM
Chrome just gave me a warning message when I tried to access cryptsy stating that the server was identified as secure.4rx.com. What's the deal with that?

SSL is down
SSL requests not supported for www.cryptsy.com
The site is not configured with SSL support.

It is not down, it is serving an invalid SSL certificate issued to an unrelated entity (secure.4rx.com) which might indicate a quite serious man-in-the-middle attack (https://en.wikipedia.org/wiki/Man-in-the-middle_attack)

Code:
www.cryptsy.com resolves to IP 166.78.0.180 Rackspace Hosting, Texas
secure.4rx.com resolves to IP 199.83.132.157 Incapsula, Delaware

Nobody should try to login even if the site comes back until this is fully resolved


UPDATE EDIT: now www.cryptsy.com resolves to IP 199.83.128.157, also Incapsula, North Carolina

Seems like Incapsula.com offers some DDoS protection and general web security and cryptsy.com just put them in front of their site? So at least not a MITM attack but possibly just some Incapsula fuckup

Please confirm BitJohn

Yes, we are using Incapsula.   Still finishing the ssl setup with them.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bigvern on June 26, 2013, 12:09:18 AM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh

Ip changes from time to time and you should not be accessing the site using the ip

BigVern


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 26, 2013, 12:13:28 AM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh

Ip changes from time to time and you should not be accessing the site using the ip

BigVern

What is your SOA for DNS?  nslookup still returns the incapsula.com records

a:\BA\main>nslookup cryptsy.com 75.75.75.75
Server:  cdns01.comcast.net
Address:  75.75.75.75

Non-authoritative answer:
Name:    cryptsy.com
Addresses:  199.83.133.236
          199.83.134.32

I thought it was rackspace, but that wont' let me query it.

a:\BA\main>nslookup cryptsy.com ns1.rackspace.com
Server:  ns.rackspace.com
Address:  69.20.95.4

*** ns.rackspace.com can't find cryptsy.com: Query refused



Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 26, 2013, 12:14:38 AM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh

Ip changes from time to time and you should not be accessing the site using the ip

BigVern

What is your SOA for DNS?  nslookup still returns the incapsula.com records

a:\BA\main>nslookup cryptsy.com 75.75.75.75
Server:  cdns01.comcast.net
Address:  75.75.75.75

Non-authoritative answer:
Name:    cryptsy.com
Addresses:  199.83.133.236
          199.83.134.32

I thought it was rackspace, but that wont' let me query it.

a:\BA\main>nslookup cryptsy.com ns1.rackspace.com
Server:  ns.rackspace.com
Address:  69.20.95.4

*** ns.rackspace.com can't find cryptsy.com: Query refused


it is my understanding that cryptsy will now operate under incapsulas dns protection layer/cdn network


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bigvern on June 26, 2013, 12:16:17 AM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh

Ip changes from time to time and you should not be accessing the site using the ip

BigVern

What is your SOA for DNS?  nslookup still returns the incapsula.com records

a:\BA\main>nslookup cryptsy.com 75.75.75.75
Server:  cdns01.comcast.net
Address:  75.75.75.75

Non-authoritative answer:
Name:    cryptsy.com
Addresses:  199.83.133.236
          199.83.134.32

I thought it was rackspace, but that wont' let me query it.

a:\BA\main>nslookup cryptsy.com ns1.rackspace.com
Server:  ns.rackspace.com
Address:  69.20.95.4

*** ns.rackspace.com can't find cryptsy.com: Query refused




Incapsula is the correct entry.   That is our new security service.

BigVern


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: nhminer on June 26, 2013, 12:26:23 AM


Incapsula is the correct entry.   That is our new security service.

BigVern

Ok, but your cryptsy.co, is not valid for their certificate.

www.cryptsy.com uses an invalid security certificate.

The certificate is only valid for the following names:
  incapsula.com , *.aguasandinas.cl , *.aldimobile.com.au , *.alyn.org , *.api.sell-n.com , *.astabis.com , *.b54.com , *.bancdeswiss.com , *.banggood.com , *.bank54.com , *.careyou.com.au , *.chc.com.sg , *.e-c.co.il , *.empireoption.com , *.epaydataonline.com , *.forexmagnates.com , *.gcmforex.com , *.grouploop.com , *.hallmarkinstantstreaming.com , *.hallmarkspiritclips.com , *.ioption.com , *.kaboodlehq.com , *.kaboodlepilot.com , *.liderforex.com , *.manage.cm , *.minit.com , *.my.truck-n.com , *.ordertickets.ca , *.partitionhost.com , *.paycall.co.il , *.pinklily.com.au , *.rushmorebingo.com , *.servertastic.com , *.smarttradefx.com , *.spicy.com.br , *.stormbattle.net , *.tamuvu.com , *.traderush.com , *.traderxp.com , *.videntfinancial.com , *.vipbinary.com , *.winoptions.com , *.xfcu.org , *.yakitome.com , *.zenobiajewellery.com , aldimobile.com.au , alyn.org , api.sell-n.com , astabis.com , b54.com , bancdeswiss.com , banggood.com , careyou.com.au , chc.com.sg , cp.truststream.co.uk , elpmultimedia.com , empireoption.com , epaydataonline.com , forexmagnates.com , gcmforex.com , hallmarkinstantstreaming.com , hallmarkspiritclips.com , ioption.com , kaboodlehq.com , kaboodlepilot.com , liderforex.com , manage.cm , minit.com , my.truck-n.com , ordertickets.ca , partitionhost.com , paycall.co.il , pinklily.com.au , recettage.ria.neopod.fm-ged.com , redcappi.com , rushmorebingo.com , servertastic.com , smarttradefx.com , spicy.com.br , stormbattle.net , tamuvu.com , traderush.com , traderxp.com , videntfinancial.com , vipbinary.com , winoptions.com , www.e-c.co.il , www.elpmultimedia.com , www.homologpedidos.sodexho.com.br , www.redcappi.com , xfcu.org , yakitome.com , zenobiajewellery.com 

(Error code: ssl_error_bad_cert_domain)

~nh


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Eli0t on June 26, 2013, 12:27:07 AM
just did a force refresh and got the same ^


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 12:44:30 AM


Incapsula is the correct entry.   That is our new security service.

BigVern

Ok, but your cryptsy.co, is not valid for their certificate.

www.cryptsy.com uses an invalid security certificate.

The certificate is only valid for the following names:
  incapsula.com , *.aguasandinas.cl , *.aldimobile.com.au , *.alyn.org , *.api.sell-n.com , *.astabis.com , *.b54.com , *.bancdeswiss.com , *.banggood.com , *.bank54.com , *.careyou.com.au , *.chc.com.sg , *.e-c.co.il , *.empireoption.com , *.epaydataonline.com , *.forexmagnates.com , *.gcmforex.com , *.grouploop.com , *.hallmarkinstantstreaming.com , *.hallmarkspiritclips.com , *.ioption.com , *.kaboodlehq.com , *.kaboodlepilot.com , *.liderforex.com , *.manage.cm , *.minit.com , *.my.truck-n.com , *.ordertickets.ca , *.partitionhost.com , *.paycall.co.il , *.pinklily.com.au , *.rushmorebingo.com , *.servertastic.com , *.smarttradefx.com , *.spicy.com.br , *.stormbattle.net , *.tamuvu.com , *.traderush.com , *.traderxp.com , *.videntfinancial.com , *.vipbinary.com , *.winoptions.com , *.xfcu.org , *.yakitome.com , *.zenobiajewellery.com , aldimobile.com.au , alyn.org , api.sell-n.com , astabis.com , b54.com , bancdeswiss.com , banggood.com , careyou.com.au , chc.com.sg , cp.truststream.co.uk , elpmultimedia.com , empireoption.com , epaydataonline.com , forexmagnates.com , gcmforex.com , hallmarkinstantstreaming.com , hallmarkspiritclips.com , ioption.com , kaboodlehq.com , kaboodlepilot.com , liderforex.com , manage.cm , minit.com , my.truck-n.com , ordertickets.ca , partitionhost.com , paycall.co.il , pinklily.com.au , recettage.ria.neopod.fm-ged.com , redcappi.com , rushmorebingo.com , servertastic.com , smarttradefx.com , spicy.com.br , stormbattle.net , tamuvu.com , traderush.com , traderxp.com , videntfinancial.com , vipbinary.com , winoptions.com , www.e-c.co.il , www.elpmultimedia.com , www.homologpedidos.sodexho.com.br , www.redcappi.com , xfcu.org , yakitome.com , zenobiajewellery.com  

(Error code: ssl_error_bad_cert_domain)

~nh

Wow, is this real? They are using one SSL certificate for all of their customers which simply includes a giant list of all the domain names, meaning every Incapsula customer could potentially impersonate every other? So banggood.com can just MITM cryptsy.com if they manage to mess with their DNS records for example. Not sure if this is a CDN requirement or something but it does sound kinda shitty to me...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 26, 2013, 12:48:08 AM


Incapsula is the correct entry.   That is our new security service.

BigVern

Ok, but your cryptsy.co, is not valid for their certificate.

www.cryptsy.com uses an invalid security certificate.

The certificate is only valid for the following names:
  incapsula.com , *.aguasandinas.cl , *.aldimobile.com.au , *.alyn.org , *.api.sell-n.com , *.astabis.com , *.b54.com , *.bancdeswiss.com , *.banggood.com , *.bank54.com , *.careyou.com.au , *.chc.com.sg , *.e-c.co.il , *.empireoption.com , *.epaydataonline.com , *.forexmagnates.com , *.gcmforex.com , *.grouploop.com , *.hallmarkinstantstreaming.com , *.hallmarkspiritclips.com , *.ioption.com , *.kaboodlehq.com , *.kaboodlepilot.com , *.liderforex.com , *.manage.cm , *.minit.com , *.my.truck-n.com , *.ordertickets.ca , *.partitionhost.com , *.paycall.co.il , *.pinklily.com.au , *.rushmorebingo.com , *.servertastic.com , *.smarttradefx.com , *.spicy.com.br , *.stormbattle.net , *.tamuvu.com , *.traderush.com , *.traderxp.com , *.videntfinancial.com , *.vipbinary.com , *.winoptions.com , *.xfcu.org , *.yakitome.com , *.zenobiajewellery.com , aldimobile.com.au , alyn.org , api.sell-n.com , astabis.com , b54.com , bancdeswiss.com , banggood.com , careyou.com.au , chc.com.sg , cp.truststream.co.uk , elpmultimedia.com , empireoption.com , epaydataonline.com , forexmagnates.com , gcmforex.com , hallmarkinstantstreaming.com , hallmarkspiritclips.com , ioption.com , kaboodlehq.com , kaboodlepilot.com , liderforex.com , manage.cm , minit.com , my.truck-n.com , ordertickets.ca , partitionhost.com , paycall.co.il , pinklily.com.au , recettage.ria.neopod.fm-ged.com , redcappi.com , rushmorebingo.com , servertastic.com , smarttradefx.com , spicy.com.br , stormbattle.net , tamuvu.com , traderush.com , traderxp.com , videntfinancial.com , vipbinary.com , winoptions.com , www.e-c.co.il , www.elpmultimedia.com , www.homologpedidos.sodexho.com.br , www.redcappi.com , xfcu.org , yakitome.com , zenobiajewellery.com  

(Error code: ssl_error_bad_cert_domain)

~nh

Wow, is this real? They are using one SSL certificate for all of their customers which simply includes a giant list of all the domain names, meaning every customer could impersonate every other? So banggood.com can just MITM cryptsy.com if they manage to mess with their DNS records for example. Not sure if this is a CDN requirement or something but it does sound kinda shitty to me...

We are on a temporary certificate until a new one is generated for the new security provider. Wait until its in place.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 26, 2013, 12:49:46 AM
We are currently having an issue with our service provider and our public IP space. All servers are functioning fine, all accounts are secure and all fund are safe. As soon as our providers fix the issue we will be back online. Thank you.


good to know ya you are prolly catching unusual amount of traffic since ya'll are now linked to that satoshi mod'd thread...thanks


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 12:51:26 AM


Incapsula is the correct entry.   That is our new security service.

BigVern

Ok, but your cryptsy.co, is not valid for their certificate.

www.cryptsy.com uses an invalid security certificate.

The certificate is only valid for the following names:
  incapsula.com , *.aguasandinas.cl , *.aldimobile.com.au , *.alyn.org , *.api.sell-n.com , *.astabis.com , *.b54.com , *.bancdeswiss.com , *.banggood.com , *.bank54.com , *.careyou.com.au , *.chc.com.sg , *.e-c.co.il , *.empireoption.com , *.epaydataonline.com , *.forexmagnates.com , *.gcmforex.com , *.grouploop.com , *.hallmarkinstantstreaming.com , *.hallmarkspiritclips.com , *.ioption.com , *.kaboodlehq.com , *.kaboodlepilot.com , *.liderforex.com , *.manage.cm , *.minit.com , *.my.truck-n.com , *.ordertickets.ca , *.partitionhost.com , *.paycall.co.il , *.pinklily.com.au , *.rushmorebingo.com , *.servertastic.com , *.smarttradefx.com , *.spicy.com.br , *.stormbattle.net , *.tamuvu.com , *.traderush.com , *.traderxp.com , *.videntfinancial.com , *.vipbinary.com , *.winoptions.com , *.xfcu.org , *.yakitome.com , *.zenobiajewellery.com , aldimobile.com.au , alyn.org , api.sell-n.com , astabis.com , b54.com , bancdeswiss.com , banggood.com , careyou.com.au , chc.com.sg , cp.truststream.co.uk , elpmultimedia.com , empireoption.com , epaydataonline.com , forexmagnates.com , gcmforex.com , hallmarkinstantstreaming.com , hallmarkspiritclips.com , ioption.com , kaboodlehq.com , kaboodlepilot.com , liderforex.com , manage.cm , minit.com , my.truck-n.com , ordertickets.ca , partitionhost.com , paycall.co.il , pinklily.com.au , recettage.ria.neopod.fm-ged.com , redcappi.com , rushmorebingo.com , servertastic.com , smarttradefx.com , spicy.com.br , stormbattle.net , tamuvu.com , traderush.com , traderxp.com , videntfinancial.com , vipbinary.com , winoptions.com , www.e-c.co.il , www.elpmultimedia.com , www.homologpedidos.sodexho.com.br , www.redcappi.com , xfcu.org , yakitome.com , zenobiajewellery.com  

(Error code: ssl_error_bad_cert_domain)

~nh

Wow, is this real? They are using one SSL certificate for all of their customers which simply includes a giant list of all the domain names, meaning every customer could impersonate every other? So banggood.com can just MITM cryptsy.com if they manage to mess with their DNS records for example. Not sure if this is a CDN requirement or something but it does sound kinda shitty to me...

We are on a temporary certificate until a new one is generated for the new security provider. Wait until its in place.

Yeah I'm waiting for a detailed report but in the meantime I am not talking about the fact that cryptsy.com is still missing from the list or that browsers are still giving a warning (because cryptsy.com is missing from the list) but I'm wondering why there is a certificate with a giant list in the first place (criticizing Incapsula)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: ohiwastedmylif on June 26, 2013, 01:02:56 AM
Yeah I'm waiting for a detailed report but in the meantime I am not talking about the fact that cryptsy.com is still missing from the list or that browsers are still giving a warning (because cryptsy.com is missing from the list) but I'm wondering why there is a certificate with a giant list in the first place (criticizing Incapsula)

Since they are using a temporary certificate they maybe all on the same temporary certificate. The sites listed could all currently be pending new certificates. That still leaves an open window for issues to occur if you knew about this exploit.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 01:12:28 AM
Yeah I'm waiting for a detailed report but in the meantime I am not talking about the fact that cryptsy.com is still missing from the list or that browsers are still giving a warning (because cryptsy.com is missing from the list) but I'm wondering why there is a certificate with a giant list in the first place (criticizing Incapsula)

Since they are using a temporary certificate they maybe all on the same temporary certificate. The sites listed could all currently be pending new certificates. That still leaves an open window for issues to occur if you knew about this exploit.

Yeah that could be, there is no good reason all the other sites would require a new certificate all at the same time though, unless there was some major incident, but let's wait and see.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bigvern on June 26, 2013, 01:36:35 AM


Incapsula is the correct entry.   That is our new security service.

BigVern

Ok, but your cryptsy.co, is not valid for their certificate.

www.cryptsy.com uses an invalid security certificate.

The certificate is only valid for the following names:
  incapsula.com , *.aguasandinas.cl , *.aldimobile.com.au , *.alyn.org , *.api.sell-n.com , *.astabis.com , *.b54.com , *.bancdeswiss.com , *.banggood.com , *.bank54.com , *.careyou.com.au , *.chc.com.sg , *.e-c.co.il , *.empireoption.com , *.epaydataonline.com , *.forexmagnates.com , *.gcmforex.com , *.grouploop.com , *.hallmarkinstantstreaming.com , *.hallmarkspiritclips.com , *.ioption.com , *.kaboodlehq.com , *.kaboodlepilot.com , *.liderforex.com , *.manage.cm , *.minit.com , *.my.truck-n.com , *.ordertickets.ca , *.partitionhost.com , *.paycall.co.il , *.pinklily.com.au , *.rushmorebingo.com , *.servertastic.com , *.smarttradefx.com , *.spicy.com.br , *.stormbattle.net , *.tamuvu.com , *.traderush.com , *.traderxp.com , *.videntfinancial.com , *.vipbinary.com , *.winoptions.com , *.xfcu.org , *.yakitome.com , *.zenobiajewellery.com , aldimobile.com.au , alyn.org , api.sell-n.com , astabis.com , b54.com , bancdeswiss.com , banggood.com , careyou.com.au , chc.com.sg , cp.truststream.co.uk , elpmultimedia.com , empireoption.com , epaydataonline.com , forexmagnates.com , gcmforex.com , hallmarkinstantstreaming.com , hallmarkspiritclips.com , ioption.com , kaboodlehq.com , kaboodlepilot.com , liderforex.com , manage.cm , minit.com , my.truck-n.com , ordertickets.ca , partitionhost.com , paycall.co.il , pinklily.com.au , recettage.ria.neopod.fm-ged.com , redcappi.com , rushmorebingo.com , servertastic.com , smarttradefx.com , spicy.com.br , stormbattle.net , tamuvu.com , traderush.com , traderxp.com , videntfinancial.com , vipbinary.com , winoptions.com , www.e-c.co.il , www.elpmultimedia.com , www.homologpedidos.sodexho.com.br , www.redcappi.com , xfcu.org , yakitome.com , zenobiajewellery.com 

(Error code: ssl_error_bad_cert_domain)

~nh

We are still waiting for the correct ssl generation to remove that error.

BigVern


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kenshin23 on June 26, 2013, 02:51:53 AM
Not sure if whatever happened has been fixed, but the site seems to be working ok for me.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 26, 2013, 02:58:35 AM
Not sure if whatever happened has been fixed, but the site seems to be working ok for me.

good times looks like the killer bath salts are flowing once again,,thanks team


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: chinchs on June 26, 2013, 03:09:54 AM
I still getting an error (not in chrome but in Iexplorer and firefox) the message say that the cert was issued for another web address... weird that chrome show the cert as OK, anyone else having this issue?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Kevlar on June 26, 2013, 03:34:43 AM
Can I get out and push? Would it help? Generating a cert isn't THAT hard...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 26, 2013, 03:37:56 AM
I still getting an error (not in chrome but in Iexplorer and firefox) the message say that the cert was issued for another web address... weird that chrome show the cert as OK, anyone else having this issue?


no we all good in the hood here swapped some pos dvc for ltc..thanks team


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Kevlar on June 26, 2013, 04:56:19 AM
The get account information is no longer working, although the order book API seems to be.

I get this: <html><head><META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"></head><iframe src="/_Incapsula_Resource?CWUDNSAI=23_689B0D76&incident_id=32000010321540621-120418174173708308&edet=12&cinfo=acfaf6fdc753810520000000" frameborder=0 width="100%" height="100%" marginheight="0px" marginwidth="0px">Request unsuccessful. Incapsula incident ID: 32000010321540621-120418174173708308</iframe></html>

When I try and make a request for my account info.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: torbank on June 26, 2013, 05:04:34 AM
Still getting an SSL error in google chrome.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bonsai99 on June 26, 2013, 05:07:02 AM
Still getting an SSL error in google chrome.
Same here.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: digitalindustry on June 26, 2013, 05:17:44 AM
John and Vern

I hope I didint bring the big hammer of the USSA down on you ?

Here is what you have to say , state publicly that caps are to be used after the war.

And that you will have no retail market for them before so.

You have to play by the rules John.

** you know the rules John , they are the same ones Iraq and Lybia learned about.


Title: API still broken Re: ** Official ** Cryptsy funds are safe and secure
Post by: woodrake on June 26, 2013, 05:32:41 AM
We are currently having an issue with our service provider and our public IP space. All servers are functioning fine, all accounts are secure and all fund are safe. As soon as our providers fix the issue we will be back online. Thank you.

Hi,

I still cannot access the API this morning. I tried HTTP instead of HTTPS incase it was the certificate, but still no joy.

I am guessing that the captcha thing in front of the site is now also in front of the API. Obviously having a "are you human" check in front of an API rather defeats the purpose! Please can you give me an idea of how soon that will be fixed?

Kate.


Title: Re: API still broken Re: ** Official ** Cryptsy funds are safe and secure
Post by: Kevlar on June 26, 2013, 06:05:26 AM
We are currently having an issue with our service provider and our public IP space. All servers are functioning fine, all accounts are secure and all fund are safe. As soon as our providers fix the issue we will be back online. Thank you.

Hi,

I still cannot access the API this morning. I tried HTTP instead of HTTPS incase it was the certificate, but still no joy.

I am guessing that the captcha thing in front of the site is now also in front of the API. Obviously having a "are you human" check in front of an API rather defeats the purpose! Please can you give me an idea of how soon that will be fixed?

Kate.

I'm having the same problem.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: ohiwastedmylif on June 26, 2013, 07:01:54 AM
Still no certificate? ...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: digitalindustry on June 26, 2013, 07:05:19 AM
http://www.youtube.com/watch?v=qMy2ZbPkyvw&feature=player_detailpage

Mr Drake explains some stuff.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Mapuo on June 26, 2013, 07:10:27 AM
Still no certificate? ...
Comming from Mars.  ;D


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: sartech on June 26, 2013, 07:41:46 AM
You attempted to reach www.cryptsy.com, but instead you actually reached a server identifying itself as incapsula.com. This may be caused by a misconfiguration on the server or by something more serious. An attacker on your network could be trying to get you to visit a fake (and potentially harmful) version of www.cryptsy.com.
You should not proceed, especially if you have never seen this warning before for this site.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: viboracecata on June 26, 2013, 07:52:28 AM
Can you tell me the time service will be OK?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: aurefos on June 26, 2013, 08:27:46 AM
Are there any issues with pending deposits? I have couple deposits with a lot more than 6 confirmations and still see it as 'pending' on cryptsy.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: igysa on June 26, 2013, 08:29:41 AM
good work all working great now !


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Amph on June 26, 2013, 08:55:24 AM
i have send 1 litecoin, but still my transaction, does not appear, and all 6 part are confirmed in my wallet
does cryptsy use the new client?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: clearcrystal on June 26, 2013, 09:26:01 AM
The website stopped working again.. I get "502 Bad Gateway"


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: rovchris on June 26, 2013, 09:28:26 AM
The website stopped working again.. I get "502 Bad Gateway"

DDOS round 2



Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 26, 2013, 09:30:59 AM
i think the 502 is more due to the ssl coming back online. they adjusted their configuration to http and now they need to go back to ssl


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: rovchris on June 26, 2013, 09:32:59 AM
i think the 502 is more due to the ssl coming back online. they adjusted their configuration to http and now they need to go back to ssl

Not sure about that man as http does not work.


Anyway its back now Woooo hooooo


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 26, 2013, 09:40:46 AM
i think the 502 is more due to the ssl coming back online. they adjusted their configuration to http and now they need to go back to ssl

Not sure about that man as http does not work.


Anyway its back now Woooo hooooo

yeah, but if when they setup ssl the dns changes to reroute through the ssl ip. until port configuration is changed from http to ssl you get a 502 bad gateway, because a http port and ssl port can't be open at the same time.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: jdebunt on June 26, 2013, 09:54:17 AM
hope it gets back up today, i want make some trades ^^


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 26, 2013, 09:57:33 AM
It's down again  :D


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r3wt on June 26, 2013, 09:59:58 AM
hope it gets back up today

that's what she said.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: jdebunt on June 26, 2013, 10:02:58 AM
hope it gets back up today

that's what she said.

hilarious :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: paladin281978 on June 26, 2013, 10:19:29 AM
502 Bad Gateway


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: r32godzilla on June 26, 2013, 10:19:42 AM
Yep still down. Nothing on twitter either.

https://twitter.com/cryptsy



Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 26, 2013, 10:32:29 AM
502 Bad Gateway


bummer ya i made one trade after the first dose monkey wrenchers busy around the clock...thanks


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 26, 2013, 10:35:40 AM
I have made Vern aware of the new issue more to follow once I have it.....


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 26, 2013, 10:39:00 AM
All is better thanks :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: toruonu on June 26, 2013, 10:39:11 AM
Well it's back up, but I don't see my incoming pending coins. I had sent 900 MEM which already have 149 confirmations, but they don't show up at cryptsy. Do you have issues with your backend wallets and web?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: toruonu on June 26, 2013, 10:47:10 AM
Ok, I guess it was temporary. The coins showed up finally, let's see if new coins I just now sent also will show up.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: toruonu on June 26, 2013, 11:13:13 AM
Aaand they're not showing up...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Makitaki on June 26, 2013, 11:22:21 AM
It seems to be a common problem. People on the chat report delays with other coins too.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: philipkdick on June 26, 2013, 12:44:23 PM
I transported Coin there over 1 hour ago and has not shown up , I've emailed support .


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: paladin281978 on June 26, 2013, 12:54:47 PM
deposits not working at Cryptsy.com at the moment?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: digitalindustry on June 26, 2013, 01:00:53 PM
doesn't sound like i'd take the risk at the moment, but i'm sure they are working on it.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: philipkdick on June 26, 2013, 01:47:40 PM
Now I'm kinda worried about weather I'm going to see these DGC again after 3 hours .

I've had no email back ,  might it be the case that DGC was attacked ?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 02:22:33 PM
Hi John, now cryptsy.com (or Incapsula on behalf of it) still uses a single shared SSL certificate which allows anybody on the following list to impersonate and potentially MITM anybody else:

DNS Name=incapsula.com
DNS Name=*.aguasandinas.cl
DNS Name=*.aldimobile.com.au
DNS Name=*.alyn.org
DNS Name=*.api.sell-n.com
DNS Name=*.astabis.com
DNS Name=*.b54.com
DNS Name=*.bancdeswiss.com
DNS Name=*.banggood.com
DNS Name=*.bank54.com
DNS Name=*.careyou.com.au
DNS Name=*.chc.com.sg
DNS Name=*.cryptsy.com
DNS Name=*.e-c.co.il
DNS Name=*.empireoption.com
DNS Name=*.epaydataonline.com
DNS Name=*.forexmagnates.com
DNS Name=*.gcmforex.com
DNS Name=*.grouploop.com
DNS Name=*.hallmarkinstantstreaming.com
DNS Name=*.hallmarkspiritclips.com
DNS Name=*.ioption.com
DNS Name=*.kaboodlehq.com
DNS Name=*.kaboodlepilot.com
DNS Name=*.liderforex.com
DNS Name=*.manage.cm
DNS Name=*.minit.com
DNS Name=*.my.truck-n.com
DNS Name=*.ordertickets.ca
DNS Name=*.partitionhost.com
DNS Name=*.paycall.co.il
DNS Name=*.pinklily.com.au
DNS Name=*.rushmorebingo.com
DNS Name=*.servertastic.com
DNS Name=*.smarttradefx.com
DNS Name=*.spicy.com.br
DNS Name=*.stormbattle.net
DNS Name=*.tamuvu.com
DNS Name=*.traderush.com
DNS Name=*.traderxp.com
DNS Name=*.videntfinancial.com
DNS Name=*.vipbinary.com
DNS Name=*.winoptions.com
DNS Name=*.xfcu.org
DNS Name=*.yakitome.com
DNS Name=*.zenobiajewellery.com
DNS Name=aldimobile.com.au
DNS Name=alyn.org
DNS Name=api.sell-n.com
DNS Name=astabis.com
DNS Name=b54.com
DNS Name=bancdeswiss.com
DNS Name=banggood.com
DNS Name=careyou.com.au
DNS Name=chc.com.sg
DNS Name=cp.truststream.co.uk
DNS Name=cryptsy.com
DNS Name=elpmultimedia.com
DNS Name=empireoption.com
DNS Name=epaydataonline.com
DNS Name=forexmagnates.com
DNS Name=gcmforex.com
DNS Name=hallmarkinstantstreaming.com
DNS Name=hallmarkspiritclips.com
DNS Name=ioption.com
DNS Name=kaboodlehq.com
DNS Name=kaboodlepilot.com
DNS Name=liderforex.com
DNS Name=manage.cm
DNS Name=minit.com
DNS Name=my.truck-n.com
DNS Name=ordertickets.ca
DNS Name=partitionhost.com
DNS Name=paycall.co.il
DNS Name=pinklily.com.au
DNS Name=recettage.ria.neopod.fm-ged.com
DNS Name=redcappi.com
DNS Name=rushmorebingo.com
DNS Name=servertastic.com
DNS Name=smarttradefx.com
DNS Name=spicy.com.br
DNS Name=stormbattle.net
DNS Name=tamuvu.com
DNS Name=traderush.com
DNS Name=traderxp.com
DNS Name=videntfinancial.com
DNS Name=vipbinary.com
DNS Name=winoptions.com
DNS Name=www.e-c.co.il
DNS Name=www.elpmultimedia.com
DNS Name=www.homologpedidos.sodexho.com.br
DNS Name=www.redcappi.com
DNS Name=xfcu.org
DNS Name=yakitome.com
DNS Name=zenobiajewellery.com


Is this a temporary workaround or the permanent approach?

Thanks


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Amph on June 26, 2013, 02:53:03 PM
just slow, but it is working


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: philipkdick on June 26, 2013, 03:22:00 PM
The funds arrived , want to confirm . ! Just slowly.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Kevlar on June 26, 2013, 05:00:28 PM
All is better thanks :)

Nope, definitely not. The User account info API is still not working.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 26, 2013, 05:21:06 PM
Hi John

I found a bug in the UI: if you click on the amount of BTC available (or LTC for some markets) in the top right corner of the "SUBMIT NEW ORDER" form to buy the maximum amount of altcoins possible with your balance at a given price then it does not correctly calculate that number.

The onclick event handler of that span element currently reads:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())*0.998);$('#TradeBuyAmount').trigger('change');" ...

but it should actually be:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())/1.002);$('#TradeBuyAmount').trigger('change');" ...

Then it calculates the correct amount


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kenshin23 on June 27, 2013, 06:39:35 PM
The site is now completely down for me at the moment. Chrome says "Error 105 (net::ERR_NAME_NOT_RESOLVED)". isup.me confirms it's down as well.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: sumantso on June 27, 2013, 06:43:01 PM
There have been problems since yesterday. 20 hours back I tried to cancel a withdrawl (hadn't confirmed in the email) but couldn't see anything under pending withdrawls. Still waiting to get it sorted out, and for some reason the support is not responding  ???


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: paladin281978 on June 27, 2013, 06:43:18 PM
down


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: trenal on June 27, 2013, 06:47:55 PM
I'm on Cryptsy so it isn't down, just seems to be a DNS issue for new queries coming in.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Lauda on June 27, 2013, 08:42:14 PM
Quote
It's not just you! http://cryptsy.com looks down from here.
So it's down again.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: rovchris on June 27, 2013, 08:49:21 PM
I can still access it!

The dns is resolving to this IP Address  199.83.130.5

If you add an entry in your hosts file for www.crypsty.com with the IP Address 199.83.130.5 it should sort you out until the DNS change has propagated.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bubbers214 on June 27, 2013, 08:50:22 PM
I'm on Cryptsy so it isn't down, just seems to be a DNS issue for new queries coming in.

Definitely just a DNS issue, pinging it resolves no IP.  But my browser on my home PC that is already logged in is able to use the site. 


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: bigvern on June 28, 2013, 12:39:02 AM
Hi John

I found a bug in the UI: if you click on the amount of BTC available (or LTC for some markets) in the top right corner of the "SUBMIT NEW ORDER" form to buy the maximum amount of altcoins possible with your balance at a given price then it does not correctly calculate that number.

The onclick event handler of that span element currently reads:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())*0.998);$('#TradeBuyAmount').trigger('change');" ...

but it should actually be:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())/1.002);$('#TradeBuyAmount').trigger('change');" ...

Then it calculates the correct amount


Thanks dude.   That is a more accurate calculation.

It has been implemented.


BigVern


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: weav on June 28, 2013, 12:41:45 AM
Hi John

I found a bug in the UI: if you click on the amount of BTC available (or LTC for some markets) in the top right corner of the "SUBMIT NEW ORDER" form to buy the maximum amount of altcoins possible with your balance at a given price then it does not correctly calculate that number.

The onclick event handler of that span element currently reads:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())*0.998);$('#TradeBuyAmount').trigger('change');" ...

but it should actually be:

Code:
<span onclick="$('#TradeBuyAmount').val(($(this).text()/$('#TradeBuyPrice').val())/1.002);$('#TradeBuyAmount').trigger('change');" ...

Then it calculates the correct amount


Thanks dude.   That is a more accurate calculation.

It has been implemented.


BigVern

Cool! np :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: barwizi on June 28, 2013, 05:59:49 AM
ok, so.....Noirbits?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Kevlar on June 28, 2013, 06:00:30 AM
when the site will work?

It seems to be mostly working now. Only the API remains broken.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: paladin281978 on June 28, 2013, 06:01:53 AM
work


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: B. Tazed on June 28, 2013, 06:05:33 AM
Your funds are never safe on cryptsy... end of story.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: paladin281978 on June 30, 2013, 02:49:25 PM
502 Bad Gateway


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Pmalek on June 30, 2013, 03:06:30 PM
Yep, problems again for Cryptsy...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: kelsey on June 30, 2013, 03:16:42 PM
well they're safe alright, safe from me being able too offload them :(


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: AZIZ1977 on June 30, 2013, 03:19:14 PM
well they're safe alright, safe from me being able too offload them :(

lol


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: jasonslow on June 30, 2013, 03:20:54 PM
502 Bad Gateway for me I cannot open the site.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Pmalek on June 30, 2013, 03:49:13 PM
They should really build the exchange again from the start. The excuse of the beta stage doesnt hold water any more...


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 30, 2013, 06:09:16 PM
Your funds are never safe on cryptsy... end of story.

cryptsy/\is rock solid in my book imho we should all help\/BTCjohn to improve the site..thanks team


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Pmalek on June 30, 2013, 06:26:35 PM
Agree, but how can we help?


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitJohn on June 30, 2013, 06:48:29 PM
Agree, but how can we help?

You guys help every day by spreading the word and keeping the record straight and we appreciate it. Some folks read the disinformation and buy into it. All I can say is give cryptsy.com a try.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: TECHICENINE on June 30, 2013, 07:24:57 PM
Agree, but how can we help?

You guys help every day by spreading the word and keeping the record straight and we appreciate it. Some folks read the disinformation and buy into it. All I can say is give cryptsy.com a try.

cryptsy/\is great the only thing i can think if is remove temp~USD markets(coming soon)\/section..thanks


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Oldminer on June 30, 2013, 07:54:58 PM
Agree, but how can we help?

You guys help every day by spreading the word and keeping the record straight and we appreciate it. Some folks read the disinformation and buy into it. All I can say is give cryptsy.com a try.

Excellent site. Please add more coins though  :)


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: rovchris on June 30, 2013, 09:03:36 PM
I have to agree crypsty is definitely the best exchange.

Without them there would literally be no value in alt coins.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Oldminer on June 30, 2013, 09:29:14 PM
Agree, but how can we help?

You guys help every day by spreading the word and keeping the record straight and we appreciate it. Some folks read the disinformation and buy into it. All I can say is give cryptsy.com a try.

Excellent site. Please add more coins though  :)


agreed/\we need more and more "coins" as if it's not confusing\/enough as it is...thanks

There's an option on the site to hide the coins your not interested in.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: dddbtc on September 16, 2013, 08:01:35 PM
We are currently having an issue with our service provider and our public IP space. All servers are functioning fine, all accounts are secure and all fund are safe. As soon as our providers fix the issue we will be back online. Thank you.

https://cryptsy.freshdesk.com/support/tickets/3097

I'm locked out of my account because the email that is being sent the 2factor code is inaccessible to me.  I've submitted photo ID scans and created a support ticket.  Please disable the 2factor email authentication so I can log in and change my email and password.

Thanks!


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Jriker1 on September 19, 2013, 12:53:58 AM
Anyone else having problems with the auto-sell not working?  Curious if it's just me.

Thanks.

JR


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Gleb Gamow on January 05, 2017, 04:23:41 AM
John, can you please post the real IP address for cryptsy.com

I believe it is 166.78.0.180 but just want to confirm it.

~nh

Ip changes from time to time and you should not be accessing the site using the ip

BigVern

What is your SOA for DNS?  nslookup still returns the incapsula.com records

a:\BA\main>nslookup cryptsy.com 75.75.75.75
Server:  cdns01.comcast.net
Address:  75.75.75.75

Non-authoritative answer:
Name:    cryptsy.com
Addresses:  199.83.133.236
          199.83.134.32

I thought it was rackspace, but that wont' let me query it.

a:\BA\main>nslookup cryptsy.com ns1.rackspace.com
Server:  ns.rackspace.com
Address:  69.20.95.4

*** ns.rackspace.com can't find cryptsy.com: Query refused




Incapsula is the correct entry.   That is our new security service.

BigVern

Ergo, Incapsula was the Cryptsy hacker ~1 month after the above posting, thus Paul Vernon can return home from China now.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: Spoetnik on January 05, 2017, 07:37:43 AM
Masterful detective work Gamow !
You finally found that damn pesky hacker  :)

Thanks for letting us all know and this so far is Bitcointalk Topic Bump of The Year.


Title: Re: ** Official ** Cryptsy funds are safe and secure
Post by: BitcoinNational on January 06, 2017, 10:52:40 AM
Bitcointalk Topic Bump of The Year

! Incapsula !

(but really does anyone have an update on the remaining Cryptsy funds) ??