Bitcoin Forum

Other => Off-topic => Topic started by: HereToTrade on November 07, 2013, 08:15:24 PM



Title: Inputs hacked?
Post by: HereToTrade on November 07, 2013, 08:15:24 PM
I went on their site and got this. Check it for yourself:

:(
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



Two hacks totalling about 4100 BTC have left Inputs.io unable to pay all user balances. The attacker compromised the hosting account through compromising email accounts (some very old, and without phone numbers attached, so it was easy to reset). The attacker was able to bypass 2FA due to a flaw on the server host side.

Database access was also obtained, however passwords are securely stored and are hashed on the client. Bitcoin backend code were transferred to 10;15Hd@mastersearching.com:mercedes49@69.85.88.31 (most likely another compromised server).

What about my coins there? If you stored more than 1 BTC, send an email to support@inputs.io with a Bitcoin address (preferably, an offline, open source light/SPV wallet like Multibit or Electrum). Use the same email you're using on Inputs. Please don't store Bitcoins on an internet connected device, regardless of it is your own or a service's.

I know this doesn't mean much, but I'm sorry, and saying that I'm very sad that this happened is an understatement.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQEcBAEBAgAGBQJSeuZ9AAoJEB7FawRj3T8Th5QH/iapt2DUuyy1j7t51y1N1LOk
+Gu5fdIAV8molXnv+InMQvxtfxWfc7zKiROSP6Zv1cXdvMrCyzKP+SnTEFshIa+0
j2FYOgLeMNmsPSw8yeR1O8vJieYlK+7imEZL4nRKA+O+mjqCT1nTCtBUAVcYQ8Uu
O6BoNLkgT8z/1ZTfw+OK4t2kw9KcC317JOv3yVugfA3xCn4HbKPRP2yFIKR49C7L
w7C2h3L1jHqLerQNjbowcyKH83BFJ2IB0cFZFFCLBI+8NQcUIcIFymxrxUV73Rqa
xlMPX2rPFcIj6yz0ABl1t2rwY2DGOvc33MYCzX82CumLx/qAXCd2uF/jG6fzQ5M=
=Ip/9
-----END PGP SIGNATURE-----


Access inputs.io if you want to verify your balance, look up your transactions, etc. Don't add coins.


Title: Re: Inputs hacked?
Post by: Lauda on November 07, 2013, 10:42:07 PM
This is like the millionth topic on the same thing.


Title: Re: Inputs hacked?
Post by: Magazine on November 07, 2013, 10:42:49 PM
This is like the millionth topic on the same thing.

OH EM GEE YOU SCAMMED ME 1337 BITCOINS

MUST LEAVE U NEG FEEDBACK!


Title: Re: Inputs hacked?
Post by: Lauda on November 07, 2013, 10:43:39 PM
This is like the millionth topic on the same thing.

OH EM GEE YOU SCAMMED ME 1337 BITCOINS

MUST LEAVE U NEG FEEDBACK!
One does simply not scam for leet number of bitcoins.


Title: Re: Inputs hacked?
Post by: monbux on November 07, 2013, 11:51:02 PM
Now people are accusing TF of running away with the coins and a full DOX was done here:
https://bitcointalk.org/index.php?topic=327178.0
Accurate or not, many people are now doubting TradeFortress.


Title: Re: Inputs hacked?
Post by: Zawamiya on November 08, 2013, 01:47:07 AM
Yes, which you can ask for partial payment now before the hot wallet goes dry......


Title: Re: Inputs hacked?
Post by: Lauda on November 08, 2013, 05:34:18 AM
Now people are accusing TF of running away with the coins and a full DOX was done here:
https://bitcointalk.org/index.php?topic=327178.0
Accurate or not, many people are now doubting TradeFortress.
Many, not so smart people, indeed.


Title: Re: Inputs hacked?
Post by: bitcoindigi on November 08, 2013, 06:12:20 AM
yes, good job OP. you can write (at least)


Title: Re: Inputs hacked?
Post by: Feneusens on November 08, 2013, 10:46:03 AM
I think TradeFrotress is really kind enough to give whatever is left. I guess if its another person he would just said the hacker took everything and GONE....


Title: Re: Inputs hacked?
Post by: MysteryMiner on November 09, 2013, 01:51:10 AM
And I see i again - not a direct hack (SQLi, 0day vuln) but bypass using e-mail to reset password. I think we should start building more secure schemes that does not involve ability to reset password once forgotten (or unknown by attacker) and that does not require e-mail when registering account.


Title: Re: Inputs hacked?
Post by: MakeBelieve on November 09, 2013, 02:28:03 AM
And I see i again - not a direct hack (SQLi, 0day vuln) but bypass using e-mail to reset password. I think we should start building more secure schemes that does not involve ability to reset password once forgotten (or unknown by attacker) and that does not require e-mail when registering account.

It needs to be done. It seems that this is a common problem and the recent news reflects that.


Title: Re: Inputs hacked?
Post by: johncarpe64 on November 09, 2013, 03:09:43 AM
Oh man, email bypass again...... it sucks....


Title: Re: Inputs hacked?
Post by: Lauda on November 09, 2013, 07:47:13 AM
And I see i again - not a direct hack (SQLi, 0day vuln) but bypass using e-mail to reset password. I think we should start building more secure schemes that does not involve ability to reset password once forgotten (or unknown by attacker) and that does not require e-mail when registering account.
Have fun recovering your email next time?


Title: Re: Inputs hacked?
Post by: MakeBelieve on November 09, 2013, 12:05:08 PM
And I see i again - not a direct hack (SQLi, 0day vuln) but bypass using e-mail to reset password. I think we should start building more secure schemes that does not involve ability to reset password once forgotten (or unknown by attacker) and that does not require e-mail when registering account.

This wasn't how it's done. I can still log in using the same password. It had something to do with the API key

Tradefortress claimed that his email chain was hacked. Therefore gaining access to the site and API.


Title: Re: Inputs hacked?
Post by: b!z on November 09, 2013, 02:35:39 PM
Yep, check link in my signature for instructions on getting a refund.


Title: Re: Inputs hacked?
Post by: FamilyDinner on November 09, 2013, 04:01:59 PM
I'm really really tired reading the same news olds all over again. :-\
Though I don't know why I'm writing this and making this thread bumped :D


Title: Re: Inputs hacked?
Post by: ScryptAsic on November 10, 2013, 01:18:23 AM
Hate hackers really, he just make someone's life miserable....


Title: Re: Inputs hacked?
Post by: MysteryMiner on November 10, 2013, 02:00:17 AM
And I see i again - not a direct hack (SQLi, 0day vuln) but bypass using e-mail to reset password. I think we should start building more secure schemes that does not involve ability to reset password once forgotten (or unknown by attacker) and that does not require e-mail when registering account.
Have fun recovering your email next time?
I never needed to recover any password in last 6 years. Tormail also did not have password recovery feature and it was great. People must learn to use computers properly and stop and think for a sec instead socializing on facefuck/twatter like dogs in heat.

Also this shows why it is more secure to have real server in your own premises instead of using colocation or VPS that have remote access and yo have no direct control over the hardware. It is really important for security that most people overlook. Why banks don't use Hostgator but use their own secured hardware? Why Bitcoin should be different in this matter?


Title: Re: Inputs hacked?
Post by: HereToTrade on November 10, 2013, 08:24:57 PM
I'm really really tired reading the same news olds all over again. :-\
Though I don't know why I'm writing this and making this thread bumped :D
Can you read the title? If you are tired of the same olds then why did you open this thread?